The Information Commissioner’s Office has reached a new memorandum of understanding (MoU) with the UK government in an effort to restore public trust after a series of data breaches and incidents within UK government departments.
The ICO says that it has been clear that the government must do more and move faster to improve data security as part of its wider data protection practices.
UK government departments have faced a number of high profile data breaches over the years, including the leak of a database of tens of thousands of Afghans to the public, which compromised their safety.
The UK government has also come under scrutiny for the data breach concerning about 10,000 officers of the Police Service of Northern Ireland. Another data leak exposed data concerning about 200 victims of abuse from the Church of England to the public, while the Legal Aid Agency breach saw sensitive data surrounding criminal cases exposed.
The new MoU sets out expectations and responsibilities for both the UK government and the ICO with a goal of building back public trust in their data security.
Both parties have agreed to work collaboratively and transparently to ensure a free flow of information is available to each party.
Within the agreement, the government’s responsibilities include publishing annual assurance statements to the public on how their data is being kept safe, as well as carrying out regular assurance exercises within various departments.
The government will turn to the ICO for expert advice as it expands and deepens a data safety culture throughout its various departments, setting out clear goals to track progress.
The MoU holds the government responsible for enacting a privacy and trust by design approach to the use of personal data or new technologies, with guidance from the ICO.
The government will also provide effective oversight through an accountable governance model to the Transformation Board, which will entail risk and audit boards regularly monitoring department-wide data protection risks and tracking progress.
Recommended reading
- ICO Reprimands NHS Highland for “Serious” Data Breach
- UK Gov Data Breaches Exposed 10K Customers’ Data, FOI Reveals
- MOD Data Breach Put Thousands of Afghan Lives at Risk
- Who Was Behind the Ministry of Defence Hack?
- UK Gov Cyber Breaches Survey 2024 | Key Stats and Data
In turn, the ICO will be responsible for working with the government to use insights to inform guidance and resources for departments, provide expert advice on best practice, and regularly visit the government’s Transformation Board for review.
“Where standards are not met or maintained, the MOU reinforces the mechanisms available to us to hold government to account and take appropriate action where necessary,” the ICO said in its statement on the MoU.
The new MoU follows the publication of the Information Security Review 2023 in August 2025, which investigated 11 incidents of data breaches within UK government departments. Ministers questioned why the government had yet to only implement 12 of the 14 recommendations outlined in the review.





