ICO Stresses Importance of Encryption for Data Security
Time 2 Minute Read

On August 28, 2013, on the UK Information Commissioner’s Office’s (“ICO’s”) blog, Simon Rice, Technology Group Manager for the ICO, discussed the importance of encryption as a data security measure. He stated that storing any personal information is “inherently risky” but encryption can be a “simple and effective means” to safeguard personal information and reduce the risk of security breaches.

Rice states that a “big misconception” regarding data security concerns the belief that user logins and passwords can provide protection equivalent to encryption. “[T]his isn’t the case,” writes Rice, “[as] in practice a password can be easily circumvented and full access to the data can be achieved.” Rice sets out two key rules for organizations to follow when using encryption: (1) select an appropriate encryption method; and (2) follow common sense practices to safeguard the encryption key.

Selecting the Correct Encryption Method

The blog aims to educate organizations about encryption and the various encryption methods widely available. Rice stresses the need for organizations to understand the different types of protection that different products offer, and to select an appropriate encryption tool based on the particular facts. The ICO also recommends certain internationally-recognized encryption software standards on its website.

Safeguarding the Encryption Key

The ICO blog highlights common sense practices to protect the encryption key, such as ensuring that laptop encryption keys and passwords are not stored with encrypted laptops, and, when sending encrypted data as an email attachment, the decryption code must not be included in the body of the same email.

Finally, Rice warns of the financial and reputational risks of failing to use encryption properly, citing three recent enforcement actions relating to improper use of encryption where the ICO imposed penalties totalling £700,000.

You May Also Be Interested In

Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office and the UK Office of Communications released a joint statement addressing the intersection of online safety and data protection in relation to age assurance.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 3 Minute Read

On February 27, 2026, the UK ICO announced a public consultation on proposed updates to its guidance concerning research, archiving and statistics to reflect the changes introduced by the Data (Use and Access) Act 2025.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page