Skip to content
Content type · 39 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: United Kingdom (39) Clear filter
UK · €300 ICO (UK) - KRA Consultancy Ltd Facts — The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related… Direct Marketing Telecommunications Marketing May 20, 2026
ICO · €1,112,100 South Staffordshire Plc: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined South Staffordshire Plc €1,112,100 on 2026-05-07 for: Insufficient technical and organisational measures to ensure information security. Security May 7, 2026
ICO · €16,610,000 Reddit, Inc.: Non-compliance with general data processing principles Information Commissioner (ICO) fined Reddit, Inc. €16,610,000 on 2026-02-23 for: Non-compliance with general data processing principles. Telecommunications IP Address Processing Feb 23, 2026
ICO · €284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… Minors Controllers Consent Feb 5, 2026
UK · €120,000 ICO (UK) - Allay Claims Ltd Facts — Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… Direct Marketing Telecommunications Consent Jan 15, 2026
ICO · €75,700 Chief Constable of the Police Service of Scotland: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined Chief Constable of the Police Service of Scotland €75,700 on 2025-12-12 for: Insufficient technical and organisational measures to ensure… Public Sector Security Public Authority Dec 12, 2025
ICO · €1,400,000 LastPass UK Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 1,228,283 (EUR 1,400,000) on LastPass UK Ltd. The controller suffered a succesfull cyber attack due to insufficient technical and organisational… Security Processing Agreement Controllers Nov 20, 2025
ICO · €6,880,000 CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… Security Processors Controllers Oct 15, 2025
ICO · €9,180,000 CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… Security Controllers Processing Agreement Oct 15, 2025
ICO · €230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… Personal Data Controllers Education Aug 4, 2025
ICO · €20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… Security Processing Agreement Controllers Jun 24, 2025
ICO · €2,700,000 23andMe, Inc.: Insufficient technical and organisational measures to ensure information security The UK DPA imposed a fine of £ 2,310,000 (EUR 2,700,000) on 23andMe, Inc. The controller, a company offering DNA testing to private individuals, failed to implement sufficient… Data Breaches Genetic Data Security Jun 5, 2025
ICO · €70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… Security Processing Agreement Controllers Apr 14, 2025
ICO · €3,500,000 Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… Access Controls Security Processing Agreement Mar 26, 2025
ICO · €904,000 Police Service of Northern Ireland: Insufficient technical and organisational measures to ensure information security The ICO fined the Police Service of Northern Ireland £750,000 (EUR 904,000) after accidentally publishing personal data of 9,483 police officers and staff on the internet. The… Security Public Sector Public Authority Sep 26, 2024
ICO · €8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… Security Controllers IP Address Apr 30, 2024
ICO · €400,000 UK Ministry of Defense: Insufficient technical and organisational measures to ensure information security The UK DPA has fined the Ministry of Defense EUR 400,000 for disclosing personal data of individuals who were to be relocated to the UK after the Taliban took control of… Personal Data Security Education Dec 13, 2023
ICO · €14,500,000 TikTok: Non-compliance with general data processing principles The UK DPA (ICO) has fined TikTok EUR 14.5 million. The ICO had found that more than one million British children under the age of 13 were using TikTok without the consent of… Minors Social Media Fairness & Transparency Apr 4, 2023
ICO · €5,033,000 Interserve Group Limited: Insufficient technical and organisational measures to ensure information security The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve… Data Breaches Security IP Address Oct 19, 2022
ICO · €1,547,000 Easylife Ltd.: Insufficient legal basis for data processing The UK DPA has imposed a fine of EUR 1,547,000 on Easylife Ltd. Easylife is a retailer that sells household items as well as services and products under its health, motor,… Healthcare Direct Marketing Health Data Oct 4, 2022
ICO · €91,000 Tavistock & Portman NHS Foundation Trust: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in… Security Public Sector Healthcare Jun 9, 2022
ICO · €9,000,000 Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… Retention Period Fairness & Transparency Privacy Impact Assessment May 18, 2022
ICO · €115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… Data Breaches Encryption Notification Obligation Mar 10, 2022
ICO · €585,000 Cabinet Office: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Cabinet Office EUR 585,000. On December 27, 2019, the Cabinet Office published a file on GOV.UK containing the names and uncensored addresses of… Data Breaches Security Privacy by Design & Default Nov 25, 2021
ICO · €11,800 HIV Scotland: Insufficient technical and organisational measures to ensure information security The British DPA (ICO) has imposed a fine of EUR 11,800 on the non-profit organization HIV Scotland. The controller had sent an e-mail to 105 people, with e-mail addresses on the… Security Privacy by Design & Default Controllers Oct 18, 2021
ICO · €29,000 Mermaids: Insufficient technical and organisational measures to ensure information security The ICO has fined transgender charity Mermaids EUR 29,000 for failing to protect the personal data of its users, in breach of Art. 5 (1) f) UK GPDR and Art. 32 (1), (2) UK GDPR.… Security Encryption Data Breaches Jul 5, 2021
ICO · €1,405,000 Ticketmaster UK Limited: Insufficient technical and organisational measures to ensure information security Ticketmaster UK Limited has been fined GBP 1.25 million (approximately EUR 1.405 million) for failing to protect the personal data of its customers with adequate security… Security Processing Agreement Personal Data Nov 13, 2020
ICO · €20,450,000 Marriott International, Inc: Insufficient technical and organisational measures to ensure information security Original Summary: The ICO issued a notice of its intention to fine Marriott International Inc due to a cyber incident which was notified to the ICO by Marriott in November 2018. A… Fines Security Law Enforcement Oct 30, 2020
ICO · €22,046,000 British Airways: Insufficient technical and organisational measures to ensure information security In July 2019, the ICO issued a notice of its intention to fine British Airways £183.39M for GDPR infringements which likely involve a breach of Art. 32 GDPR. The proposed fine… Security Human Resources Personal Data Oct 16, 2020
UK · €130,000 ICO - CPS Advisory Limited Facts — CPS Advisory Limited (CPSAL) conducted direct marketing calls in relation to personal pensions. The data CPSAL used to conduct the calls had been purchased from third… Direct Marketing Representatives Supervisory Authorities Sep 4, 2020
ICO · €320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… Healthcare Healthcare Liability Dec 17, 2019