Serious Privacy
The PICCASO award winning Podcast, for those who are interested in the hottest field of human rights and laws on the digital frontier. Whether you are a professional who wants to learn more about privacy and privacy laws, data protection, GDPR or cyber law or someone who just finds this fascinating, we have topics for you from data management to cybersecurity, from social justice to data ethics and AI and digital identity protection. In-depth information on serious privacy topics including interviews with privacy leadership, privacy culture, serious discussions, and more.
This podcast, hosted by Dr. K Royal, Paul Breitbarth and Ralph O'Brien, features open, unscripted discussions with global privacy professionals (those kitchen table or back porch conversations) where you hear the opinions and thoughts of those who are on the front lines working on the newest issues in handling personal data. Real information on your schedule - because the world needs serious privacy.
Follow us on BlueSky (@seriousprivacy.eu) or LinkedIn
Serious Privacy
12 years in ICO Complaints (with Dom Smith) AND Meta settlement
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The real problem with complaints isn’t that people are complaining.
It’s that unhappy people don’t usually show up unless something already went wrong. So when the ICO says it has to triage harder, that’s the tension.
Welcome to the Serious Privacy podcast, where Paul Breitbarth, Ralph O'Brien, and Dr. K Royal connect with Dom Smith of the UK's Information Commissioner's Office to discuss his role in addressing complaints and changes he has seen over the last 12 years. We'll learn a little about him and how his experiences and perspective over the years has shaped him as a data protection professional.
Before you hear the episode, you will first hear an emergency segment to discuss the settlement Meta reached with U.S. states in the children’s harm court case.
@trustarc
If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!
Subscribe today HERE
Back the Board Game!
https://www.kickstarter.com/projects/seriousprivacy/serious-privacy-the-data-game
Powered by TrustArc
From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.
You're listening to the award-winning Serious Privacy Podcast sponsored by Trust Arc. Please welcome your hosts, Paul Breitbart, Ralph O'Brien, and Dr. K Royal.
RalphEverybody loves a good moan, and with data usage today, there's plenty to moan about. And recently, the UK's ICO has published a new complaints policy. Significant changes in how complaints and data protection are handled. And that's attracted attention, adding in legal cases like Dello, new complaints process under the Data Use and Access Act. People in the UK might just be wondering what's going on. I should declare from the outset that I, Ralph O'Brien, have been vocal in my opposition to the new policy and approach. So this isn't a conversation where we're going to talk about complaints in the abstract. I want to understand from our wonderful guest today what it's supposed to achieve, why it's changed, and whether my concerns, of course, are justified. So today we're joined by D, who brings an extraordinary wealth of 19 years of experience dealing with complaints and other such things at the Information Commissioner's Office. So he's in a particularly good position to help us understand what's really going on inside the regulator. So we welcome Dith and my name is Ralph O'Brien. My name is Paul Breitbart.
KAnd I'm K Royal, and welcome to Serious Privacy. I feel like I'm being surrounded by Brit. Europeans, yes, Brits now. And Europeans. Maybe I should say welcome to serious privacy, but I don't see that happening. I don't see that happening. Welcome, Dom. So glad you joined us today.
DomThank you for having me. And Ralph, just to say, I think you've actually aged me seven years there. It's 12 years. So my experience isn't as advanced as you think. But yeah, 12 years at the ICO.
PaulYou do know that data protection years of experience are like dog years, right? They count for seven each.
DomCertainly feels that way. Yeah.
KI'll go for that one. I'll go for that one. Okay, so. Do y'all have rice crispy treats over there? Yes. Okay. Here's the unexpected question. How much sawdust can you put in a rice krispie treat before people start to notice?
RalphNone. Certainly unexpected. I didn't expect the sawdust to like and even prefacing it with the rice krispies, I was still unprepared. Dom?
DomI don't know. Probably a lot. You're probably gonna tell me I don't know, like maybe a ten ten grams?
KThey're pretty dry, right? And sometimes they can get chewy.
DomIs that not much? No, I don't know. You're asking the wrong person. I think I don't think anyone's the right person to ask that question, too, is it? But you're certainly asking the wrong person.
PaulI certainly think it will depend on what kind of rice crispy treats you're talking about, because I remember my late grandmother used to give me white chocolate bars with rice crispy as a crunch inside them. Those were really good when I was a kid, but I'm pretty certain that you would immediately taste the sawdust. So I would say none, none at all. The serious privacy good cookbook. Now we've added sawdust.
KRight. Still an idea. We have a draft.
PaulI mean it's coming under the Christmas tree, right? So it's sawdust is fitting.
KBut I will say I do a lot of commercial rice crispy treats because of the three grandkids, right? And we had one a few weeks ago that literally tasted like I was biting into cardboard. Like it had been burnt or something at the factory, and I was like, ew, this is gross.
PaulWe have that with the office snacks.
KYou could put a sprinkle in it and probably never notice, right? Especially the commercial ones, but homemade ones I would think you'd have to notice pretty quick.
RalphI yeah, I'm just disappointed that you bought them at the shop.
KI don't make them. In whose world do I make Rice Krispie treats?
RalphYeah, fair enough. In which world do you cook extensively?
KExactly.
RalphSo as the easy starter for Quen 10 question, Dom, we normally just allow you to just take a moment to just talk a little bit about who you are and how you got into this wonderful world of data protection. So before I argue grilling you, ease yourself in.
DomYes. So yeah, how did I get into data protection? I think geography is the actual answer to this. So I grew up uh right by Jodrel Bank, which people in the UK may know is the largest land telescope either in Europe or the UK, I'm not sure which one, but it's a large telescope, and that's just down the road from Wilmslow, Cheshire, which is of course the home of the Information Commissioner's Office. And in an Easter holiday, when I was in my final year of university, I was back up at home and I didn't really know what I wanted to do. So I was just looking for entry-level jobs that were easy to commute to my parents' house, just round the corner from Georgeville Bank. And so, therefore, the reason I ended up at the Information Commissioner's Office is because I managed to somehow get an interview and I walked into Wycliffe House, and I can still remember it now. I walked into Wycliffe House, which is the name of the building of the ITO's head office, and I was in the grey Marks and Spencer's suit, which is probably a bit ill-fitting, and I can still remember it sticking to me with sweat as I waffled on for an hour. My only knowledge of privacy law at that point was, and I guess this is an anti-privacy law, is the USA Patriot Act. My degree was around American history and politics, so I had a lot of people.
KYeah, not a good one to know.
DomYeah. So I sort of that had that opened my eyes a little bit to the sort of the importance of privacy and rights and protections of laws because of that law doing the opposite. And I remember I waffled on about that end thought, and I remember walking out back out of the doors at Wycliffe House and thinking, I know absolutely nothing about data protection, and I'm never walking through these doors again. Twelve years later, I'm still walking out of those doors, and I'm still most days thinking, I don't think I know much about data protection. But what I do know and what I have learned is understanding why this matters to people, understanding the different ways that this shows up, the different things that frustrate people, the different challenges that we have as a regulator, where you've got organizations and big tech wanting one thing and government wanting one thing, and members of the public on the face of it wanting the same thing, but often individually, they all want very different things and navigating that. And so one of the big things I'm passionate about is understanding people on both sides. So it's I'm really passionate about the people that bring complaints to us and some of the things that they've seen and want to tell us about. But also what I've seen in these 12 years is practitioners like yourselves, dedicated people who also want to get it right, and some of the challenges within that. And that's very much my expertise is understanding the people behind it all. I don't confess to be the biggest expert in the legislation. There's people at the ICO that know far more about legislation than I do, but that's where I think I bring my relevance to the ICO role is this is what matters to people. This is what we're seeing on the ground.
PaulSo, what is your background? What is the expertise that you bring on top of all the legal expertise that the others have?
DomI think for me, it's as I alluded to, it's understanding why it matters to someone. I think when what I see, and I'm a big advocate for trying to say to people, it's not necessarily just a data protection issue, something else has gone awry, and when you're just focusing on the legislation and the law, what actually matters to the purpose of person can go missing. And that's often where I see organizations fall down when they've not done things well, and it's often where we've had to we've I've been in meetings in the ICO where I've said, okay, we're getting lost a little bit in terms of you're right, that is what the legislation says, that is what the guidance says. But actually, if you strip it back, this person wants this thing, and it's not always as straightforward as or it feels for the individual quite straightforward, but to us we get lost in the legislation. So it's remembering there's real people, and I think that's the big role that I and a few of my colleagues try to play with in the ICO is there's real people here, and it's not because people are deliberately not thinking about that, it's because naturally the nature of the work that we do, if you're not dealing with those people, you don't speak to those people on a day-to-day basis, like our case officers do, they don't get that same feel for it.
RalphThat's something I've I've always said actually. People don't put in subject access requests because they're happy. People always say to, oh my god, we're under this deluge of AI-generated access requests and complaints. And I say, Yeah, but that still requires an effort for someone to do, and therefore they're not going to do that if they're happy, right? What does the customer want? Sometimes they're treating the customer nicely in the first place, make this entire thing entirely preventable. So the situation is changing at the moment and the policy is changing. Perhaps before we go a little bit further, perhaps Tom, it might be useful for you to tell us from your perspective what's changing and why in the current landscape.
DomYeah, so in the complaints landscape, the big change for us is we're bringing in a new programme called Data Protection Transformation. And this is like a couple of years of work with people, and this has been designed by people that are in the complaints function. And I think we want the same thing as what the people that are perhaps critical of this approach want, and that is for the ICO to be a more effective, better regulator and to be able to tackle some of the most challenging, difficult cases that that come through to us. And there was an acknowledgement that we're never going to have infinite resource and we need to be more strategic and we need to make sure that the cases where we can have the biggest impact get seen to and that actually we look to do more with them and be more effective. So we went about designing a sort of threshold, sorry, not threshold, a triaging system whereby cases used to come in and it was just gone as a date order thing. So you could have one case which was pretty low level, and that might not even be a data protection matter. That's a large chunk of cases, that's not really a data protection issue. And then you also have cases where there was real severe harm to someone and it was really serious. And it just went into a queue and it would be allocated as and when, and it wasn't until it was allocated. What we've acknowledged is we need to be a lot better at that in terms of triaging cases. So that's the first thing that we need to do is go, is this a case that we want to look at and do more on, or is this a case that we don't? So the first big improvement is actually looking at things a lot sooner to understand what the issues are. And that's what we've built. And then within that, those cases which we go, actually, we don't think this is something that we want to pursue, we will log. But actually, what we do as a complaints department is we sit on an awful lot of intelligence. As I was saying before, we're there reminding this is what people care about, here's what's coming through to us, using that data to then inform more strategic decisions and to play into other parts of the ICO to say, we can see that there's this trend here, we can see that this organization has had so many complaints. Is this something we need to look at on a more strategic level? But not losing sight of those cases where actually the harm is really severe. And I think it came back to a conversation where lots of us within our part of the ICO were saying, if we do nothing, sorry, by trying to do everything, we risk doing nothing basically, and we don't want to be in that space. We would rather do something than nothing, and trying to do everything at the moment wouldn't we wouldn't be plausible. Since we started designing this though, we have seen an unprecedented amount of cases come through to the ICO. So I think in 24, 25, we got 42,500 complaints. It was about three and a half thousand cases a month. 25-26 that went up to about 78,000, 79,000 cases, so almost double. That's still continuing to go up. As of today, I think we're forecasting around potentially 8,800 cases a month this financial year. So that's more than double from two years ago. Why the increase? That's the big question, which I don't think we've fully been able to get to the bottom of. I think a lot of people will jump and say AI. That's definitely a driver, I think, within that. But I think it would be unfair to say that's the only reason.
KYeah.
DomI think that particularly speaking in the UK, I think my observation, and this is purely my observation, it's not based on any sort of research or grounding, but I think since the pandemic, there has been more than more mistrust in organisations and authority in the UK. I think the sort of political climate of the UK has perhaps led into some of that, particularly around public bodies. I think, particularly in the public sector, resources are so finite that, again, unfortunately, these issues will often get passed pushed aside by big organizations. So I think the general dissatisfaction, I think the fact that AI is making it more accessible for people, and I think that just the general state of the economy and the fact that organizations themselves are struggling, as I said, particularly in the public sector, I think is a melting pot of why. I don't think you can really exactly pinpoint what it is, but I think from when I speak to practitioners, subject access requests are increasing. And then that translates. Around 55 to 60% of complaints we receive are usually related to subject access requests. So it's the majority of complaints that we see.
PaulYeah, I hear a lot of organizations also saying that their D SARS indeed have doubled year on year in in recent years. In part, yes, because of AI, because it's a lot easier to file one and have AI draft a letter for you.
KYeah.
PaulNot that it's needed, but that it's happening. And because of the involvement of AI, the D SARS themselves also become more complex and more granular, meaning that there is more room for mistake in timelines. There is more room for mistake also in content, which then leads to complaints procedures that a lot of people also start to make use of attorneys and law firms or legal aid assurance to file DSARs on their behalf, immediately legalizing the whole process, meaning that it's also more likely that complaints end up with a supervisory authority if somebody is not satisfied with the response. Because even if as an organization you provide everything, it's very well possible that it's not what the data subject wants to hear. They want maybe a different outcome to what the process has been, which is not the purpose of the DSAR, obviously. But also on the regulatory side, the ICO is not unique. We've seen all over the world an increase in the volume of complaints. We had the conversation with commissioners of Canada and Australia in recent weeks. We've seen the annual report in the Netherlands, in Ireland, in Sweden, in wherever, all of them showing similar big increases. So I do believe that this is a bigger topic that we as a data protection community need to discuss to see how we are going to handle it while upholding the fundamental right.
KI have a little bit of a theory. Because what I've heard from people is that the request and therefore the complaints are increasingly by employees. And I do think technology and AI is reducing jobs. And that's when someone files a D Sarge generally, is when they've lost a job. Sometimes it's because they legit want some data, and sometimes it's just to harass the employer. Right. And in then that case, so it's indirectly, but I've heard from a lot of people that they're seeing like from 0% now to it's 50% or more of the DSAR requests that they're getting, and it's from terminated employees. And a lot of them because of technology jobs, made them redundant. So I don't know if that feeds into anything. Dom, you might be able to speak whether you get complaints from people from an employee perspective or from a customer perspective, or from someone complaining on their neighbor having a ring camera.
DomWe get it, we get it all. I think all of those things you've named, we definitely get in abundance. I think Valve, though, touched on it earlier is that as a general rule of thumb, and this is a general rule of thumb, happy people don't tend to make subject access requests. And I think we are living in an incredibly and increasingly uncertain world where people are dissatisfied. And then you are marrying that up with the generative AI models and AI models, large language models that are allowing people to quickly access and vent their frustration, their dissatisfaction in the world. And then you've got a tool that's no longer just saying, Oh, you might be able to make a subject's access request, it's writing the request for you, it's telling you things that you need. And I think one of the big concerns that I have, and one of my sort of wider concerns, and this isn't just about complaints to the ICO, this is a general sort of concern in the world at the moment, is are we going to risk having AI answering AI and people just hiding behind this thing of how do we use AI to answer the AI requests? Right. And I think what that loses, and this is what I'm really passionate about, want to keep talking about, is there's real people either side of that, and the AI is removing that connection, and I think that is really problematic. And one of the things that I talk about with subject access requests, and it's what I was able to talk about privacy spaces, was how can you, as a practitioner, be a little bit more on the front foot to sort of prepare yourself for that, to show to the person, whoa, whoa, whoa, we've got all of this. Because it's very easy to with the the obvious example is someone makes a subject access request and they're asking for absolutely everything, and then they get the response and then they run that through AI, and then AI tells them they're entitled to even more things and they don't really understand it themselves. But on the contrary to that, I've seen a couple of examples where people have received too much information in that they just want something very specific. They've used AI to generate the subject access request, which is telling them they're entitled to everything. And because people don't understand their rights fully, they don't understand how to ask for it, they don't understand that they can perhaps specify, they then end up with bundles and bundles of pages where they think, well, what's all this? I just wanted to find out a specific thing that you hold. So I think that what it's doing is yes, it's making it more accessible, but it's risking sort of people having the conversation of what is it that you want? And I think it's how do you do that? It's very it's easier said than done, of course. But I think there's a human connection point there missing, and how you fix that, I don't know.
RalphI will jump in though, because I don't see the people understanding what they're entitled to as a bad thing. Yes, you've got a tool that now educates you in what you may or may not be entitled to, and yes, you might only have wanted one thing, but your right under law is for all personal data that relates to you. And therefore, if that's what the individual asks for, that's what you have to provide, that's the price of managing data. And I come I've just come across as really unsympathetic. Please don't think I'm unsympathetic to the controllers and processors who are processing the process.
KOh, you're completely unsympathetic.
RalphWho have got to deal with this? Please don't think that I'm unsympathetic to the hardworking staff at the ICO. I whatever my criticism is of the policy position, we're all good people trying to do good things for other good human beings, right? So good people at the Ice Wall, good people with good intentions. Trevor Burrus, Jr.
KAnd I've tried to get my my team to do this as well. When someone asks for everything, reassure them, yes, we're going to collect everything for you and respond back. But is there something in particular that you're looking for, we're happy to find that first and go ahead and send it along while we compile the rest of the request. Because quite often they are looking for one thing, right? I want to find that horrible email from blank blank, whatever.
PaulAaron Powell And that is something that I wouldn't provide. Because it I would not provide the copy of the email.
KIt doesn't necessarily mean they get it.
PaulBecause it's not part of age protection. It's the email itself is not personal data. They can have the personal data that's in the email, but it's not an e-evidence request.
KAaron Powell But my point was if they're looking for something in particular, nothing stops you from asking them, assuring them you're going to react to the entire request. But is there something in particular you're looking for?
RalphAaron Powell And this is one of the problems we've always had. The law says you don't have to provide it if you're manifestly unfounded, abuse or process. And also said if you're looking for legal discovery, then you should use the legal discovery process. But the law also said they're purpose blind and you're allowed, not allowed to ask why. So you've got this like, you can say no if it's for the wrong reason, but you're not allowed to ask the reason. So let me tell you a story, Don. You've got a person with a read, they're really upset. They um they're really upset, they put in a subject access request. The person spends up to a calendar month on answering that subject access request. In fact, even worse, they suddenly say, hey, it's complex. We're going to take a further two, three months down the line. Now, under the Date Use and Access Act, the individual can then complain to that controller, can't go directly to the ICO, has to go to that controller. They have, I know they can go to the ICO, but the ICO will probably say, Have you gone to the controller? And then the controller then has 30 days to acknowledge, deals with their complaints process, so we're now four, five, six months on. Then the person complains to the ICO, and then it goes into the triage process. And in all likelihood, 50% of the time, perhaps, it's decided it's not something that's worthy of investigation. Now that person is now seven, eight months down the line before things are ultimately said no, even if they say yes. What is it, thirty weeks to a case officer now? Yes, it's longer than that at the moment, yeah. Longer than that. And then the and then looking at the statistics, it's what? And forget it something like 67% informal uh sixty-seven percent no further action, thirty-three percent informal response, statistically negligible chance of enforcement. You're in the 0.0. And I appreciate the resources, I appreciate the difficulty the ICO has. But how is that good for the individual?
DomI think what I would say is this is the this is the unique position I think the ICO has always found itself in in terms of I think we're unique in the sense that we are a regulator, and so it is our role to be an and we're also unique in that we're a cross-economy regulator. We have to deal with large government departments, we also have to deal with the one-man band and everything in between. And so we have to, as a regulator, have an impact to improve information rights, and the new strategy is obviously around building trust within the UK and I guess beyond. So this when you're on track to receive the number of cases we're receiving, we're not realistically going to be able to deal with those 100,000. So we then have to think strategically about okay, how does that individual who's not received their SR, whilst we might not be able to satisfy that individual, what can we do as a regulator to reduce the chances of individuals not being able to get subject to access requests responded to in the future? And that is to then look at which organizations are particularly bad at this, which organizations are getting it wrong. Let's go for them first, because that's impacting more people. And by being more targeted and more strategic with which cases we take forward, we can then look at okay, what can we do in that space? Because I completely take your point around very few go through to actual investigation. A lot of that is the logistics of how we manage things. And again, the proportionality of it all, because someone not getting a response to the subject's access request is not going to trigger an investigation. But what might trigger an investigation is when we spot actually organ this this organization A, they have they continuously do this, so there's a root problem there. So we want to be more strategic at going after them, so that one, it'll mean that we can be more targeted in terms of the organizations that are particularly poor, where it's a systemic failing of the organization as opposed to perhaps a one-off incident. And two, longer term, and this is longer term, and this is where we should rightly be challenged and critiqued as this continues, is as we take that action and as we target that action, that will hopefully send out more of a message of you need to get this right because of X, Y, and Z. And that will allow us to move into that space where we can do more. Because I completely understand from an outsider's perspective, you look at those stats that you've just reeled off and it goes, what are you doing with complaints? But equally, there were lots of complaints where a little bit of an ICO intervention, a little bit of a a nudge, a little bit some of those cases which you said they were perhaps informal, or even the ones that get recorded no further action, sometimes it just coming to us can be enough of an organization to say, Oh yeah, we need to get on with this, that the complaints come to us. So I think it's I understand where you're coming from, but I think what we're saying is to target it appropriately and proportionately and to actually have an impact, we do need to be strategic. As I said, by trying to do everything, we'll risk doing nothing. So actually, let's be more targeted. I appreciate that that means that sometimes we're going to make decisions that people don't like and they don't benefit from it. To sort of an analogy I've been using recently on this point is we're a little bit like a referee. And I so my my football team, my soccer team, Stoke City, every week I go and I blame the refs, and the refs are useless, they're awful, they're biased, they're absolutely incompetent. I will go on Twitter and absolutely say what I think about them. And then when I take a step back and look at it and go, what is it I actually want from the referees? They're always going to make decisions I don't like. That's the nature of it. And referees are always going to come under criticism, and they should. They do get things wrong. They it's fair game, they deserve to be scrutinized. But actually, what we want what I think people want from a referee, or what I want from a referee, is I want consistency. I want to go, okay, what is the benchmark? What are the rules that you are applying to this game, and how are you going to consistently apply it? And the ICO, in my view, is a little bit like a regulator. We get a complaint from a data subject or a member of the public, and whatever decision we make, we either risk upsetting or annoying the data control. And then there's plenty of organizations. I go to conferences where DPOs tell me how we're on the side of the complainant, and then you listen to you ask our case officers whether the complainants think we're on the side of the complainant, and they'll say, No, you're in the back pocket of these organizations. So we're in that, we are a bit like, and it would be easy to say, oh, therefore, we're damned if we do, we're damned if we don't. I don't see it like that. I see it as, you know what, it's fair game that sometimes we're going to make decisions that people don't like. It's fair game that we're criticized. We should, I think it's healthy that there's a debate that people care about how we're regulating. I think that's really good. But what we need to do as a regulator, and I think this is what our new date protection transformation program does, is it sets out what we're going to do with cases. This is how we're going to triage them. This is what the threshold approach looks like in terms of us potentially asking further questions. These are the types of cases that we consider high harm where we will give our attention. Is it going to be perfect? No. Do we want will we constantly want to improve it? Yes. But is it also important that people critique it and hold us to account? Also, yes. And I think that's how I see it is we are here to basically referee the landscape. We've got to, well, it's not that we want to please everyone, but I think actually what we do need to do is consistency. And so people aren't getting the unexpected. And again, I think one of the risks of us continuing casework the way we were doing is it did lead to that unexpectated unexpectation of what will the ICO do with this? Why have you done that with this case? But this exact same case you've done something completely different with. And I think that's because it's really difficult with the volumes we're getting to be consistent without a framework. And that's what this framework provides. So it's the early days. I think it's really healthy that there's a debate about it. But one of the reasons why I wanted to sort of, I'm so passionate about talking about it is because I want us to be a better regulator. I want us to get things right, and I'm genuinely curious about the concerns around it, but also outlining, like, look, yeah, so that individual valve that you talked about, yeah, sometimes we are going to make a decision that they don't like, that they're not going to benefit from. But actually, let's create a level playing field for everyone so they understand what we're interested in, what we're going to look at, and hopefully that can move us into a place where our complaints function does tie into the rest of the ICO in a in a more seamless fashion and does help us be a better regulator.
PaulSo, Ralph, the conclusion is that you are a hooligan screaming at the referee. I I do to a large extent agree, Dom, that also the informal resolution trajectory sometimes could be an easier fix also for the data subject, that a phone call from the ICO or a stern letter already helps to move the data controller into compliance. Yeah. My main concern there, and that's not specifically for the ICO, I've been saying that on this podcast for the better part of 300 and something episodes, is that we don't see a lot of detail from the data protection authorities on that informal conflict resolution. Whereas that is also a form of interpreting data protection law. It's not through the yeah. So if you talk about a level playing field and consistency, it is also important for other data controllers to learn from the informal resolution that is taking place. And I would love to see more from any data protection authority. For example, in their annual report with a summary of, okay, so this is, I don't know, the top 25 of informal resolutions that we've done this year. This is how we interpreted the law, and this is the lesson learned for other data controllers out there.
DomYeah, I like that suggestion. I think, as I said, what one of the things that we want to, or one of the things that I talk about, and I think what the ICO does want to be better at is how can we do that? And I think again, given the position that we're in as a complaints department, we haven't really got the breathing space to think about the more creative, proactive things that we could do. So again, another benefit, hopefully, of this framework down the line is it I'm not saying we'll necessarily do that, but it will give us the opportunity to have more conversations around what can we do as a regulator to promote good practice based off case studies, based off things that we are seeing. So yeah, that again, that was part of the design of this model. It has been more tricky because when we designed the model, it was designed when we were looking at, as I said, three and a half, four thousand cases a month. And it's more than doubled in that two years. So it is, we're not quite in the position we thought. We knew it would probably go up, but not to the extent that it has. But no, I think that's what we're always looking to do as a regulator is how can we be more innovative and creative to get that message out there. But the starting point is having that framework.
RalphSo I've got one last question because we do like to bring these in at a fairly decent time. You talk about being consistent. Now, this is perhaps one where I do have a lot of sympathy for the ICO because it's all change, right? There's no the ICO is now going to be the Information Commission. I'm not going to talk too much about the elephant in the room, but there's been leadership changes at the top. You're moving from Wilmslow to Manchester, and there's been a little bit more regionalization as well. So it must be a turbulent place to work, let's put it that way. As well as I was on a webinar today from the Open Data Institute about DCMS consultations, changes to data protection law or AI and international data transfers and all this kind of good stuff. So, how is the ICO providing consistency? What does the future hold in a time where the ICO itself is in a massive state of flux? And my kind of heart goes out to you, Dom.
KQuick question there, Dom, right? Quick question. Yeah.
DomI think what I would say is like on look, the ICO is full of brilliant colleagues that are doing brilliant work. And like the Manchester Office Move, I'm personally quite excited about it. So it's natural, it's change, right? And certainly a logistical change like the Manchester Office Move. There'll be some colleagues that happy days, perfect. There'll be other colleagues where it'll be now more difficult for them to commute in or whatever. So naturally it depends who you asking the ICO what their view on is on that. I'm personally excited for that. I think politically it is perhaps a potentially good move. I think it ties in quite nicely at the moment with Andy Burnham moving the government up north, and that's completely coincidential, but it is quite nice. There's Manchester, and I'm biased because I'm for for people outside the UK, Wilm or people that don't aren't from the north of the UK, Wilmslow is like a 15-minute, 20-minute train journey into Manchester city centre. So Wilmslow is pretty close to Manchester, it's not geographically miles away. So, but I think politically it perhaps puts on the map a little bit more in terms of people know Manchester, they know where it is. And I think so that that's quite exciting. So I think yes, there's lots of change. I think the day job is continuing as is, and as I said, there's lots of colleagues doing lots of good work. We've got a new part of the duo stuff, is that we need to have a strategy. Obviously, there's the governance change. So at the moment, I wouldn't describe it as turbulent per se. I would say it's definitely a time of change, and we're still navigating that a little bit in terms of what does that look like. But I think the things that aren't going to change from a complaints perspective is unhappy people make complaints and they want that to be resolved, and that's going forward. I don't think is going to change too much, and that's what we're very much focused on in my area is how do we deliver an ICO that works for people. And I think some of the changes will help with that, to be honest. So I think that it's a good opportunity for us as an organization to think about the future of regulation, as you'll be well aware, it's very difficult to regulate in this world at the moment in terms of how quickly things like new technology are moving forwards and the governance structures and things. Yeah, they're a formality, but from a ground point of view, people are going to complain, and we need to be in the best position to respond to those complaints, regardless of what a change in legislation might say, or what a governance structure might do, or what a government department might look like. So I think that it's quite an exciting time, and I think it's a time where we can really start to think as an ICO, how can we? I think the Manchester office move is a big sort of it feels like quite a nice time for us to move there, a bit of a fresh start for us with the duo and the governance structure. So yeah, I'm not sure I'd call it turbulent. I think I would say it's a time of change, definitely, and some people like change more than others. I personally quite like change, so I'm embracing it. So yeah, we'll see. But I think as as I said, my my drive now and is how can we as an ICO and how can I shed a light into what we're doing? That's what I want to see us do more of is things like this engagement, go out and speak openly and honestly. And I think there is an appetite again with the ICO to do that. I am going to quickly plug our conference, which is the Data Protection Practitioners Conference, on Tuesday, the 13th of October. You can sign up on our website. Last year, I think we've got about 7,000 people sign up. This year, whilst it is virtual, it is going a lot of it is going to be recorded live from our new Manchester office in the studio setting. And it's quite exciting. And I think it's going to bring a whole new dynamic in terms of how we present. So it's not just going to be slideshows, it's going to be different things. There's talk of, I don't know where it's up to, there's talk of a quiz show potentially around your complaints. So we're doing things a little bit differently. And I think that one of the things I'm really passionate about moving forwards with the ICO is how can we be better at engaging? How can we get our message out there so that we can show that we are a regulator that can have an impact? So, yeah, that's very much what I would say is the current mood for me at the ICO at the moment, Ralph.
KNice. And that's a good note, Dean, Don.
RalphRalph, working to leave work. Thank you very much, Dom. We do appreciate you coming on and here's for the future and uh more open ICO and look forward to uh seeing you around the circuit. Yeah, likewise. Thanks.
DomThank you so much for having me. I appreciate it. Thank you. Thank you.
PaulAnd until next week, goodbye.
KBye, y'all.
TimNow that was serious privacy. Please subscribe on your favorite podcast app and leave us a review. You can find us on LinkedIn, Instagram, and Blue Sky at Serious Privacy. Feel free to drop us a question or a comment. We'd love to hear from you.