Source · Data protection & FOI enforcement
ICO Enforcement Actions
225 total actions
63 monetary penalties
£52,533,773 total fines
Information Commissioner's Office enforcement actions — monetary penalties, enforcement notices, reprimands, and undertakings for data protection and FOI failures.
Enforcement actions
The Information Commissioner (the Commissioner) issues a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. This enforcement action follows a cyber incident in which the personal data of approximately 10,000 UK data subjects may have been affected.
Chief Constable Commissioner for the Metropolis/ Metropolitan Police Service (MPS)
Incident 1 (ICO Ref: INV/0034/2025), concerning the service of unredacted documents in support of a Stalking Protection Order application; and Incident 2 (ICO Ref: INV/0138/2024), concerning the disclosure of email addresses when contacting victims of the Honeytrap Matter.
Geoffrey Smith
A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence.
Debbie Okparavero and Maliha Islam – Proceeds of Crime Act
We have secured successful outcomes at Proceeds of Crime Act (POCA) hearings, resulting in a total of £118,852.32 in confiscation orders being handed to Greater Manchester based former RAC employees Debbie Okparavero and Maliha Islam.
Thermotech Wall and Loft Surveys Ltd
In April 2025, the ICO carried out a search warrant to obtain evidence in relation to TWLS and its compliance with PECR. Following an extensive investigation, it was revealed that between 1 October 2024 to 31 March 2025, TWLS instigated 575,062 unsolicited direct marketing calls to numbers registered with the TPS for more than 28 days. This resulted in 132 complaints being made to the TPS and the ICO reporting tools.
Thermotech Wall and Loft Surveys Ltd
In April 2025, the ICO carried out a search warrant to obtain evidence in relation to TWLS and its compliance with PECR. Following an extensive investigation, it was revealed that between 1 October 2024 to 31 March 2025, TWLS instigated 575,062 unsolicited direct marketing calls to numbers registered with the TPS for more than 28 days. This resulted in 132 complaints being made to the TPS and the ICO reporting tools.
KRA Consultancy Ltd
KRA Consultancy Ltd was fined £300,000 for sending over 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of PECR. The messages resulted in over 60,000 complaints to the 7726 spam reporting service.
KRA Consultancy Ltd
KRA Consultancy Ltd was issued with an enforcement notice for sending over 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of PECR. The messages resulted in over 60,000 complaints to the 7726 spam reporting service.
Rizwan Manjra – Proceeds of Crime Act
We have secured a £355,880.10 confiscation order against former Manchester motor insurance worker, Rizwan Manjra, who was previously found guilty of securing unauthorised access to personal information on his work computer systems for his own financial gain.
South Staffordshire Plc and South Staffordshire Water Plc
The Information Commissioner’s Office (ICO) has imposed a fine of £963,900 on South Staffordshire Plc & South Staffordshire Water Plc for the infringement of Article 5(1)(f) and Article 32(1) of the UK General Data Protection Regulation. This enforcement action follows a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated.
SA Assistance Ltd
Contravention of Regulation 21A and 24 of the PECR. SA Assistance Ltd instigated calls to individuals about claims management services without consent.
Energy Prices Direct Limited
Contravention of Regulations 21 and 24 of the PECR. Energy Prices Direct Limited offer energy switching services. Information demonstrated that they had obtained information from the public domain and list providers, but failed to screen the data against the TPS/CTPS prior to making a marketing call.
The Queen Elizabeth Hospital King’s Lynn NHS Foundation Trust
The Information Commissioner’s Office (ICO) has issued an enforcement notice to Queen Elizabeth Hospital King’s Lynn NHS Foundation Trust for its poor handling of requests made under the Freedom of Information Act (FOIA) 2000.
The University Hospitals Birmingham NHS Foundation Trust
The Information Commissioner’s Office (ICO) has issued an enforcement notice to University Hospitals Birmingham NHS Foundation Trust for its poor handling of requests made under the Freedom of Information Act (FOIA) 2000.
Jacksons Marketing Ltd
Jacksons Marketing Ltd was fined £130,000 for making 232,776 unsolicited live direct marketing calls between 29 January 2024 and 12 December 2024 to telephone numbers that had been registered with the Telephone Preference Service (TPS) for more than 28 days. This resulted in 12 complaints being made to the TPS and the Commissioner.
Jacksons Marketing Ltd
Jacksons Marketing Ltd was fined £130,000 for making 232,776 unsolicited live direct marketing calls between 29 January 2024 and 12 December 2024 to telephone numbers that had been registered with the Telephone Preference Service (TPS) for more than 28 days. This resulted in 12 complaints being made to the TPS and the Commissioner.
Reddit, Inc.
We imposed a £14,472,500.00 penalty to Reddit, Inc. for infringing Articles 5(1)(a), 6, and 8, and Article 35 of the UK GDPR. We found that Reddit, Inc.:
Calderdale Council
The Commissioner of Police for the City of London
A reprimand has been issued to The Commissioner of Police for the City of London (COLP), after it failed to meet its data protection obligations in responding to SARs within the statutory timeframe during the period 1 April 2023 to 31 July 2025, thereby contravening Article 12(3) UK GDPR and s45(3) DPA 2018.
North Tees and Hartlepool NHS Foundation Trust
Christopher Munro and William Chipoma
Two further people have been convicted following our extensive investigation into the unlawful accessing and sale of personal information obtained from over 400 garages across the UK, as well as claims management and insurance companies.
Chief Constable of Cumbria Constabulary
MediaLab.AI, Inc.
£247,590 penalty imposed on MediaLab.AI, Inc. in respect of infringements of Articles 5(1)(a), 6, 8 and 35 UK GDPR. MediaLab operated the Imgur social media platform in the UK prior to 30 September 2025 and allowed children under the age of 13 to access the platform, purportedly subject to a requirement for parental supervision and whilst claiming to rely on the Article 6(1)(a) UK GDPR (consent) lawful basis. However, MediaLab had no means of determining the age of its users and thus no means of ensuring that it obtained parental consent in respect of users under the age of 13, as required by Article 8 UK GDPR due to the fact that MediaLab offered infrormation society services (i.e. the Imgur platform) directly to children in the UK purportedly on the basis of consent. Therefore, MediaLab did not have a valid lawful basis for processing the personal data of children under the age of 13 and thus processed their personal data unlawfully. In addition, MediaLab failed to carry out a DPIA p
TMAC Ltd
TMAC contravened regulations 21 and 24 of PECR and the ICO issued a monetary penalty of £100,000 and an enforcement notice.
TMAC Ltd
TMAC contravened regulations 21 and 24 of PECR and the ICO issued a monetary penalty of £100,000 and an enforcement notice.
London Borough of Lambeth
Home Office
Allay Claims Ltd
MPN and EN issued to Allay Claims Ltd due to a large volume of unsolicited SMS being sent, promoting PPI tax refund services
Allay Claims Ltd
MPN and EN issued to Allay Claims Ltd due to a large volume of unsolicited SMS being sent, promoting PPI tax refund services
Staines Health Group
Reprimand Issued - Staines Health Group sent excessive medical details about a terminally ill patient to their insurance company. The patient requested that five years of medical records be sent to them to review, before being sent to the insurer in order to progress the claim. But, instead of five years medical history being sent to the patient, Staines Health Group sent 23 years of medical records direct to the insurer. The patient believed the excessive disclosure of unnecessary medical records led to a reduction in the payout of their claim. Failures of Staines Health Group included a lack of written process for staff to follow when handling insurance requests and a lack of regular refresher data protection training for staff.
Police Service of Scotland
The Information Commissioner's Office (ICO) has fined the Police Service of Scotland £66,000 and issued a Reprimand for serious failures in the handling of sensitive personal information.
ZMLUK Limited
ZMLUK Limited were issued with an MPN due to sending unsolicited emails promoting energy saving products.
Post Office Limited
On 25 April 2024, Post Office Limited (POL) uploaded an unredacted copy of a legal Settlement Deed to its corporate website instead of the intended redacted version. The Settlement Deed contained the personal data of 502 claimants who were part of the 2017 group litigation brought against POL which exposed the Horizon IT Scandal.
LastPass UK Ltd
£1,228,283 penalty issued to password management provider LastPass UK Ltd on 20 November 2025 in respect of infringements of Article 5(1)(f) and Article 32(1)(f) UK GDPR. LastPass' failure to implement appropriate technical and organisational security measures allowed a threat actor to exfiltrate personal data relating to approximately 1.6 million UK customers from its backup database. However, due to LastPass' "zero knowledge" encryption system, the most sensitive personal data stored in LastPass customers' password vaults remained encrypted at all times, even after exfiltration by the threat actor.
London Borough of Redbridge
Lead Pronto Ltd
Lead Pronto Ltd were issued with an MPN and an EN due to sending unsolicited SMS promoting Government funded boiler grants.
Lead Pronto Ltd
Lead Pronto Ltd were issued with an MPN and an EN due to sending unsolicited SMS promoting Government funded boiler grants.
Capita plc and Capita Pension Solutions Ltd
The Information Commissioner’s Office has fined Capita plc and Capita Pension Solutions Ltd a combined £14m following a cyber attack in April 2023 which saw hackers gain access to over 6m people’s data.
Qonain Hussain
A former insurance claims advisor has been sentenced for unlawfully accessing personal injury claim records.
Bharat Singh Chand
Bharat Singh Chand is a self-employed lead generator. Between 3 December 2023 and 3 July 2024, he sent or instigated the sending of 966,449 direct marketing SMS messages in breach of regulations 22 and 23 of PECR. This resulted in 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice.
Bharat Singh Chand
Bharat Singh Chand is a self-employed lead generator. Between 3 December 2023 and 3 July 2024, he sent or instigated the sending of 966,449 direct marketing SMS messages in breach of regulations 22 and 23 of PECR. This resulted in 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice.
Jason Blake
The director of a care home in Bridlington, Yorkshire, has been fined for refusing to respond to a request for a resident’s personal information – known as a subject access request (SAR).
Green Spark Energy Ltd
Green Spark Energy Ltd (GSE) was investigated as part of a wider operation set up by the Commissioner to assess and analyse complaint trends in relation to the energy and home improvements sector.
Home Improvement Marketing Ltd
Home Improvement Marketing Ltd (HIML) was investigated as part of a wider operation set up by the Commissioner to assess and analyse complaint trends in relation to the energy and home improvements sector.
Green Spark Energy Ltd
Green Spark Energy Ltd (GSE) was investigated as part of a wider operation set up by the Commissioner to assess and analyse complaint trends in relation to the energy and home improvements sector.
Home Improvement Marketing Ltd
Home Improvement Marketing Ltd (HIML) was investigated as part of a wider operation set up by the Commissioner to assess and analyse complaint trends in relation to the energy and home improvements sector.
Bristol City Council
The Information Commissioner’s Office (ICO) has issued an enforcement notice to Bristol City Council (BCC) for failing to comply with its legal obligations to respond to people who asked for the personal information the council held on them – known as a subject access request (SAR).
Birthlink
The Information Commissioner’s Office (ICO) has fined Scottish charity Birthlink £18,000 after it destroyed approximately 4,800 personal records, up to ten percent of which may be irreplaceable.
South Yorkshire Police
A reprimand has been issued to South Yorkshire Police for failing to ensure it had appropriate technical security and organisation measures in place which led to the accidental deletion of 96,174 pieces of original Body Worn Video footage.
23andMe
The Information Commissioner has fined 23andMe, Inc £2,310,000 for infringements of Articles 5(1)(f) and 32(1) of the UK GDPR between 25 May 2018 and 31 December 2024.23andMe failed to implement appropriate security measures to protect the personal information of 155,592 UK users, following a large-scale cyber attack in 2023.The penalty follows a joint investigation conducted by the ICO and the Office of the Privacy Commissioner of Canada.
Actions by type
Read the chart values
| Action type | Actions |
|---|---|
| Monetary Penalty Notice | 63 |
| Enforcement Notice | 54 |
| Reprimand | 101 |
| Criminal Prosecution | 7 |
The ICO has taken 225 enforcement actions tracked here, including 63 monetary penalties and 101 reprimands. Total fines: £52,533,773.
Public bodies subject to ICO enforcement — NHS trusts, police forces, councils — can be cross-referenced with their inquiry recommendation delivery records to surface patterns between governance failures and accountability gaps.