ICO admits it takes over six months to assign officer to information disuse cases: "A clear incentive for non-compliance"
THE Information Commissioner's Office (ICO) own website admits it takes 29 weeks to assign a case officer as experts warned it is "a clear incentive for non-compliance".
The ICO’s own complaints page says data protection complaints are being assigned to case officers within 29 weeks of submission.
This means that making a complaint about how an organisation has used your personal information will take over six months.
HR experts and business owners have hit out at the length of time it takes.
Kate Underwood, Founder at Southampton-based Kate Underwood HR and Training, said that “if your personal data is being mishandled, shared, or used to make decisions about you, that is 29 weeks where it could still be happening”.
She pointed out that organisations are expected to respond to rights requests like a subject access request within one month.
She added: "If you need the data for a tribunal, the ICO’s 29 week wait is basically sabotage. Employment Tribunal deadlines do not pause because a regulator has a queue. Real life does not pause either. Witnesses move on, systems get updated, emails mysteriously disappear, and suddenly the one thing you needed to prove your case becomes ‘we cannot locate it’. Funny that.
"And what is happening to your personal data while you wait? It can still be processed, stored, shared, or ignored. So are we meant to walk into a tribunal and say, ‘I would love to evidence this properly, but the ICO will assign my complaint in seven months’?
“If data protection rights are real, there should be a fast track for cases linked to live litigation like an employment tribunal, safeguarding concerns, or ongoing harm. Otherwise this is not enforcement. It is admin theatre.”
Colette Mason, Author & AI Consultant at London-based Clever Clogs AI, said a wait of over six months will mean organisations are incentivised to misuse data.
She continued: "The ICO's 29-week assignment window is a clear incentive for non-compliance. While businesses face tight one-month deadlines on subject access requests, the enforcement body operates on a timeline that makes ignoring data protection rules look like the lifestyle choice.
"If your data is being misused right now, that's over six months where the misuse continues unchecked, decisions get made about you, and the organisation knows full well the cavalry won't arrive until well into next year.
"Another British farce worthy of the end of the pier. Are we comfortable calling this system 'data protection' when the only thing it reliably protects is organisations who can't be bothered to comply?"
Kundan Bhaduri, Entrepreneur, Investor and Landlord at London-based The Kushman Group, said it was a “scandal”.
He added: "The way I see it, the real scandal isn't the delay itself – it's what happens to your data while you wait in regulatory purgatory. Your information keeps getting processed, shared, and exploited for half a year while the ICO shuffles paperwork and promises eventual attention.
"Meanwhile, organisations quickly find out that GDPR compliance is essentially voluntary if you're willing to gamble on enforcement delays. The ICO has become a complaints theatre that performs the illusion of data protection while offering none of the substance.
“They're now proposing to make this worse by refusing to investigate many complaints unless there are substantial numbers about the same controller. If your personal information is being misused right now, the regulator's advice is apparently to wait until Christmas and hope someone else complains about the same company.”
Newspage contacted ICO for comment.



