Source · PHSO decision

Information Commissioner's Office

Ref: P-005365 Statement Decision date: 11 May 2026 Jurisdiction: UK Government Closed After Initial Enquiries

Mr H complained the ICO mishandled his data breach complaint against the council, defending it despite acknowledged GDPR breaches and not taking enforcement action.

Complaint handling

Outcome

AI summary
The ombudsman found no indications of failings in the ICO's handling of Mr H's complaint and took no further action.

The complaint

3. Mr H complains the ICO mishandled his complaint of 28 October 2024. Mr H complained to the ICO about data breaches by his local council. He says the ICO defended the council’s position, despite acknowledging it had breached GDPR. He says the ICO failed to address his concerns and failed to address why it did not take enforcement action.

4. As a result, Mr H says this has obstructed his ability to assess evidence for family and civil court proceedings. He says this has left him at a legal disadvantage. Mr H says it has also prolonged harm to his reputation, prevented him from correcting false records, and undermined his rights under the Victims Code.

5. Mr H says he has been left for nearly a year since his original complaint. Mr H says he has suffered ongoing stress, financial costs, and denial of justice.

6. Mr H is seeking an investigation into the ICO’s complaint handling, an acknowledgement of any failings and service improvements.

Background

7. On 2 April 2024, Mr H submitted a Subject Access Request (SAR) with his local council.

8. On 18 June, the local council responded. It refused to provide Mr H with the personal data of his children. In its decision, it explained it was only permitted to disclose personal information to the data subject or an authorised representative. It explained it was unable to provide Mr H with the requested information as it had not established right of access.

9. On 28 October, Mr H raised a complaint with the ICO regarding the council’s handling of his SAR. The ICO made enquiries with the council and issued its response on 8 May 2025.

10. On 8 July, Mr H requested his complaint be escalated. The ICO provided further responses to the complaint on 6 and 11 August.

Findings

13. Before we decide if we should conduct a detailed investigation of a complaint, we look at whether there are signs the organisation has got something wrong. We do this by comparing what should have happened with what did happen. We have done this and have not found any indications that something has gone wrong.

Complaint handling

14. Mr H says the ICO mishandled his complaint of 28 October 2024. He says it failed to address his concerns and failed to address why it did not take any enforcement action.

15. Mr H says he suffered ongoing stress, financial costs and a denial of justice. He says the delays in responding to his SAR obstructed his ability to obtain evidence for family court proceedings. Specific to the ICO’s complaint handling, Mr H told us he was left without a response for nearly a year. It must have been upsetting for Mr H at the time.

16. We asked the ICO for the relevant policies in place to inform its decision making. It told us there are no specific guidelines setting out how decisions should be reached on data protection complaints. Such decisions are based on the supporting evidence provided and the application of data protection legislation in the circumstances provided.

17. The ICO told us Section 165(5) of the DPA sets out its responsibility to investigate data protection complaints to the appropriate extent and to provide an outcome. It says outcomes are not legally binding but represent the case officer’s view of the matter raised. Where appropriate, an outcome may include recommendations for steps the organisation in question may take to address the issue raised or to improve its overall information rights practices.

18. DPA Section 165 (4) says if the Commissioner receives a complaint, they must –

(a)take appropriate steps to respond to the complaint (b)inform the complainant of the outcome of the complaint (c)inform the complainant of the rights under section 166 and (d)if asked to do so by the complainant, provide the complainant with further information about how to pursue the complaint.

19. Section 165(5) says the reference to taking appropriate steps in response to a complaint includes –

(a)investigating the subject matter of the complaint, to the extent appropriate, and (b)informed the complainant about progress on the complaint, including about whether further investigation or coordination with a foreign designated authority is necessary.

20. The ICO also told us its Regulatory Action Policy is also used to consider if formal action should be taken. Generally, it takes an overview of all concerns raised about an organisation with a view to improving compliance with data protection law. Decisions on regulatory action must be proportionate and are typically based on an organisation’s overall performance, rather than the specific circumstances of individual cases.

21. We reviewed the Policy and noted it emphasised proportionality. Specifically, the ICO seeks to focus and respond to breaches of legislation involving highly sensitive information, adversely affecting groups of individuals, and/or impacting vulnerable individuals.

22. The Policy says the ICO acts proportionally, exercising discretion as to when, in what manner, and to what extent enforcement is required. It is selective when exercising this discretion. It says it applies resources more broadly to the areas of greatest risk and potential or actual harm to the community. It says it applies its fining and other enforcement powers where they are effective, proportionate and dissuasive.

23. The Policy says the ICO will adopt a selective approach to the action it takes. When deciding whether and how to respond to breaches of information rights obligations, it considers set criteria including the nature and seriousness of the breach, the number of individuals affected, the cost of measures to mitigate risk or harm, and the public interest in regulatory action being taken.

24. The Policy says the ICO considers each case on its merits and within the context of any compliance breach. As a general principle, the more serious, high impact, international or repeatedly breaches can expect stronger regulatory action.

25. We have reviewed the ICO’s complaint file in full. As the local council is not subject to our primary investigation, we have only referred to the events which are most relevant. This includes any actions taken by the ICO case officers in their handling of Mr H’s concerns.

26. On 28 October, Mr H complained to the ICO about his local council’s decision to refuse him access to his children’s reports with family services. Mr H also complained that the council held and used inaccurate and incorrect personal information about him.

27. In January 2025, the ICO updated its website to explain the possible outcomes of complaints. We note these outcomes include: telling the complainant there has been no infringement of the law, logging the complaint, and telling the organisation to do more work to resolve the complaint.

28. It also says the ICO does not normally take regulatory action for individual complaints, as it wants organisations to comply with the law without it using its formal powers.

29. On 22 January 2025, Mr H contacted the ICO for an update. The ICO responded on 27 January to explain it was dealing with a significant number of complaints. It explained it was taking longer than expected to allocate cases to case officers. It explained it dealt with complaints in date order of receipt and was currently working on cases from mid-October.

30. On 4 March, the ICO case officer wrote to Mr H to advise they had been allocated to his case. They summarised the concerns and asked Mr H for further information. Mr H responded to the questions on 5 March.

31. On 19 March, the ICO case officer explained they would raise the matter with the council. They contacted the council to ask for further information around the SAR.

32. We consider this action is in line with Section 165 of the DPA. The ICO case officer requested additional information to assist with their investigation into Mr H’s concerns.

33. Mr H emailed the ICO case officer with further information on 20 March and 2 April. He requested the ICO take immediate enforcement action regarding his data request. We cannot see the ICO actioned this request, which is in line with its Policy. The ICO’s Policy says it acts proportionally and is selective when exercising whether enforcement is required.

34. The council emailed the ICO case officer on 7 April to explain it was experiencing delays in collating the information. As an explanation for the delay had been provided, and we cannot see any evidence of a more serious impact, we do not consider it would have been in line with the ICO’s Policy to implement any enforcement powers at this stage.

35. On 15 April, Mr H emailed the ICO case officer to express concerns about the lack of response. He requested an update on his complaint. The ICO case officer responded to explain they had written to the council for further information. However, the council was experiencing delays in providing a response. We consider this update is in line with Section 165(5)(b) of the DPA. The ICO case officer chased the council for an update.

36. On 17 April, the council wrote to the ICO case officer with its response to their questions. We have noted the most relevant information contained within the response. The council stated the circumstances with the families changed since the initial SAR was received on 2 April 2024. Mr H had submitted a new SAR on 8 April 2025. The council confirmed disclosure of information would be considered based on present circumstances.

37. On 8 May, the ICO case officer acknowledged this information. They explained it would be appropriate for the council to review the new request and respond appropriately. The case officer wrote to Mr H on the same day to explain their actions and to advise it was appropriate to allow the council the opportunity to respond. Mr H objected to this response and requested immediate regulatory intervention by the ICO.

38. The ICO’s Policy outlines what regulatory actions it can take. For example, conducting assessments of compliance with the DPA, issuing information notices and issuing warnings where proposed action threatens non-compliance with data protection legislation.

39. The Policy also outlines the ICO can issue reprimands, enforcement notices and administer fines and fixed penalties. As per the Policy, the ICO is selective and proportionate with any regulatory actions taken. As a principle, it takes stronger regulatory action in breaches that are deemed high-risk.

40. We consider the ICO case officer acted in line with the Policy. As the council intended to consider the SAR due to a change in circumstances, it was proportionate to allow it the opportunity to respond.

41. On 22 May, the ICO case officer acknowledged these concerns. They wrote to the council on 23 May to explain they had received further concerns it was utilising an extension to the timeframe for a response. They requested justification for the extension. We consider this to be in line with the ICO’s Policy, as well as Section 165 of the DPA.

42. On 28 May, the council emailed the ICO case officer to advise it aimed to respond to the request by 8 July 2025. It offered an explanation as to the reasons for the extension.

43. The ICO case officer noted there was no further action to take. They wrote to Mr H on 27 June to advise that they felt the extension request was appropriate. We consider this explanation to be in line with Section 165 of the DPA. The ICO wrote to Mr H with the outcome of his complaint. Mr H requested his complaint be escalated.

44. On 4 July, the ICO case officer wrote to Mr H to apologise for the length of time the complaint had taken. They explained if Mr H did not receive a response to his SAR, he could raise the matter back to the ICO. They outlined Mr H had the right to request a case review and signposted him to information about this. This is in line with Section 165 of the DPA.

45. On 8 July, Mr H emailed the ICO to advise he had not had a response to his SAR and requested his case be escalated.

46. On 17 July, the ICO case officer wrote to Mr H to confirm they had set up a case review as per his request. This is in line with the ICO’s complaints information. This says if complainants disagree with the outcome of a data protection complaint, they should contact it for consideration under its case review process.

47. The ICO case officer explained the matter would be passed to a reviewing officer with a response aim of 30 calendar days. They sent a chaser to the council, noting it had exceeded the statutory timeframe for a response. This notice is in line with the regulatory actions the ICO can take. Specifically, the ICO can issue information notices and warnings where proposed action threatens non-compliance with the DPA.

48. According to the complaint file, the council provided the SAR electronically on 16 July. Mr H requested a paper copy, which we note he confirmed receipt of on 18 July. The council updated the ICO case officer.

49. On 6 August, the ICO provided the outcome of its review into the handling of Mr H’s data protection complaint. We note this is in line with the response aim of 30 calendar days.

50. The reviewing officer felt the complaint had been dealt with reasonably and in line with casework processes. They explained referring the matter back to the organisation involved is one of the outcomes the ICO can consider, and that this was appropriate. Mr H responded the same day to advise he was unhappy with this outcome.

51. We consider this explanation to be in line with the ICO’s Policy. It is for the ICO to decide, using its own discretion, of what (if any) regulatory actions to take.

52. On 11 August, the ICO case officer wrote to Mr H with an update on the data protection complaint. They explained they felt the council did not comply with its obligation to respond to the SAR of 8 April 2025 within the statutory timeframe. However, beyond this failing, they were satisfied the council appropriately applied the conditions of data protection legislation. As such, there was no further role for the ICO to take.

53. This explanation is in line with Section 165 of the DPA. The ICO wrote to Mr H with the outcome of his complaint. As above, the ICO’s Policy empowers it to decide whether to take any regulatory action. At this time, the ICO’s website had been updated to explain it is unlikely it will take regulatory action for individual complaints.

54. We note the ICO case officer also wrote to the council. They explained their opinion in that the council did not comply with its obligations to respond to the request within the statutory timeframe. Specifically, the timeframe had been extended to a final deadline of 8 July, but the response was only issued on 16 July.

55. We consider this to be in line with the ICO’s Policy. It logged the infringement, as per the possible outcomes outlined in its Policy and on its website at the time. It explained this to both parties involved in the complaint, as per Section 165 of the DPA.

56. The reviewing officer signposted Mr H to obtain legal advice if he wished to pursue the matter further. This is in line with the ICO’s complaints process. It says if complainants are unhappy with how the ICO has interpreted the law, they should consider taking legal advice.

57. Overall, we have not seen any indications the ICO did anything wrong in how it dealt with Mr H’s complaint.

58. Section 165 of the DPA and the ICO’s Policy gives the organisation discretion to respond to complaints appropriately and proportionately. We understand Mr H is unhappy with this and wanted the ICO to take stronger regulatory action. However, we have not seen sufficient evidence to indicate it should have done so.

59. We consider the actions taken – obtaining explanations from the council, updating Mr H on the progress and outcome of his complaint, and logging an infringement – to be in line with the ICO’s Policy. We have not seen any indications of wrongdoing. For this reason, we do not propose to take any further action on Mr H’s complaint.

60. We realise this is unlikely to be the outcome Mr H was looking for when he approached us and can understand if he may be disappointed by this. We hope we have explained fully the careful consideration we have given to his case and we thank him for bringing his concerns to our attention.

Our decision

1. We have carefully considered Mr H’s complaint about the Information Commissioner’s Office (ICO). We are sorry to hear of the circumstances that led Mr H to approach us. It must have been frustrating and distressing for him to receive the outcome of his complaint.

2. Having looked at the evidence available to us, we have not seen any indications of failings in the ICO’s handling of Mr H’s complaint. We have therefore decided not to take any further action on Mr H’s complaint. We hope he is reassured by our explanation below.

Other decisions about Information Commissioner's Office

View all decisions for this organisation →

Decision details

Reference
P-005365
Decision type
Statement
Jurisdiction
UK Government
Decision date
11 May 2026
Outcome
Closed After Initial Enquiries
Responsible body
Information Commissioner

Complaint summary

AI
Summary
Mr H complained the ICO mishandled his data breach complaint against the council, defending it despite acknowledged GDPR breaches and not taking enforcement action.

Source links