UK data watchdog draws up plans for 'data protection by design'
The ICO will also retrain its own staff in AI and big data as part of its new technology strategy

The Information Commissioner's Office (ICO) plans to create a "regulatory sandbox" as part of its first ever technology strategy to help organisations build adequate data protection into their products before they are released.
The scheme forms part of the UK data watchdog's wider Technology Strategy, announced yesterday, which outlines eight priorities for the regulator between now and 2021, including educating both businesses and the public on emerging technologies such as AI and big data.
One of those goals will be the creation of a sandbox that provides a means for organisations to test products and services they produce against the regulatory requirements enforced by the EU's incoming General Data Protection Regulation. The ICO hopes this will allow for "data protection by design", where adequate safeguards can be baked into a product as it's being created.
ICO hands out £600,000 worth of fines in nuisance marketing crackdown General Data Protection Regulation (GDPR) ICO: Use GDPR to earn customers' trust
The sandbox will draw upon an existing model that was deployed by the Financial Conduct Authority in 2016, which allows companies to test products, services, business models, and delivery mechanisms in a controlled environment to ensure consumer protections are in place.
Consultations with the tech industry on the creation of the sandbox are expected to begin later in the year.
The regulator also plans to tackle a lack of internal expertise in fields proving to be the most disruptive for businesses, with it committing to reskill and retrain its own employees. Specifically, the ICO wants to develop a better understanding of areas such as cyber security, artificial intelligence, big data, machine learning, and IoT.
This will partly be remedied through the creation of technology apprenticeships at the ICO in partnership with UK universities, and by engaging with tech-focused professional bodies, academics, and industry and public sector networks, according to the regulator.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
As part of this initiative, the ICO will create a two-year postdoctoral role looking at the effect of AI on data privacy. It will also establish an annual ICO conference on Data Protection and Technology to help showcase industry innovations, and a "panel of forensic investigators" that will support current regulatory investigations.
The 2018-21 strategy is underpinned by the idea that new technologies should not come at the expense of data protection and privacy rights, according to information commissioner Elizabeth Denham.
"Staying relevant in the context of ever changing technology must become a core component of the ICO's strategic goals, otherwise the ICO will fail to deliver the regulatory outcomes the public expect," said Denham.
The Technology Strategy will support an existing four-year Information Rights Strategic Plan announced in 2017 - an effort to increase public trust in government, public bodies and the private sector when it comes to user data.
Image: Shutterstock
Dale Walker is a contributor specializing in cybersecurity, data protection, and IT regulations. He was the former managing editor at ITPro, as well as its sibling sites CloudPro and ChannelPro. He spent a number of years reporting for ITPro from numerous domestic and international events, including IBM, Red Hat, Google, and has been a regular reporter for Microsoft's various yearly showcases, including Ignite.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott Published
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly Published
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly Published
-
TikTok could be hit with £27m fine for failing to protect children's privacy
News Social media firm issued with a notice from the ICO for potential violations of UK data protection laws
By Bobby Hellard Published
-
What is AdTech and why is it at the heart of a regulation storm?
In-depth The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say
By Carly Page Published
-
ICO crackdown on AI recruitment part of three-year vision to save businesses £100 million
News ICO25 outlines a fresh approach that involves releasing learning materials, advice, and a new ICO-moderated discussion forum for businesses
By Connor Jones Published
-
Clearview AI fined £7.5m over improper use of UK data
News Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database
By Bobby Hellard Published
-
UK data watchdog cut IT spending by £1.2 million during pandemic
News The ICO’s IT budget has been slashed by around 23% since 2019
By Sabina Weston Published