ICO administrative fines — Article 83 UK GDPR two-tier framework
The Information Commissioner's Office (ICO) is the United Kingdom's supervisory authority for data protection under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). The ICO's power to impose administrative fines for violations of UK GDPR is established by Article 83 UK GDPR and exercisable only by giving a penalty notice under DPA 2018 section 155, as provided in section 115(9).
Two-tier maximum fine structure
Article 83 UK GDPR establishes two levels of maximum administrative fines, commonly referred to as the "standard maximum amount" and the "higher maximum amount." The maximum fine in each case depends on whether the controller or processor is an "undertaking" (a concept that encompasses the entire economic entity, not just the individual legal person that committed the breach).
Standard maximum amount (Article 83(4) UK GDPR): £8,700,000 or, in the case of an undertaking, 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. This tier applies to infringements of controllers' and processors' obligations under Articles 8, 11, and 25–39 UK GDPR (including data protection by design and default, security measures, data protection impact assessments, and DPO designation), certification-body obligations under Articles 42–43, and monitoring-body obligations under Article 41(4).
Higher maximum amount (Article 83(5) UK GDPR): £17,500,000 or, in the case of an undertaking, 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. This tier applies to infringements of the core processing principles and lawful-basis requirements under Articles 5, 6, 7, and 9; data-subject rights under Articles 12–22; international-transfer requirements under Articles 44–49; obligations under Part 5 or 6 of Schedule 2 to DPA 2018; and non-compliance with a Commissioner's order under Article 58(2) or failure to provide access under Article 58(1). Non-compliance with a Commissioner's order also triggers the higher maximum under Article 83(6).
Article 83(3) cap for linked infringements
Where a controller or processor intentionally or negligently infringes several provisions of UK GDPR in the same or linked processing operations, the total administrative fine must not exceed the maximum specified for the gravest infringement. The ICO may impose a separate fine for each individual breach arising from the same or linked processing operations, provided the combined total does not exceed the applicable statutory maximum for the most serious violation.
Article 83(2) factors
Article 83(2) UK GDPR requires the ICO to give due regard to eleven enumerated factors when deciding whether to impose a fine and its amount, including: the nature, gravity, and duration of the infringement; the number of data subjects affected and level of damage suffered; the intentional or negligent character of the breach; any action taken to mitigate damage; the degree of responsibility taking into account technical and organizational measures implemented under Articles 25 and 32; any relevant previous infringements; the degree of cooperation with the Commissioner to remedy the breach; the categories of personal data affected; how the infringement became known to the Commissioner; compliance with previous enforcement measures; adherence to approved codes of conduct or certification mechanisms; and any other aggravating or mitigating factors, including financial benefits gained or losses avoided.
Effective, proportionate, and dissuasive requirement
Article 83(1) UK GDPR mandates that the Commissioner ensure administrative fines are "effective, proportionate and dissuasive" in each individual case. This principle guides both the decision to impose a fine and the calculation of its amount. In March 2024, the ICO published comprehensive Data Protection Fining Guidance setting out the ICO's methodology for calculating fines and applying the Article 83(2) factors.
The UK statutory framework mirrors the EU GDPR administrative-fine regime under Regulation (EU) 2016/679, with two principal divergences: the sterling-denominated caps (£8.7 million and £17.5 million, respectively) replace the euro amounts (€10 million and €20 million), and references to "the supervisory authority" are replaced with "the Commissioner." The substantive Article 83(2) factors and the effective-proportionate-dissuasive standard remain identical.
Source: Article 83, Regulation (EU) 2016/679 (UK GDPR) Source: Data Protection Act 2018, section 115 Source: Data Protection Act 2018, section 155–157
ICO corrective powers — Article 58 UK GDPR investigative and corrective toolkit (post-DUAA 2025 updates)
The Information Commissioner's Office (ICO) possesses a comprehensive suite of investigative and corrective powers under Article 58 UK GDPR, as incorporated and further developed in UK law. The Data Protection Act 2018 (DPA 2018) and—critically—the Data (Use and Access) Act 2025 (DUAA), effective in stages between June 2025 and February 2026, have expanded and refined these enforcement powers.
Article 58 categories and key DPA 2018 overlays Article 58 UK GDPR continues to establish three categories of authority: investigative powers (Article 58(1)), corrective powers (Article 58(2)), and authorisation/advisory powers (Article 58(3)). DPA 2018 Part 6 and associated Schedules overlay important procedural requirements.
Post-2026 enhancements under the Data (Use and Access) Act 2025 DUAA introduced substantive, non-cosmetic changes to the ICO's Article 58 toolkit:
1. Information notices expanded: Section 142 DPA 2018 (as amended) now expressly allows information notices to require production of documents (not just "information") and clarifies that such notices can cover all matters relevant to ICO’s functions.
2. Assessment notices and compulsory reports: DUAA amended section 146, empowering the ICO to issue assessment notices that require recipients to commission and pay for detailed investigative reports by an “approved person.” This brings ICO's audit powers in line with the "skilled person" review model seen in other UK regulatory regimes. Non-compliance attracts direct enforcement or penalty consequences.
3. New interview notice powers: New sections (DPA 2018, ss. 148A–148C) authorize the ICO to compel individuals (including directors and staff) to attend interviews, answer questions, and sign statements. Statutory safeguards apply; refusal, non-attendance, or providing false/misleading information can result in a penalty.
4. Timelines for penalty notices: DUAA inserted a requirement into Schedule 16 that, where the ICO issues a notice of intent to impose a penalty, the final penalty notice must follow within six months (or as soon as practicable), with written notification where no final penalty is given.
5. Governance overhaul: The Information Commissioner is now chair of a new multi-member Information Commission, rather than a sole officer. This corporate-body model applies to all enforcement functions (commenced Q1 2026).
6. PECR and EITSET enforcement alignment: DUAA extends ICO’s enforcement powers (assessment, information, enforcement, and penalty notices) to the Privacy and Electronic Communications Regulations (PECR) and the EITSET regime, with harmonized thresholds and procedural protections.
Procedural context and domestic divergences: The core Article 58 powers (investigative, corrective, and advisory) remain patterned on the EU GDPR, but UK law now features: (a) express powers for assessment and interview notices beyond those in the EU regime; (b) stricter timelines on penalty issuance; and (c) a governance shift to a commission structure. The notice regime (information, assessment, enforcement, penalty) now has sharpened legal effect, increased compliance leverage, and explicitly includes PECR.
Effective and transitional dates: Most amendments commenced by February 5, 2026, with transitional rules for enforcement actions initiated before that date (e.g., where a notice of intent preceded full implementation). Organisations should refer to DPA 2018 (post-DUAA), relevant Schedules, and government commencement orders for precise legal effect.
Source: Article 58, UK GDPR Source: Data Protection Act 2018, section 115 Source: Data Protection Act 2018, as amended by DUAA 2025 Source: DUAA 2025 Factsheet — ICO enforcement powers (gov.uk) Source: ICO consultation on post-DUAA enforcement guidance
Private right to compensation — Article 82 UK GDPR damage requirement and Lloyd v Google
Data subjects in the United Kingdom hold a direct statutory right to seek compensation from controllers and processors for breaches of the UK General Data Protection Regulation (UK GDPR). This private right of action operates independently of administrative enforcement by the Information Commissioner's Office (ICO) and permits individuals to bring civil proceedings in court without first exhausting administrative remedies.
Article 82 UK GDPR statutory framework
Article 82(1) UK GDPR provides that "any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered." The statute imposes two distinct requirements: (i) proof of an infringement of UK GDPR and (ii) proof of damage caused by that infringement. Controllers are liable for damage caused by processing that infringes UK GDPR; processors are liable only where they have failed to comply with obligations specifically directed to processors or have acted outside or contrary to lawful controller instructions (Article 82(2) UK GDPR). A controller or processor is exempt from liability if it proves it is not in any way responsible for the event giving rise to the damage (Article 82(3) UK GDPR).
"Non-material damage" includes distress — DPA 2018 section 168
The Data Protection Act 2018 (DPA 2018) clarifies that "non-material damage" for the purposes of Article 82 UK GDPR includes distress (section 168(1) DPA 2018). This statutory definition confirms that claimants may recover compensation for emotional harm, anxiety, or upset resulting from unlawful processing, in addition to material losses such as financial detriment. The inclusion of distress as compensable damage mirrors the position under the predecessor Data Protection Act 1998 section 13(2), though the UK GDPR regime does not require proof of pecuniary loss as a precondition to distress-based claims.
Lloyd v Google and the damage requirement
The Supreme Court's November 2021 decision in Lloyd v Google LLC [2021] UKSC 50 established that compensation under UK data-protection law is not available for a bare infringement of statutory duties without proof of actual damage. Although the case was decided under the Data Protection Act 1998, the Court's analysis is highly persuasive for Article 82 UK GDPR claims. The claimant had sought to bring a representative action (opt-out class action) on behalf of approximately four million iPhone users whose browsing activity Google allegedly tracked without consent via the "Safari Workaround" between 2011 and 2012. The claimant argued that "loss of control" of personal data constituted compensable damage without the need to prove individualised material loss or distress.
The Supreme Court unanimously rejected this argument, holding that the statutory right to compensation requires proof of two distinct elements: (i) a contravention of the applicable data-protection legislation and (ii) damage caused by that contravention. The Court concluded that interpreting "damage" to encompass the mere fact of unlawful processing would collapse these two requirements into one and render the statutory language requiring damage superfluous. Lord Leggatt, writing for the Court, stated that section 13 of the 1998 Act "cannot reasonably be interpreted as giving an individual a right to compensation without proof of material damage or distress whenever a data controller commits a non-trivial breach of any requirement of the Act." The Court emphasised that while loss of control may feature as part of a claimant's case—particularly where it leads to further harm such as distress, financial loss, or misuse of data—it does not, standing alone, constitute compensable damage.
The Supreme Court expressly declined to decide whether the same interpretation applies to Article 82 UK GDPR, noting differences in statutory language (in particular, Recital 146 to the EU GDPR, which mentions "loss of control" as an example of damage, though recitals do not form part of UK retained law post-Brexit with the same weight). However, the Court's core holding—that proof of damage distinct from and caused by the infringement is required—remains highly influential. Practitioners should anticipate that UK courts will require claimants to demonstrate actual harm (whether material loss or distress) and not merely the fact of a technical breach.
Representative actions and collective redress — DPA 2018 section 187
DPA 2018 section 187 enables representative bodies to bring compensation claims under Article 82 UK GDPR on behalf of data subjects. Article 80(1) UK GDPR (as modified by Schedule 6 to DPA 2018) permits a data subject to authorise a qualifying body or organisation to exercise the data subject's rights under Articles 77, 78, and 79 (complaint to the ICO, judicial remedy against the ICO, and judicial remedy against a controller or processor). Section 187(1)(b) DPA 2018 extends this to Article 82 compensation claims: a data subject may authorise such a body to exercise the right to compensation on the data subject's behalf. A qualifying body must (i) be constituted on a not-for-profit basis and (ii) have objectives that are in the public interest and relate to the protection of data subjects' rights (section 187(3)–(4) DPA 2018).
Lloyd v Google held that representative actions under CPR 19.6 (the English procedural rule permitting one or more persons to sue as representatives of others with "the same interest") are viable for data-protection claims only where all represented persons have the same interest in the relief sought. The Supreme Court confirmed that representative actions may be suitable for (i) declaratory relief establishing a defendant's liability or (ii) damages calculated on a uniform per-capita basis common to all class members. However, where compensation requires individualised assessment of harm—because distress or financial loss varies from person to person—a representative action is not procedurally permissible. The Court suggested a bifurcated approach: a representative claim to establish liability, followed by individual or coordinated claims for damages assessed on a case-by-case basis. DPA 2018 section 188 grants the Lord Chancellor power to make regulations governing representative-body proceedings, including provision for assessment of compensation, settlement, and costs, though no such regulations have been enacted as of June 2026.
Jurisdiction and venue
Proceedings under Article 82 UK GDPR are brought in the High Court, the county court (in England and Wales), the High Court or county court (in Northern Ireland), or the Court of Session (in Scotland), per DPA 2018 section 180(1)(e) and (2)(e). For processing to which Part 4 of DPA 2018 applies (law enforcement processing), jurisdiction is confined to the High Court or Court of Session (section 180(3)). Controllers and processors established outside the United Kingdom may be served with proceedings subject to the court's permission under the Civil Procedure Rules governing service out of the jurisdiction.
Joint and several liability — Article 82(4)–(5) UK GDPR
Where multiple controllers or processors are involved in the same processing and are responsible for damage, each is liable for the entire damage to ensure effective compensation to the data subject (Article 82(4) UK GDPR). A controller or processor that has paid full compensation may claim contribution from other controllers or processors involved in the same processing, in proportion to their respective responsibility for the damage (Article 82(5) UK GDPR). This joint-and-several regime mirrors tort principles in English law and prevents data subjects from bearing the risk of an insolvent defendant.
Source: Article 82, UK GDPR Source: Data Protection Act 2018, section 168 Source: Data Protection Act 2018, section 187
Criminal offences under DPA 2018 — sections 170, 171, and 173 unlawful processing, re-identification, and evidence alteration
The Data Protection Act 2018 (DPA 2018) creates several criminal offences for deliberate breaches of UK data protection law, functioning alongside the UK General Data Protection Regulation (UK GDPR). These offences are prosecuted by the Crown Prosecution Service or the equivalent authority in Scotland/Northern Ireland and are separate from the administrative enforcement regime exercised by the Information Commissioner’s Office (ICO).
Section 170 DPA 2018: Unlawful obtaining, disclosing, procuring, or retaining personal data Section 170(1) makes it an offence, if done knowingly or recklessly and without the data controller’s consent, to: (a) obtain or disclose personal data, (b) procure disclosure to another person, or (c) after obtaining data, retain it. The mental element requires the individual to know or be reckless as to the lack of consent. Negligence is not sufficient.
Section 170(2) provides statutory defences, which as of 5 February 2026 (per Data (Use and Access) Act 2025) now read: it is a defence to prove that the act was necessary for preventing, investigating, or detecting crime; required or authorised by law; or justified by public interest. Prior to this, "investigating" was not included. Section 170(3) further allows defences based on the defendant’s reasonable belief in a legal right to the act, or the reasonable belief that consent would have been given. Section 170(4)–(6) also criminalise the offer to sell or selling of personal data obtained in breach of s.170(1), including advertising such data for sale.
Section 171 DPA 2018: Re-identification of de-identified personal data Section 171(1) creates an offence, committed knowingly or recklessly and without the controller’s consent, to re-identify information that has been de-identified so as no longer to be attributable to a specific individual. Section 171(2)–(4) define de-identified data, "re-identification," and provide statutory defences, including the amendment, effective 5 February 2026, that necessity for "investigating" crime is now a defence alongside preventing or detecting crime. Other defences include action authorised by law or justified by public interest, and, for certain journalistic or academic activities, a reasonable belief of public interest, as well as effectiveness testing (s.172). Section 171(5) criminalises downstream use (processing) of data unlawfully re-identified.
Section 173 DPA 2018: Alteration of personal data to prevent disclosure Section 173 makes it an offence to alter, deface, block, erase, destroy or conceal personal data to prevent disclosure that may be required under an information or assessment notice issued by the Commissioner (ICO). This preserves the integrity of regulatory and investigatory processes under DPA 2018.
Penalties and procedure (Section 196; Section 197) Penalties for offences under these sections include a fine upon conviction (unlimited in England and Wales for summary conviction since the removal of limits by the Legal Aid, Sentencing and Punishment of Offenders Act 2012; up to the statutory maximum in Scotland/Northern Ireland; and a fine on indictment). There is no custodial sentence for any of these offences—Parliament’s choice for DPA 2018, in contrast to e.g. the Computer Misuse Act 1990. The courts may also order forfeiture or destruction of material involved (Section 196(3)–(5)).
Proceedings may be instituted in England and Wales only by the Commissioner or with the Director of Public Prosecutions’ consent (Section 197), and in NI only by or with the DPP for Northern Ireland. Section 197 also extends the limitation period for prosecuting s.173 offences—summary proceedings may be brought within six months of the prosecutor’s knowledge (with a three-year outer limit from the date of the offence).
Relationship to administrative enforcement Criminal and administrative penalties may both follow from a single event, but criminal prosecution is typically reserved for the most serious or wilful breaches; most enforcement is administrative.
Material update: The statutory defences for s.170(2)(a) and s.171(3)(a) were expanded effective 5 February 2026 by the Data (Use and Access) Act 2025 to include "investigating" crime as a lawful ground.
Source: Data Protection Act 2018, section 170 Source: Data Protection Act 2018, section 171 Source: Data Protection Act 2018, section 173 Source: Data Protection Act 2018, section 196 Source: Data Protection Act 2018, section 197 Source: Data (Use and Access) Act 2025, amendments to DPA 2018
ICO fining methodology — March 2024 Data Protection Fining Guidance and leading enforcement decisions
The Information Commissioner's Office (ICO) published comprehensive Data Protection Fining Guidance in March 2024 setting out when it will impose administrative fines under Article 83 UK GDPR and how it calculates the appropriate amount. The guidance replaces sections of the November 2018 Regulatory Action Policy and applies to all fines issued under the UK GDPR and Data Protection Act 2018 (DPA 2018), including new cases and ongoing investigations where a notice of intent has not yet been issued. It does not apply to fines under the Privacy and Electronic Communications Regulations 2003 (PECR).
Five-step fining methodology — March 2024 Guidance
The March 2024 Guidance establishes a five-step approach to calculating an appropriate fine, which the ICO applies holistically rather than mechanistically. The five steps are:
Step 1: Assessment of seriousness of the infringement. The ICO evaluates the nature, gravity, and duration of the infringement by reference to the Article 83(2)(a) factors and categorises the breach according to degree of seriousness (low, medium, high, or very high seriousness). This assessment examines the nature of the processing, scope of processing, number of data subjects affected, level of damage suffered, whether the infringement was intentional or negligent, and the duration of the infringement. The Guidance clarifies that the assessment of intentionality or negligence examines the individual circumstances of each case; examples of evidence the ICO will consider include whether senior management authorised the unlawful processing, but such evidence is illustrative rather than determinative.
Step 2: Determination of the applicable statutory maximum. The ICO identifies whether the infringement falls within the "standard maximum amount" under Article 83(4) UK GDPR (£8.7 million or 2% of worldwide annual turnover, whichever is higher) or the "higher maximum amount" under Article 83(5) UK GDPR (£17.5 million or 4% of worldwide annual turnover, whichever is higher). The higher maximum applies to infringements of the core processing principles under Articles 5, 6, 7, and 9 UK GDPR, data-subject rights under Articles 12–22, and international-transfer requirements under Articles 44–49. For undertakings (economic entities that may include parent companies with decisive influence over the infringing controller or processor), the ICO determines the "total worldwide annual turnover in the preceding financial year" by reference to the entire undertaking, not solely the legal entity that committed the breach. The Guidance explains how the ICO will assess whether a parent company exercises decisive influence, taking into account factors such as ownership structure, financial dependency, operational integration, and governance oversight.
Step 3: Calculation of a starting point. The ICO applies a percentage of the applicable statutory maximum based on the seriousness categorisation determined at step 1. The Guidance sets out indicative percentage ranges for each seriousness category. For undertakings, this percentage is applied to the higher of the fixed sterling cap or the turnover-based percentage cap. The ICO will generally use annual turnover as the primary indicator of an organisation's size and financial position, but will also consider other financial indicators such as profits, net assets, or dividends where relevant. For organisations that are not undertakings (including public authorities, sole traders, and small entities without significant turnover), the starting point is determined by reference to the fixed sterling cap and the organisation's financial position.
Step 4: Adjustment for aggravating and mitigating factors. The ICO considers the Article 83(2) factors not already accounted for at step 1, including: any action taken to mitigate damage suffered by data subjects; the degree of responsibility taking into account technical and organisational measures implemented under Articles 25 and 32; any relevant previous infringements; the degree of cooperation with the Commissioner to remedy the breach and mitigate adverse effects; the categories of personal data affected; how the infringement became known to the Commissioner (whether by breach notification, complaint, or proactive disclosure); compliance with previous ICO measures under Article 58(2); adherence to approved codes of conduct or certification mechanisms; and any other aggravating or mitigating factors, including financial benefits gained or losses avoided as a result of the infringement. The Guidance clarifies that cooperation beyond the ordinary legal duty of cooperation under Article 31 UK GDPR and DPA 2018 section 63 may be treated as a mitigating factor, including where a controller or processor responds to ICO requests in a manner that enables the enforcement process to conclude significantly more quickly or effectively.
Step 5: Final review for effectiveness, proportionality, and dissuasiveness. The ICO conducts a holistic review of the proposed fine amount in light of all the circumstances of the case to ensure the fine meets the Article 83(1) UK GDPR requirement that administrative fines be "effective, proportionate and dissuasive in each individual case." At this stage the ICO may adjust the fine amount (upward or downward) to ensure it achieves the statutory objective. For public authorities, the ICO applies its "public sector approach": it will only issue a fine in the most egregious cases where infringements are especially serious, and the fact that the organisation is a public authority is relevant to the assessment of the nature of the processing (step 1), the determination of the maximum fine (step 2), and the financial position used at step 3. The ICO may reduce the overall fine on a public body at step 5, provided the fine remains effective, proportionate, and dissuasive.
In exceptional circumstances, the ICO may further reduce a fine where a controller or processor is unable to pay the proposed amount because of its financial position. The Guidance states that the ICO is not bound by previous fining decisions, but it will have regard to the level of fines set in previous cases where relevant and will explain the reasons for the fine amount in each case to ensure transparency.
Leading ICO enforcement decisions — illustration of the fining framework in practice
The March 2024 Fining Guidance has been applied in a series of major ICO enforcement actions, predominantly targeting security failures under Article 32 UK GDPR following cyber-attacks:
Advanced Computer Software Group Ltd (March 2025) — £3.07 million. The ICO fined Advanced £3.07 million for security failings that compromised the personal data of 79,404 individuals and caused disruption to the provision of essential healthcare services, including NHS 111 services. This was the ICO's first monetary penalty imposed directly on a processor under the UK GDPR, signalling that processors will be held directly accountable for breaches of their Article 28 and Article 32 obligations. The ICO's investigation found that Advanced's subsidiary had failed to implement appropriate technical and organisational measures to protect personal data processed on behalf of its controller customers, including gaps in the deployment of multi-factor authentication (MFA), insufficient vulnerability scanning, and inadequate patch management. The ICO initially proposed a fine of £6.1 million, which was reduced to £3.07 million following a voluntary settlement under the ICO's informal settlement practice. The penalty notice applied the March 2024 Fining Guidance and emphasised that Advanced processes personal data for Critical National Infrastructure sectors (health and social care) and the Commissioner expected Advanced to be aware of the health sector's status as Critical National Infrastructure and the severity of risks to data subjects' rights and freedoms.
23andMe Inc. (2025) — £2.31 million. The ICO fined US genealogy company 23andMe £2.31 million for security failures following a massive data breach in 2023 that exposed personal data including genetic information. The fine reflects the ICO's heightened scrutiny of security measures for processing special-category personal data under Article 9 UK GDPR (genetic data) and the cross-border applicability of the UK GDPR to non-UK controllers processing UK data subjects' information.
Capita plc (October 2025) — £14 million settlement. The ICO agreed to a £14 million settlement with Capita, the largest ICO settlement to date. The original proposed fine was £45 million, but Capita received a substantial reduction for settling early, admitting the infringement, and agreeing not to appeal. The breach affected 6.6 million people across multiple organisations. The core failure was a 58-hour delay in quarantining a compromised device after detecting suspicious activity; the ICO found that Capita failed to act quickly enough to contain the breach. The settlement illustrates the ICO's use of early-resolution incentives to reduce regulatory costs and secure admissions, mirroring enforcement settlement frameworks used by the Financial Conduct Authority and Ofcom.
British Airways plc (October 2020) — £20 million. The ICO imposed a £20 million fine on British Airways for security failures that led to a cyber-attack between June and September 2018 in which a malicious actor compromised internal BA systems, traversed the network, and edited a Javascript file on BA's website to exfiltrate customer payment-card data and login credentials. The ICO found that BA failed to process personal data in a manner ensuring appropriate security, in breach of Article 5(1)(f) and Article 32 GDPR. The ICO's initial notice of intent proposed a fine of £183.39 million (1.5% of BA's worldwide turnover), which was reduced to £20 million following representations and in light of the economic impact of the COVID-19 pandemic on the aviation sector. This remains the ICO's second-largest final monetary penalty to date and illustrates the ICO's willingness to impose fines at the top end of the statutory scale for serious security breaches involving large volumes of personal data, while exercising discretion to account for an organisation's financial position and external economic conditions under the Article 83(1) proportionality requirement.
Police Service of Northern Ireland (2024) — £750,000. The ICO fined the Police Service of Northern Ireland £750,000 for a data breach that exposed the personal information of its entire workforce, including officers, staff, and their locations. This fine illustrates the ICO's application of the public-sector approach: the fine was issued only after a determination that the breach was egregious and especially serious, and the amount reflects a reduction from what would have been imposed on a private-sector undertaking of equivalent scale. The breach raised acute risks given the sensitive nature of policing data and the potential for targeting of officers and staff.
DPP Law Ltd (April 2025) — £60,000. The ICO fined DPP Law Ltd, a Merseyside-based law firm, £60,000 following a cyber-attack in June 2022 that led to highly sensitive personal data (including data related to crime, military, family fraud, sexual offences, and actions against the police) being published on the dark web. The breach affected clients subject to statutory anonymity protections under sections 44–45A of the Youth Justice and Criminal Evidence Act 1999 and sections 39 and 49 of the Children and Young Persons Act 1933. The ICO found infringements of Articles 5(1)(f), 32(1), 32(2), and 33 UK GDPR (the Article 33 breach notification infringement related to DPP's failure to notify the Commissioner within 72 hours as required). The penalty notice applied the March 2024 Fining Guidance and calculated a single penalty ensuring the total did not exceed the maximum for the gravest infringement (Article 5(1)(f), subject to the £17.5 million / 4% higher maximum). The modest fine amount reflects DPP's size (fewer than 250 staff) and financial position.
Emerging enforcement trends — 2024–2026
ICO enforcement activity in 2024–2025 reflects a strategic shift: the ICO issued fewer fines but collected substantially more in monetary penalties. In the first half of 2025, the ICO issued six fines totalling approximately £5.6 million, already more than double the £2.7 million collected across 18 fines throughout the whole of 2024. The average fine rose from approximately £150,000 in 2024 to over £2.8 million in the first half of 2025. Two-thirds of fines in the first half of 2025 were for UK GDPR breaches (predominantly Article 32 security failures), compared to one-sixth in 2024; the remainder were for Privacy and Electronic Communications Regulations (PECR) marketing violations. This signals the ICO's prioritisation of data-protection security enforcement over telemarketing and spam enforcement, and a preference for fewer, larger, more impactful penalties over high-volume low-value fines.
The ICO has indicated it will introduce a formal settlement procedure offering structured fine reductions for early resolution: discounts of up to 40% for settlement before a notice of intent, 30% after notice of intent, and 20% after written representations. This framework was the subject of a consultation in late 2025 on draft Data Protection Enforcement Procedural Guidance and is expected to be formalised in 2026. The settlement framework aims to reduce the cost of contested proceedings for both the ICO and the regulated entity and incentivise early engagement and admissions.
Source: Data Protection Fining Guidance, March 2024 Source: ICO publishes new fining guidance, 18 March 2024 Source: Advanced Computer Software Group Ltd monetary penalty notice, 27 March 2025 Source: British Airways plc penalty notice, 16 October 2020 Source: DPP Law Ltd monetary penalty notice, 14 April 2025 Source: ICO public sector approach
Challenging ICO enforcement actions — appeals, First-tier Tribunal jurisdiction, and statutory time limits
A controller, processor, or other person who receives an enforcement notice, penalty notice (administrative fine), or certain other formal actions from the Information Commissioner's Office (ICO) has a statutory right to challenge that action before the First-tier Tribunal (Information Rights), the specialist tribunal with jurisdiction over UK data protection enforcement. The Data Protection Act 2018 (DPA 2018) delineates the available appeal routes, the grounds, and the applicable statutory time limits for each primary notice type.
What enforcement actions can be appealed?
- Enforcement notices (section 149 DPA 2018): Any person on whom an enforcement notice is served may appeal under section 162(1)(a).
- Penalty notices (administrative fines under UK GDPR or DPA 2018): Appeals are available under section 162(1)(b).
- Information notices and assessment notices: Appeals for information notices (section 142) and assessment notices (section 146) are also permitted.
- Variation or cancellation of notices: Section 162(1)(c)-(e) confirms the right to appeal a decision to vary, cancel, or refuse to cancel a notice.
Who decides the appeal and what powers does the Tribunal have?
- The First-tier Tribunal (Information Rights chamber) hears these appeals. The Tribunal may uphold, annul, or substitute its own decision for the ICO’s decision, and may give directions to the Commissioner (section 162(4)-(5) DPA 2018). This de novo jurisdiction means the Tribunal does not simply review for legal error but may reconsider the merits of the Commissioner's decision. Either party may further appeal, with permission, to the Upper Tribunal on a point of law.
Statutory time limits
- The notice recipient must typically lodge the appeal within 28 days of the notice being given (section 162(2), and Tribunal Procedure (First-tier Tribunal) (General Regulatory Chamber) Rules 2009, rule 22). There is a limited discretion for the Tribunal to allow late appeals where the interests of justice so require.
Suspensive effect
- Lodging an appeal does not automatically suspend the effect of the notice, unless the Tribunal directs otherwise (sections 153(6), 155(8), and 162(7) DPA 2018). A party may apply to the Tribunal for a stay or suspension pending the outcome of the appeal.
Special carve-outs and practical notes
- Appeals against urgent enforcement notices (section 153 DPA 2018) and penalty notices (section 155) are subject to the same regime. For criminal prosecution, the right of appeal is governed by the ordinary criminal procedure and not by section 162 DPA 2018.
This appeal framework is critical for recipients of high-value fines or intrusive orders, ensuring both procedural fairness and access to judicial review. Practitioners should check the text of the individual notice for confirmation of the relevant statutory section and appeal deadline.
Source: Data Protection Act 2018, sections 149–162, Tribunal Procedure (First-tier Tribunal) (General Regulatory Chamber) Rules 2009, rule 22
PECR monetary penalties — pre- and post-2025 regime, thresholds, and ICO enforcement powers
The Privacy and Electronic Communications Regulations 2003 (PECR) set out UK rules for direct marketing, cookies, and electronic privacy distinct from the UK GDPR. The enforcement framework for breaches of PECR has long featured a unique penalty regime—separate from UK GDPR/DPA 2018—but reforms effective 19 June 2025 under the Data Use and Access Act 2025 (DUAA) will raise the stakes to GDPR levels and expand the ICO’s toolkit.
Pre-2025 PECR penalty framework: Until 19 June 2025, the Information Commissioner's Office (ICO) may issue a monetary penalty notice under Regulation 31 PECR, with a maximum fine of £500,000 for sufficiently serious contraventions. According to the ICO, this cap applies to both organisations and directors, and penalties are reserved for breaches likely to cause "substantial damage or substantial distress"—such as nuisance calls, unlawful electronic marketing, or tracking set without consent. When deciding on a penalty, the ICO must consider whether the breach was deliberate or negligent and whether reasonable steps were taken to prevent it; aggravating and mitigating factors (harm to individuals, complaints, remedial steps) are also considered. The ICO allows a 20% discount for early payment of monetary penalties, as detailed in its annual reports (see p. 57, 2023–24 report). Source: ICO — PECR regime: What are PECR? Source: ICO Annual Report 2023–24, p.57
Post-2025 reforms: DUAA harmonisation and raised caps: The Data Use and Access Act 2025, effective 19 June 2025, aligns the PECR penalty regime with UK GDPR. From this date, the Secretary of State may increase the maximum penalty for PECR breaches to £17.5 million or 4% of worldwide turnover (whichever is higher), matching UK GDPR fine tiers—though the uplift is at the Secretary’s direction, not fully automatic. The DUAA also arms the ICO, for the first time in PECR enforcement, with assessment notices, compulsory witness attendance, and technical assessment powers (the ability to require explanations of how systems or processes work, and to commission technical reports about compliance) for use in PECR investigations—the same investigative tools as under the UK GDPR. Source: ICO — The Data Use and Access Act 2025: Summary of the changes (May 2025)
Concurrent enforcement and operational implications: A single incident may breach both PECR (for unlawful marketing or tracking) and UK GDPR (for underlying processing or transparency failures). The ICO may bring separate enforcement actions and fines under both, but is required to ensure overall penalties are effective, proportionate, and dissuasive in aggregate. Post-June 2025, UK privacy enforcement for cookies, direct marketing, and electronic tracking is subject to the same maximum penalty risks as core personal data processing, fundamentally raising the business consequences for PECR violations.
Source: ICO — PECR regime: What are PECR? Source: ICO Annual Report 2023–24, p.57 Source: ICO — The Data Use and Access Act 2025: Summary of the changes (May 2025)
Urgent enforcement notices — DPA 2018 s.153: immediate powers and suspensive effect
Section 153 of the Data Protection Act 2018 (DPA 2018) gives the Information Commissioner’s Office (ICO) the power to issue an urgent enforcement notice against a controller or processor where the Commissioner believes that the urgency of the case makes it necessary to take immediate action. This provision is designed for high-risk situations—such as where delay could cause substantial damage or distress to individuals—that cannot wait for the standard enforcement process.
Trigger and requirements for urgency The ICO may issue an urgent enforcement notice “without delay” if the urgency of the case requires it (s.153(1)). Unlike under a standard notice (s.149), the recipient is not entitled to make representations before the urgent notice takes effect. The notice must state the reasons for urgency, its immediate effect, and specify the period for which it will have effect. Section 153(3) requires that the duration be stated—the notice cannot be open-ended.
Immediate effect and procedural safeguards An urgent notice takes effect immediately upon service (s.153(2)), and can require the recipient to take or refrain from specific data processing activities as set out in the notice. The recipient retains the right to make representations after receipt, and the Commissioner must consider any such representations “as soon as reasonably practicable” (s.153(5)). The Commissioner may cancel or vary the notice in light of these representations or on their own initiative (s.153(4)).
Appeal and suspension The recipient of an urgent enforcement notice may appeal to the First-tier Tribunal (Information Rights), which may decide to suspend or annul the notice while considering the appeal (s.153(6)). The notice remains in force unless and until the Tribunal makes such a direction.
Practical consequences Urgent enforcement notices are available for exceptional cases where waiting for the ordinary process would risk substantial harm. For example, rapid action might be required to halt a data breach or the unlawful disclosure of sensitive data. However, s.153 does not prescribe specific factual scenarios—as of 2026, there is limited published ICO or Tribunal caselaw applying the urgent mechanism.
Replacement or transition to standard notice If the urgency passes or further procedure is needed, the Commissioner can cancel the urgent notice and may issue a standard enforcement notice under s.149 (s.153(4)), restoring the full representations procedure.
Obstruction of ICO investigations — DPA 2018 section 148, amended by DUAA 2025 and SI 2026: criminal offences for obstruction and non-cooperation
Section 148 of the Data Protection Act 2018 (DPA 2018) establishes a criminal offence for obstructing the Information Commissioner’s Office (ICO) in exercising its formal investigative powers, specifically when responding to information or assessment notices. This core offence remains in force but has been substantially elaborated and supplemented by amendments from the Data (Use and Access) Act 2025 (DUAA 2025) and 2026 consequential regulations.
Offence under section 148 (pre- and post-amendment) Under section 148(1), it is an offence if a person, in purported compliance with an information notice or assessment notice issued by the ICO:
- (a) knowingly or recklessly makes a false statement in a material respect; or
- (b) intentionally obstructs, or fails to give the Commissioner or their staff such reasonable assistance as is necessary, in conducting an assessment under section 146.
This covers both actively false or reckless statements and passive refusal or failure to cooperate with official ICO assessments or on-site audits. The penalty upon conviction is a fine (unlimited in England and Wales; statutory maximum on summary conviction in Scotland or Northern Ireland; or a fine on indictment). There is no custodial penalty. Courts may make additional orders for destruction/forfeiture of documents connected with the offence (s.196(3)–(5)).
Material amendments by DUAA 2025 and SI 2026 Effective in stages from June 2025 to June 2026 (SI effective 26 March 2026), DUAA 2025 has added key enhancements:
- Sections 148A–148C inserted: New statutory interview notice regime. The ICO may now serve interview notices requiring individuals (including directors or key staff) to attend and answer questions under formal caution and to sign a formal record under threat of criminal penalty. Section 148C makes it an offence knowingly or recklessly to make a material false statement in response to an interview notice, mirroring the s.148 (information/assessment notice) offence. Section 148B imposes restrictions and safeguards (e.g. subject’s right to legal advice; limitation on compelled privileged information).
- Updated procedures and more robust criminal offence framework for non-cooperation or providing false information during investigations, extending criminal liability to formal interviews as well as documentary responses. These amendments are now in force as of 26 March 2026 per the SI.
Relationship to other enforcement/criminal provisions Section 148 continues to operate alongside other DPA 2018 offences (e.g. sections 170, 173), but now sits at the center of a broader statutory toolkit for penalising obstruction or non-cooperation in ICO investigations, including both documentary and compelled-interview contexts.
Judicial treatment As of June 2026, there remain no published criminal prosecutions or tribunal decisions interpreting amended s.148 or the new s.148A–C interview powers.
Source: Data Protection Act 2018, section 148 Source: Data Protection Act 2018, section 196 Source: Data (Use and Access) Act 2025, sections 97–100 (ICO interview powers/obstruction) Source: Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026
Statutory time limits for prosecutions and penalty notices under DPA 2018 and UK GDPR
The Data Protection Act 2018 (DPA 2018) sets statutory limitation periods for some enforcement actions and prosecutions under UK data protection law. The details differ depending on the nature of the action and have been affected by recent statutory amendments.
1. Criminal prosecution for alteration of data to prevent disclosure (section 173 DPA 2018): Section 197 DPA 2018 specifies limitation periods for prosecution under section 173 (alteration, erasure, blocking, or destruction of data to prevent disclosure). For these offences:
- Summary proceedings must be brought within "six months beginning with the day on which the prosecutor first knew of evidence sufficient in the prosecutor's opinion to justify proceedings for the offence, but no later than three years after the commission of the offence."
- The prosecutor must certify the relevant knowledge date; this certification is conclusive for timing purposes under section 197(5)–(6).
This provision allows prosecution where evidence emerges long after the incident, but sets a three-year absolute outer limit.
2. ICO monetary penalty notices — statutory time limit revised (DUAA 2025): The original DPA 2018 regime did not set a statutory period for the ICO to issue a penalty notice after discovering a violation. However, the Data (Use and Access) Act 2025, effective 5 February 2026, substantively amends Schedule 16:
- The Commissioner must generally issue a penalty notice within six months of serving a notice of intent.
- If it is not reasonably practicable to issue the penalty notice within those six months, the Commissioner must do so as soon as reasonably practicable thereafter, with written notification to the recipient giving reasons for the delay.
- This relaxes the previously strict six-month rule and gives the ICO leeway in complex or exceptional cases.
3. Civil compensation claims (Article 82 UK GDPR/section 167 DPA 2018): There is still no express statutory limitation period under the DPA 2018 for civil claims by data subjects for compensation. The default six-year general limitation in section 2 of the Limitation Act 1980 will usually apply in England and Wales. However, there is no controlling UK appellate judgment explicitly confirming this for Article 82 claims as of June 2026.
Summary table: | Action | Limitation period | Statutory source | |--------|------------------|-----------------| | Criminal prosecution (s.173, summary) | 6 months from prosecutor's evidential knowledge (max 3 years from offence) | s.197 DPA 2018 | | ICO penalty notice (administrative fine) | 6 months from notice of intent, or as soon as reasonably practicable thereafter, with written notice of delay | Sch. 16, DPA 2018 (as amended by DUAA 2025) | | Civil compensation (Art. 82 UK GDPR) | No express statutory limit; 6-year general limit under Limitation Act 1980 likely applies | — |
Material update: From 5 February 2026, the deadline for the ICO to issue a penalty notice after a notice of intent is no longer a strictly fixed six-month maximum; issuance may occur later if not reasonably practicable, provided written notice and reasons are given.
Source: Data Protection Act 2018, section 197 Source: Data Protection Act 2018, Schedule 16 (as amended by Data (Use and Access) Act 2025) Source: Data (Use and Access) Act 2025, section 101
Personal liability of directors and officers — DPA 2018 and PECR
Directors and officers of UK companies face personal liability for certain breaches of data protection and electronic communications law under the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations 2003 (PECR). These frameworks assign personal criminal liability to individuals in positions of managerial responsibility, and—since February 2026—dramatically increase the risk for PECR monetary penalties to levels equivalent to those under the UK GDPR.
Personal criminal liability: DPA 2018 section 198 and PECR regulation 30 Section 198 DPA 2018 provides that if a company (body corporate) commits a criminal offence under the Act with the consent, connivance, or neglect of a director, manager, secretary or similar officer, both the company and that individual are liable and may be prosecuted. Covered offences include unlawful obtaining or disclosure of data (s.170), re-identification of de-identified data (s.171), obstruction of the ICO (s.148), and other specified offences in Part 7 of the DPA 2018. Regulation 30 of PECR mirrors this, making directors, managers, and equivalent officers personally guilty where PECR offences are committed through their consent, connivance, or neglect.
Director financial liability for PECR monetary penalties: post-2026 regime While DPA 2018 does not assign directors or officers direct financial responsibility for administrative fines (which only the corporate entity pays), the PECR regime includes express personal liability. Since the Data Use and Access Act 2025 (in force from 5 February 2026), the maximum PECR penalty that may be enforced against companies—and, where relevant, their directors personally—has increased from £500,000 to up to £17.5 million or 4% of global turnover (whichever is greater), bringing PECR in line with UK GDPR penalty tiers. This regime applies to PECR breaches (such as unlawful marketing or unlawful cookie use) committed with the requisite mental state by directors or officers. The ICO may pursue the penalty against the individual if the company fails to pay, as confirmed in guidance and annual enforcement reports.
No direct individual fines under UK GDPR/DPA 2018 administrative penalty regime Administrative fines for breaches of UK GDPR or DPA 2018 Article 83 are only levied on controllers or processors as corporate entities. Individual officers are not personally liable for these administrative fines, but remain subject to criminal liability and, for PECR, heightened personal exposure.
Director disqualification Repeated or egregious data protection violations by directors may be reported by the ICO to the Insolvency Service for consideration of disqualification as a company director under the Company Directors Disqualification Act 1986, although the ICO itself cannot directly disqualify directors.
Summary of material changes -- From 5 February 2026, individual director liability for PECR monetary penalties is now aligned with the much higher UK GDPR tiers and should be treated as a significant compliance risk for officers in regulated entities.
Source: Data Protection Act 2018, section 198 Source: Privacy and Electronic Communications Regulations 2003, Regulation 30 Source: ICO — The Data Use and Access Act 2025: Summary of the changes (May 2025)
ICO powers to ban or suspend processing — Article 58(2)(f) UK GDPR and DPA 2018 section 149
The Information Commissioner's Office (ICO) can impose a temporary or permanent limitation—including a ban—on processing personal data by a controller or processor if a breach of the UK General Data Protection Regulation (UK GDPR) or Data Protection Act 2018 (DPA 2018) is found. This power, colloquially called a "ban order," is one of the strongest corrective measures available to the ICO, and is grounded in Article 58(2)(f) UK GDPR and its implementation via DPA 2018 section 149.
Statutory authority: Article 58(2)(f) UK GDPR authorises the ICO to "impose a temporary or definitive limitation including a ban on processing." In UK law, this power is exercised through an enforcement notice (DPA 2018 s.149), which enables the Commissioner to direct a person to take or refrain from specified steps to remedy a breach. Section 149(2)(c) explicitly includes the ability to require a controller or processor to stop processing personal data, either partially or fully. Any such notice must be targeted and proportionate, with requirements tailored by the ICO to remedy the particular failure (s.149(6)).
Procedural framework: The enforcement notice must state the legal reasons for its issuance, the provisions breached, the specific steps required, and the period for compliance. A ban—partial or total—will only be issued when lesser steps (such as warnings, reprimands, or requirements to change technical controls) do not suffice to protect data subjects’ rights and freedoms. The power is generally reserved for egregious or ongoing breaches, or where the risk to individuals is especially acute.
Context and usage: Bans under this statutory regime are rare but have severe implications for the recipient, potentially halting business-critical data processing. Recipients have a right of appeal to the First-tier Tribunal (DPA 2018, s.162). Practical application—including cases where the ICO has considered or implemented bans—should be understood as context, not as an element directly rooted in the statutory language. This section is grounded in the authorities cited; illustrative enforcement examples are discussed elsewhere only if supported by public ICO decisions or Tribunal judgments.
Source: Article 58(2)(f), UK GDPR Source: Data Protection Act 2018, section 149
"Undertaking" for fine calculation — group turnover, decisive influence, and the UK GDPR Article 83 cap
The administrative fine regime under Article 83 UK GDPR, as incorporated into UK law, hinges on whether the controller or processor is an "undertaking"—a concept that determines whether the maximum monetary penalty is based on a fixed sterling cap (£8.7 million/£17.5 million) or a percentage of total worldwide turnover for the group (2%/4%), whichever is higher. The practical scope of the term "undertaking" thus has existential significance for corporate groups facing regulatory fines under UK data protection law.
What is an "undertaking"? The term is not defined in the UK GDPR or DPA 2018, but is interpreted in line with settled EU competition law: an undertaking is any economic unit capable of commercial activity, encompassing the entire controlling corporate group, not just the infringing legal entity. This is the approach adopted by the ICO (see March 2024 Data Protection Fining Guidance, Part 3.2). The definition extends to any parent undertaking exercising a "decisive influence" over the subsidiary that committed the infringement. Factors weighed by the ICO include shareholding, board composition, financial dependency, operational integration, and effective control over policy and decision-making. Notably, decisive influence does not require day-to-day direction: the ability to exercise control, even if not actually used, satisfies the test.
Attribution of turnover for fine calculation Article 83(4)–(5) UK GDPR and DPA 2018 section 155(7) direct that the cap be calculated as a percentage of "total worldwide annual turnover in the preceding financial year" of the entire undertaking deemed responsible. The ICO, following EU and UK competition caselaw (including C-97/08 Akzo Nobel), will assess the full consolidated turnover of all entities forming the economic unit. That means the risk of a very substantial penalty, potentially orders of magnitude greater than the fixed sterling cap, for multinational groups with high global revenues—even when the UK affiliate committing the breach is a modest subsidiary. The ICO also considers public and third-sector bodies on this principle: non-corporate or public undertakings with consolidated budgets may see those figures used as the reference for fine calculation.
Disputes over group attribution Organisations may dispute their inclusion in a wider undertaking, seeking to argue that they form a standalone economic unit. The ICO’s Fining Guidance sets out its expectations for evidence of independent management, operational separation, and absence of decisive influence. In practice, few large groups succeed on this argument. The ICO will make a factual assessment—its published penalty notices (see Capita, 23andMe, British Airways) explain how group turnover was calculated and why the percentage cap applied.
Current enforcement posture (2024–2026) Recent ICO penalties have consistently calculated the percentage cap at the group level, mirroring the approach of EU supervisory authorities and UK competition regulators. The result is that large groups face maximum penalties vastly exceeding the sterling cap, lending real weight to proportionality arguments at the final assessment stage. Practitioners should prepare group-wide financial disclosures and address the "undertaking" test early when responding to monetary penalty notices.
Source: Data Protection Fining Guidance, March 2024, Part 3.2 Source: Article 83 UK GDPR Source: Data Protection Act 2018, section 155
ICO assessment notices and compulsory audits — DPA 2018 section 146 powers and procedures
Section 146 of the Data Protection Act 2018 (DPA 2018) empowers the Information Commissioner’s Office (ICO) to issue assessment notices, requiring controllers or processors to submit to a statutory audit of their processing for compliance with the UK General Data Protection Regulation (UK GDPR), DPA 2018, or associated data protection law. Assessment notices are distinct from information notices (section 142) and enforcement notices (section 149) within the ICO’s statutory toolkit.
Issuing an assessment notice The ICO may serve an assessment notice when it considers it necessary to evaluate compliance with data protection law (s.146(1)). For government departments, ministerial approval is required (s.146(2)). At least 7 days’ advance notice is generally required, unless a warrant is obtained (s.146(3)). The notice must set out the audit’s date and scope.
Audit powers, recipient obligations, and the new power to commission reports A recipient of an assessment notice must:
- permit entry by the ICO to relevant premises,
- provide access to equipment and documents,
- allow the ICO to copy records or information, and
- permit staff interviews (s.146(4)-(5)).
Refusing or obstructing an assessment notice is a criminal offence under s.148. Legally privileged information is protected (s.146(6)).
2025 amendment — compulsory reports The Data (Use and Access) Act 2025 (effective 19 June 2025) amended section 146 to give the ICO a new power: an assessment notice may now require the recipient to secure and provide a report prepared by an “approved person” on matters specified in the notice, in a form and within a period stated by the ICO (see new s.146(8)–(11)). This mechanism goes beyond ordinary document production or interviews, mirroring the power of financial regulators to require independent audits or reports by skilled persons. The ICO may designate required qualifications for the “approved person” and direct the scope and detail of the investigation/report. Noncompliance with the report requirement attracts the same legal consequences as other failures to comply with an assessment notice.
Procedural requirements (Schedule 15) Schedule 15 to DPA 2018 sets further protections: recipient representatives may be present; copying/removal of records is limited to what is necessary for compliance (Sch.15 paras 3-4). The ICO can apply for a warrant under s.154 for unannounced audits if needed.
Enforcement and appeal Failure to comply may result in the ICO seeking a warrant or issuing an enforcement notice. Recipients have a statutory right of appeal to the First-tier Tribunal (s.162). The 2025 amendment materially expands the ICO’s investigation means and must be factored into compliance planning post-June 2025.
Material change (effective 19 June 2025): The new report commissioning power, added by the Data (Use and Access) Act 2025, is the most significant enhancement of ICO assessment notice powers since DPA 2018’s inception.
Source: Data Protection Act 2018, section 146 Source: Data Protection Act 2018, Schedule 15 Source: Data (Use and Access) Act 2025, section 70
Publication and retention of ICO enforcement actions — website policy and six-year window
The Information Commissioner's Office (ICO) website retention policy (Version 6.1, effective 1 February 2025) sets out the periods for which enforcement actions and related records are publicly available or retained internally. As of this policy update, items associated with criminal enforcement cases and civil enforcement cases where action was taken—such as undertakings, enforcement notices, monetary penalty notices, reprimands, practice recommendations, and information notices—are retained and published for six years from the closure of the case or the conclusion of any appeal.
Material change (February 2025): Prior to February 2025, the standard retention period for these enforcement action records was two years. The policy was extended to six years by the ICO Website Retention Policy, Version 6.1 (see p. 3). This is a significant extension and directly impacts how long such actions are visible on the ICO’s public site and retained internally. Where the ICO investigates a civil case and determines that no enforcement action is required, case records are retained for only three years from case closure. This clarification also replaced prior ambiguity in retention of non-actioned case records.
For individuals fined or subject to enforcement (as opposed to legal persons), the ICO will remove identifying details from the website after twelve months, but the name of the associated company or organisation remains for the remainder of the six-year period if enforcement action was issued. In all cases, publication and retention may be withheld or redacted if necessary to prevent disproportionate harm, protect national security, or safeguard vulnerable data subjects.
Practitioner note: Organisations should not rely exclusively on the ICO's public register for compliance or reputation tracking: after the expiry of the statutory window, notices and penalty records are no longer available on the site. Maintaining independent archives of any notices or outcomes received is best practice for compliance history and response planning.
Source: ICO Website Retention Policy, v6.1, February 2025 Source: ICO Retention and Disposal Policy, June 2024