Information Commissioner's Office

The Information Commissioner's Office (ICO) is a non-departmental public body which reports directly to the Parliament of the United Kingdom and is sponsored by the Department for Science, Innovation and Technology.[1] It is the independent regulatory office (national data protection authority) dealing with the Data Protection Act 2018, the General Data Protection Regulation, and the Privacy and Electronic Communications (EC Directive) Regulations 2003 across the UK; and the Freedom of Information Act 2000 and the Environmental Information Regulations 2004 in England, Wales and Northern Ireland and, to a limited extent, in Scotland.

The Data (Use and Access) Act 2025 provides for the abolition of the office of Information Commissioner and the transfer of functions to a new body, the Information Commission. As of July 2026, these measures have not come fully into effect.

The role of Information Commissioner is currently vacant, with chief executive Paul Arnold temporarily holding the Commissioner's responsibilities since John Edwards resigned on 19 June 2026 after an independent workplace investigation found that there was a case to answer.

Role of the Information Commissioner

The Information Commissioner is an independent official appointed by the Crown. The Commissioner's decisions are subject to appeal to an independent tribunal and the courts. The Commissioner's mission is to "uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals".[2]

Replacement by the Information Commission

The Data (Use and Access) Act 2025 created a body called the Information Commission, whose members (between 3 and 14 in number) are appointed by the Secretary of State.[3][4] These measures came into force via statutory instrument in July 2025,[5] but the provisions to abolish the office of Information Commissioner and transfer their powers to the commission are not yet in force as of July 2026.[3]

Commissioners

John Edwards

في 26 أغسطس/آب 2021، عُيّن جون إدواردز مفوضًا جديدًا للمعلومات، خلفًا لإليزابيث دينهام. وأعلنت الحكومة البريطانية أنه سيتجاوز الدور التقليدي للهيئة التنظيمية، وأن مهمته ستُوازن بين حماية الحقوق وتعزيز الابتكار والنمو الاقتصادي. كما أكدت على ضرورة حماية الخصوصية بأقل قدر ممكن من التدخل، وأنها ستعطي الأولوية للسماح بإرسال البيانات الشخصية دوليًا إلى دول مثل الولايات المتحدة وكوريا وسنغافورة ودبي وكولومبيا، وغيرها، وأنها تسعى إلى سياسة بيانات تُحقق مكاسب للشركات (مقارنةً بالأفراد)، وأنها ترغب في التخلص من نوافذ ملفات تعريف الارتباط المنبثقة المتكررة. [ 6 ]

استقالة إدواردز

في 26 فبراير 2026، تنحى إدواردز عن مهامه في مكتب مفوض المعلومات [ 7 ] ريثما يتم إجراء تحقيق مستقل في مسائل غير محددة تتعلق بالموارد البشرية. وفي 10 يونيو 2026 [ 8 أعلن مكتب مفوض المعلومات انتهاء التحقيق، وخلص إلى وجود "قضية تستدعي الرد". وقد أحيلت القضية الآن إلى وزارة العلوم والابتكار والتكنولوجيا للنظر فيها. وخلال فترة غياب إدواردز، تولى بول أرنولد (الرئيس التنفيذي) وفريق الإدارة التنفيذية قيادة مكتب مفوض المعلومات. وفي ختام التحقيق، اعتُبر إدواردز "غير قادر مؤقتًا على أداء مسؤولياته"، مما استدعى نقلًا رسميًا مؤقتًا للمسؤوليات إلى بول أرنولد. وفي 19 يونيو 2026، أعلن إدواردز استقالته، معترفًا بأن منصبه أصبح لا يُطاق، ومقرًا بوجود حالات "أساء فيها التقدير وقام بمحاولات فكاهية غير لائقة وتسببت في الإساءة". [ 9 ]

أعلنت ليز كيندال ، وزيرة الدولة البريطانية للعلوم والابتكار والتكنولوجيا ، لاحقاً عن مراجعة مستقلة لثقافة ومساءلة وحوكمة مكتب مفوض المعلومات، وعن نيتها تعيين مجلس إدارة غير تنفيذي بأغلبية نسائية. [ 10 ]

إليزابيث دينهام

بعد تعيين إليزابيث دينهام مفوضةً للمعلومات في بريطانيا عام 2016، أجرت هيئة مفوض المعلومات تحقيقاتٍ واسعة النطاق في شركات إيكويفاكس، وياهو، وتالك تالك، وأوبر، وفيسبوك؛ وفرضت غرامةً قصوى بموجب قانون حماية البيانات لعام 1998، بلغت 500 ألف جنيه إسترليني، على فيسبوك، [ 11 ] لانتهاكها قانون حماية البيانات. كما أشرفت دينهام على اختتام تحقيق هيئة مفوض المعلومات في أنشطة جمع التبرعات للجمعيات الخيرية، وسلسلة من الغرامات المفروضة على الشركات المتورطة في التسويق المزعج. [ 12 ]

Denham welcomed the introduction of the General Data Protection Regulation (GDPR)[13] that came into effect in May 2018, as well as the Data Protection Act 2018.[14]

Christopher Graham

During his time as IC, Graham gained new powers: to issue monetary penalties for breaching the Data Protection Act 1998; to issue monetary penalties under the Privacy and Electronic Communications Regulations. He raised concerns over harm and distress caused by nuisance calls.[15] Graham succeeded Richard Thomas in 2009.

Richard Thomas

During Richard Thomas' tenure as Commissioner, the ICO was particularly noted for raising serious concerns over the Government's proposed British national identity card and database, as well as other similar databases such as the Citizen Information Project, Universal Child Database, and the NHS National Programme for IT, stating that the country was in danger of sleepwalking into a surveillance society,[16] drawing attention to the misuse of such information by the former states of the Eastern bloc and Francisco Franco's Spain.

Legislation

Data Protection Act 2018

The Data Protection Act 2018[14] received royal assent on 23 May 2018. It updates data protection laws in the UK, supplementing the General Data Protection Regulation (GDPR), implementing the EU law enforcement directive, and extending data protection laws to areas not covered by the GDPR. The new Act aims to modernise data protection laws to ensure they are effective in the years to come.

The data protection charge on UK data controllers to support the Act is under the Data Protection (Charges and Information) Regulations 2018. Exemptions from the charge were left broadly the same as for the previous Act: largely some businesses and non-profits internal core purposes (staff or members, marketing and accounting), household affairs, some public purposes, and non-automated processing.[17][18] The register of fee payers, which excludes those data controllers that are exempt from paying a fee, is publicly available and searchable at the website of the ICO,[19] which also gives links to the ICO's counterparts around Europe.

Data Protection Act 1998

كانت المملكة المتحدة، بصفتها عضواً في الاتحاد الأوروبي ، ولا تزال، بصفتها عضواً سابقاً، خاضعة لنظام صارم لحماية البيانات . أنشأ قانون حماية البيانات لعام 1984 منصباً كان يُسمى آنذاك مسجل حماية البيانات، وكان على الأشخاص الذين يعالجون البيانات الشخصية تسجيل حقيقة معالجتهم لتلك البيانات في سجل مراقبي البيانات. وبموجب أحكام توجيه المفوضية الأوروبية 95/46 (الذي تم تقديمه في المملكة المتحدة كقانون حماية البيانات لعام 1998 ، بدلاً من كونه نظاماً تشريعياً بموجب قانون الجماعات الأوروبية لعام 1972 )، تم تغيير اسم المنصب إلى مفوض حماية البيانات ، ثم لاحقاً إلى مفوض المعلومات .

اللائحة العامة لحماية البيانات (GDPR)

اللائحة العامة لحماية البيانات (GDPR) قانون جديد على مستوى أوروبا يحل محل قانون حماية البيانات لعام 1998 في المملكة المتحدة. دخلت اللائحة العامة لحماية البيانات حيز التنفيذ في 25 مايو 2018، وتحدد متطلبات كيفية تعامل المؤسسات مع البيانات الشخصية. وهي جزء من نظام حماية البيانات في المملكة المتحدة، إلى جانب قانون حماية البيانات الجديد لعام 2018 (DPA 2018). بعد خروج المملكة المتحدة من الاتحاد الأوروبي في 31 يناير 2020 ، لا تزال اللائحة العامة لحماية البيانات جزءًا من القانون المحلي البريطاني بموجب المادة 3 من قانون الاتحاد الأوروبي (الانسحاب) لعام 2018 .

قانون حرية المعلومات لعام 2000 ولوائح المعلومات البيئية لعام 2004

في عام ٢٠٠٥، تم توسيع نطاق صلاحيات المفوض ليشمل إنفاذ قانون حرية المعلومات لعام ٢٠٠٠ ولوائح المعلومات البيئية لعام ٢٠٠٤، وتم تغيير اسم المنصب من مفوض حماية البيانات إلى مفوض المعلومات. أما إنفاذ قانون حرية المعلومات (اسكتلندا) لعام ٢٠٠٢ ، الذي ينطبق على السلطات العامة المفوضة في اسكتلندا، فهو من مسؤولية مفوض المعلومات الاسكتلندي ، وهو مسؤول حكومي مستقل، حيث لا ينطبق القانون البريطاني على هذه السلطات.

تصدر مفوضية المعلومات توجيهات بشأن تشريعات حرية المعلومات، والتي يتم تحديثها وفقًا لخطة العمل الاستراتيجية 2019/20 - 2021/22، " الانفتاح بالتصميم" . [ 20 ]

لوائح الخصوصية والاتصالات الإلكترونية (توجيه المفوضية الأوروبية) لعام 2003 (PECR)

In November 2011 the ICO was given the powers to impose monetary penalties of up to £500,000 for breaches of the Privacy and Electronic Communications Regulations (PECR). PECR applies to organisations that wish to send marketing messages through electronic means i.e. phone, fax, email, text; use cookies or provide electronic communication services to the general public. As with the GDPR, these regulations continue to apply following Brexit.

Nuisance calls

In March 2013, commenting on a fine of £90,000 imposed on Cumbernauld fitted kitchen company DM Design for nuisance marketing calls, the Information Commissioner said that "this fine will not be an isolated penalty. We know other companies are showing a similar disregard for the law and we've every intention of taking further enforcement action against companies that continue to bombard people with unlawful marketing texts and calls." In 2014, the Government changed the law to "lower the legal threshold for consumer harm".[21] This made it easier for the ICO to "take enforcement action against more organisations breaching the Privacy and Electronic Communications Regulations (PECR)".[22]

In October 2018 the ICO fined two companies a total of £250,000 that made nearly 1.73 million direct marketing phone calls to people registered with the Telephone Preference Service (TPS).[23] In December 2018, the Commissioner welcomed the new law that means the ICO can now hold company bosses directly responsible and has the power to fine them personally for breaches of the Privacy and Electronic Communications Regulations (PECR).

Environmental Information Regulations 2004

The Information Commissioner is also responsible for appeals made under the Environmental Information Regulations 2004.

Enforcement

Prior to 2010 the enforcement powers were limited to issuing enforcement notices and to pursuing those alleged to have broken the Data Protection Act 1998 through the courts. In 2010 The Information Commissioner was granted the power to issue fines, known as monetary penalties, by its own authority, granted in April 2010. The first such were served on 24 November 2010.[24] From 2010, the ICO were also given the powers to serve Assessment Notices, which can be issued to organisations who are unwilling to work alongside the ICO and are at risk of breaking the principles of the Data Protection Act 1998. During the Leveson Inquiry in 2012 it came to light that the ICO had felt unable to challenge the press related to allegations of breaches due to the power of the press and perceived weakness of its own powers.[25]

From 25 May 2018 the ICO were granted new enforcement powers under the new data protection laws, including the ability to fine organisations €20 million (or equivalent in sterling) or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher, for breaching data protection laws.[26]

Investigations

Operation Motorman

In 2002, under 'Operation Motorman', the ICO under Richard Thomas raided various newspaper and private investigators' offices, looking for details of personal information kept on unregistered computer databases. The operation uncovered numerous invoices addressed to newspapers and magazines, which detailed prices for providing the journalists with personal information, with 305 journalists being identified as having been the recipients of a wide range of information.[27]

In 2006, a request under the Freedom of Information Act led to the publication of a report to the British Parliament called "What Price Privacy Now?".[28] The newspaper with the highest number of requests was the Daily Mail with 952 transactions by 58 journalists; the News of the World came fifth in the table, with 182 transactions from 19 journalists.[27] The Daily Mail immediately issued a press release, in which it rejected the accusations within the report. Editor Paul Dacre said that Associated Newspapers only used private investigators to confirm public information, such as dates of birth.[27]

في جلسة استماع أمام لجنة برلمانية في يوليو 2011، بعد يوم من إلقاء القبض على الرئيسة التنفيذية السابقة لشركة نيوز إنترناشونال، ريبيكا بروكس ، وإطلاق سراحها بكفالة على خلفية فضيحة التنصت على الهواتف في الشركة ، صرّح داكر بأنه لم "يتسامح" قط مع التنصت على الهواتف أو التجسس على صحيفته، لأن كلا الفعلين "إجراميان" بشكل واضح. [ 29 ]

جمعية الاستشارات

في 23 فبراير 2009، داهم مكتب مفوض المعلومات (ICO) مكتب جمعية الاستشارات (TCA) في درويتويتش ، وأصدر إشعارًا تنفيذيًا ضد الجمعية بموجب أحكام قانون حماية البيانات. وجاء إجراء مكتب مفوض المعلومات عقب مقال نُشر في 28 يونيو 2008 في صحيفة الغارديان ، بقلم الصحفي فيل تشامبرلين، حول مزاعم التلاعب بالقوائم السوداء في قطاع البناء. [ 30 ]

سوني

في عام 2013، فرض مكتب مفوض المعلومات غرامة قدرها 250 ألف جنيه إسترليني على شركة سوني كمبيوتر إنترتينمنت أوروبا المحدودة، بعد اختراق العديد من أنظمة بلاي ستيشن وسرقة أسماء المستخدمين وعناوينهم وأرقام هواتفهم وتفاصيل بطاقاتهم الائتمانية. وخلص المكتب إلى أن سوني كانت تمتلك معلومات مفرطة عن مستخدميها، وأن أنظمة الأمان لديها كانت غير كافية. [ 31 ]

استخدام تقنية التعرف على الوجه من قبل أمازون وفيسبوك

شهد شهر مايو 2018 زيادة في التدقيق على كل من فيسبوك وأمازون فيما يتعلق بتقارير استخدام البيانات الشخصية البيومترية دون موافقة أصحابها. [ 32 ]

كامبريدج أناليتيكا وفيسبوك

في 23 مارس 2018، داهم مكتب مفوض المعلومات المقر الرئيسي لشركة كامبريدج أناليتيكا في لندن وسط تقارير تفيد بأن الشركة جمعت البيانات الشخصية لملايين مستخدمي فيسبوك كجزء من حملة للتأثير على الانتخابات الرئاسية الأمريكية لعام 2016. [ 33 ]

في أكتوبر/تشرين الأول 2018، فرض مكتب مفوض المعلومات غرامة قدرها 500 ألف جنيه إسترليني على فيسبوك، وهي الحد الأقصى المسموح به بموجب القوانين السارية وقت وقوع الحوادث، وذلك لانتهاكها قانون حماية البيانات. وخلص تحقيق المكتب إلى أن فيسبوك، بين عامي 2007 و2014، عالجت المعلومات الشخصية للمستخدمين بطريقة غير عادلة، إذ سمحت لمطوري التطبيقات (وتحديدًا ألكسندر كوجان وشركته GSR بصفتهم عملاء لشركتي SCL Ltd وCambridge Analytica) بالوصول إلى معلوماتهم دون موافقة صريحة ومستنيرة، بل وسمحت بالوصول حتى لو لم يقم المستخدمون بتنزيل التطبيق، وإنما كانوا مجرد "أصدقاء" لأشخاص قاموا بتنزيله. [ 11 ]

أوبر

في نوفمبر 2018، فرض مكتب مفوض المعلومات غرامة قدرها 385 ألف جنيه إسترليني على شركة أوبر لتقصيرها في حماية المعلومات الشخصية لعملائها خلال هجوم إلكتروني. وقد سمحت سلسلة من الثغرات الأمنية التي كان من الممكن تجنبها في أمن البيانات للمهاجمين بالوصول إلى البيانات الشخصية لحوالي 2.7 مليون عميل بريطاني وتنزيلها من نظام تخزين سحابي تديره الشركة الأم الأمريكية لأوبر. [ 34 ]

إيكويفاكس

في سبتمبر 2018، فرض مكتب مفوض المعلومات غرامة قدرها 500 ألف جنيه إسترليني على شركة إيكويفاكس المحدودة لتقصيرها في حماية المعلومات الشخصية لما يصل إلى 15 مليون مواطن بريطاني خلال هجوم إلكتروني وقع عام 2017. وقد أثر هذا الحادث، الذي وقع بين 13 مايو و30 يوليو 2017 في الولايات المتحدة، على 146 مليون عميل على مستوى العالم. [ 35 ]

تيك توك

في فبراير 2019، بدأ مكتب مفوض المعلومات (ICO) تحقيقًا في منصة مشاركة الفيديو وتطبيق الهاتف المحمول TikTok ، عقب الغرامة التي تلقتها الشركة الأم ByteDance من لجنة التجارة الفيدرالية الأمريكية ، لجمعها معلومات من قاصرين دون سن 13 عامًا، في انتهاك لقانون حماية خصوصية الأطفال على الإنترنت في الولايات المتحدة . وفي حديثها أمام لجنة برلمانية، قالت مفوضة المعلومات إليزابيث دينهام إن التحقيق يركز على قضية جمع البيانات الشخصية، بالإضافة إلى نوعية مقاطع الفيديو التي يجمعها الأطفال ويشاركونها عبر الإنترنت، ونظام المراسلة المفتوح في المنصة الذي يسمح لأي شخص بالغ بمراسلة أي طفل. وأشارت إلى أن الشركة قد تكون انتهكت أحكام اللائحة العامة لحماية البيانات (GDPR) التي "تُلزم الشركة بتوفير خدمات وحماية مختلفة للأطفال". [ 36 ]

إنترسيرف

في أكتوبر/تشرين الأول 2022، غُرِّمت شركة إنترسيرف 4.4 مليون جنيه إسترليني لانتهاكها قانون حماية البيانات في مايو/أيار 2020، ما مكّن المتسللين من الوصول إلى بيانات ما يصل إلى 113 ألف موظف في الشركة. ورغم اكتشاف رسالة بريد إلكتروني تصيدية، ذكرت مفوضية المعلومات (ICO) أن إنترسيرف "أخفقت في التحقيق بدقة في النشاط المشبوه". ونتيجةً لذلك، تمكن المهاجم من اختراق 283 نظامًا و16 حسابًا، وإزالة برنامج مكافحة الفيروسات الخاص بالشركة، وتشفير البيانات الشخصية للموظفين الحاليين والسابقين. ونفت إنترسيرف تهاون موظفيها أو استجابتها، مؤكدةً أنها سعت أيضًا إلى الحد من المخاطر في الأنظمة التي تدعم العمليات الجارية في تيلبري دوغلاس ومجموعة ميتي. [ 37 ] وكانت هذه الغرامة رابع أكبر غرامة تُفرض على الإطلاق من قبل مفوضية المعلومات. [ 38 ]

قائمة مفوضي المعلومات

أدوار مماثلة في أوروبا

ينعكس دور لجنة التحقيق في جميع أنحاء دول الاتحاد الأوروبي والمنطقة الاقتصادية الأوروبية التي لديها مسؤولون مماثلون تم إنشاؤهم بموجب نسخهم من التوجيه 95/46 .

انظر أيضاً

مراجع

  1. "العلاقة مع وزارة العلوم والابتكار والتكنولوجيا" . ico.org.uk. 11 أبريل 2023. تم الاطلاع عليه بتاريخ 23 يونيو 2023 .
  2. "مكتب مفوض المعلومات" . مكتب مفوض المعلومات . تم الاطلاع عليه بتاريخ 7 يناير 2010. مكتب مفوض المعلومات هو الهيئة المستقلة في المملكة المتحدة التي أُنشئت لحماية حقوق المعلومات في المصلحة العامة، وتعزيز الشفافية من جانب الهيئات العامة، وحماية خصوصية البيانات للأفراد.
  3. ١ ٢ "قانون البيانات (الاستخدام والوصول) لعام ٢٠٢٥، الجزء ٦: مفوضية المعلومات" . www.legislation.gov.uk . ١٩ يونيو ٢٠٢٥. مؤرشف من الأصل في ٢٤ فبراير ٢٠٢٦. تم الاطلاع عليه في ٢٦ يوليو ٢٠٢٦ .
  4. "قانون البيانات (الاستخدام والوصول) لعام 2025، الجدول 14: مفوضية المعلومات" . www.legislation.gov.uk . مؤرشف من الأصل في 14 فبراير 2026. تم الاطلاع عليه في 26 يوليو 2026 .
  5. الصك التشريعي رقم 904 لسنة 2025، قانون البيانات (الاستخدام والوصول) لسنة 2025 (بدء النفاذ رقم 1)، اللوائح لسنة 2025
  6. "إصلاحات جذرية في حماية البيانات تستهدف النوافذ المنبثقة لملفات تعريف الارتباط" . بي بي سي نيوز . 26 أغسطس 2021. تم الاطلاع عليه بتاريخ 26 أغسطس 2021 .
  7. "Head of UK data watchdog voluntarily steps aside amid HR probe". POLITICO. 25 April 2026. Retrieved 10 June 2026.
  8. "Temporary governance changes at the ICO". ico.org.uk. 10 June 2026. Retrieved 10 June 2026.
  9. "ICO boss John Edwards announces resignation following investigation". BBC News. 19 June 2026. Retrieved 26 July 2026.
  10. Booth, Robert (8 July 2026). "Minister 'appalled' as ex-data watchdog prepares to sue woman who raised harassment concerns". The Guardian. Retrieved 8 July 2026.
  11. 12"ICO issues maximum £500,000 fine to Facebook for failing to protect users' personal information" (Press release). Information Commissioner's Office. 25 October 2018. Retrieved 22 August 2020.
  12. "Nuisance calls and messages". Information Commissioner's Office. Retrieved 22 August 2020.
  13. "Guide to the General Data Protection Regulation (GDPR)". Information Commissioner's Office. Retrieved 22 August 2020.
  14. 12"Data Protection Act 2018". Information Commissioner's Office. Archived from the original on 7 August 2018. Retrieved 22 August 2020.
  15. "Targeting the worst offenders and cutting nuisance calls". 3 April 2014. Archived from the original on 19 June 2017. Retrieved 24 March 2018.
  16. Patrick Foster, "Big Brother surveillance means no one is safe, experts warn", The Times, 27 March 2007, accessed 16 September 2007
  17. Review of exemptions from paying charges to the Information Commissioner's Office(PDF) (Report). Department for Digital, Culture, Media and Sport. November 2018. Retrieved 30 April 2020.
  18. "The Data Protection (Charges and Information) Regulations 2018 – Schedule Exempt Processing". legislation.gov.uk. Retrieved 30 April 2020.
  19. "Register of fee payers". Information Commissioner's Office. Retrieved 22 August 2020.
  20. ICO, "About the Guide to freedom of information", accessed 26 December 2021.
  21. "Nuisance Calls Action Plan"(PDF). Department of Culture, Media and Sport. Retrieved 8 April 2016. lower the legal threshold for consumer harm
  22. "Nuisance Calls Action Plan"(PDF). Department of Culture, Media and Sport. Retrieved 8 April 2016. take enforcement action against more organisations breaching the Privacy and Electronic Communications (EC Directive) Regulations 2003
  23. "ICO fines two firms for over one million nuisance calls made to TPS subscribers" (Press release). 26 November 2018. Retrieved 22 August 2020.
  24. "BBC News – First Data Protection Act fines issued by commissioner". BBC Online. BBC. 24 November 2010. Retrieved 24 November 2010. The commissioner said the fines – the first he has issued – would "send a strong message" to those handling data.
  25. "The Frontline". 1 December 2011. Archived from the original on 28 April 2016.
  26. "Penalties". Information Commissioner's Office. Retrieved 22 August 2020.
  27. 123"Info Chief's broadside at Press over data crimes". Press Gazette. 15 December 2006. Archived from the original on 11 January 2012. Retrieved 18 July 2011.
  28. "What Price Privacy Now?". Information Commissioners Office. 15 December 2006. Retrieved 18 July 2011.{{cite web}}: CS1 maint: deprecated archival service (link)
  29. "Daily Mail editor Paul Dacre 'never approved hacking'". BBC News. 18 July 2011. Retrieved 18 July 2011.
  30. Chamberlain, Phil (28 June 2008). "Enemy at the gates". The Guardian. Retrieved 7 September 2015.
  31. "Sony fined over PlayStation hack". BBC News. 24 March 2018. Retrieved 24 March 2018.
  32. Frenkel, Sheera (8 May 2018). "Facebook to Reorganize After Scrutiny Over Data Privacy (Published 2018)". The New York Times. ISSN 0362-4331. Retrieved 6 December 2020.
  33. Gonzales, Richard (23 March 2018). "U.K. Investigators Raid Cambridge Analytica Offices In London". NPR.
  34. "ICO fines Uber £385,000 over data protection failings" (Press release). Information Commissioner's Office. 27 November 2018.
  35. "Credit reference agency Equifax fined for security breach" (Press release). Information Commissioner's Office. 20 September 2018. Retrieved 22 August 2020.
  36. Hern, Alex (2 July 2019). "TikTok under investigation over child data use". The Guardian. ISSN 0261-3077. Retrieved 13 July 2020.
  37. Prior, Grant (24 October 2022). "Interserve hit with £4.4m fine after cyber attack". Construction Enquirer. Retrieved 24 October 2022.
  38. Allen, Tom (24 October 2022). "ICO serves Interserve £4.4m fine after cyberattack". Computing. Retrieved 24 October 2022.
  39. "John Edwards is confirmed as the new Information Commissioner" (Press release). London: Department for Digital, Culture, Media and Sport. 21 December 2021. Retrieved 21 December 2021.
  40. "UK's new Information Commissioner formally appointed". 15 July 2016. Archived from the original on 18 September 2016. Retrieved 25 July 2016. Her Majesty The Queen has approved the appointment of Elizabeth Denham as the UK's Information Commissioner.
  41. McNally, Paul (13 January 2009). "Christopher Graham is new Information Commissioner". Press Gazette.
  42. Lashmar, Paul (27 November 2000). "Elizabeth France: This woman's watching you, Big Brother". The Independent. Retrieved 9 August 2011.