Source · Data protection & FOI enforcement
ICO Enforcement Actions
225 total actions
63 monetary penalties
£52,533,773 total fines
Information Commissioner's Office enforcement actions — monetary penalties, enforcement notices, reprimands, and undertakings for data protection and FOI failures.
Enforcement actions
We issued a reprimand to the London Borough of Hammersmith and Fulham after hidden data within a spreadsheet was inadvertently disclosed in response to a Freedom of Information Act request. The hidden data included personal information relating to 6,528 individuals, 2,342 of whom were children.
Darian Bishop trading as ECO4U
Between 9 January 2023 to 9 October 2023, there were 194,110 unsolicited direct marketing calls made to subscribers who were registered with the TPS and who had not notified Darian Bishop that they were willing to receive such calls. This resulted in 21 complaints which were submitted to the Commissioner and the TPS.
Darian Bishop trading as ECO4U
Between 9 January 2023 to 9 October 2023, there were 194,110 unsolicited direct marketing calls made to subscribers who were registered with the TPS and who had not notified Darian Bishop that they were willing to receive such calls. This resulted in 21 complaints which were submitted to the Commissioner and the TPS.
DPP Law Ltd
The Information Commissioner has fined law firm DPP Law Ltd £60,000 for its infringements of Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR between 25 May 2018 and 17 July 2022.
AFK Letters Co Ltd
It was found that between January and September 2023, AFK made 95,277 spam calls resulting in several complaints being made to the ICO and TPS. AFK did not provide evidence that anyone whose number had been called had consented to receiving calls from the company. The ICO has issued a £90,000 fine.
AFK Letters Co Ltd
It was found that between January and September 2023, AFK made 95,277 spam calls resulting in several complaints being made to the ICO and TPS. AFK did not provide evidence that anyone whose number had been called had consented to receiving calls from the company. The ICO has issued a £90,000 fine.
Advanced Computer Software Group Limited
The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (Advanced) £3.07m for security failings that put the personal information of 79,404 people at risk.
Greater Manchester Police
We issued a reprimand to Greater Manchester Police for failing to ensure that appropriate technical or organisational measures were in place to protect the accidental loss of CCTV data and the failure to provide a data subject with their personal data, both without undue delay and by the end of the applicable period of one month.
Smart Home Ensured Limited
Between 4 July 2023 to 24 August 2023 Smart Home Ensured Limited made 14,508 unsolicited calls for direct marketing purposes in breach of Regulation 21 of PECR. The company has been issued with an Enforcement Notice.
Glasgow City Council
A reprimand was issued to Glasgow City Council as during the period between 01 April 2023 to 01 March 2024, they responded to 45% of incoming subject access requests within the statutory timeframe, thereby infringing Articles 12(3), 15(1) and 15(3) of the UK GDPR.
City of Edinburgh Council
A reprimand was issued to City of Edinburgh Council as during the period between 01 January 2023 to 31 December 2023, it had failed to respond to 40% of Subject Access Requests within the statutory timeframe of one calendar month, thereby infringing Articles 12(3), 15(1) and 15(3) of the UK GDPR.
United Lincolnshire Teaching Hospitals NHS Trust
A reprimand was issued to United Lincolnshire Teaching Hospitals NHS Trust as during the period between 01 March 2021 to 31 March 2022, it had failed to respond to 32% of Subject Access Requests within the statutory timeframe of one calendar month, thereby infringing Articles 12(3), 15(1) and 15(3) of the UK GDPR.
Breathe Services Ltd
Breathe Services Ltd (BSL), a debt advice company based in Bolton, first came to the attention of the ICO as part of a wider investigation into complaints received about unsolicited phone calls to potentially vulnerable individuals.
Breathe Services Ltd
Breathe Services Ltd (BSL), a debt advice company based in Bolton, first came to the attention of the ICO as part of a wider investigation into complaints received about unsolicited phone calls to potentially vulnerable individuals.
Money Bubble Ltd MPN
It was found that between October – November 2022, the company made 168,852 spam calls resulting in several further complaints being made to the ICO and TPS. MBL did not provide evidence that anyone whose number had been called had consented to receiving calls from the company. The ICO has issued a £120,000 fine.
Money Bubble Ltd EN
It was found that between October – November 2022, the company made 168,852 spam calls resulting in several further complaints being made to the ICO and TPS. MBL did not provide evidence that anyone whose number had been called had consented to receiving calls from the company. The ICO has issued a £120,000 fine.
ESL Consultancy Services Ltd
Between 15 September 2022 and 5 December 2023, a total of 37,977 complaints were received regarding direct marketing messages which were sent at the instigation of ESL. The company has been fined £200,000 and issued with an enforcement notice.
ESL Consultancy Services Ltd
Between 15 September 2022 and 5 December 2023, a total of 37,977 complaints were received regarding direct marketing messages which were sent at the instigation of ESL. The company has been fined £200,000 and issued with an enforcement notice.
Quick Tax Claims Limited
An ICO investigation revealed that Quick Tax Claims Limited had sent 7,863,547 unlawful text messages over the course of a month, resulting in 66,793 complaints – 93% of these stating there was no ‘opt out’ option.
Quick Tax Claims Limited
An ICO investigation revealed that Quick Tax Claims Limited had sent 7,863,547 unlawful text messages over the course of a month, resulting in 66,793 complaints – 93% of these stating there was no ‘opt out’ option.
Southend-on-Sea City Council
We issued a reprimand to Southend-on-Sea City Council in Essex after hidden data on a spreadsheet released as part of a freedom of information request revealed the sensitive personal details of staff.
National Debt Advice Limited
National Debt Advice sent 129,902 unsolicited direct marketing text messages to individuals in breach of regulation 22 of PECR resulting in over 4,000 complaints to the 7726 spam reporting service. The company was fined £30,000 and issued with an enforcement notice.
National Debt Advice Limited
National Debt Advice sent 129,902 unsolicited direct marketing text messages to individuals in breach of regulation 22 of PECR resulting in over 4,000 complaints to the 7726 spam reporting service. The company was fined £30,000 and issued with an enforcement notice.
WerepairUK Ltd
WerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £80,000 and issued with an enforcement notice.
WerepairUK Ltd
WerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £80,000 and issued with an enforcement notice.
Service Box Group Limited
Service Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £40,000 and issued with an enforcement notice.
Service Box Group Limited
Service Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £40,000 and issued with an enforcement notice.
Police Service of Northern Ireland
The Police Service of Northern Ireland has been fined £750,000 for infringing Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024.
Bonne Terre Limited t/a Sky Betting and Gaming
We issued a reprimand to Bonne Terre Limited, trading as Sky Betting and Gaming, for unlawfully processing people’s data through advertising cookies without their consent.
The Labour Party
The Labour Party were issued with a reprimand for failing to respond to people’s request for their own personal data, also know as a subject access request, and for failing to respond to peoples request for erasure.
Coastal Windows & Conservatories (UK) Limited
Coastal Windows & Conservatories Limited made over 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people variously saying they had not consented to receiving such calls or received repeated calls despite requests to stop.
Coastal Windows & Conservatories (UK) Limited
Coastal Windows & Conservatories Limited made over 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people variously saying they had not consented to receiving such calls or received repeated calls despite requests to stop.
Chelmer Valley High School
Chelmer Valley High School have been issued a reprimand in respect of Article 35(1). The school failed to complete a Data Protection Impact Assessment (DPIA) prior to introducing facial recognition technology for the purposes of cashless catering.
London Borough of Hackney
The Information Commissioner’s Office has issued the London Borough of Hackey with a reprimand following a cyber-attack in 2020 that led to hackers gaining access to and encrypting 440,000 files, affecting at least 280,000 residents and other individuals including staff.
Levales Solicitors LLP
Reprimand issued to Levales Solicitors LLP (‘Levales’) in respect of Articles 32(1)(b) and 32(1)(d). A threat actor accessed Levales’ cloud-based server using legitimate credentials and subsequently published data on the dark web. The incident affected 8,234 UK individuals, of which 863 individuals were deemed at high risk because of the nature of the data involved. The investigation found Levales were not ensuring the ongoing confidentiality of its processing systems and did not implement appropriate organisational measures.
The Electoral Commission
Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s systems and was able to access personal data held as part of the Electoral Register. This incident impacted approximately 40,000,000 individuals, and the initial access was gained via several unpatched software vulnerabilities. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.
Clyde Valley Housing Association
Clyde Valley Housing Association have received the following reprimand because of an infringement that occurred in July 2022 when they released a new customer portal. This portal included personal data of data subjects and residents found they were able to view personal information such as names and addresses about other residents. A resident reported this to Clyde Valley Housing Association, however this concern was not escalated appropriately which led to data remaining viewable on the portal for a further 5 days until further residents reported the issue and Clyde Valley Housing Association suspended the portal.
University Hospital of Southampton NHS Foundation Trust
A reprimand is being issued to University Hospital of Southampton NHS Foundation Trust as they have only responded to 59% of incoming SARs within the statutory timeframe during the period of 01 August 2022 to 01 July 2023.
Home Office
An enforcement notice and a warning have been issued to the Home Office for failing to assess the privacy risks posed by the electronic monitoring of people arriving in the UK by unauthorised means. The ICO has been in discussion with the Home Office regarding its pilot to place ankle tags on, and track the GPS location of, up to 600 migrants who arrived in the UK and were on immigration bail. Although the pilot ended in December 2023, the Home Office has retained the GPS location data collected by the tags and will continue to be able to access and use that data including sharing it with other third-party organisations. The enforcement notice orders the Home Office to update its internal policies, access guidance and privacy information in relation to the data retained from the pilot. The warning issued also states that any future processing on the same basis will be in breach of data protection law and will attract enforcement action.
Birmingham Children's Trust Community Interest Company
Reprimand issued to Birmingham Children’s Trust Community Interest company in respect of Article 5(1)(f) and 32(1)(b) and 2. A child protection plan containing inappropriate personal data, in the form of criminal allegations against a child, was sent to the family the plan was produced for. Although the care plan itself was authorised for the family to view, the criminal allegations were not relevant to the plan, or authorised for the family’s view. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.
Chief Constable of Kent Police
A reprimand is being issued to Kent Police in respect of an incident in February 2021 when a Kent Police officer took a photograph of an individual’s identity document using her personal mobile phone and uploaded the image onto Telegram, a social media application. From the evidence provided to the ICO, the Telegram distribution group onto which the image was uploaded was being used by multiple UK police forces and international law enforcement agencies for the purpose of combatting vehicle crime. The Kent Police officer did not inform the individual that further processing of his personal data would take place; how it would be processed; or the purpose for doing so.
Dover Harbour Board
A reprimand is being issued to Dover Harbour Board in respect of the creation and use of a social media distribution group, initially created in WhatsApp but later migrated to Telegram. From the evidence provided to the ICO, the distribution groups were used by multiple UK police forces and international law enforcement agencies for the purpose of combatting vehicle crime. The distribution groups were created by an officer from the Port of Dover Police using his personal mobile phone without organisational oversight or compliance with data protection legislation.
Mayor’s Office for Policing and Crime (MOPAC)
Within the London.gov.uk website, there was a webform to contact the London Victims’ Commissioner as well as other webforms. Between 11-14 November 2022, a member of GLA intended to give four members of MOPAC permission to the webforms. However, instead of granting permission to the four members of MOPAC, they made two web forms public. On 23 February 2023 MOPAC were made aware by a member of the public that it was possible for users to click a button that would enable users to access information on every query that had been submitted via the form. 394 people were later notified of the breach due to the nature of the personal data that was made publicly accessible on the forms.
Pinnacle Life Limited
Pinnacle Life Limited
The Central Young Men’s Christian Association
The Central YMCA sent an email to individuals participating in a programme for people living with HIV using “CC” rather than “BCC”, revealing the email addresses to all recipients. 166 individuals could be identified or potentially identified from their email address. As a result, it could be inferred that these individuals were likely to be living with HIV. The Central YMCA have been fined £7,500 and issued a reprimand.
The Central Young Men’s Christian Association
The Central YMCA sent an email to individuals participating in a programme for people living with HIV using “CC” rather than “BCC”, revealing the email addresses to all recipients. 166 individuals could be identified or potentially identified from their email address. As a result, it could be inferred that these individuals were likely to be living with HIV. The Central YMCA have been fined £7,500 and issued a reprimand.
Chief Constable West Midlands Police
A reprimand has been issued to West Midlands Police after the force repeatedly incorrectly linked and merged the records of two individuals with similar personal data. West Midlands Police failed to ensure the accuracy of the personal data of these two individuals, resulting in multiple incidents where officers attended a wrong address, including on one occasion when there were serious safeguarding concerns relating to one of the individuals.
Penny Appeal
The Information Commissioner’s Office (ICO) has issued an Enforcement Notice to Penny Appeal, for sending 461,650 spam text messages over a ten day period. These messages were sent to a database of individuals who had never agreed to receive marketing communication from Penny Appeal.
Ministry of Defence
The MOD sent emails inadvertently using the “To” field rather than the “BCC” field. 265 unique email addresses were disclosed in breach of GDPR Article 5(1)(f). The MOD were fined £350,000.
Actions by type
Read the chart values
| Action type | Actions |
|---|---|
| Monetary Penalty Notice | 63 |
| Enforcement Notice | 54 |
| Reprimand | 101 |
| Criminal Prosecution | 7 |
The ICO has taken 225 enforcement actions tracked here, including 63 monetary penalties and 101 reprimands. Total fines: £52,533,773.
Public bodies subject to ICO enforcement — NHS trusts, police forces, councils — can be cross-referenced with their inquiry recommendation delivery records to surface patterns between governance failures and accountability gaps.