This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
The Lens

Digital developments in focus

| 3 minute read

Summer data protection forecast: Insights from the new ICO strategy, EDPB and more

Data protection regulators on both sides of the Channel are signalling a pivot towards pragmatism. A regime change in the UK Government this week is shortly going to be followed by a reshuffle at the UK’s data protection regulator, with the ICO due to become the Information Commission in the autumn. In this blog we provide an essential forecast for data protection practitioners looking ahead to this new era. So what do recent publications from the UK and EU authorities tell us about the outlook for personal data regulation and enforcement? 

New ICO strategy 

On 10 July, the ICO published its new corporate strategy for 2026-2028 for consultation. This new strategy follows on from the ICO's ICO25 strategy and covers the transition period to the new Information Commission. Relative to ICO25, the new strategy is narrower and more focused, both in page count and in the scope of the regulator’s ambitions. Just four areas are now highlighted as regulatory priorities; these are:

  • Personal data use that helps, not harms, children
  • Promoting trust and transparency in AI
  • Public services that use people’s data responsibly
  • Building cyber resilience to keep people’s data safe 

The strategy reflects that pressure on the ICO’s resources has meant that “difficult choices and important trade-offs” need to be made. The ICO is committing to focus as much effort as possible on these four priorities, as areas where it can make the greatest difference, and it will be reporting on each of them annually. The regulator does also stress that it will maintain capacity and flexibility to respond to unexpected risks and other areas of public interest.

The strategy indicates that the ICO will focus its enforcement action on “criminals and negligent or irresponsible organisations” as part of its efforts to prevent harm while enabling innovation. Although in the past the regulator has tended to express its enforcement focus in terms of areas posing the greatest risk of harm to individuals, we don’t expect this latest position to mark a significant shift in the ICO’s enforcement approach in practice. However, the new phrasing does emphasise the importance of organisations documenting and being able to demonstrate their responsible data use to the regulator, particularly against a backdrop of escalating cyber risk.

Another reopening of the UK GDPR?

Since the start of July, the Department of Science, Innovation and Technology (DSIT) has opened consultations on the impact of personal data regulation on AI and international data flows, and separately the Department of Business and Trade has opened a consultation on workplace monitoring. These consultations aim to enable the Government to assess whether “further guidance, targeted changes or more fundamental reform is needed”.

With changes from the Data (Use and Access) Act 2025 (DUA Act) to the UK international transfers and automated decision-making (ADM) regime only taking effect in February (see here), and the ICO’s landmark AI and ADM code of practice still outstanding (due to be published “soon”, according to the ICO at the PL&B conference on 8 July), organisations could be forgiven for thinking these consultations feel premature. However, it is likely that they are part of long-planned DUA Act impact monitoring. Whether there is any real potential for significant outcomes flowing from them is currently unclear, particularly following the new Government’s reshuffle of departments that has involved the scrapping of DSIT (‘Digital’ has moved back to DCMS and the Business department has taken on Innovation, Science and Technology).

EDPB focuses on innovation 

As in the UK, the EU data protection regulators remain under pressure to balance the protection of personal data with facilitating innovation. In a session chaired by Rebecca Cousin, Carolina Foglia from the EDPB Secretariat said that the EDPB is in favour of simplification, but “not at any cost”. Carolina referenced a number of initiatives supporting the EDPB’s Helsinki statement, from how they interact with stakeholders to the publication of guidance clarifying the interplay between the GDPR and digital regulation (with the final guidelines on the interplay with the DMA and DSA expected by the end of the year). The EDPB has also recently called for the establishment of a new information sharing network between EU digital regulators to increase regulatory coherence. Taken together with its newly pragmatic anonymisation guidance (discussed here), these developments indicate that the EDPB is also working hard to help cultivate an ecosystem that supports data use. 

Meanwhile, negotiations on the EU’s Digital Omnibus are set to progress through the autumn and into next year and may bring some further pro-business relaxations to the EU GDPR regime. However, emerging negotiating positions suggest that some of the proposed changes (e.g. around the definition of personal data) are likely to be watered down.   

In summary, the message from regulators and legislatures is clear: data protection compliance remains essential, but there is growing appetite to support responsible data use. Practitioners should stay alert to developments this autumn as the landscape continues to shift.

Sign up to receive the latest insights. Click here to subscribe to The Lens Blog.

Tags

dp