Back Computing Rights groups accuse ICO of 'collapse in enforcement activity'
A group of 73 civil rights organisations, campaigners, lawyers and academics has written to Chi Onwurah - chair of Parliament’s Science, Innovation and Technology Committee - demanding an enquiry into the Information Commissioner’s Office (ICO), the UK’s data protection watchdog, for what they say is a failure to properly investigate and punish data breaches.
In an open letter , the signatories, which include the Open Rights Group, Big Brother Watch, Foxglove, Fair Vote UK and the Good Law Project, claim the ICO has significantly reduced its enforcement activities, particularly in the public sector, leading to a surge in data breaches.
The catalyst for the action was the ICO’s decision not to investigate the Ministry of Defence (MoD) after a serious breach exposed personal details of 19,000 Afghans fleeing the Taliban, but Open Rights Group’s legal and policy officer Mariano delli Santi, described this as “the final straw”. “After years of failing to hold public sector organisations to account, the failure of the ICO to investigate the most serious data breach in UK history is the final straw,” he wrote in a blog .
“The ICO’s public sector approach must end before more people are harmed by data breaches at the hands of the government and public authorities.
“A data regulator that fails to deter bad practices is not worth having. We need a strong data regulator which is not afraid to take action against both the government and private sector.”
The ICO prioritises engagement over punitive action, but the open letter argues this softly-softly approach has failed to deter data breaches, with the ICO’s own figures showing an 11% increase in reported breaches and an 8% rise in complaints against public sector organisations.
“The picture that emerges is one where the ICO public sector approach lacks deterrence and fails to drive the adoption of good data management across government and public bodies,” the letter states.
The signatories also claim that action against private sector companies has also declined under the leadership of the current Information Commissioner John Edwards, with the watchdog’s latest report revealing “a sharp drop in formal investigations, criminal prosecution, and in the issuing of enforcement notices, monetary penalties, and reprimands,” despite an increase in the number of complaints by the public.
The letter calls for an investigation by the Science, Innovation and Technology Committee into the reduction of enforcement activity by the ICO and its apparent failure to prioritise data protection.
An ICO spokesperson said: “We have a range of regulatory powers and tools to choose from when responding to systemic issues in a given sector or industry. We respect the important role civil society plays in scrutinising our choices and will value the opportunity to our approach during our regular engagement.”
If you’re a current or aspiring cybersecurity leader check out the Computing Security Leaders Summit on March 26th 2026. Packed with content including business continuity planning, bridging the cyber skills gap and cloud resilience, its promises to be full of insight and practical advice to take away. Register here for your free place.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
