Written evidence submitted by The Information Commissioner’s Office (CYB0025)
About the ICO
- The Information Commissioner’s Office (ICO) has responsibility for promoting and enforcing data protection and information rights. This includes responsibilities under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Freedom of Information Act 2000 (FOIA), the Network and Information Systems Regulations 2018 (NIS), the Environmental Information Regulations 2004 (EIR) and the Privacy and Electronic Communications Regulations 2003 (PECR).
- The ICO is independent from government and upholds information rights in the public interest, promoting openness by public bodies and data privacy for individuals. The ICO provides guidance and support to individuals and organisations, aimed at helping organisations to comply, and it takes appropriate action when needed.
Data Protection and Cyber-resilience
- The ICO plays a role in supporting the cyber-resilience of the UK through overseeing compliance with the UK GDPR and Regulated Digital Service Providers (RDSPs) under the NIS Regulations. These Regulations are concerned in part with addressing cyber threats in the UK.
- Data protection legislation in the UK is a driving force for many organisations’ cybersecurity processes. As is recognised by DCMS’ (as was) study in 2020, the implementation of the UK GDPR had a direct impact on cybersecurity, improving the security measures taken by organisations across the UK.[1]
- As a whole economy regulator, including of Government and the public sector, our regulatory remit covers the four key industries identified by the Committee.
- The UK GDPR applies to public and private sector organisations, and includes as a key principle, the appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.[2] Section 2 of Chapter IV of the UK GDPR details further requirements in this regard, as well as on breach reporting to the Commissioner and to data subjects.
- The Network and Information Systems (NIS) Regulations apply to a number of essential service and digital service providers operating in the UK. The ICO is the competent authority responsible for RDSPs under the Regulations, such as online search engines, online marketplaces, and cloud computing services. RDSPs must identify and take appropriate and proportionate measures to manage the risks posed to the security of network and information systems on which the service relies. They must (for example) register with the ICO and report incidents with substantial impact to us.
The ICO and Cyber-resilience
- The ICO aims to build trust in the digital economy by encouraging the responsible processing of personal data. This includes the proper safeguarding of personal data against unauthorised or unlawful processing, and against accidental loss, destruction or damage. This is a key aspect of data protection, and it is reflected in our strategic enduring objectives of ICO25.[3]
- We assist organisations in meeting their responsibilities for data security by delivering regulatory certainty with respect to the appropriate technical and organisational measures required to protect personal data. This includes our guidance on cyber security,[4] among others.
- The legislation we oversee also includes requirements for breach reporting to the ICO. We publish data security incident trends based on the incident reports we receive.[5] Our latest data from Q2 2023 (April-June) indicates that cyber incidents increased 157% compared to the same timeframe last year, with ransomware accounting for the largest incident type reported, at 17%. The largest percentage increases in incidents reported from Q2 2022 to Q2 2023 were in the finance, insurance and credit sector.
- In discharging our duties, we cooperate and collaborate with our regulatory counterparts and other stakeholders to provide regulatory coherence. In September 2023, the ICO and National Cyber Security Centre (NCSC) entered into a Memorandum of Understanding to work together on the development of cyber security standards and guidance, information sharing, assessing and influencing improvements in cyber security of regulated organisations, deconfliction between the NCSC and ICO in relation to incident management and working together on public communications.[6]
- In that vein, we have made clear our position on ransomware payments in a joint letter with the NCSC, where we recognise that paying ransoms only incentivises other criminals, and emphasise that such payments will not reduce enforcement action from the ICO.[7] We have also published guidance on ransomware and data protection compliance.[8]
- The ICO has delivered sessions on other key aspects of cyber, including how to manage supply-chain security,[9] and keep personal data secure,[10] and workshops on cybersecurity[11] through our annual Data Protection Practitioners' Conference.
- In terms of our enforcement action, we have fined a number of organisations for failing to implement appropriate security safeguards for personal data. This included a 500,000 fine issued against the Cabinet Office in 2021.[12]
- As part of our cooperation with international data protection authorities, the ICO sponsored a Resolution at the Global Privacy Assembly in 2022 on International Cooperation Capacity Building for Improving Cybersecurity Regulation and Understanding Cyber Incident Harms.[13]
Conclusion
- Data protection forms an important aspect of the UK’s overall cyber-resilience strategy. The ICO is committed to carrying out its role in delivering the outcome of a safe and resilient digital ecosystem, particularly as it pertains to critical national infrastructure. We wish the Committee well in pursuing its inquiry, and welcome the opportunity to expand on the information provided in this submission.
10 November 2023
[1] Impact_of_GDPR_on_cyber_security_outcomes.pdf (publishing.service.gov.uk)
[2] Article 5(1)(f)
[3] ico25-strategic-plan-0-0.pdf
[4] Security, including cyber security | ICO
[5] Data security incident trends | ICO
[6] ncsc-mou-20230912.pdf (ico.org.uk)
[7] ICO and NCSC stand together against ransomware payments being made | ICO
[8] Ransomware and data protection compliance | ICO
[9] Cyber attacks! How to manage supply chain security - YouTube
[10] Cyber-attacks - how can I keep personal data secure? - YouTube
[11] Cybersecurity panel session | ICO
[12] Cabinet Office | ICO
[13] 15.1.b.-Resolution-on-International-Cooperation-Capacity-Building-for-Improving-Cybersecurity-Regulation-and-Understanding-Cyber-Incident-Harms-vf.pdf (globalprivacyassembly.org)