Privacy notice

Privacy notice

This privacy notice tells you what to expect when you use the ICO’s blogger site. Blogger is a Google product so we recommended you also read the Google privacy notice here to find out how and why it is processing your data and how you can exercise your data protection rights. 


This privacy notice will tell you;
  • What personal data we process
  • The purpose and legal basis for processing
  • What we do with the information you provide us
  • How long we keep this information
  • What are your rights?

What personal data we process

We will only process your personal data if you choose to give this to us when you;
  • comment on our blog post; 
  • sign up to receive email notifications about new posts and you provide your personal email address; or
  • you choose to email us directly.
The personal data we process can include your google account username and your email address. Additionally, if you include your name or any other personal data in your comments this will be processed by us.

You are however able to leave comments anonymously if you wish and we would discourage you from including any personal data within your comments. We will delete any comment from the platform that includes special category personal data. 

The purpose and legal basis for processing

If you provide us your personal data when you comment on our blog post the lawful basis we are relying on to process your personal data is article 6(1)(e) of the GDPR, which allows us to process personal data when this is necessary for the performance of our public tasks in our capacity as a regulator.

If you choose to provide your email address to us to receive updates when a new blog post is published the lawful basis we are relying on to process this information is your consent under article 6(1)(a) of the GDPR. This means you have the right to withdraw your consent, or to object to the processing of your personal data for this purpose at any time. If you do that, we’ll update our records immediately to reflect your wishes

What we do with the information you provide us

In order to create an auditing framework that is fit for purpose, it is essential we consult actively with stakeholders. We have determined that for this stage of the consultation a blog with a comment function is the best way to collect this feedback. Our purpose for collecting this information is so you are able to make comments about the information we provide in our blogs and enter into a public debate about the subject matter. We will process any other personal data provided in the responses for the purpose of informing the development of our framework and guidance.

If you posted a comment you are able to delete this yourself at any point. You can also email the ICO at AIAuditingFramework@ico.org.uk to request the comment be deleted at any time. 

How long we keep this information

The blog site will remain active until the consultation concludes in Summer 2020 and we will retain some information after the closure of the blog in line with our retention schedule. All comments will therefore remain live until then so we can refer back to them if necessary.

What are your rights?

Under data protection law, you have rights we need to make you aware of. The rights available to you depend on our reason for processing your information. You can find out more information about your rights in relation to our processing here.