Should be minus government criminals fact agreed with me then I asked for enforcement as the criminal did nothing still do nothing These people are worse than criminals and proves crime does pay and... Toon meer
We verifiëren geen specifieke claims omdat reviewers hun eigen mening mogen geven. We kunnen reviews echter wel als 'Geverifieerd' bestempelen als we bevestiging hebben dat er een zakelijke interactie heeft plaatsgevonden. Meer informatie
Om de integriteit van het platform te beschermen, wordt elke review op ons platform – al dan niet geverifieerd – gescreend door onze geautomatiseerde software. Deze software kan inhoud identificeren en verwijderen die in strijd is met onze richtlijnen, inclusief reviews die niet zijn gebaseerd op een echte ervaring. We zijn ons ervan bewust dat we weleens wat over het hoofd zien, dus je kunt altijd reviews rapporteren waarvan je denkt dat we ze hebben gemist Meer informatie
Lees wat reviewers zeggen
Sent me a letter telling me if I don’t register by a certain date (about 2 weeks from the date of the letter) they will fine me £4K. They hadn’t even established what my business is before sending the... Toon meer
Hopelessly useless waste of government resources and tax payers funding. I submitted a dsar to a data controller and then raised a complaint when no response was forthcoming during the statutory perio... Toon meer
I submitted a complaint to the I.C.O. against Lloyds Bank who failed to respond to a DSAR request - no surprise there, of course. The I.C.O. wrote to tell me that they had decided "NOT to undertake a... Toon meer
Bedrijfsgegevens
Informatie afkomstig van verschillende externe bronnen
The Information Commissioner’s Office is the UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.
Contactgegevens
Water Lane, SK9, Wilmslow, Verenigd Koninkrijk
- ico.org.uk
Geen gegevens bekend over review-uitnodigingen
Dit bedrijf heeft hun klanten niet uitgenodigd, dus reviews zijn mogelijk niet representatief
Zo gebruikt dit bedrijf Trustpilot
Ontdek hoe ze hun reviews verzamelen, beoordelen en modereren.
The ico is toothless and useless
The ico is toothless and useless. America actually has better protection for people who suffer a data breech. If a UK company allows your data to be hacked, YOU not the company have to pay for protection at a cost of £340! (Cifa £30, experian £130, equifax £180)
Unfit for purpose
As indicated by previous reviewers, ICO is obstructive and weak on both enforcement and customer service. They simply don't adequately consider a case in the round and may, in fact, be likely to compound any prior stress or inconvenience raised in respect of the original complaint.
It's complaints process is neither accessible nor fit for purpose.
If there were a rating below zero, I wouldn't hesitate for a moment
If there were a rating below zero, I wouldn't hesitate for a moment.
A cosmetic body designed to absorb public anger—and money—and protect systemic corruption.
This institution has proven to be nothing more than a superficial, useless entity whose primary function is to absorb public frustration and project a deceptive image of regulatory oversight. In reality, it acts as a shield to protect systemic corruption within a broken judicial system.
With over a thousand employees, productivity remains virtually non-existent, as public resources are consumed by staff who prioritise bureaucratic delays and the invention of evasive, soothing rhetoric over actual duties.
The official metrics expose this regulatory farce and administrative bad faith: out of nearly 40,000 data protection complaints received last year, the watchdog issued only two fines and a mere five enforcement orders. The ICO has explicitly confirmed that unless an individual faces what they narrowly define as "significant harm," they will simply shuffle valid complaints into a digital filing cabinet for "information purposes only" without any investigation.
Using "third-party data protection" as a pretext to provide curated summaries and altered extracts instead of original, unadulterated records is a deliberate tactic to suppress evidence of gross violations and block the path to justice. When huge swathes of data breaches carry zero consequences, the law becomes optional, public trust is completely destroyed, and accountability is reduced to mere performance theatre
Dont waste your time its just a quango…
Dont waste your time its just a quango masquerading as a investigative agency . They take you through a process that they know beforehand will never resolve . used them few times , a state corporate patsy as all regulators in the UK are ,
Had my Information refused from a
Had my Information refused from a. Energy company whom had an agent sexually harass me so according to these clowns a denial of an access request and call transcripts is not something they deal with , how the hell do you people sleep at night. Disgusting.
Stealth Tax by another name (ICO)
It is clear this Organisation only exists as another 'stealth tax' on UK businesses that process data... e.g. all of them.
When it comes to enforcing clear statutory breaches, the ICO is woefully negligent and inadequate.
Despite having been presented with clear statutory breaches, that were received much later than the GDPR rules require, the ICO sent me a short letter explaning they will not be doing anything about it.
ABSOLUTELY FARCICAL.
Disinterested, poorly trained front-line call handlers clearly targeted on the number of calls answered, rather than the number of issues properly dealt with.
As this is a public body, I have now requested a Freedom of Information request into the handling of my complaint, who made the decision that went against best practice and also contacted several MP's and escalated a complaint to the Parliamentary and Health Service Ombudsman who are the ones the ICO allegedly report to.
The ICO in its current state is not fit for purpose and clearly just another means for the UK Govt to take another tax off businesses.
If the ICO cannot enforce GDPR non-compliance, then what exactly do they exist for? I think I've already answered that, to rinse businesses for more money.
Money paid for no good reason plus they…
Money paid for no good reason plus they send very aggressive emails. After reading the other reviews on here it is clear this organisation should be disbanded and all monies they have received should be repaid.
Data protection rights in theory, case closure in practice
I approached the ICO expecting an independent regulator that would thoroughly investigate concerns about my personal data and help ensure that my information rights were respected.
The ICO states that it exists to "empower" members of the public, "uphold information rights", and "safeguard and empower people". It also says that it promotes transparency and protects individuals' information rights.
Unfortunately, my experience was very different.
My complaint concerned a Subject Access Request to a tenant referencing company. A landlord reference had clearly been obtained, validated and used during the referencing process, yet the substantive contents remained heavily redacted. The limited information eventually disclosed contained inaccuracies, which naturally raised concerns about the accuracy of the information that remained hidden.
The ICO ultimately accepted the company's position and closed the case.
What I found most disappointing was the process. Despite being told that the matter would receive further consideration and be allocated to a case officer, no one ever contacted me to discuss the issues, clarify concerns, or explore the evidence before the outcome was issued. The ICO later explained that there was no requirement for a case officer to speak to me before reaching a decision.
The ICO's final position was that it had considered the matter to the extent it considered appropriate and that the case was closed. It also stated that it would not provide any further response.
My difficulty with this is simple: the ICO concluded that it had not seen evidence of wider accuracy problems, yet the substantive information that could have confirmed or disproved those concerns remains redacted. As a data subject, I am left in the position of being unable to assess whether the undisclosed information is accurate while simultaneously being told there is insufficient evidence to question it.
The result is that I have less confidence in the practical protection offered by the complaints process than I did before I started it.
The ICO speaks about empowering individuals, protecting information rights and promoting transparency. My experience was of a regulator that closed the file without ever speaking to me and left substantial questions unanswered.
Did not take up my complaint about yougov
Yougov banned me at 25 pounds, half way to 50, I complained to ico that this was a breach of data protection, to say I must give my passport to earn the rest of the 25 to let me be able to earn 50, and complained yougov were ignoring my subject access request, because I wanted to know their data on me in case they banned me for a wrong reason. Ico said they would do nothing about it, and did not bother that I am being asked to give my passport to even have a chance of getting what I earned. Even sending a non descript response to my letter. I thought subject access requests were a right, and am surprised they can demand my passport if I want to earn the rest of the 50.
Why does the ICO even exist?
Why does the ICO even exist?!
Following a dispute with Currys I followed all steps necessary to acquire my information. I completed a Subject access request (SAR) gave them an extension etc. Nothing. I need this information as I know Currys hold proof that they owe me compensation.
I then followed all necessary steps to make a complaint to the ICO. It took TWO MONTHS to get a response.
That response was essentially "It's not a big enough issue for us to investigate"
So I can do nothing. Currys can break GDPR laws and nothing happens.
Terrible on all levels
Do not waste valuable time or air that you will never get back.
There communication is horrific
You barely get any responses to emails, & when you ask for updates on your cases, they simply dismiss you
If they ever do respond, they will NEVER support the person raising the complaint and alway send the same copy & paste responses to all complaints
The process they put people through with delays of over a year are truly awful and at the end of it, you get a piece of A4 paper, most of which is filled with generic information & one sentence which states " we consider the organisation did all they should"
Biased, & always in favour of the business, never supportive or in favour of the person raising the complaint, shocking delays in time frames, still relying on covid back logs, some 6 years since covid, terrible system for logging complaints.
An absolute waste of everyones time.
Doesn't actually enforce GDPR
Doesn't actually enforce GDPR
I was stonewalled by a company for a subject access request. They refused to fulfil it and ignored all communication on the topic.
The ICO took months to even acknowledge the complaint, and then further months to start investigating. At which point they took everything the company said at face value despite evidence to the contrary. When challenged, the ICO refused to provide any evidence to back up their claims.
Toothless organisation that serves no purpose.
Should be closed down
The ICO does not deserve any public funding, when organisations are in breach they do nothing but fob off with generic templated responses. They are not fit for purpose. Every penny given to this organisation is a penny wasted. They need to be stripped of all public funding.
absolutely useless
absolutely useless. they should be shut down so we dont have to waste any time, resources and public money on such poor services
The ICO is fundamentally ineffective
The ICO is fundamentally ineffective. They will cite a 40 (FORTY) week response time to complaints, even those that are likely to cause serious harm. They are then unlikely to properly read the complaint as made, instead looking for the quickest way to dismiss it and take no action. I think the message is clear that the ICO and the UK government couldn't care less about your data. Except perhaps when they want it for their own purposes.
ICO Endorsement of Human Rights Abuse by the Controller
I took Hacking and Paterson Management Services (HPMS) to Court to obtain my original call recordings to allow me to evidence HPMS altered a call recording to avoid a loss and have me pay the costs of their incompetence. After a 20 month battle during which HPMS identified a 3rd party called Oak Innovation as having possession and ownership of my call recordings the Court granted a Court Order against HPMS to provide me with my true original call recordings.
HPMS overcame the Court Order by substituting the recording with the same disputed as edited digital recordings and destroyed the metadata to prevent disclosure of the fact the original call recordings were not provided.
Not knowing what a 'Recordx', the call recording program HPMS uses, original call recording is I asked for ICO help. I was told the ICO don't get involved with complaints which have reached Court and I should persuade the Court I had not received my original call recordings.
After the Court dismissed my complaint the ICO informed me I could find a demonstration video of 'Recordx' on YouTube under the search 'Introduction to Oak Call Recorder' and suggested I take my complaint back to court.
The ICO ignored the availability and integrity breaches HPMS deception created. I challenged staff on the helpline to enforce the reporting of the data breaches only to be told there is no such thing as availability and integrity breaches, only data breaches. What idiots.
Tucked away at GDPR Article 94 is confirmation European Data Protection Board guidelines remain applicable to UK GDPR. ICO staff are not aware that data subjects have rights. Everything ICO staff need to understand individuals data rights can be found in European Data protection Board Guidelines 01/2022 Right of Access . ICO actions instead endorsed HPMS Human Rights abuse of my right of access to my personal data. My right of access is a fundamental right which is protected by ECHR Article 8.
This organisation is not fit for purpose and is the next Post Office scandal. GDPR gave the Information Commissioner the power and authority to ensure Controllers complied with individuals data rights and the ICO immediately abuses that authority putting burden of proof onto the data subject.
Anyone struggling with call recording issues, the Court of Justice of the European Union Case Law C-487/21 provided confirmation of what obtaining a copy of personal data in terms of Article 15(3) of the GDPR. In terms of my call recording it needs to faithful, that is provided without undue delay and within one month in any case. My recording was provided 225 days after being located and me making my SAR which automatically disqualifies the recording as being a lawfully recognised copy. It must have the characteristics (metadata in the case of an MP3 file) to qualify as a copy which it did not. Will Shepherd informed me I have no right to the metadata Luke Wilson informed me the ICO can't comment on how to validate a recording after they removed the only method of validation. These two should not be working at the ICO in any other role other than the car park attendant.
Court of Justice of the European Union Case law C-340/21 paragraph 52 confirms GDPR Article 5(1) puts the burden of proof on the Controller but sadly the ICO staff are not aware of this either.
My complaint is now with the PHSO after which, as I reside in Europe, the EDPB will need to resolve this if the ICO continue to refuse to administer GDPR correctly.
GDPR is fit for purpose, sadly the ICO is not.
UK's top data and AI regulator quits…
UK's top data and AI regulator quits after 'inappropriate' humour
Top dog gone, when is this incompetent quango going to be shut down.
Liv McMahon
Technology reporter
Published
19 June 2026
John Edwards, the UK's information commissioner, has resigned following a workplace investigation.
"I have accepted that there have been occasions where I exercised poor judgement and made attempts at humour that were inappropriate and caused offence," he said in a statement on Friday.
The Information Commissioner's Office (ICO) is responsible for regulating AI in the UK and also oversees data protection regulation and the freedom of information law.
Science Secretary Liz Kendall said she had "seen evidence of the vulgar and highly sexualised language that was used in his interactions with his staff and am extremely concerned that he continues to describe these incidents as misplaced humour".
In a post on the networking site LinkedIn,, external she wrote: "Multiple women shared testimony to the investigator on feeling offended, shocked and uncomfortable following interactions with Mr Edwards.
Awful - Needs to be dissolved and replaced
Publicly funded body but unless you can demonstrate significant harm (ie royalty or in the public eye) they hide behind their investigation guidelines and refuse to even look at it.
Their position is well known and encourages organisations to breach data protection without fear or consequences.
We may as well through GDPR in the bin if the body responsible for enforcing it openly says they will only look into the biggest breaches.
Service Should be Scrapped
Very poor service yet again as with all our other Quangos. In my honest opinion, the ICO should be completely defunded.
Absolutely useless.
You don't need to go past their website to see that they decide what is "harm" and they decide to act on whether they will take action. It seems like you do all the work, assemble all your evidence to be given the brush off. Honestly I don't see the point of this waste of space.
Dit is Trustpilot
Iedereen kan een review op Trustpilot achterlaten n.a.v. een ervaring met een bedrijf. Gebruikers hebben het recht om hun feedback op elk moment te wijzigen of te verwijderen, en elke gepubliceerde review is zichtbaar zolang het account van de betreffende gebruiker actief is.
Wij beveiligen ons platform met behulp van toegewijde specialisten en slimme technologieën. Lees meer over hoe wij nepreviews bestrijden.
Lees meer over Trustpilots reviewproces.
Hier vind je 8 tips voor het schrijven van een goede review.
Verificatie helpt ervoor te zorgen dat echte mensen de reviews schrijven die je op Trustpilot ziet staan.
Beloningen aanbieden voor reviews of een slechts een bepaalde groep mensen vragen om een review te schrijven, kan de TrustScore beïnvloeden. Dit is in strijd met onze richtlijnen.








