PUBLICTEC | DATA PROTECTION UPDATE
May 2026 | Public Sector
Practical updates. Regulatory developments. Stronger information governance.
May has brought three particularly important developments: the countdown to new data protection complaints requirements, new ICO guidance on AI-generated FOI requests, and a major cyber-security enforcement action.
🤖 ICO responds to the rise of AI-generated FOI requests
On 6 May, the ICO published dedicated guidance to help public authorities deal with requests created using artificial intelligence.
Public authorities reported receiving more requests that are lengthy, complex, require clarification, or incorrectly quote legislation.
Important principle
An FOI request does not become invalid simply because AI was used to produce it.
Authorities should apply the same legal principles regardless of how the request was drafted.
PublicTec View
AI may dramatically reduce the effort required for someone to produce numerous complicated requests.
FOI teams should therefore focus on:
- •Efficient triage → Clarification → Good records → Search processes → Case management → Publication schemes
⏰ New complaints requirement only weeks away
On 19 May, the ICO reminded organisations that new statutory data protection complaints requirements would take effect on 19 June 2026.
Organisations would need to provide a clear complaints route, acknowledge complaints within 30 days, investigate appropriately and communicate the outcome.
Public-sector preparation
Review how a data protection complaint moves between:
- •Customer Services → Corporate Complaints → Information Governance → Legal → DPO
A complaint should not disappear between different organisational teams because nobody identifies its data protection component.
🔐 Nearly £1m cyber fine provides major warning
The ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 following a major cyber attack affecting 633,887 people.
The investigation identified inadequate monitoring, obsolete software, unpatched critical systems and weaknesses in vulnerability management. Only 5% of the IT environment was being monitored.
PublicTec View
Although this particular enforcement action related to a utility provider, the lessons are directly applicable to public services.
The ICO expects basic cyber-security controls to work.
Boards should receive assurance covering:
- •Patching → Vulnerabilities → MFA → Privileged accounts → Logging → EDR → Backups → Recovery testing
🧠 ICO sets direction for AI regulation
On 29 May, the ICO published its response to government on enabling safe AI-powered innovation.
Its planned work includes providing greater certainty around AI, automated decision-making and biometrics, including development of an AI code of practice and guidance relating to agentic AI. The work explicitly covers the private and public sectors.
Public-sector question
Do you actually know where AI is already being used?
Consider:
- •Microsoft 365 → HR → Recruitment → Contact centres → Fraud → Benefits → Social care → Case management → Transcription → Analytics
An organisational AI register is becoming an increasingly useful governance control.
✅ MAY PUBLIC SECTOR CHECKLIST
01 | Complaints process Be ready before 19 June.
02 | AI FOI Brief FOI officers on the ICO's new guidance.
03 | Cyber assurance Ask for current vulnerability and patching metrics.
04 | AI register Identify AI already deployed across departments.
05 | DPIAs Review high-risk AI and automated processing.
06 | Leadership assurance Put data protection and cyber risk onto appropriate governance agendas.
PublicTec Technology | Data Protection | Governance
Practical support. Clear advice. Better governance.
This newsletter provides general information and guidance and should not be treated as legal advice. Individual circumstances should always be considered when making data protection decisions.