
Information Commissioner's Office
United Kingdom"The UK's independent regulator for data protection and freedom of information"
About
The Information Commissioner's Office (ICO) is the United Kingdom's independent regulatory body responsible for upholding information rights. It enforces the Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), the Privacy and Electronic Communications Regulations (PECR), the Freedom of Information Act 2000, and other related legislation. The ICO operates as a non-departmental public body sponsored by the Department for Science, Innovation and Technology, but reports directly to Parliament, ensuring its independence from government.
Headquartered in Wilmslow, Cheshire, with offices in London, Edinburgh, Cardiff, and Belfast, the ICO has a workforce of around 750 full-time equivalent staff. Its regulatory powers include investigating complaints, issuing enforcement notices, and imposing fines. Notable recent penalties include a £20 million fine against British Airways for a 2018 cyberattack, an £18.4 million fine against Marriott International, and a £7.5 million fine against TikTok for failing to protect children's data. The ICO also provides guidance to organizations on compliance, runs public awareness campaigns such as Your Data Matters, and operates a regulatory sandbox for innovative data protection approaches.
The current Information Commissioner is John Edwards, who took office on 3 January 2022. Edwards previously served as New Zealand's Privacy Commissioner from 2014 to 2021, bringing international regulatory experience. He succeeded Elizabeth Denham (2016–2021), Christopher Graham (2009–2016), and earlier commissioners. The ICO is widely regarded as one of the most influential data protection authorities globally, often cited in international regulatory discussions.
Mission
The ICO's mission is to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. It aims to empower people through their information rights, ensure organizations handle personal data responsibly, and foster trust in the digital economy. The ICO seeks to achieve this through enforcement, guidance, education, and engagement with stakeholders.
History
The ICO traces its origins to the Data Protection Act 1984, which created the position of Data Protection Registrar. This made the UK one of the first countries to establish a dedicated data protection authority, following the Council of Europe's Convention 108. Eric Howe became the first Registrar in 1984, tasked with overseeing a new regime for computerized personal data. The office operated under this name until the Data Protection Act 1998, which strengthened individual rights and aligned UK law with the EU Data Protection Directive.
A major shift came with the Freedom of Information Act 2000. The office was renamed the Office of the Information Commissioner in 2000, and then the Information Commissioner's Office in 2001. The FOI Act fully came into force in 2005, giving the ICO powers to compel public bodies to disclose information. The Data Protection Act 2018 and the EU GDPR took effect in 2018, dramatically expanding the ICO's enforcement capabilities, including the power to impose fines up to £17.5 million or 4% of global turnover. After Brexit, the ICO became responsible for the UK GDPR, a domestic version of the regulation.
Under John Edwards, the ICO has focused on emerging technologies, issuing guidance on AI, facial recognition, and biometric data. In 2023, it launched a consultation on generative AI and large language models. The office also continues to enforce data protection law vigorously, with high-profile fines and investigations into major tech companies and government departments. The ICO remains a key participant in international forums such as the Global Privacy Assembly.
Subdivisions
Regulatory Assurance
Directorate responsible for investigations, enforcement, and audit.
Regulatory Futures
Directorate covering policy, technology, and innovation.
Corporate Services
Directorate handling finance, human resources, and digital services.
Notable People
Eric Howe
Data Protection Registrar · 1984–1994
First Data Protection Registrar, established the office.
Elizabeth France
Data Protection Registrar · 1994–2002
Oversaw transition to the Data Protection Act 1998.
Richard Thomas
Information Commissioner · 2002–2009
Led the office during the implementation of the Freedom of Information Act 2000.
Christopher Graham
Information Commissioner · 2009–2016
Oversaw early GDPR preparations and major enforcement actions.
Elizabeth Denham
Information Commissioner · 2016–2021
Led the ICO during the introduction of the GDPR and Data Protection Act 2018.
John Edwards
Information Commissioner · 2022–present
Current commissioner, previously New Zealand Privacy Commissioner.
Steve Wood
Deputy Commissioner
Led policy and regulatory strategy.
Milestones
1984
Data Protection Act 1984 creates the Data Protection Registrar.
1998
Data Protection Act 1998 replaces the 1984 act, strengthening rights.
2000
Freedom of Information Act 2000 passed; office renamed Office of the Information Commissioner.
2001
Official name change to Information Commissioner's Office.
2005
FOI Act fully comes into force; ICO gains powers to enforce public disclosure.
2018
Data Protection Act 2018 and EU GDPR take effect; ICO gains enhanced enforcement powers.
2020
UK leaves the EU; ICO becomes responsible for UK GDPR.
2022
John Edwards becomes Information Commissioner.
2023
ICO issues record £20 million fine against British Airways for 2018 data breach.
Teams
Organization Info
- Founded
- 1984
- Headquarters
- Wilmslow
- Country
- United Kingdom
- Information Commissioner
- John Edwards
- Parent
- Department for Science, Innovation and Technology
- Type
- Government
- Leader
- John Edwards
- Employees
- 749
- Revenue
- £56.4 million (2022-2023)
Financials
- Revenue
- 56.4 million GBP
- Budget
- 56.1 million GBP
- Employees
- 749
Official Website
ico.org.uk/
Join the community
fans discussing