Header image

Inside the ICO’s new enforcement toolkit: what organisations need to know

Technology | 16/03/2026

Privacy Laws & Business United Kingdom Report (Issue 144, March 2026) has published an in depth analysis by Katie Hewson and Alison Llewellyn on the ICO’s draft Data Protection Enforcement Procedural Guidance and its new powers introduced by the Data (Use and Access) Act 2025 (DUAA).

The article covers:

  • the ICO’s risk based approach to opening investigations;
  • expanded information gathering powers granted under the DUAA (including document production, “approved person” reports and interview notices); and
  • the new settlement procedure with potential fine reductions (up to 40% pre notice of intent); and
  • sets out practical steps to prepare for investigations and make strategic use of early engagement and settlement.

Read the full analysis (PDF, courtesy of Privacy Laws & Business).

Share Article

Related Expertise

Contributors