Data analysed by cybersecurity and data privacy experts at Bridewell from the Information Commissioner’s Office (ICO) reveals that data privacy complaints across several major UK industries have continued to rise year-on-year.
The increase highlights growing public awareness and scrutiny around the handling of personal data. Complaints have been made to the ICO by members of the public about data protection concerns.
The research analyses complaints made between October 2023 and September 2024 and October 2024 and September 2025. It shows that the finance, health and online technology and telecoms sectors received the highest number of complaints across both reporting years.
The finance, insurance and credit sector received the highest number of complaints both years. Between October 2023 and September 2024, there were 4,422 complaints made to the ICO, which increased by 5% between October 2024 and September 2025 to 4,630. The high number of complaints in this sector highlights the continued pressure on organisations that process large volumes of sensitive financial data.
The health sector ranked second for complaint volumes, with cases increasing from 3,903 to 4,082, a rise of 179 complaints year-on-year. The trend reflects the complex data protection challenges faced by healthcare providers and related organisations managing highly sensitive personal information.
While the retail and manufacturing sectors had fewer data privacy complaints, they saw the sharpest year-on-year increase. Complaints rose 12% from 2,421 between October 2023 and September 2024 to 2,714 between October 2024 and September 2025.
While there are rising complaint volumes, the analysis identified a 22% decrease in cases resulting in informal action responses when comparing the period from October 2023 to September 2024 with October 2024 to September 2025. At the same time, there has been a 14% increase in instances in which investigations concluded with ‘No Further Action’ taken.
This trend may indicate a shift toward higher enforcement thresholds, with regulators prioritising cases that demonstrate clear risk, harm, or repeated non-compliance. In situations where no further action is taken, the stated rationale is often that insufficient information was provided.
This highlights the importance of assessing the level of harm, and maintaining thorough documentation of any harm experienced as a result of the organisation’s handling of personal information.
Recommended reading
- ICO: Data Protection Not An Excuse When Tackling Scams, Fraud
- Only Half Of UK Businesses Report Full Data Privacy Compliance
- ICO Tackles Data Protection Compliance on UK’s Top 1,000 Websites
Bridewell’s Cyber Security in Financial Services report revealed 39% of organisations consider data privacy and protection one of their biggest cybersecurity challenges.
Organisations operating in highly regulated or data-intensive sectors are facing growing pressure to strengthen governance, improve incident response readiness and demonstrate accountability in how they handle personal data.
“Rising complaint volumes in sectors like financial services and healthcare show that public expectations around data protection continue to grow,” Chris Linnell, associate director of data privacy at Bridewell said.
“Organisations can’t treat privacy as a compliance box-ticking exercise; it must be central to business operations.”
The findings come amid increased regulatory scrutiny around the protection of personal data, including enforcement action against organisations that fail to safeguard children’s privacy or implement appropriate safeguards.
Most recently, Reddit was fined over £14 million for failures to carry out a data protection impact assessment and not checking the age of users accessing its platform.
“Cases like this highlight the escalating reputational, financial, and operational costs of inadequate privacy controls,” Linnell added.





