ICO Enforcement Powers 2026: What UK Directors Must Know Now | INFORMD Executive Briefing

ICO Enforcement Powers 2026: What UK Directors Must Know Now

The ICO now holds unprecedented enforcement powers under the Data (Use and Access) Act 2025, including the right to compel individual directors and executives to attend formal interviews and to mandate independent technical audits at an organisation’s expense. For UK boards, this transforms data protection from a compliance checkbox into a personal accountability risk that cannot be managed at arm’s length.

What New Enforcement Powers Does the ICO Hold in 2026?

The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025 and came into force on 19 June 2026, materially strengthens the ICO’s enforcement toolkit in three areas. First, the ICO can now require organisations to commission and pay for independent technical reports during investigations — assessments conducted by ICO-approved experts, not the organisation’s own advisers. Second, the ICO can compel named individuals to attend formal interviews, with consequences for false or misleading statements. Third, the ICO has enhanced powers to require organisations to establish and publish formal data protection complaints processes, with accountability for how complaints are investigated and resolved.

These powers build on an existing fine regime that reached a record level in October 2025 when the ICO fined Capita £14 million following a cybersecurity breach that exposed the data of 6.6 million individuals. Although the fine was reduced from an initial assessment of £45 million, the Capita case signals that the ICO is willing to impose significant sanctions for systemic security failures — not just policy breaches.

According to Clifford Chance’s November 2025 analysis of the ICO’s new enforcement procedural guidance, the ICO is developing more structured investigation processes designed to improve the speed and predictability of enforcement outcomes. For boards, this means ICO investigations will be more systematic and harder to manage through prolonged correspondence.

Executive Action:

  • Brief your board on the scope of the ICO’s new compelled interview powers — directors should understand that a formal ICO investigation can now require personal attendance, not just written submissions from legal counsel.
  • Ensure your data protection complaint handling process was in place by 19 June 2026 — this was the first operational obligation triggered by the DUAA commencement date.
  • Review whether your data protection legal budget covers the cost of an ICO-mandated independent technical report, which is now a potential enforcement obligation.

What Is the Personal Liability Exposure for Directors in 2026?

UK GDPR and the DUAA 2025 do not create direct personal liability for directors in the way that health and safety legislation does. However, the combination of compelled interview powers and false statement consequences creates a qualitatively different risk environment. A director who provides misleading information in an ICO-compelled interview faces potential criminal liability under the DUAA’s information offences, not merely civil penalty exposure for the organisation.

This is compounded by the accountability principle under UK GDPR Article 5(2), which requires organisations to be able to demonstrate compliance — not merely assert it. Where the ICO determines that an organisation cannot demonstrate the accountability it claims, and where senior individuals have made representations to the contrary in formal proceedings, the risk of individual consequences increases.

The ICO’s approach to the public sector also provides a signal for private sector boards. The ICO has publicly stated it prefers early engagement over large fines in the public sector — but this preference has not been extended uniformly to commercial organisations, particularly in financial services and technology where the ICO has demonstrated willingness to fine at scale. According to the ICO’s own enforcement records, its 2025 fines included Capita (£14m), and prior years included British Airways (£20m) and Marriott (£18.4m), with each case involving failures that board-level governance could have prevented.

Executive Action:

  • Ensure your DPO has board-level access and is included in all material risk discussions involving personal data — the ICO will expect the DPO to have had visibility of the decisions it is investigating.
  • Conduct a board-level accountability review: can you demonstrate, with documented evidence, that the board approved and monitored data protection policies, received breach notifications, and acted on DPO recommendations?
  • Review director indemnity insurance to confirm it covers personal exposure arising from ICO compelled interview proceedings and associated legal representation costs.

What Does the Capita £14 Million Fine Tell Boards About ICO Priorities?

The Capita enforcement action is the most instructive recent precedent for boards. The ICO’s investigation found that Capita had failed to implement adequate technical and organisational security measures, resulting in unauthorised access to personal data held on behalf of a number of pension fund clients. The breach exposed the records of approximately 6.6 million individuals across multiple clients — a systemic third-party outsourcing risk that board oversight should have detected and required management to remediate.

The ICO’s decision to reduce the fine from £45 million to £14 million reflects mitigating factors, including steps taken post-breach to improve security. But the substantive finding — that the organisation’s security measures were inadequate for the risk profile of the data it processed — is a direct board governance failure. Under the UK Corporate Governance Code, the board is responsible for determining the nature and extent of the principal risks the company is willing to take, and for ensuring that appropriate systems of risk management and internal control are in place.

Boards should read the Capita case as a template for how the ICO constructs liability: systemic technical failure plus inadequate board-level risk governance equals regulatory action at the highest level of the penalty range, subject to mitigating conduct.

Executive Action:

  • Require a board-level data protection and cybersecurity risk report at least annually, covering: the data the organisation holds, the third parties with whom it is shared, the security controls applied to high-risk processing, and the status of any open ICO investigations or subject access request backlogs.
  • Review third-party data processor agreements to confirm they meet DUAA 2025 requirements, including complaint handling provisions and independent audit rights.
  • Ensure your breach response plan names a board-level sponsor and is tested at least annually — the ICO will assess the quality of post-breach response as a mitigating factor in any penalty calculation.

How Should Boards Demonstrate Accountability to the ICO’s 2026 Standard?

The DUAA 2025’s accountability obligations require organisations to treat data protection complaints handling as part of their broader governance framework — not as a customer service function. By 19 June 2026, every organisation processing personal data was required to have a formal complaints process that can identify, assess, investigate and resolve complaints consistently and transparently. Boards should require the DPO to report on complaint volumes, resolution times, and patterns — exactly as they would require operational KPIs from any other function.

The ICO has also signalled that it will use the new mandatory complaints process as an early investigative tool. Where an organisation fails to handle complaints consistently, the ICO can use that failure as evidence of systemic accountability shortfalls — escalating from complaints handling to full investigation without requiring a separate triggering event.

For boards operating in sectors under heightened ICO scrutiny — financial services, healthcare, education, and technology platforms — the standard for demonstrating accountability is effectively set by the ICO’s published enforcement decisions. Boards should review recent enforcement actions not just for fine quantum, but for the governance failures the ICO identified and the evidence standards it applied.

Use the INFORMD governance self-assessment tools to evaluate your board’s current data protection accountability documentation. Access the executive briefing library for ongoing ICO guidance analysis as enforcement practice develops through 2026.

Frequently Asked Questions

What new enforcement powers did the ICO receive under the Data Use and Access Act 2025?

Under the DUAA 2025, the ICO can compel named individuals to attend formal interviews with consequences for false statements, require organisations to commission independent technical reports at their own expense, and mandate formal data protection complaints processes. These powers came into force on 19 June 2026.

Can the ICO hold individual directors personally liable under UK data protection law?

UK GDPR does not create direct personal liability for directors as individuals. However, the DUAA 2025 creates criminal exposure for individuals who provide false or misleading information in ICO-compelled interviews. Directors also face reputational and professional risk where board governance failures are identified in published enforcement decisions.

What was the significance of the ICO’s £14 million fine against Capita?

The Capita fine, issued October 2025 for a breach exposing 6.6 million individuals, is the ICO’s largest to date. It was reduced from £45 million. The case establishes that systemic security failures in third-party outsourcing are a board governance issue, and that post-breach remediation can reduce but not eliminate penalty exposure.

What is the minimum data protection complaints process UK organisations needed by June 2026?

By 19 June 2026, organisations processing personal data must have a formal process that can identify, assess, investigate and resolve data protection complaints consistently and transparently. The ICO can use complaints handling failures as evidence of systemic accountability shortfalls, triggering broader investigation.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.

Similar Posts