Award entries: Innovation

Entries submitted

Entry Agency / Authority
Spain – Data Protection Commissioner
European Union – European Data Protection Supervisor (Contrôleur Européen de la Protection des Données)
United Kingdom – Information Commissioner’s Office (ICO)
Brazil – Autoridade Nacional de Proteção de Dados
Nigeria – Nigeria Data Protection Commission
Australia – Office of the Australian Information Commissioner
Nigeria – Nigeria Data Protection Commission
United Kingdom – Information Commissioner’s Office (ICO)
Canada – Information and Privacy Commissioner of Ontario
Canada – Information and Privacy Commissioner of Ontario

STRATEGY FOR THE IMPLEMENTATION OF AI IN THE SPANISH DATA PROTECTION AGENCY, TECHNOLOGICAL DEVELOPMENT AND GUARANTEE OF FUNDAMENTAL RIGHTS

Brief Description

A key pillar of the AEPD’s transformation into a smart and anticipatory public authority is the ethical integration of AI into its internal processes. The initiative provides a comprehensive model for introducing generative AI while protecting fundamental rights, confidential information and institutional trust. It combines a pioneering public Internal Policy for the Use of Generative AI and its implementation annex, an internal AI portal with user rules, approved tools and use-case procedures, a network of AI facilitators across business units, and privacy-preserving proofs of concept using open models and local processing. The AEPD’s strategy offers a model for responsible public-sector transformation in which innovation and the protection of fundamental rights advance together. Based on transparency, strong governance and collaboration, it modernises internal processes and lays the foundations for more efficient, ethical and people-centred public administration.

WEC Online

Brief Description

WEC Online is an open-source web application designed to empower data protection authorities (DPAs), privacy compliance teams, and website administrators and owners to conduct automated website privacy scans through an intuitive, user-friendly interface. Based on the Website Evidence Collector (WEC) CLI tool, it identifies critical issues such as insecure forms, third-party tracking (cookies, web beacons, local storage), and encryption gaps. While currently hosted in EU data centers (accessible via the secure testa network) for EU institutions, bodies, and agencies (EUIs), WEC Online is freely available for adoption by any DPA or regulator worldwide. Reports are easily accessible and downloadable directly from the interface.

Review of regulation 6 PECR for online advertising

Brief Description

Online advertising is a key part of the UK economy. At the same time, the Privacy and Electronic Communications Regulations (PECR) (originally derived from the EU e privacy Directive 2002/58/EC) and the UK GDPR play an important role in protecting people’s rights and freedoms. Online advertising is enabled by storage and access technologies, such as cookies, scripts and tags, and web storage. Regulation 6 of PECR prohibits storing and accessing information on people’s devices without consent, unless an exception applies. This is the case whether or not the information is personal data. Under the current framework, almost all online advertising requires consent, even where the privacy risks are relatively low. To support our growth commitments to government, we reviewed how regulation 6 may inhibit development of more privacy-preserving advertising models. We assessed a range of advertising activities to identify those that present lower privacy risks and could operate without consent.

Pilot Project for the Regulatory Sandbox on Artificial Intelligence and Data Protection of the National Data Protection Agency

Brief Description

The Regulatory Sandbox is an experimental environment supervised by the ANPD to monitor the development and testing of artificial intelligence system projects involving the processing of personal data. During the project, the Agency monitors the selected initiatives and evaluates aspects related to personal data protection, risk management, and regulatory compliance. The testing phase consists of six cycles, each accompanied by the drafting of a monitoring report. These reports present the main findings identified throughout the testing, contributing to the monitoring of the initiatives and the consolidation of lessons learned within the scope of the project. The proposal seeks to support the development of regulatory instruments aimed at the use of artificial intelligence systems in contexts involving the processing of personal data.

Virtual Privacy Academy (VPA): Nigeria’s National Digital Platform for Scalable Privacy Education through Nollywood Film and Storytelling

Brief Description

The Virtual Privacy Academy (VPA) is a national digital learning platform established by the Nigeria Data Protection Commission (NDPC) to make high-quality privacy education accessible, scalable and relevant across Nigeria. As organizations increasingly process personal data, many employees lack practical understanding of their privacy responsibilities. Traditional classroom training can be costly, inconsistent and difficult to scale. The VPA addresses this gap through standardized, legally grounded and accessible online learning designed for Nigeria’s diverse workforce. Its distinguishing innovation is the use of a professionally produced Nollywood film to bring privacy principles to life through relatable workplace scenarios, familiar characters and practical decision-making. This culturally relevant approach makes complex privacy concepts engaging, accessible and memorable.

The module covers Interactive videos, exercises, quizzes for completion in approximately one hour.

The Notifiable Data Breach (NDB) statistics dashboard

Brief Description

The Notifiable Data Breach (NDB) statistics dashboard presents key statistics on data breach notifications received by the OAIC under the NDB scheme since the scheme’s commencement in February 2018. The dashboard provides an interactive presentation of this data and will be updated twice-yearly. It has been created to help reporting entities and stakeholders understand the volume of data breaches reported to the OAIC, the number of people affected, causes and sectoral trends.

NDPC/DIAL Collaboration on Privacy by Design in Early Stage Innovation

Brief Description

In 2025, the Nigeria Data Protection Commission (NDPC) partnered with the Digital Impact Alliance (DIAL) to pilot a co-creative regulatory sandbox embedding “Privacy by Design” into early-stage innovation. The initiative supported nine Nigerian startups using AI and Digital Public Infrastructure (DPI) to address maternal mortality, healthcare access, and financial inclusion challenges across Kano, Kaduna, Gombe, and Lagos. The NDPC provided hands-on regulatory oversight, DPO support, and practical data protection and DPIA training. The initiative culminated in a landmark White Paper, Privacy by Design in Early-Stage Innovation: How Data Protection Advances AI-Driven DPI in Nigeria, unveiled by the National Commissioner of the NDPC at the Global Digital Infrastructure Summit in Cape Town. It has been recognised as Africa’s first practice-driven privacy sandbox model and offers a scalable blueprint for balancing data protection, AI innovation, and DPI governance.

ICO AI and Biometrics Strategy: Automated Decision Making in Recruitment

Brief Description

The ICO has tackled the issue of Automated Decision Making (ADM) in recruitment. It did this in an innovative, collaborative way, by engaging with employers who have deployed automated recruitment tools and producing an industry facing report, supported by engagement and communication, to directly change market behaviour.

Principles for the Responsible Use of Artificial Intelligence

Brief Description

Artificial Intelligence is rapidly reshaping how decisions are made and services are delivered, creating significant opportunities but also serious risks to individuals and communities. To help organizations realize AI’s benefits while preventing harm, Ontario’s Information and Privacy Commissioner (IPC) and Ontario’s Human Rights Commissioner (OHRC) jointly issued the Principles for the Responsible Use of AI. The six Principles translate privacy, access, and human rights obligations into clear expectations across the AI lifecycle: from development and procurement, to deployment, ongoing monitoring, and decommissioning. Building on the IPC–OHRC’s 2023 joint statement and aligned with emerging provincial, national, and international frameworks, the Principles provide organizations with an integrated, practical roadmap for AI systems that are valid and reliable, safe, privacy-protective, human-rights affirming, transparent, and accountable. This joint regulatory approach promotes regulatory certainty, consistency, public trust, and responsible innovation.

De-identification Guidelines for Structured Data

Brief Description

Given the rapid pace of technological change, the importance of using data responsibly for the public good, and the changing regulatory landscape, the IPC decided to review and update its De-identification Guidelines first published in 2016. Key updates include a twelve-step operational guide, supported by practical checklists, case studies, and appendices that walk users through key methodologies. This guidance helps organizations take practical steps to safeguard privacy without sacrificing data utility. The guidance emphasizes the importance of risk mitigation throughout the entire de-identification cycle, from preparation to assessment to ongoing monitoring. The updated de-identification guidance reflects the IPC’s vision as a modern and effective regulator with real-world impact. It supports IPC strategic priorities by establishing clear ways organizations can protect privacy while unlocking the value of data for research, innovation, and the public good.