ICO publishes Annual Report 2025/2026

The UK Information Commissioner’s Office (ICO) published its annual report in July 2026.

This year, I thought I’d move with the times and ask AI to help me to review the report and pull out the relevant figures. I started with a test query: “How many calls to its helpline did the ICO receive in the year?” Its answer: 1,097,131. Looking at the table on page 54, this figure is entirely incorrect, and AI did not know how it had come up with it. So instead I reverted to my antiquated technique of reading the report myself!

As John Edwards resigned from his role as Information Commissioner in June (with no permanent replacement yet appointed), there was no customary foreword from the Commissioner, but otherwise the Annual Report sets out similar details of its activities and financial statements between April 2025 and March 2026.

The report covers the last full year of the Information Commissioner’s Office, as the role and powers have now transferred to the Information Commission (as from 30 September 2026). Its head office has also moved from Cheshire to Manchester. It has decided still to refer to itself as the “ICO” (Information Commission’s Office), thus avoiding the need for them and us to update a pretty much infinite number of references to “ICO” everywhere we go.

Some highlights from the report:

  • The Executive Team has agreed three particular organisational causes: children’s privacy, AI and biometrics, online tracking.
  • A flagship achievement was the ICO’s “Better Records Together” campaign, resulting in new guidance on how to access care records, as many people who spent time in care struggle to access their care records.
  • In February 2026, the ICO fined MediaLab.AI Inc. £247,590 for using children’s data unlawfully on its Imgur social media platform, and Reddit £14.47 million for failing to use children’s data lawfully.
  • In July 2025, the First-tier Tribunal delivered judgment in the ICO’s favour in relation to TikTok’s appeal against its £12.7 million monetary penalty notice (for allowing up to 1.4 million UK children under the minimum age of 13 to use its platform). TikTok appealed to the Upper Tribunal, and the hearing took place in May 2026. Whilst after the date of the annual report, the Upper Tribunal’s dismissed the appeal in July 2026 and remitted the case to the First-tier Tribunal. However, TikTok subsequently withdrew its appeals and agreed to pay the fine.
  • In March 2026, the ICO called on tech firms to strengthen age assurance measures so children cannot access services that aren’t designed for them.
  • In November 2025, the ICO published clearer definitions of organisations in scope of its public sector approach and the circumstances under which it may issue fines.
  • The ICO completed its review of top 1,000 UK websites (following cookie compliance work), and 979 of these met its compliance standards. Though, later in the report, the ICO refers to 99% of the top 1,000 websites meeting its standards as at May 2026, which is greater than 979 of 1,000.
  • The ICO introduced a new approach to handling data protection complaints: it focuses on cases where it’s clear that there’s serious harm and whether it can “help organisations improve how they protect people’s data through advice, training or action”. The ICO saw a big increase in the number of complaints and did not meet their target timescales for addressing them – see below.

My summary of enforcement action and caseloads is set out in the tale below.

The full annual report is available at www.ico.org.uk.

Enforcement and caseloads – some statistics

Queries made to the ICO The ICO received 281,093 calls to its helplines over the course of the year (a similar number to last year). 98% were answered. There were 61,132 live chat requests (about 4,000 fewer than last year), with 97% answered. 4,692 calls and 2,123 chats went unanswered. There were 11,431 requests for written advice (up from 10,739 last year), with 11,475 requests completed during the course of the year.
Data protection regulatory action The report states that the ICO concluded 62 UK GDPR investigation cases (up from last year), and 280 incidents (also up from last year).

Later in the report there are graphs of casework for incidents and investigations. These have different figures – 349 incidents completed, and 100 investigations completed. So I don’t understand the differences in the figures.

  • 7 reprimands (another decrease from the year before): including relating to disclosures in error and people’s rights.
  • 8 UK GDPR penalty notices totalling £32,402,373 (up from last year, and including the £14.47m fine against Reddit and £14,000,000 against Capita plc and £2,310,000 against 23and Me).
  • Enforcement notices relating to subject access requests issued to Bristol City Council and South Wales Police.

Note the report also indicates that £18,259,000 of the monetary penalties imposed (including those under DPA and PECR) are currently under appeal.

The report indicates that the ICO also imposed £7,400 of GDPR fines, which potentially relates to fines for pre-Brexit processing activities.

Privacy and electronic communications regulatory action The ICO issued 10 monetary penalty notices totalling £1,445,000 and 10 enforcement notices for PECR breaches. This is up on last year, but still not as high as the year before (2023/2024).

See also below in relation to PECR complaints.

Note on monetary penalties and fines: Paragraph 18 of schedule 13 to the Data (Use and Access) Act 2025 (in force on 5 February 2026) amended section 157 of the DPA 2018 so that the ICO may now issue fines of up to £17.5 million or 4% of global turnover under PECR (as well as UK GDPR) (previously the maximum amount is £500,000).

Criminal investigations The ICO concluded its largest ever criminal prosecution. Nine warrants were issues and devices seized, and two defendants were subsequently found guilty of conspiring together to access or obtain the personal information of people from vehicle repair garages without their consent.

The ICO also secured a conviction against the Director of Bridlington Lodge Care Home for blocking, erasing or concealing information following a subject access request made by the daughter of a resident on behalf of her father (for whom she held a Power of Attorney).

The ICO’s Financial Investigation Unit secured their first confiscation order for a total of £33,125, plus costs against two former RAC employees who had previously pleaded guilty to offences under the Computer Misuse Act 1990 and DPA.

Audits The ICO conducted 85 audits and follow-up audits (up from 77 last year) across a range of sectors. Executive summaries are published on the ICO’s website.

These include audits and risk reviews relating to: education technology in schools; information and cyber security within social care organisations and educational organisations; facial recognition technology by the police sector; cyber security and governance at children’s secure care units in Scotland and Northern Ireland; governance of children’s data within NHS children’s hospitals; and age assurance solutions.

As with last year, 99% of the ICO’s audit recommendations were accepted or partially accepted.

Data protection complaints The ICO received 76,743 data protection complaints. This is a big increase (over 34,000) from 42,315 in the previous year.

Disappointingly, the report doesn’t elaborate on the subject matters of the complaints, as it has done in previous years. For as long as I can remember, the right of access (subject access requests) has been the top reason for complaints cited in the ICO’s annual report. And this year the report is silent on this! So, sadly, we don’t know.

The ICO issued 62,211 outcome decisions offering advice and recommendations to improve information handling (up by about 26,000 from last year). The caseload at year end was 31,321 (about double that of last year).

Only 27.4% of complaints were responded to within 90 days (down from 30% last year, and well below the ICO’s target of 80% which it achieved two years ago). Only 69.5% were responded to within six months (down from 98.4% last year, and well below the ICO’s target of 90%). Last year, the ICO commented that they were exploring options to improve these percentages. The report comments that the continued low percentages are due to a ‘sustained and unprecedented growth’ in the volume of data protection complaints. It states that they have recruited additional case officers and made changes to the complaints process and increased use of technology to help for future years.

There doesn’t appear to be a breakdown on which sectors generated the most complaints.

In 83% of the cases, advice was given, and no further action taken (16% more than last year). In 17% of cases, informal action was taken (16% down from last year). There is no “Other” row, which leads to the question of whether additional investigatory or regulatory action was taken in any of the cases. Note also the low figures for regulatory action taken in the row above.

The increase in “no further action taken” perhaps reflects the change in the ICO’s approach to handling complaints, which is to focus on cases where it’s clear that there’s serious harm. And note that this change in approach is also intended to assist to reduce their backlog of cases. Though this approach, and the delays in assessing complaints, may cause frustration for individuals whose rights (for example requests for access to data) have not been addressed appropriately, but are considered not to reach this threshold of harm.

PECR complaints 48,395 concerns were reported in relation to telesales calls and texts (unsolicited marketing communications) (about 1,000 fewer than last year). They are broken down as 52% where the recipients spoke with a person, 34% with a recorded voice, and 14% spam texts.

24,710 concerns about emailing marketing were reported (down just under 5,000 from last year).

3,906 concerns about cookies were reported (down about 600 from last year). The ICO has also been assessing websites’ compliance with cookies rules.

In December 2025, the ICO reported that 979 of 1,000 top UK websites met the ICO’s compliance checks. The annual report provides that, in May 2026, 99% of the top 1,000 UK websites were meeting its compliance checks, and that 20 preliminary enforcement notices have been issued to those that didn’t pass the checks.

Note also: Section 112 of the Data (Use and Access) Act 2025 (and Schedule 12) introduced (as from 5 February 2026) a new Schedule A1 to PECR which provides new circumstances where consent to cookies is not required. These are areas which were considered to present a low risk to people’s privacy.

Self-reported breaches There were 17,431 self-reported personal data breaches (an increase of about 5,000 from last year). 12,620 cases were completed (up about 420 from last year), but the increase in numbers meant that 6,317 were remaining at the end of the year.

Note that two of these were breaches reported by the ICO to itself (due to misaddressed communications).

In 90% of cases assessed, informal action was taken, and 7% of cases, no further action was taken. Reasons for no action were where the breach was recorded but regulatory action criteria was not met, where it was not a personal data breach, or “unassigned” or “no action”!

Note: the ICO’s publication “ICO25 – Our regulatory approach” sets out its risk-based approach to regulatory action. It states its focus is usually on areas of high risk where non-compliance could do the most harm.

An investigation was pursued in 2% of cases, once more down from the previous year. Regulatory action was taken in 0% of the cases.

As with last year, the full industry breakdown doesn’t seem to be reported, but the report states that the highest reporting sectors remained health, education and childcare.

The most common type of incident continued to be emailing, posting or faxing personal information to the wrong person, in just over 20% of breaches.

This once more demonstrates the need for awareness and training amongst staff, as human error is a key reason for incidents.

65.3% of reports were closed within 30 days (down from 83.7% last year, and which is below the ICO’s 80% target). However, only 0.6% were over 12 months old (significantly down from 25.3% of cases last year, and against a target of fewer than 1%).

Freedom of information cases 10,713 freedom of information complaints were received. This is up about 3,000 from last year, and the largest number ever. The ICO considers that AI tools are increasing people’s confidence in engaging with the complaints process. 8,714 cases were closed (about 1,000 more than last year). At the end of the year, the caseload was 3,505.

84% of cases were closed within six months (below the ICO’s target of 90%), and 0.1% of caseload is over 12 months old.

In 23% of cases, a statutory decision notices were served. In the other cases, either no further action was taken, or there was an informal resolution. There doesn’t seem to be reference to information notices.

2,027 statutory decision notices were issued (a similar number to last year). For 740, the complaints were upheld (similar to last year), 368 were partially upheld, and 919 were not upheld.

There were 305 appeals to the First-tier Tribunal and 79 appeals to the Upper Tribunal (both a similar number to last year). There 12 appeals to the Court of Appeal, and 6 to the High Court. Of First-tier cases closed in the year, 74% were successfully defended by the ICO.

Information requests to the ICO 2,740 information requests were made to the ICO, and 2,727 were completed. These are both about 400 more than last year. 1,288 were made under data protection laws, 1,313 under freedom of information laws, 123 were hybrid, and 3 were made under the Environmental Information Regulations 2004.

The ICO completed 97.6% of information rights requests within statutory timescales (with a target of 100%).

Olivia Whitcroft, principal of OBEP, 5 October 2026

This article provides general information on the subject matter and is not intended to be relied upon as legal advice. If you would like to discuss this topic, please contact Olivia Whitcroft using the contact details set out here: Contact Details