Search

How can we help?

Icon

Most organisations failing to inform users about use of their personal data

The ICO has led a global investigation of website privacy communications on behalf of the Global Privacy Enforcement Network (GPEN) and found many organisations’ data protection practices are lacking.

Globally, GPEN came to the conclusion that in relation to privacy communications, organisations tended to be vague, and lacked specific details. A majority of organisations reviewed also demonstrated failures in:

  • specifying how and where information would be stored;
  • adequately explaining whether data would be shared with third parties and what information would be shared;
  • providing users with a clear means of removing their personal data from a website;
  • making it clear how a user could access data held about them; and,
  • providing information on the safeguarding of data.

Providing users with a clear means of removing their personal data from a website

The findings come as instant messaging giant WhatsApp has received a further warning from the Article 29 Working Party, which found that the information provided on WhatsApp’s privacy policy was “seriously deficient as a form of consent.” It also did not inform users that by agreeing to the terms and conditions, they would be agreeing to their personal data being shared with Facebook group companies. There are also concerns that WhatsApp users are unable to freely consent to data being shared and the Working Party have requested that the company introduces these controls in order to comply with the GDPR.

Clearly, many companies worldwide still have a long way to go to meet upcoming GDPR requirements. These requirements are not only applicable to organisations based within the EU, but also those that do business within the EU. The UK government has confirmed that despite Brexit, the GDPR will apply to the UK.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

Pub
  • 16 March 2026
  • Corporate and M&A

Shareholder Disputes: Managing Shareholder Buyouts and Exits – Episode 3

Join Stuart Mullins and Nicky Goringe Larkin for the third and final episode of our Shareholder Disputes series, where we move from prevention to resolution—exploring what happens when a founder’s exit becomes unavoidable.

art
  • 13 March 2026
  • Employment

When Immigration compliance becomes discrimination: The UK’s uncomfortable workplace balance

UK employers today operate under powerful, and some may say conflicting, legal pressures. On one hand, they must prevent illegal working under UK immigration laws.

art
  • 09 March 2026
  • Commercial Real Estate

Commercial Rent Deposits – A brief overview

A rent deposit is money provided by a tenant to its landlord as security for payment of the rent and performance of the tenant’s covenants contained in the lease.

art
  • 03 March 2026
  • Employment

International Women’s Day 2026 – Supporting equality and inclusion for a better, happier workforce

This year, International Women’s Day is inviting everyone to think differently about equality and how it can benefit everyone. The theme this year is ‘Give to Gain’.

art
  • 02 March 2026
  • Employment

10 facts an employer should know about holding personal data

Personal data is any information that can be used to identify an employee.

art
  • 27 February 2026
  • Litigation and dispute resolution

How (not!) to serve a winding up petition on a company using a default address

This case concerned an appeal by DG Resources Ltd (“DG”) on the basis that a winding up petition brought by HMRC (the “Petition”) was invalidly served.