On 20 October 2025, the UK Information Commissioner's Office (ICO) published an update on its work to raise data-protection standards across the public sector. This follows its earlier correspondence with the Cabinet Office (Letter from the Information Commissionerabout widespread inconsistencies in how government departments handle citizens' data. The government has now committed to a coordinated, cross-departmental approach to strengthen data-protection accountability, establish a dedicated central team to set and monitor standards, and roll out new information-management training for all civil servants. (2025-09-26 Dame Chi Onwurah MP – SIT Committee) 
 
Source: ICO (UK) – https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/update-on-our-work-to-raise-data-protection-standards-in-the-public-sector/ 

Summary of the story

The ICO's update marks a turning point in how the UK government intends to handle data protection across public bodies. For years, the ICO has raised concerns about inconsistent data governance practices, weak accountability structures, and fragmented training. The new plan seeks to address these shortcomings by embedding a culture of compliance and proactive risk management across departments, agencies, and local authorities. 

Why this matters globally

This development matters far beyond the UK. Governments worldwide face mounting scrutiny over how they protect personal information—particularly as digital transformation accelerates public-service delivery. A centralised, accountable model of governance, like the one now being introduced in the UK, could serve as a blueprint for other nations seeking to reduce data breaches and increase trust in government data use.

Similar stories around the world

In Australia, the Office of the Australian Information Commissioner (OAIC) recently called for a unified government data-protection framework after multiple state-level breaches exposed citizens’ information. In the United States, the Office of Management and Budget (OMB) launched its own data-governance initiative to strengthen cybersecurity and privacy within federal agencies. In the European Union, the European Data Protection Board (EDPB) has urged member states to harmonise data-protection practices across ministries and public authorities.

The real problems that arose

The ICO’s intervention stemmed from persistent problems: poor data-sharing controls, weak breach-reporting mechanisms, outdated records-management systems, and insufficient training. Many departments lacked clarity on who was responsible for data protection, leading to siloed accountability and avoidable incidents of data loss and exposure.

What went wrong

Government departments often failed to integrate data-protection by design into their projects. Some had no central oversight of data-governance risks, relied on manual processes, and treated data protection as a compliance exercise rather than a leadership priority. The ICO’s findings suggested that even when guidance existed, implementation was inconsistent and not monitored effectively.

What they didn’t have in place

  • No unified, cross-department data-governance framework
  • Limited or outdated staff training on data protection and information-management principles
  • Poor visibility into data inventories and retention policies
  • Insufficient incident-response planning

How this could have been prevented or fixed

A structured, organisation-wide information-governance programme could have prevented many of these issues. This includes:

  • Establishing a central accountability framework to track compliance across departments
  • Implementing automated records-management systems to maintain control over personal data
  • Conducting regular data-protection impact assessments (DPIAs)
  • Ensuring mandatory training for all staff, refreshed annually
  • Developing clear escalation procedures for data incidents

What have they put in place?

Here are the key points from the government letter regarding upcoming measures to improve information security:

Governance & Accountability

  • Government Digital Service (GDS) will coordinate cross-government data protection risks and compliance.
  • Government Chief Data Officer (GCDO) will be accountable for managing these risks.
  • A new dedicated team will report to the GCDO to set standards and respond to risks.
  • A joint commitment with the ICO will be established to raise standards and enable proactive collaboration.
  • A Technology Risk Group, chaired by DSIT, will unify major technology risks and report to senior boards.
  • The ICO will be invited to key board meetings to support continuous improvement.

Policy & Processes

  • Assurance exercise led by Cabinet Office and DSIT to assess departmental risk measures.
  • Review of risk appetite for threat-to-life data breaches by departmental audit committees.
  • Review of information asset registers to assess tolerance of high-risk personal data at the OFFICIAL classification.
  • Model action plan for data breaches to be developed with GSG, ICO, and GCDO.
  • Adherence to personal data security principles, especially in new services like Digital ID.

Technology Measures

  • Strengthened strategic relationship with Microsoft to reduce accidental data breaches and improve use of security tools.
  • Improved Data Loss Prevention (DLP) adoption and support for departments using Microsoft Purview Information Protection.

Culture & Training

  • New communications campaign in Q1 2026 to raise awareness of data breach consequences.
  • Training and empowerment for information management professionals and rollout of new training for all civil servants.

ICO Collaboration

  • Joint commitment with ICO to be finalized by end of 2025 for standard-setting and feedback.
  • ICO participation in governance boards to reinforce collaboration and improvement.

Have you read this article and thought you and your organisation needs help?

We at Leadership Through Data can do just that. Our training solutions help public sector organisations embed data-protection compliance into everyday operations. Our courses are great for both public and private sectors.

Consultancy

We can offer consultancy on all aspects of your data framework

Training courses & programmes

  • Information governance frameworks to review and refresh your ideas to underpin your whole approach Information Governance Training Course | UK & IRE
  • Training for Roles that are required to embed accountability and improve information culture:
  • Thematic training:
  • Training that helps you embed good governance and security in M365:
    • Microsoft 365 Purview Information Protection & Data Loss Prevention Training Course (UK/US/ANZ)
    • Microsoft 365 Teams Information Governance & Protection Training Course (UK/US/ANZ)
    • Microsoft 365 Purview Records Management Training Course (UK/US/ANZ)

By implementing these tools, organisations can not only meet regulatory expectations but also build public trust through transparency and accountability.