Skip to main content
ICO Priorities Shift Under New LeadershipSupervisory Authorities & Enforcement
4 min readFor Data Protection Officers (DPOs)

ICO Priorities Shift Under New Leadership

John Edwards took office as U.K. Information Commissioner on January 4, 2022, marking a shift in the ICO's approach. If your compliance program treats the ICO as static, you're already behind.

Edwards has used his initial public appearances, including a chat with German Federal Commissioner Ulrich Kelber at the IAPP Global Privacy Summit, to signal his priorities. For DPOs managing U.K. operations, these early signals are significant. The ICO's enforcement stance, guidance priorities, and international alignment all stem from the Commissioner's strategic choices.

Changes Under Edwards

The ICO now operates under a Commissioner with substantial experience in international data protection. Edwards, formerly New Zealand's Privacy Commissioner, has a background in managing cross-border data flows and working with various supervisory authorities. This experience influences his approach to the role.

His listening tour across the U.K. and participation in international forums show a focus on dialogue rather than unilateral action. This is crucial because the ICO's interpretation of GDPR obligations, enforcement priorities, and willingness to issue new guidance all depend on Edwards' strategic direction.

Key Developments

International collaboration over isolation. Edwards' joint appearance with Kelber and participation in international forums suggest the ICO will continue aligning with EU supervisory authorities on core interpretations, even as the U.K. considers legislative changes. Your compliance team should expect ICO guidance to reference EDPB opinions and coordinate with EU enforcement patterns, especially on cross-border processing.

Potential changes to U.K. data protection law. Edwards has publicly addressed proposed changes to U.K. data protection law, though specific reforms are still under review. This creates planning uncertainty for organizations that assumed post-Brexit regulatory stability. Your compliance framework may need revision in the next legislative cycle.

Engagement over enforcement escalation. Edwards' listening tour and emphasis on dialogue suggest a shift toward more collaborative enforcement. This doesn't imply leniency, but organizations showing good-faith compliance and transparent communication may receive different treatment than those who ignore ICO inquiries.

Focus on cross-border data flows. Edwards has discussed transborder data flows in his public statements. For organizations relying on standard contractual clauses or adequacy decisions for U.K. transfers, this signals continued ICO scrutiny of transfer impact assessments and supplementary measures.

Implications for Your Team

Don't wait for final legislative text or formal guidance updates to adjust your compliance posture. The Commissioner's priorities influence ICO staff behavior long before official policy changes.

If your organization processes U.K. personal data, your compliance documentation should reflect potential regulatory shifts. Your data protection impact assessments, legitimate interests assessments, and processor contracts need flexibility to accommodate changes without requiring complete rewrites.

Your relationship with the ICO matters more under Edwards' approach. Organizations that engage proactively, respond thoroughly to ICO inquiries, and demonstrate transparent decision-making will likely fare better. This means your DPO needs direct escalation paths to senior leadership and authority to commit resources to ICO responses.

For multinational organizations, the ICO's continued alignment with EU supervisory authorities means you can't treat U.K. and EU compliance as completely separate tracks. Your Article 30 records of processing activities, DSAR procedures, and personal data breach notification protocols should maintain consistency across both jurisdictions unless specific divergences emerge.

Action Items by Priority

Immediate: Audit your transfer mechanisms. Review every cross-border data transfer involving U.K. personal data. Verify that your standard contractual clauses include required supplementary measures and that your transfer impact assessments address U.K.-specific considerations. Edwards' focus on transborder flows means the ICO will scrutinize these arrangements.

Within 30 days: Establish ICO engagement protocols. Document clear procedures for responding to ICO inquiries, including escalation paths, response timelines, and communication standards. Your team should know exactly who drafts responses, who reviews them, and who has authority to commit the organization to specific actions. Edwards' collaborative approach rewards organizations that respond thoroughly and promptly.

Within 60 days: Review your compliance flexibility. Identify which elements of your compliance program depend on current U.K. law remaining unchanged. For each dependency, develop contingency approaches that could accommodate regulatory changes. Your processor contracts should include amendment procedures that don't require complete renegotiation. Your transparency obligations should be documented in systems that allow rapid updates to privacy notices.

Within 90 days: Monitor ICO guidance and enforcement patterns. Assign someone on your team to track ICO enforcement actions, guidance updates, and public statements. Edwards' priorities will become clearer through the ICO's actions over his first year. Your compliance program should adapt as those patterns emerge, not after they're codified in formal policy.

Ongoing: Maintain EU supervisory authority awareness. Even as the U.K. pursues its own legislative path, Edwards' emphasis on international collaboration means ICO positions will often align with EDPB guidance and EU supervisory authority enforcement. Your team should monitor both U.K. and EU developments, looking for areas where the ICO signals alignment or divergence.

ICO Guidance

By understanding and adapting to these shifts, your team can stay ahead of potential regulatory changes and maintain robust compliance.

You Might Also Like