Search

How can we help?

Icon

Most organisations failing to inform users about use of their personal data

The ICO has led a global investigation of website privacy communications on behalf of the Global Privacy Enforcement Network (GPEN) and found many organisations’ data protection practices are lacking.

Globally, GPEN came to the conclusion that in relation to privacy communications, organisations tended to be vague, and lacked specific details. A majority of organisations reviewed also demonstrated failures in:

  • specifying how and where information would be stored;
  • adequately explaining whether data would be shared with third parties and what information would be shared;
  • providing users with a clear means of removing their personal data from a website;
  • making it clear how a user could access data held about them; and,
  • providing information on the safeguarding of data.

Providing users with a clear means of removing their personal data from a website

The findings come as instant messaging giant WhatsApp has received a further warning from the Article 29 Working Party, which found that the information provided on WhatsApp’s privacy policy was “seriously deficient as a form of consent.” It also did not inform users that by agreeing to the terms and conditions, they would be agreeing to their personal data being shared with Facebook group companies. There are also concerns that WhatsApp users are unable to freely consent to data being shared and the Working Party have requested that the company introduces these controls in order to comply with the GDPR.

Clearly, many companies worldwide still have a long way to go to meet upcoming GDPR requirements. These requirements are not only applicable to organisations based within the EU, but also those that do business within the EU. The UK government has confirmed that despite Brexit, the GDPR will apply to the UK.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 02 April 2026
  • Commercial Real Estate

Can I have access to a neighbour’s land to carry out works to my property?

As a landowner, maintaining and repairing your property is important. It may be the case that to do so, you will need to access the land of a neighbour.

art
  • 01 April 2026
  • Privacy and Data Protection

Recognising DSARs: top tips for organisations

The UK GDPR grants Data Subjects, who are the individuals to whom the personal data relates, rights over their personal data, including the rights of access, correction and erasure.

art
  • 30 March 2026
  • Employment

Legislative Changes – What Employers Need to Know for April 2026

With the phased implementation of the Employment Rights Act 2025 (ERA), alongside other legislative updates, April 2026 brings a wide range of important changes for employers.

Pub
  • 27 March 2026
  • Corporate and M&A

Shareholder Disputes: What to do when disputes arise – Episode 4

Join Stuart Mullins and Jack Hobbs for episode four of our Shareholder Disputes podcast series as they confront the realities of shareholder fallouts and share practical strategies for managing these complex situations.

art
  • 24 March 2026
  • Immigration

Spouse Visa – Is your relationship genuine and subsisting?

For years many couples have become frustrated by the requirements for a spouse visa as the rules and guidance are difficult to understand. A significant amount of applications are rejected on the basis of the applicant not providing the adequate documents to evidence the relationship requirement.

art
  • 20 March 2026
  • Corporate and M&A

Drag-Along & Tag-Along Rights: Why Every Company Needs Them

When starting a company, very few founders are aware of the potential issues around shares, share ownership and the implications of that when selling their company.