Telegram Channel

More...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

More...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

More...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Only letter and space (from 2 till 30 characters)
Enter correct number, ex. +380777777777

ICO Launches Consultation on Draft Guidance for Data Anonymisation in Research

ICO Launches Consultation on Draft Guidance for Data Anonymisation in Research

The UK Information Commissioner’s Office (ICO) has launched a public consultation on new draft guidance. The document addresses anonymisation and pseudonymisation for research, archiving, and statistical purposes. The consultation period will remain open until 19 October 2026.

Target Audience and Regulatory Scope

This draft guidance is particularly relevant for universities, healthcare organizations, and technology providers. Furthermore, the ICO explains how to apply data minimisation principles within modern research environments. In addition, the text clarifies how organizations should approach the new safeguards introduced under the Data (Use and Access) Act 2025 (DUAA).

Mandatory Safeguards and Governance Frameworks

The DUAA requires organizations to implement effective technical and organizational measures for data minimisation. Consequently, identifiability risks must be assessed and managed throughout the entire research lifecycle. To assist with compliance, the ICO highlights the “Five Safes” governance framework. Therefore, adopting this framework helps organizations demonstrate appropriate safety controls across people, projects, settings, data, and outputs.

Limitations of TREs and Synthetic Data

Trusted research environments (TREs), trusted third parties (TTPs), and synthetic data effectively reduce privacy risks. However, these tools do not automatically render data anonymous. In fact, synthetic datasets generated from real personal data can still pose re-identification risks. As a result, organizations must evaluate access models carefully depending on who receives the dataset.

Challenges with Unstructured Datasets

Standard de-identification methods often fail when applied to unstructured formats. Indeed, speech recordings, video feeds, images, and sensor data frequently contain embedded personal attributes. This issue is especially critical for AI developers training models on large sets of clinical notes or behavioral logs. Thus, data minimisation must be embedded into the design stage of every project.

Recommended Immediate Actions

Although the guidance is currently in draft form, organizations should review their practices today. First, research teams need to audit existing DPIAs, access controls, and data-sharing agreements. Second, if identifiable data is required for a project, organizations must clearly justify why anonymised or pseudonymised options are not suitable.

Order service

with our specialists

Only letter and space (from 2 till 30 characters)
Enter correct number, ex. +380777777777
Only name@mail.com format accepted
Only letter, numbers and spaces (from 2 till 30 characters)
Any questions left?

Sign up for free consultation with our specialist

Only letter and space (from 2 till 30 characters)
Enter correct number, ex. +380777777777