Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

Similarly, the Investigatory Powers Act 2016 (IPA) and the Regulation of Investigatory Powers Act 2000 (RIPA) regulate electronic surveillance and intercep - tion in the UK and contain associated safeguards. These laws are increasingly being enforced by UK governmental authorities – including the ICO and sector-specific regulators such as the FCA – as well as by private individuals and organisations. Regula - tors are also increasingly collaborating on cyberse - curity enforcement; for example, the ICO has teamed up with: • the Competition and Markets Authority; • the Office of Communications (Ofcom); and • the FCA to form the Digital Regulation Co-opera - tion Forum (DRCF). In addition to legislation, English “common law” con - tains rules that are relevant to cybersecurity. There is a legal and ethical duty of confidence: information shared in confidence must not be disclosed without legal authority. The duty applies to information not already in the public domain and is subject to a num - ber of exceptions, including where disclosure: • has been consented to by the discloser; or • is required by law. The FCA rules, the PSRs, the OSA, the IPA, the RIPA and other sector-specific or specialised laws or the common-law duty of confidence are not further con - sidered in this guide. 1.3 Cybersecurity Regulators The competent UK regulator can differ for each of the key UK cybersecurity legislations under consideration. UK GDPR and DPA In the UK, the ICO – which will be reconstituted as the “Information Commission” as mandated by the Data (Use and Access) Act 2025 (the “DUA Act”) – is responsible for monitoring the application of the UK GDPR and the DPA and taking enforcement action against organisations for non-compliance with such legislation, including investigating personal data breaches and inadequate security measures. The ICO may initiate an investigation of its own accord

or based on a complaint submitted by, for example, a private individual or organisation. The ICO also has the power to conduct both off-site and on-site audits. Please note that prosecutions under the DPA can only be brought by the ICO or by (or with the consent of) the Director of Public Prosecutions (DPP). In November 2025, the ICO published new draft guidance on how it proposes to conduct data protection investigations and enforcement actions, including when and how it expects to use its new investigative and enforcement powers granted under the DUA Act. NIS Regulations Under the NIS Regulations, the “competent author - ity” is determined on an industry-by-industry basis by the DSIT, which oversees the implementation of the NIS Regulations across the UK. For OESs in the oil sector, for example, the competent authority in Eng - land, Scotland and Wales is the Secretary of State for Energy Security and Net Zero – whereas in Northern Ireland it is the Department of Finance. The ICO is the competent authority for RDSPs. Competent authorities may be reactive or proactive in the incidents they choose to investigate, and they are supported by the National Cyber Security Cen - tre (NCSC), which offers technical advice (except in healthcare, where this support is provided by the National Health Service (NHS) Digital). Certain organi - sations are also subject to regular compliance audits from their relevant competent authority – failing these audits can lead to fines of up to the greater of 4% of annual worldwide turnover or GBP17 million. PECR and CA 2003 As regards the PECR, the ICO may audit service pro - viders’ compliance under Regulation 5B of the PECR. Notifiable personal data breaches under Regulation 5A of the PECR must be reported to the ICO. The ICO is, in turn, responsible for investigating the breach and taking any subsequent enforcement action. However, with regard to the CA 2003 (a companion to the PECR), Ofcom is the primary regulator. Pur - suant to Section 105C of the CA 2003, Ofcom may carry out an audit of the security measures taken by a network provider or a service provider under Section 105A. Notifiable security breaches under Section 105

444 CHAMBERS.COM

Powered by