Search

How can we help?

Icon

Most organisations failing to inform users about use of their personal data

The ICO has led a global investigation of website privacy communications on behalf of the Global Privacy Enforcement Network (GPEN) and found many organisations’ data protection practices are lacking.

Globally, GPEN came to the conclusion that in relation to privacy communications, organisations tended to be vague, and lacked specific details. A majority of organisations reviewed also demonstrated failures in:

  • specifying how and where information would be stored;
  • adequately explaining whether data would be shared with third parties and what information would be shared;
  • providing users with a clear means of removing their personal data from a website;
  • making it clear how a user could access data held about them; and,
  • providing information on the safeguarding of data.

Providing users with a clear means of removing their personal data from a website

The findings come as instant messaging giant WhatsApp has received a further warning from the Article 29 Working Party, which found that the information provided on WhatsApp’s privacy policy was “seriously deficient as a form of consent.” It also did not inform users that by agreeing to the terms and conditions, they would be agreeing to their personal data being shared with Facebook group companies. There are also concerns that WhatsApp users are unable to freely consent to data being shared and the Working Party have requested that the company introduces these controls in order to comply with the GDPR.

Clearly, many companies worldwide still have a long way to go to meet upcoming GDPR requirements. These requirements are not only applicable to organisations based within the EU, but also those that do business within the EU. The UK government has confirmed that despite Brexit, the GDPR will apply to the UK.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

Pub
  • 08 January 2026
  • Privacy and Data Protection

Data Protection Audits: Launch Event

Join us for a breakfast networking session on Thursday 26th February 2026 as we officially launch our Data Protection Audit services.

art
  • 08 January 2026
  • Privacy and Data Protection

Data Protection – what’s happened in 2025?

2025 has been a lively year for the data protection sphere, with the main talking point coming from the UK’s data reform Bill finally receiving Royal Assent on 19 June 2025.

art
  • 07 January 2026
  • Commercial Real Estate

Real Estate: update and 2026 expectations

The previous year has been an eventful one for the commercial property sector.

art
  • 06 January 2026
  • Commercial Real Estate

FAQ – Buying a commercial property in England and Wales

If you want to invest in the commercial property market in England and Wales (the two countries share the same jurisdiction), it is important to understand that the process differs significantly from buying a property in France.

art
  • 05 January 2026
  • Immigration

UK Immigration changes in 2025: What to expect in 2026

This wrap-up brings together the key developments from across the year, highlighting what has changed, what is still evolving, and what organisations should be planning for as we move into 2026.

Pub
  • 01 January 2026
  • Public Procurement

Procurement Challenges under the Procurement Act 2023

Taking prompt advice is essential as unsuccessful bidders have just ten days within which to issue court proceedings if they want to benefit from the automatic suspension provided for in the Regulations, which prevents the contracting authority from awarding the contract to anyone else.