On 10 August 2026 the Isle of Man Information Commissioner issued Reprimand 2026/003 to the Cabinet Office, the first the Commissioner has published in full and as a case study. The organisation did not skip its Data Protection Impact Assessment. It wrote one, amended it, put it to the Data Protection Officer for review and obtained Senior Information Risk Officer sign-off. It still infringed five provisions of the Applied GDPR: Article 25, Article 5(1)(c), Article 5(1)(a), Article 5(1)(f) and Article 5(2). The reason is narrow and uncomfortable. By the time the document was signed, its body text described a process the organisation had already decided not to follow, while the risk calculator attached to it scored 5 out of 5 for the likelihood that personal data would be placed at risk. The assessment existed. It simply no longer described the processing.
What happened
Our guide to when a DPIA is required and what it must contain sets out the duty. Cabinet Office, a department of the Isle of Man Government responsible for elections through its Crown and External Relations division, is the controller. The 2026 electoral canvass began on 6 January 2026, with household enquiry forms posted to households. The last full canvass was in 2021, so the data was likely to contain inaccuracies from moves, newly eligible voters and deaths.
Under the original plan, envelopes went to a nominated head of household with the form pre-populated with the details of people registered to vote there; where nobody had been nominated, the envelope went to "The Occupier" with nothing pre-populated. Cabinet Office then found that 53 per cent of residences had no nominated head of household. Believing this would harm the response rate, it decided to address every form to "The Occupier" and pre-populate all of them with names, dates of birth and jury eligibility status.
On 7 January 2026 the Commissioner's office received two phone calls from members of the public, and Cabinet Office reported the breach that day, reference PDB/1636, within 72 hours of first being made aware and so within the Island's breach notification duty. Two people were thought to be affected; the final estimate was 3,215, about 5 per cent of the 63,962 people whose details were included. Cooperation is recorded in mitigation, including an unsuccessful attempt to stop deliveries and following the Commissioner's advice on public communications.

The five findings
The five provisions describe one decision from five angles, not five separate lapses.
| Article | What it requires | What the Commissioner found |
|---|---|---|
| Article 25 | Data protection by design and by default | Adopted although the organisation's own scoring made a breach certain, with an alternative design available |
| Article 5(1)(c) | Data minimisation | Dates of birth are absent from the public register and were included only to separate identical names: "ultimately disproportionate". Jury eligibility status combined with date of birth identifies exemption from jury service for reasons other than age, and speculation "could potentially lead to reputational damage" |
| Article 5(1)(a) | Lawfulness, fairness and transparency | A lawful basis existed, but "It is unlikely that people would expect their information to be distributed by post with no named addressee" |
| Article 5(1)(f) | Integrity and confidentiality | Personal data was disclosed by correspondence addressed to "The Occupier" "despite having identified a foreseeable risk that the information could be accessed by persons other than the intended individuals", and appropriate technical and organisational measures were not implemented |
| Article 5(2) | Accountability | The risk assessment "recognised that there was a certainty that a personal data breach would occur", and the controller must be able to demonstrate compliance with every Article 5(1) principle |
Cabinet Office argued that the register's public availability justified the inclusion. The Commissioner rejected that, the register being viewable only at designated sites with no copies or particulars taken. "Information being legitimately publicly available, with appropriate restrictions, is not equivalent to information being made readily available to unspecified third parties via post." The lawful basis, an obligation to maintain a register of electors under the Registration of Electors Act 2020 and the Registration of Electors Regulations 2021, did not answer the point: "Compliance with one element of the principle, does not compensate for failure to comply with another."
If your assessments are signed but never reconciled to the processing as built, start there.
Where it actually went wrong
The failure is not that nobody looked. It is that what they looked at no longer matched what was going to happen.
When the decision changed, the risk calculator was amended and scored 5 out of 5 for the likelihood that personal data would be placed at risk, which Cabinet Office stated was "understood to indicate a certainty" that a breach would result. It went for DPO review and SIRO sign-off. The recorded comment: "I am content that this will pose very low risk to the rights and freedoms of individuals."
"This version of the DPIA contained conflicting information." The calculator described the new plan and indicated a breach was certain; the body text still described the original process, under which those forms would not be pre-populated. The DPO confirmed they were not aware the planned processing would involve pre-populating forms addressed to "The Occupier", and the SIRO confirmed the DPIA was signed off on the DPO's approval, which rested on inaccurate information.
Timing is part of the finding: "The amendments were made to the DPIA at a late stage of the process and the amended DPIA was presented to the DPO as a time-sensitive piece of work." A reviewer to a deadline reads the document in front of them; where the narrative describes an abandoned plan, review cannot catch it, whether the adviser is internal or an outsourced DPO.

"Accepting" a risk is a decision someone has to be able to read back
The calculator shows Cabinet Office proposed to "accept" the risk. Acceptance is legitimate; the reasoning has to survive being read back, and here it moved. An email to the DPO on 7 January 2026 said the risk was accepted "on the basis that people are able to update their information on the electoral register at any time". By 28 January 2026 the rationale given to the Commissioner was that the risk could not be avoided, reduced or transferred under the proposed approach to addressing the envelopes.
The Commissioner disposes of both: "Cabinet Office could have reduced the risk by reverting back to the original plan of addressing the HEFs to 'The Occupier' and leaving the contents blank." A risk is only unavoidable within a fixed approach, and the approach was what had changed.
Sizing it was possible too: afterwards, Cabinet Office used UK Electoral Commission information to indicate that between 1,000 and 5,000 households may have received data belonging to someone who no longer lived there, and the Commissioner notes "this same metric could have been used during the planning process".
What this changes about your sign-off process
The point is narrow: sign-off assures the document, so the document has to be the plan.
Three things follow. A change of approach belongs in the body of the assessment, not only in the scoring, because the narrative is what a reviewer reads. The two must be reconciled before the document leaves the author: a top-of-scale likelihood beside a description of low-risk processing is a contradiction on the face of the paper. And sign-off needs a version, a date and an identifiable change since the version last seen.
The cheapest control sits at signature: someone confirms that the document still describes what the organisation is going to do. A late amendment under time pressure is the reason to ask, not to skip. Accountability under Article 5(2) stays with the controller.
We work with Isle of Man controllers on version control, reconciliation and confirmation at signature.

Common mistakes we see
The most common, and the one this case shows, is amending the risk score without amending the assessment. A calculator is quick to change; the narrative is slower, and gets left behind.
Close behind is treating "accept" as a box rather than a decision, usually where a mitigation is inconvenient rather than genuinely unavailable. We also see the leap from "this is already public" to "so it can be sent anywhere", and a reviewer's comment treated as a guarantee rather than a view on what was shown.
Frequently asked questions
Four questions follow from a reprimand published in this much detail.
Does a reprimand mean a fine?
No. It is the corrective power under Article 58(2)(b) of the Applied GDPR, issued "when the Information Commissioner believes there has been an infringement of the Applied GDPR, but the infringement is not serious enough to warrant a fine or enforcement notice". Data subjects may still seek compensation for material or non-material damage.
Can a reprimand be appealed?
No. "There is no appeal against the issue of a reprimand to the Data Protection Tribunal." The Commissioner lists all reprimands, names the organisations, and publishes some in detail "to help others learn and improve compliance".
Does having a DPIA protect us?
Only so far as it is accurate. The Commissioner recorded in mitigation that Cabinet Office ran a DPIA before the canvass and obtained DPO feedback and SIRO sign-off, but that "these efforts were undermined as the DPIA did not accurately convey the method of processing that was then carried out".
Does this apply to private-sector controllers?
Yes. Article 58(2)(b) reaches "a controller or a processor", and the provisions engaged, Article 25 and the Article 5 principles, bind any controller under the Data Protection Act 2018 and the Applied GDPR.
If a late amendment reached your reviewer this week, it is worth knowing what they would see.
Cabinet Office did everything its process asked of it and still infringed five provisions, because the process was asking about a plan already abandoned.
