Data Protection Insight: Preparing for October 2025

Date Posted:Tue, 30th Sep 2025

Data Protection Insight: Preparing for October 2025

September brought several developments pointing in the same direction. Schools face new safeguarding expectations, age assurance is moving from theory into practice, the ICO has stepped up action on Subject Access Requests (SARs), and a nursery chain has suffered a major cyber attack.

 

The common theme is clear- policies on paper are not enough. Regulators expect to see compliance in practice, backed by evidence.

Although some headlines focus on education and local authorities, the lessons apply to every organisation- finance, retail, shipping, healthcare, marketing, and higher education included.

The real test is simple:

can you show that the appropriate people have the appropriate access to the appropriate data, and that no one else does? 

Two Wake-Up Calls: A Nursery Breach and a SAR Enforcement

The Kido nursery incident

A group calling itself Radiant broke into systems used by an international nursery chain and published samples of children’s profiles. They claim to hold data on about 8,000 children and even contacted some parents with ransom demands. The ICO and the NCSC are investigating with law enforcement. This is a strong reminder that organisations holding sensitive data: early years, education, care, and healthcare are prime targets for criminals. 

The lesson for all controllers: incident response must be more than a document saved in a folder.

 Precautionary steps data controllers can take:

  • Restrict access to photos and records on a need-to-know basis
  • enable multi-factor authentication by default
  • practise how you would warn affected people,
  • inform regulators, and restore services.
  • if you use third-party apps for parent communication or photos, check contracts, access logs, and refresh credentials now. 

Bristol City Council’s SAR enforcement

After years of delay and 63 complaints between April 2023 and January 2025, the ICO has issued an enforcement notice against the Council. Some people reported distress because they could not access their information on time.

The ICO made its position very clear. Sally-Anne Poole, Head of Investigations, said:

“Subject access requests are a fundamental right that allows people to know what information organisations hold about them and how it is being used. Despite our repeated engagement with Bristol City Council over a sustained period of time, limited progress has been made to clear a backlog of requests. Our investigation has found that the Council’s approach towards compliance demonstrates a poor organisational attitude towards data rights and compliance with the law. This enforcement notice requires them to clear their SAR backlog in a timely manner, and make lasting improvements to bring their practices in line with the law.”

 The notice requires the Council to:

  1. Contact everyone with overdue SARs and explain the delays.
  2. Clear the oldest cases within 30 days.
  3. Provide weekly updates to the ICO until the backlog is resolved.
  4. Produce an action plan within 90 days, setting out responsibilities and timelines.
  5. Within 12 months, fix systems and processes so future SARs are completed on time, with proper staffing and training. 

The lesson for all controllers: SAR discipline is a core duty, not a ‘nice-to-have’. Keep a live SAR register, track deadlines, resource the function properly, and test your process quarterly with a mock request from start to finish. 

What Every Controller Can Do Now 

  • Access – Reduce privileges to what people truly need and record the justification.
  • Awareness – Run regular phishing tests for departments such as finance, HR, marketing and logistics teams, who are most often targeted.
  • Evidence – Keep logs, training records, DPIAs and Board updates ready.

If a regulator asked tomorrow, could you prove your policies are being followed? 

Education in the Spotlight

Schools and colleges

Keeping Children Safe in Education 2025 puts renewed focus on secure safeguarding records with access controls. Attendance registers are now safeguarding tools, so accuracy and secure sharing with local authorities are vital. Data Sharing Agreements should be logged in the Record of Processing Activities, and behaviour or attendance data must not sit in open spreadsheets. From 10 November, Ofsted will begin using the new ‘report card’ in volunteer schools, with inspections starting in December. By September 2026, schools must also plan how RSHE data will be protected and only shared when necessary.

Universities

Where AI affects admissions or student support, human oversight is expected. Cross-border research requires GDPR safeguards and Transfer Impact Assessments. Student records and research datasets continue to attract ransomware groups. 

The message is the same:

do not just document compliance, be ready to show it through access logs, training evidence, and auditable processes.

 Age Assurance: Turning Principles into Practice

With the Online Safety Act now in force, more services are adopting age assurance. Done well, it protects children, done poorly it creates new risks.

Five steps controllers should follow:

The ICO has approved two certification schemes:

Age Appropriate Design Certification Scheme – for services used by children.

Age Check Certification Scheme – for providers of age-assurance solutions.

This applies beyond gaming and social media, e-learning platforms, age-restricted retailers, and marketers who segment by age must also comply. 

United Kingdom – Regulators are focusing on the use of automated decision-making and AI tools. Organisations must provide transparency and clear explanations where automated systems significantly affect people—for example, in credit scoring, price setting, or automated grading. The ICO expects businesses to be able to explain how these tools work in practice, what data feeds into them, and how risks of unfair outcomes are being managed.

European Union – Enforcement action is rising. Regulators have issued fines against organisations for late responses to Subject Access Requests (SARs) and for for relying on unclear, ‘one-size-fits-all’ privacy notices that leave individuals uninformed. Controllers are expected to provide specific, timely, and accessible information, backed by evidence of compliance.

Saudi Arabia – The Personal Data Protection Law (PDPL) requires that information given to individuals is clear and easy to understand, often meaning Arabic in practice. Proposed amendments for 2025 are set to strengthen these obligations, particularly around transparency, and individual rights. Organisations operating in the Kingdom should prepare now for tighter requirements.

United Arab Emirates – The UAE Data Office continues to stress the importance of sector-level compliance and readiness for breaches. Supervisory activity is expected to grow in 2025, with a focus on demonstrating practical evidence of compliance, not just written policies. Organisations should keep incident response and breach notification procedures under review.

DIFC – Regulation 10 on AI. Firms operating in the financial centre are required to map their AI systems, assess risks, and assemble evidence of compliance. The DIFC provides guidance and an AI Accelerator programme to help organisations benchmark their systems. While this is sector-specific, the direction of travel is clear: evidence-based AI governance is becoming the standard expectation. 

TenIntelligence Thoughts

Having policies on paper is not enough, regulators want proof that they are being lived day to day.

For schools, that means showing safeguarding records and registers are kept secure. For universities, it is about controlling admissions and research data.

For businesses, it means keeping systems and customer records safe. For marketing teams, it means using contact lists and tracking tools in the right way. For online platforms, it means making sure age checks are legal and fair

Real compliance means being able to show your work, not just write it down. 

If you have questions or would like help with any of the issues raised in this newsletter, please submit your query here.

Written by

Lynsey Hanson | Global Data Protection Officer

Click here to read the original article.