Who Do You Complain to When the ICO Breaks the Rules?
The Information Commissioner’s Office (ICO) is supposed to be the guardian of data protection rights in the United Kingdom.
It tells businesses how they must handle personal information. It publishes guidance about Data Subject Access Requests (DSARs). It receives complaints when organisations fail to respond, miss deadlines or refuse to provide personal data.
It can (but rarely does in our experience) investigate, criticise and, in appropriate cases, take enforcement action.
That is why we are starting to submit DSARs to the ICO on behalf of our clients, so that we can identify any failings and challenge the ICO when it simply closes valid complaints.
But what happens when the ICO itself fails to comply?
The statutory deadline passed, no disclosure was forthcoming and no request for an extension.
So, who do you complain to when the body responsible for enforcing data protection law cannot meet the obligations it oversees?
We’ve requested an answer to that question.
Another regulator that marks its own homework
The normal route is straightforward.
If a bank, insurer, claims company, local authority or other organisation fails to respond properly to a subject access request, the individual is told that they can complain to the ICO.
But when the ICO itself fails to respond, the individual (or their representative) is presumably expected to complain to the ICO about the ICO.
The same organisation becomes the data controller accused of failing to comply, the recipient of the complaint and the body initially responsible for deciding whether its own conduct was acceptable.
Will the regulator fine itself, order itself to provide disclosure, or simply close the complaint against itself?
It is the regulator marking its own homework.
An internal complaints procedure may be necessary as a first step, but it does not answer the wider problem. The ICO is supposed to be the place people go when their information rights have been ignored. Those people should not then find that the regulator is capable of the same conduct, followed by the same delays and defensive processes they were trying to escape.
How many bodies are genuinely fit for purpose?
Sadly, this is not an isolated failure.
We have already seen serious problems with the Financial Conduct Authority and the Financial Ombudsman Service.
The FCA imposes standards on regulated firms but has shown weakness time and time again, allowing scandal after scandal to develop, and often seemingly seeking to ‘protect the market’ over protecting consumer.
The Financial Ombudsman Service decides whether businesses have investigated complaints fairly and properly. Yet we have seen cases where crucial evidence was not obtained, obvious questions were not asked and conclusions were reached before the relevant facts were available, possibly so that targets are hit.
Now the ICO, the body responsible for protecting information rights, has failed to provide disclosure following a request made under those very rights.
Three different organisations. Three different areas of responsibility. The same recurring problem.
Accountability seems to work in one direction
If a regulated business misses a deadline, it may face a complaint.
If it repeatedly ignores correspondence, questions may be raised about its governance, staffing, controls and senior management oversight.
If it fails to provide personal data, it may be accused of breaching the UK GDPR and the Data Protection Act 2018.
Those standards are entirely reasonable. The problem is that public bodies appear able to avoid the same level of immediate scrutiny.
The ICO should now explain when the request was received, why it was not answered within the required period, what searches have been undertaken and when the outstanding information will be provided.
It should also explain what internal controls exist to identify overdue subject access requests and why those controls failed in this case.
A generic apology about workload is not enough. Neither would a vague promise that the matter is being looked into. Businesses are repeatedly told that a lack of resources does not remove their legal obligations. The regulator cannot credibly adopt a different position when the pressure falls on its own organisation.
Public confidence is being steadily eroded
Bodies such as the ICO, FCA and FOS rely heavily on public confidence.
They want individuals to believe that complaints will be treated fairly, that evidence will be considered properly and that the rules will be applied without fear or favour.
That confidence cannot survive indefinitely when the organisations concerned appear unable or unwilling to follow the standards they attempt to impose.
Trust does not come from publishing guidance, issuing press releases or using words such as transparency, fairness and accountability.
It comes from conduct, from meeting deadlines, answering difficult questions and providing information even when that information may be uncomfortable.
It comes from applying the same rules internally that are enforced externally.
When a regulator fails to do that, it damages far more than one individual request. It damages the credibility of the entire regulatory system.
So who regulates the regulator?
There are internal complaints procedures. There may be routes to the Parliamentary and Health Service Ombudsman, usually involving referral through a Member of Parliament. Court remedies may also be available where data protection rights have been infringed.
But none of that answers the basic point.
No person should need to navigate a chain of complaints, political referrals and possible legal proceedings simply to make the UK’s data protection regulator comply with a routine Data Subject Access Request.
The ICO should be setting the highest standard, not testing how much delay and frustration an individual will tolerate before giving up.
When the body responsible for enforcing data protection law cannot provide personal data within the period required by law, it is no longer simply an administrative error.
It becomes a question of competence and accountability.
Most importantly, it becomes a question of whether yet another government-appointed body is genuinely fit for purpose.
The ICO cannot continue judging the failures of others while treating its own failures as something that can be dealt with later.
A regulator that cannot comply with the rules it enforces has no credible answer when asked why anyone else should.






