Regulator Profile
ICO
Information Commissioner's Office
Enforcement RegulatorQuick links
What ICO does
Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. All businesses processing personal data must pay ICO data protection fee.
Legal framework
Legislation that ICO enforces.
Primary legislation
- Computer Misuse Act 1990 Act 1990
- Data Protection Act 2018 Act 2018
- Data (Use and Access) Act 2025 Act 2025
- PSTIA 2022 Act 2022
Secondary legislation
- Data Protection (Charges and Information) Regulations 2018 UK Statutory Instrument 2018
- DUAA 2025 (Commencement No. 6) Regulations 2026 UK Statutory Instrument 2026
- Network and Information Systems Regulations 2018 UK Statutory Instrument 2018
- Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 UK Statutory Instrument 2011
- Privacy and Electronic Communications Regulations 2003 UK Statutory Instrument 2003