Select Page
Author: Adrian Ramdat (Director of Training & Consultancy)

April 2025

IPCO’s Data Assurance Programme 

The Investigatory Powers Commissioner’s Office (IPCO) has emphasised the importance of robust data handling practices in its ongoing Data Assurance Programme. This initiative, launched in response to compliance challenges identified within the UK intelligence community, underscores the necessity of adhering to legal frameworks such as the Investigatory Powers Act (IPA) 2016 and the Regulation of Investigatory Powers Act (RIPA) 2000 (and the Scottish equivalent, RIPSA).

The Importance of Data Assurance

The Data Assurance Programme is designed to inspect and support compliance with the statutory safeguards governing the retention, review, and disposal of data obtained through covert surveillance, the use of covert human intelligence sources (CHIS), and communications data. This effort aligns with other legislative requirements, including the Data Protection Act 2018.

Key objectives of the programme include:

Ensuring Lawful Retention: Verifying that all data obtained under IPCO oversight is retained in compliance with statutory requirements.

Promoting Best Practices: Embedding a culture of adherence to legal obligations across all authorities under IPCO oversight.

Addressing Technical Challenges: Assisting organisations in navigating compliance issues related to the use of diverse data-handling and storage systems.

Challenges in Data Retention

IPCO inspectors have observed several recurring challenges, including:

Prolonged Data Retention: Authorities frequently retain data longer than necessary due to incomplete implementation of retention and disposal policies or a conservative approach to data storage.

Inadequate Disposal Practices: Data often remains on personal devices or email systems without appropriate review or deletion processes.

Technical Limitations: Some storage systems lack functionalities to facilitate timely and secure data disposal.

A cited example highlighted that surveillance data, while initially used legitimately for investigations, was later stored on personal desktops and email systems without clear retention or disposal plans. Such practices contravene surveillance codes of practice and risk undermining public trust.

The Role of the Authorising Officer

Everyone involved in covert activity has a responsibility to manage the product that is obtained in the correct manner but the authorising officer plays a pivotal role in ensuring compliance with data retention, review, and disposal safeguards. IPCO has highlighted the need for authorising officers to:

Understand Data Pathways: Maintain full oversight of how data obtained through IPA and RIPA is handled, stored, and ultimately disposed of within their organisation.

Demonstrate Accountability: Be prepared to justify the retention and handling of data during IPCO inspections, ensuring transparency and adherence to legal requirements.

Strengthening Safeguards

To address these issues, IPCO recommends a proactive approach to data management. Inspections now focus on ensuring that:

  • Safeguarding policies and disposal schedules are current and robust.
  • Data storage systems are secure and designed to support proper data disposal.
  • Staff are trained to minimise unnecessary data duplication and manage data pathways effectively.
  • Authorising officers are equipped to lead their organisation’s compliance efforts.

Authorities are urged to undertake immediate actions, including:

  • Reviewing compliance obligations under IPA and RIPA/RIPSA codes of practice.
  • Updating internal policies to ensure accuracy and relevance.
  • Mapping data pathways to establish clear retention schedules.
  • Ensuring application safeguards reflect organisational practices.
  • Disposing of data retained beyond necessary durations.
  • Empowering authorising officers with the tools and knowledge to effectively oversee data safeguards.

Supporting Lawful and Ethical Practices

IPCO’s Data Assurance Programme represents a critical component of its mandate to uphold lawful and ethical use of investigatory powers. By addressing these challenges, IPCO aims to foster confidence in the integrity of data management practices across public authorities.

Staff are encouraged to engage with IPCO inspectors during their inspections to demonstrate their commitment to safeguarding data. Through these collaborative efforts, the programme aspires to set a high standard for compliance, balancing operational needs with the public's expectation of accountability.

A number of organisations have been criticised by IPCO and given notices of non-compliance, meaning they could lose their powers under RIPA or RIPSA, so these requirements can´t be underestimated or ignored.

If you aren´t aware of these requirements then The Signature Brand is pleased to offer you and your colleagues a RIPA/RIPSA Bitesized even that lasts approx. 90 minutes and is delivered via Ms Teams, in real time which clearly explains the requirements in relation to managing covertly obtained product. Contact us now for further details or to enquire as to we can assist you achieve compliance.