The Information Commissioner’s Office has established a new division devoted to protecting personal information held by businesses.
The new Regulatory Action Division will use the Commissioner’s powers to regulate the behaviour of organisations and individuals that collect, use and keep personal information, to ensure compliance with the Data Protection Act 1998.
What they say
Assistant Commissioner (Regulatory Action) David Smith said: “Changes in the structure of the Information Commissioner’s Office that have come into effect this week are designed to make life tougher for the minority of businesses that don’t take their data protection obligations seriously.
Previously complaints were handled by a compliance team, but now for the first time the ICO has teams of specialists devoted solely to using the Commissioner’s powers to bring about compliance with the law. Negotiation will usually be our first option, but we won’t hesitate to take legal action swiftly against businesses where the circumstances warrant it.”
There has been a recent – in the ICO words – explosion in the number of businesses holding personal information, and with that surge, an increase in the potential for the information to be misused, it is claimed. The Regulatory Action Division will use powers including criminal
prosecution, non-criminal enforcement and audit to ensure that personal information is properly protected, the ICO says. It will take action wherever data protection obligations are ignored, examples need to be set or issues need to be clarified. This will include taking action against organisations which are required to register with the Commissioner’s Office, but fail to do so.




