Reddit’s £14.47m ICO fine — what UK businesses need to do as child protection enforcement ramps up

We break down what the ICO found and outline three key steps that UK businesses should take now.
We make the difference. Talk to us: 0333 004 4488 | hello@brabners.com
The definition of personal data has always been broad. It can include any information which identifies or relates to a living individual. This can either be directly or indirectly from that information in combination with other information.
A previous ICO (Information Commissioners Office) case highlighted that a dog’s name could lead to an individual’s identity being revealed, and this blog covers what is considered personal data and the importance of reviewing all the data you hold.
What is personal data?
The UK GDPR provides us with a non- exhaustive list of identifiers, which includes your name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
What about your dog’s name?
An ICO decision discussed how, via indirect identification, a name of a dog could lead to the identification of a living individual and therefore be considered personal data.
The Police received a request for information under the Freedom of Information Act (FOIA). The person had been bitten by a police dog during an illegal rave and had incurred a number of injuries. The request included the question:
The police refused the request under section 40(2) of the FOIA which provides a non-disclosure exemption for personal information, if it is the personal data of an individual other than the requester and where one of the conditions listed in section 40(3A) (3B) or 40(4A) is satisfied.
Following the non-disclosure, a complaint was made to the ICO. The ICO considered whether the withheld information would constitute personal data and if it was, would the disclosure of the data breach any data protection principles.
Even though an individual cannot be directly identified from the information, it may still be possible to indirectly identify them. Knowing the name of the police dog and undertaking a cursory search of the web with the dog’s name also revealed the name of its handler.
The ability to find out the identity of the police dog handler with this secondary identifying information meant that the dog’s name fell within the definition of personal data.
The ICO also confirmed that indirect identification would be the case in respect of colleagues who, even if the dog’s name was not within the public domain, would still know who the handler was. Therefore, the dog’s name was considered personal data that would identify and relate to the handler.
Whilst this is not a new concept, it does highlight that organisations need to look carefully at how they categorise personal data and reinforces that what constitutes personal data should always be considered on a case-by-case basis.
If you need any help in categorising personal data or considering personal data when completing a subject access request or a request under FOIA please contact Eleanore Beard in the Brabners Data Protection team.

We break down what the ICO found and outline three key steps that UK businesses should take now.

We look at the UK GDPR and the Data Protection Act 2018 and outline how the GDPR can apply to both organisations and individuals as data controllers.

We break down the key proposed reforms in the Digital Omnibus Package and outline what businesses should do to prepare.

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

We explore the new Order that gives local authorities a new ability to shape below-threshold procurement markets in ways that were previously off-limits.

We examine the consequences of Palou’s defection and the wider lessons for businesses negotiating contracts with athletes or other high‑value individuals.

We explore the key developments that in-house lawyers should have on their radar and what they mean for your organisation in the year ahead.

We explore the upcoming changes introduced by the Procurement Act 2023, when they take effect and what they mean for contracting authorities.

We outline the key takeaways from our Games Tech Connect session on how generative AI is being used in video game development.

We outline what you need to know about the UKIPO's proposed fee increases across patents, trade marks and designs.

We explain the impact of the cyber-attack on JLR's workforce and outline what to do to protect your business and minimise the impact if an incident occurs.

We outline eight key steps to put your organisation in the strongest position for a prompt and effective response to any cyber-attack.

Some tech businesses are exploring how their commercial frameworks could evolve through smarter, values-driven contracting.

We explore how contracting authorities must approach contract variations under the Procurement Act 2023.

We explore the potential of AI Growth Zones to transform the region through investment and job creation while also highlighting ongoing environmental concerns.

We break down the key takeaways from the final ruling and consider what they mean for the evolving relationship between IP law and AI development.

We explore the new minimum financial thresholds that will apply to public contracts and the application of the Procurement Act 2023 from 1 January 2026.

We explore how charities will need to manage their marketing activities and supporter consent once the secondary legislation takes effect.

We're thrilled to have been commended in three separate categories in The Times Best Law Firms 2026.

We explore how weak cybersecurity and slow responses can trigger major data breaches and resulting ICO fines.

Our litigation team achieved a successful outcome for Docutech Office Solutions Ltd in a major claim against a former employee and his new employer.

We explore the potential impact of AI on existing copyright laws and delve into the other IP and cross-border issues that arise from the use of global AI tools.

The EU Data Act is a regulation designed to reshape the European data economy by establishing harmonised rules for data access, sharing and portability.

Designed to amend the UK’s existing data privacy regime, the DUA Act will affect the UK GDPR, PECR and the Data Protection Act 2018.

The European Union Intellectual Property Office (EUIPO) has ushered in a new chapter for design protection with reforms to the legal framework governing design rights.