FOI request detail

Data protection complaints

Request ID: FOI-0797-2223
Date published: 27 July 2022

You asked

Could you let me know how many data protection complaints you have received in the last two years and how much money has been spent in dealing with data protection complaints in the last two years. Could you provide me number of complaints where TFL have breached the GDPR, breaches reported to ICO and general complaints as well in the last to years.

We answered

TfL Ref: FOI-0797-2223

Thank you for your revised request received by us on 7 July 2022 asking for information about data protection complaints.

Your request has been considered in accordance with the requirements of the Freedom of Information Act and our information access policy. I can confirm that we hold some of the information you require.

We publish details of breaches reported to and complaints received from the Information Commissioner’s (ICO) Office twice a year through our Audit and Assurance Committee https://board.tfl.gov.uk/ieListMeetings.aspx?CId=139&Year=0. In 2020 there was only one data protection report to the Committee due to the pandemic, so it covered October 2019 to September 2020. Between October 2019 and March 2022 TfL notified 5 data breaches to the ICO. During this 2 ½ year period the ICO received 39 complaints about TfL processing of personal data, of which 5 were determined to be unfounded.

We don’t record whether the subject of a complaint received directly from the public has breached the GDPR. For example, a member of the public may state that they haven’t received all information relating to a Subject Access Request (SAR), and ask for a review of the response whilst providing details of the information they believe is missing. The additional details provided may allow a further search to be carried out, but the initial search may still have been proportionate based on the initial request received. We received 136 complaints and requests for review directly from the public between April 2020 and March 2022.

We don’t record or have any way of calculating the cost of dealing with complaints. There are no full time data protection complaint investigators. During this time the Privacy and Data Protection team has been staffed by 6 – 7 full time employees who provide appropriate advice and guidance to the business on privacy and data protection. They investigate and resolve data breach incidents and complaints from data subjects or the Information Commissioner, evaluate systems and practices associated with the processing of personal data, maintain our data processor agreements and privacy notices, develop information sharing protocols and procedures with partner organisations, support the handling of data subject rights requests and provide privacy and data protection training and outreach activities.

If this is not the information you are looking for, or if you are unable to access it for any reason, please do not hesitate to contact me.

Please see the attached information sheet for details of your right to appeal as well as information on copyright and what to do if you would like to re-use any of the information we have disclosed.

Yours sincerely

Eva Hextall
FOI Case Management Team
General Counsel
Transport for London

Back to top

Want to make a request?

We'll email you the response within 20 working days.


We'll publish the response online without disclosing any personal information.