The ICO is introducing the Sandbox service to support organisations who are developing products and services that use personal data in innovative and safe ways.
Organisations will have the opportunity to engage with us; draw upon our expertise and advice on mitigating risks and ‘data protection by design’, whilst ensuring that appropriate protections and safeguards are in place.
In order to develop the Sandbox, the ICO is launching the beta phase for a sample of participant organisations to try out the service.
The beta phase will provide a free, professional, fully functioning service for approximately ten organisations, of varying types and sizes, across a number of sectors.
The beta phase comprises:
- Application period: 29 March - 24 May (submission deadline)
- Selection period: May - July
- Planning and operational period: July 2019 - September 2020
There are a number of benefits to your organisation participating in the Sandbox. These may include:
- access to ICO expertise and support;
- enhanced confidence in the compliance of your finished product or service;
- a better understanding of the data protection frameworks and how these effect your business;
- being seen as accountable and proactive in your approach to data protection, by customers, peer-organisations and the ICO, leading to increased consumer trust in your organisation;
- supporting the UK in its ambition to be an innovative economy; and
- contributing to the development of products and services that can be shown to be of value to the public.
Frequently asked questions
Will the ICO provide us with a hosted environment to conduct our work in?
No, we will not be hosting environments as part of the Sandbox beta phase. You will be responsible for providing your own IT infrastructure.
Will the ICO assist us to procure data?
No, we are unable to advise you about where or how to procure data. Nor are we able to provide any funding to assist you in procuring data.
Will we be able to use real customer (live) data or can we use created/stimulated (dummy) data for testing?
You may use either live or dummy data to test your products so long as they are compliant with data protection law. Using dummy data may be preferable as it does not carry any risk to data subjects. If you are processing live data, you will need to complete a DPIA beforehand if it is likely to result in a high risk to the data subject. We will not be providing live or dummy data and therefore we expect you to source your own data for testing.
Will the ICO deal with other regulators on our behalf?
We will not deal with other regulators on your behalf. However, if your proposed product or service is subject to other regulations, we ask that you notify us about this in your application. We may ask you to provide evidence about how the product or service complies with these other regulations and we may contact other regulators to confirm this is the case.Will the ICO be providing financial support as part of the Sandbox?