UK will not get data breach notification law
Private firms will not be required to tell the ICO when they lose data.

The Government has announced it will not be implementing a data-breach notification law.
Government departments are already required to notify the Information Commissioner's Office (ICO) of any potential data losses, and the data breach notification law would also have made it compulsory for private businesses.
A similar law is already in effect across the US, however, the ICO reported in July that it saw little benefit in enacting it here. Instead the ICO has produced guidance for businesses on when it should be notified of data breaches as a matter of good practice. The Government agrees with this stance.
"After considering the analysis of the experience of the US in the area of data-breach notification legislation, the Government is not intending to implement similar legislation to that in operation in the US," said the Ministry's report, dismissing the law.
"As a matter of good practice any significant data breach should be brought to the attention of the ICO and that organisation should work with the ICO to ensure that remedial action is taken.
"The ICO will take into account the failure of an organisation to notify any breaches of the data protection principles when considering enforcement action."
The Government's stance could put it at odds with the EU, which plans to force companies to own up to data breaches as part of its new ePrivacy Directive.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The decision also flies in the face of a report into personal internet security by the House of Lords Select Committee on Science and Technology, which concluded that data breach notification "would be among the most important advances that the United Kingdom could make in promoting personal Internet security."
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
New Zealand privacy commissioner tipped to become next ICO head
News John Edwards is said to be an 'anti-Facebook' regulator who would fit well in the UK's plans to clamp down on big tech
By Bobby Hellard
-
What is a freedom of information (FOI) request?
In-depth We look at the mechanism citizens can use to hold public bodies to account
By Dale Walker
-
ICO hints at Facebook hypocrisy over data protection goals
News Elizabeth Denham asks Facebook to drop appeal after CEO's call for greater internet regulation
By Bobby Hellard
-
ICO to investigate Google over GDPR violations
News UK Watchdog to liaise with other European regulators over 'forced consent' push by the tech giant
By Bobby Hellard
-
ICO myth-busts on the flow of data post Brexit
News The Information Commissioner explains how data will move between the UK and EU in a no-deal scenario
By Bobby Hellard
-
Leave.EU faces big fine over data law breaches
News Information commissioner reveals Leave.EU was fined a total of £75,000 for “serious breaches”
By Alan Martin
-
ICO website knocked offline for more than 24 hours
News The outage was caused by an “unprecedented electrical surge” that damaged its host’s circuits
By Keumars Afifi-Sabet
-
Elizabeth Denham appointed ICO boss
News Denham will be tasked with helping the UK leave the EU without any knock-on effects on privacy
By Clare Hopping