The Information Commissioner's Office (ICO) has published research concluding that a statutory regulatory sandbox for innovative products and services is feasible, but would require changes to data protection legislation and careful safeguards to protect the regulator's independence and individuals' rights.
A regulatory sandbox is a supervised environment in which organisations can develop and test innovative products and services with support and advice from a regulator, working through compliance questions before deployment rather than after.
The ICO's own Regulatory Sandbox has operated for more than eight years as a place for organisations to test new ideas, explore data protection risks and build privacy into new products and services by design. Projects have ranged from tools helping students manage their information when applying for further education to AI and sensor-based technologies designed to improve social care and prevent falls.
Participation in a conventional Regulatory Sandbox must still comply with the UK GDPR and the Data Protection Act 2018 throughout. A statutory sandbox goes further, however, using legislation to permit limited, supervised departures from specific legal requirements during testing.
The research, carried out with the Regulatory Innovation Office's AI Capability Fund, examined the viability of a data protection Statutory Regulatory Sandbox (SRS). The ICO's findings report, published on 30 July alongside supporting research, reached three headline conclusions:
1. A data protection SRS is feasible, but government and the ICO would need to address important challenges, including protecting the ICO's independence and ensuring individual rights are transparently protected through alternative but equivalent accountability and governance mechanisms.
2. Public trust must be at the heart of any SRS, with innovations delivering clear public benefit - people are willing to see new and novel data use where it delivers better services and outcomes for everyone.
3. Demand for an SRS is niche, but the potential impact is significant if key economic opportunities and societal benefits can be unlocked faster.
Any SRS would operate within ICO oversight and safeguards. It would require changes to data protection legislation and the ICO says it will be for government to decide next steps. The regulator positions the report as a contribution to policy development as government advances its thinking on the Regulating for Growth Bill and the AI Growth Lab.
The ICO said that existing sandboxes have limits, including the ability to use live personal information in cases that push the boundaries of the data protection principles, and creating space for issues requiring multiple regulators to balance risks across different domains, such as privacy and competition. These constraints, it argued, can slow the pace at which regulators deliver certainty on the rules of the road for emerging technologies, slow innovation, and leave users of new technologies confused or unprotected.
The regulator said it is drawing on international and domestic models, citing the Singaporean PDPC and the FCA, and its work through the Digital Regulation Cooperation Forum, which piloted an AI and digital hub offering multi-agency advice from the CMA, FCA, Ofcom and the ICO. It is also one of four regulators supporting the government's Advisory AI Growth Lab for legal services and is working with firms through the FCA's AI Lab.
Alongside the SRS work, the ICO committed to improving its existing sandbox to run faster and produce clearer outputs and conclusions for participants, while cautioning that organisations must be willing to bring the hard problems and accept that co-creation also means accepting limits on tech deployment where privacy, safety and individual rights are at play.
The findings report and supporting research are available at: https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/statutory-regulatory-sandbox/

