Source · Data protection & FOI enforcement
ICO Enforcement Actions
225 total actions
63 monetary penalties
£52,533,773 total fines
Information Commissioner's Office enforcement actions — monetary penalties, enforcement notices, reprimands, and undertakings for data protection and FOI failures.
Enforcement actions
Serco Leisure, Serco Jersey and seven associated community leisure trusts have been issued enforcement notices ordering them to stop using facial recognition technology and fingerprint scanning to monitor employee attendance. The ICO's investigation found that Serco and the trusts have been unlawfully processing the biometric data of more than 2,000 employees at 38 leisure facilities for the purpose of monitoring attendance.
Dr Telemarketing
Dr Telemarketing
Chief Constable Dorset Police
Chief Constable Dorset Police have continuously infringed Article 12(3) of the UK GDPR and Part 3, Chapter 3, Section 54 of the DPA 2018 for over four years. In this case, Dorset Police have had a subject access request backlog since 2018 which has resulted in a large number of subject access requests not being responded to within the legislative timeframe of one or three (where extension is appropriately applied) calendar months.
Chief Constable Devon and Cornwall Police
Chief Constable Devon and Cornwall Police have continuously infringed Article 12(3) of the UK GDPR and Part 3, Chapter 3, Section 54 of the DPA 2018 for over four years. In this case, Devon and Cornwall Police have had a subject access request backlog since 2018 which has resulted in a large number of subject access requests not being responded to within the legislative timeframe of one or three (where extension is appropriately applied) calendar months.
L.A.D.H Limited
L.A.D.H Limited sent 31,329 direct market text messages to individuals in breach of regulation 22 and 23 of PECR. The company was fined £50,000 and issued with an enforcement notice.
L.A.D.H Limited
L.A.D. H Limited sent 31,329 direct market text messages to individuals in breach of regulation 22 and 23 of PECR. The company was fined £50,000 and issued with an enforcement notice.
Crown Prosecution Service
An Enforcement Notice has been issued to the Crown Prosecution Service in relation to a contravention of the sixth data protection principle in section 40 DPA 2018. The contravention was identified following an investigation into the disclosure of an unencrypted USB device, containingpersonal data, to an unauthorised third party.
Skean Homes Ltd
Poxell Ltd
Skean Homes Ltd
Poxell Ltd
Grocery Delivery E-Services UK Ltd t/a HelloFresh
The Information Commissioner’s Office (ICO) has fined food delivery company HelloFresh £140,000 for a campaign of 79 million spam emails and 1 million spam texts over a seven-month period. The marketing messages were sent based on an opt-in statement which did not make any reference to the sending of marketing via text, and which was also bundled with an age confirmation statement which was likely to unfairly incentivise customers to agree. Customers were also not given sufficient information that their data would continue to be used for marketing purposes for up to 24 months after cancelling their subscriptions.
South Tees Hospitals NHS Trust
The reprimand was issued as the South Tees Hospitals NHS Trust (the Trust) was found to have not ensured that its staff were fully trained and prepared to deal with correspondence that was particularly sensitive, and which had been referred to the Trust via legitimate but unusual channels. Staff were not provided with appropriate guidance to ensure that they could deal with sensitive correspondence in every situation. The effect of the infringement was that significant distress was caused to the family of a child patient at a time that was already particularly traumatic for the family.
Finham Park Multi Academy Trust
Finham Park Multi Academy Trust have been issued a Reprimand in respect of Articles 5 (1) (f) and 32 (1) (b). An unauthorised third party utilised compromised credentials to access and encrypt Finham Park’s systems. 1843 UK Data Subjects were affected by the incident, and the ICO’s investigation found Finham Park did not have adequate account lockout or password policies in place.
Daniel George Bentley and Taipan Trading Ltd
Daniel George Bentley is a sole trader and director of Taipan Trading Ltd. Between 1 May 2022 and 31 July 2023 he and his company sent over 2.5 million unsolicited direct marketing text messages to individuals in breach of regulations 22 and 23 of PECR.
Bank of Ireland
BOI failed to ensure the accuracy of customers’ default loan status which led to inaccurate personal data being held on their account which was subsequently incorrectly recorded on customers’ credit profile.
Charnwood Borough Council
Reprimand issued for the disclosure of the new address of the data subject to an ex-partner who was the alleged perpetrator of domestic abuse against the data subject. This caused significant distress to the data subject and has the potential to result in actual harm. In addition, the investigation highlighted that the process to make address changes was not properly communicated to the data subject, and that there was an absence of a written and well communicated process for dealing with correspondence in these sensitive circumstances for staff to use. In addition, the Council had not ensured that all members of staff involved in this incident had received data protection training in the twelve months prior to the incident.
NHS Fife
The Information Commissioner’s Office (ICO) has issued a reprimand to NHS Fife, after an unauthorised individual was able to enter a ward and access the personal information of 14 patients.
Intelling Ltd
GRS (Roadstone) Limited
The Information Commissioner (the Commissioner) issues a reprimand to GRS (Roadstone) Limited in respect of infringements of Article 32 (1) (b) and Article 32 (1) (d) of the UK GDPR. The organisation did not have appropriate security measures in place, which resulted in an unauthorised Threat Actor being able to exfiltrate the individual personal data of current and former employees.
DPG Professional Services Ltd
DPG Professional Services Ltd
Complete Marketing Services Ltd
Complete Marketing Services Ltd
University Hospital of Derby and Burton NHS Trust (UHDB)
UHDB failed to have adequate processes in place, especially when processing special category data, which resulted in referrals for out-patients’ appointments not being processed in a timely manner. In some cases, this led to delays of up to two years before medical treatment was arranged.
Argentum Data Solutions Ltd
Between 1 January 2021 and 31 January 2022 there were a total of 2,330,423 SMS sent without consent. 24,309 were sent by ADS directly and it allowed its lines to be used by third parties to send the remaining 2,306,114. These messages were sent in breach of regulation 22 of PECR. ADS came to our attention following a review of complaints received by the 7726 spam reporting tool.
Police Service of Northern Ireland (PSNI)
Police Service of Northern Ireland (PSNI) failed to have appropriate measures in place to prevent unlawful sharing of personal data including criminal data with the United States Department of Homeland Security (DHS)
Argentum Data Solutions Ltd
Between 1 January 2021 and 31 January 2022 there were a total of 2,330,423 SMS sent without consent. 24,309 were sent by ADS directly and it allowed its lines to be used by third parties to send the remaining 2,306,114. These messages were sent in breach of regulation 22 of PECR. ADS came to our attention following a review of complaints received by the 7726 spam reporting tool.
Outsource Strategies Ltd
Outsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints from people variously saying they received repeated calls despite requests to stop and that the callers were aggressive.
Outsource Strategies Ltd
Outsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints from people variously saying they received repeated calls despite requests to stop and that the callers were aggressive.
Gap Personnel Holdings Limited
The Information Commissioner (the Commissioner) issues a reprimand to Gap Personnel Holdings Limited in respect of infringements of Article 32 (1), Article 32 (1) (b) and Article 32 (1) (d) of the UK GDPR. The organisation did not have appropriate security measures in place, which resulted in an unauthorised threat actor being able to access individuals personal data twice within a 12-month period.
Optionis Group Limited
The data controller suffered a ransomware attack, which resulted in the exfiltration of personal data. A reprimand was issued in respect of specific infringements of the UK GDPR, which include lack of multi-factor authentication, an inadequate account lockout policy, and no clear Bring Your Own Device policy.
Chief Constable West Mercia Police and Chief Constable Warwickshire Police
On 21 June 2021 West Mercia Police and Warwickshire Police erroneously decommissioned a server containing a Warwickshire Police application. This application contained Warwickshire Police data from between November 2001 and early 2014. The data which has been lost on this application is unrecoverable.
Digivo Media Limited
Between 24 March 2021 and 7 September 2021 there were 415,041 texts delivered without valid consent – breach of Regulation 22 of PECR. Digivo came to the ICO’s attention following a review of debt management complaints received via the SPAM reporting tool.
Digivo Media Limited
Between 24 March 2021 and 7 September 2021 there were 415,041 texts delivered without valid consent – breach of Regulation 22 of PECR. Digivo came to the ICO’s attention following a review of debt management complaints received via the SPAM reporting tool.
MCP Online Ltd
Between 1 January 2022 and 28 September 2022 there were 20,939 calls made to CTPS or TPS registered numbers – breach of Reg 21 and 24 of PECR. MCP came to the ICO’s attention following a review of complaints made to the Telephone Preference Service (TPS) in November 2021 as part of Operation Torc, which has been set up to investigate unsolicited pensions calls.
MCP Online Ltd
Between 1 January 2022 and 28 September 2022 there were 20,939 calls made to CTPS or TPS registered numbers – breach of Reg 21 and 24 of PECR. MCP came to the ICO’s attention following a review of complaints made to the Telephone Preference Service (TPS) in November 2021 as part of Operation Torc, which has been set up to investigate unsolicited pensions calls.
Nottinghamshire County Council
A social worker sent copies of a Child and Family Assessment report to the mother and her two ex-partners: each the father of one of her two children. The report contained sensitive personal data which should have been redacted from the copies sent to the partners.
RHAP Ltd
RHAP Ltd made 15,288 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £65,000 and issued with an enforcement notice.
RHAP Ltd
RHAP Ltd made 15,288 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £65,000 and issued with an enforcement notice.
House Hold Appliances 247 Ltd
House Hold Appliances 247 Ltd made 19,069 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £55,000 and issued with an enforcement notice.
Cover Appliance Limited
Cover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £200,000 and issued with an enforcement notice.
F12 Management Ltd
F12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £200,000 and issued with an enforcement notice.
House Hold Appliances 247 Ltd
House Hold Appliances 247 Ltd made 19,069 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £55,000 and issued with an enforcement notice.
F12 Management Ltd
F12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £200,000 and issued with an enforcement notice.
SGS Home Protect Ltd
SGS Home Protect Ltd made 24,214 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £70,000 and issued with an enforcement notice.
SGS Home Protect Ltd
SGS Home Protect Ltd made 24,214 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £70,000 and issued with an enforcement notice.
Cover Appliance Ltd
Cover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The company was fined £200,000 and issued with an enforcement notice.
Ministry of Justice
The Information Commissioner (the Commissioner) issues a reprimand to the Ministry of Justice (the MoJ) in accordance with Article 58(2)(b) of the UK General Data Protection Regulation in respect of certain infringements of the UK GDPR.
Actions by type
Read the chart values
| Action type | Actions |
|---|---|
| Monetary Penalty Notice | 63 |
| Enforcement Notice | 54 |
| Reprimand | 101 |
| Criminal Prosecution | 7 |
The ICO has taken 225 enforcement actions tracked here, including 63 monetary penalties and 101 reprimands. Total fines: £52,533,773.
Public bodies subject to ICO enforcement — NHS trusts, police forces, councils — can be cross-referenced with their inquiry recommendation delivery records to surface patterns between governance failures and accountability gaps.