Earlier quoted context omitted.
The ICO can fine, but almost certainly won't. It's a failed regulator.
> It's a failed regulator. Not sure I would go this far, but I do agree with this > The ICO can fine, but almost certainly won't But only because one the U.K. leaves the EU, the ICO will struggle to actually enforce its fines when all of the companies involved are notional operating in the EU with little direct presence in the U.K.
Both for competence reasons (see also: the collapse of the AIQ enforcement, and the climb-downs in Mariot and BA cases) and for... I don't know why in the adtech case.
The ICO has evidence of wide-scale criminal behaviour in the adtech industry.
And yet they flat-out refuse to take enforcement action.
They're even proud of the fact they're refusing to do their job - they put it in their annual report!
And even in their non-data protection duties, they've all but given up enforcing the Freedom of Information Act. Statutory timelines are apparently now utterly meaningless. The ICO has even stopped publishing data on compliance levels.
It looks like Denham wants to spend her time as Information Commissioner issuing tough-sounding press releases and threatening (but ultimately flawed) pre-enforcement notices and then using the publicity from those to become a Thought Leader in AI ethics.