ICO launches consultations on data protection reforms

  • Corporate Governance
Peninsula Group Limited - An employer exploring a data breach

Peninsula Team, Peninsula Team

(Last updated )

The Information Commissioner’s Office (ICO) has launched two new consultations on changes to data protection laws that are set to be introduced under the Data (Use and Access) Act 2025 (the Act), which received Royal Assent on 19 June 2025.

The ICO is consulting on draft guidance it has published which will support organisations with understanding and applying amendments relating to data protection complaints and a new lawful basis for processing personal data in the public interest known as ‘recognised legitimate interest’.

What is processing personal data?

Get instant, expert answers to your HR questions...

Ask Brainbox
0800 158 2313Speak to an expert 24/7

The consultation on the ICO’s draft Complaints guidance for organisations is open until 23.59 on 19 October 2025. The ICO says that by June 2026, organisations must comply with the new requirement to have a process in place to handle data protection complaints introduced by the Act. A complaint can come from anyone who is unhappy with how an organisation has handled their personal data, i.e. in response to a subject access request or where there has been a data breach. Organisations will be required to:

A separate consultation on the ICO’s draft Recognised legitimate interest guidance has also been opened. ‘Recognised legitimate interest’ is a new lawful basis for processing personal data introduced by the Act, although not yet in force.

This is different to the current ‘legitimate interests’ lawful basis that already exists under the GDPR. The draft guidance sets out five recognised legitimate interest conditions for processing personal data that is in the public interest, including crime prevention, safeguarding, national and public security, emergencies and public task disclosure requests.

The consultation runs until 23.59 on 30 October 2025.

What should be included in a GDPR policy?

Get instant, expert answers to your HR questions...

Ask Brainbox
0800 158 2313Speak to an expert 24/7

Related articles

  • sport

    Blog

    Managing sporting events in the workplace

    Sporting fans are spoilt for choice this summer — whatever your preference, there are tournaments, matches and action to follow in a wide range of sports, not to mention the men’s FIFA World Cup that kicks off on 11 June 2026. While this can be a time for celebration, it’s also potentially a time for HR issues to arise. For employers looking to get ahead of the game and get ready for this year’s sporting summer, we set out our top tips below.

    Peninsula Logo
    Peninsula Team Peninsula Team
    • Corporate Governance
  • employer

    Blog

    Organisations to be liable for a broader range of offences committed by senior managers

    The Crime and Policing Act 2026 (the Act) has now gained Royal Assent and, as it comes into force from 29 June 2026, it will bring in new ways in which organisations may be held criminally responsible for crimes committed by senior managers acting with “corporate authority”.

    Peninsula Logo
    Peninsula Team Peninsula Team
    • Corporate Governance
  • labor

    Blog

    CIPD publishes latest Labour Market Outlook

    The CIPD’s Labour Market Outlook report for Spring 2026 has found that UK employers are prioritising cost management over growth as rising business costs and global uncertainty impact employer confidence.

    Peninsula Logo
    Peninsula Team Peninsula Team
    • Corporate Governance
Award-winning services

Take the first step towards a safer business. Answer a few questions about your HR and Health & Safety management and we’ll direct you to the support you need

Contact us
0800 158 2313Speak to an expert 24/7