Croydon Council is taking steps to bolster its information governance practices, aiming for a more robust and compliant approach across all departments. This initiative aims to foster a cultural shift within the organisation, prioritising data protection and compliance with various legal duties concerning information management1.

The move follows a recent meeting of the Audit & Governance Committee, where members reviewed the council's Information Governance Improvement Plan. The plan seeks to address weaknesses in accountability, ownership, and knowledge of data protection practices throughout the organisation. A key theme identified was the need for cultural change to successfully fulfil statutory responsibilities.

A cartoon house illustrating cyber security vulnerabilities.
A cartoon house illustrating cyber security vulnerabilities.Source: Audit & Governance Committee papers, 30 October 2025

Key areas of focus include:

  • Establishing a Defined Data Protection Officer (DPO) Function: This aims to provide clear leadership and expertise in data protection matters.
  • Quantifiable Information Governance Framework (IGF): The council is working to create a measurable framework to assess and improve its information governance practices.
  • Service-Led Model: Transitioning to a model where service areas take greater ownership of information governance, supported by a central team providing guidance and monitoring compliance.

The council aims to achieve a cultural shift across the organisation, promoting a proactive approach to data protection and compliance. This includes:

  • Increasing awareness and ownership of information governance at the service level. While specific training programs are not bespoke for key roles, the council acknowledges that mandatory training completion rates for data protection and information security modules are very poor across the whole organisation's workforce, and training completion recording is unreliable.
  • Empowering a privacy by design culture to ensure good practice is integrated into transformation and operational decisions.
  • Establishing a small central Information Management Team to monitor compliance and provide support to service areas.

According to the Public reports pack 30th-Oct-2025 18.30 Audit Governance Committee, the council has already invested in improving its performance in responding to Subject Access Requests (SAR) and Freedom of Information (FOI) requests. The Information Governance Action Plan 25/27 outlines further steps to enhance data protection impact assessments, data sharing agreements, and overall compliance with data protection regulations.


  1. This legislation includes, but is not limited to, the Data Protection Act 2018; the General Data Protection Regulation (UK) 2021; Freedom of Information Act 2000; Environmental Information Regulations 2004; Computer Misuse Act 1990; Protection of Freedoms Act 2012; Local Government Act 1996; Re-use of Public Sector Information Regulations 2015 and the newly enacted Data (Use and Access) Act 2025. ↩