Source · Data protection & FOI enforcement
ICO Enforcement Actions
225 total actions
63 monetary penalties
£52,533,773 total fines
Information Commissioner's Office enforcement actions — monetary penalties, enforcement notices, reprimands, and undertakings for data protection and FOI failures.
Enforcement actions
Simply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The company was fined £40,000 and issued with an enforcement notice.
Simply Connecting Ltd
Simply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The company was fined £40,000 and issued with an enforcement notice.
Gloucester City Council
The Information Commissioner (the Commissioner) issues a reprimand to Gloucester City Council in respect of infringements of Article 32(1)b, Article 32(1)c and Article 32(1)d of the UK GDPR. Gloucester City Council failed to implement appropriate technical and organisational measures to properly secure their systems.
This Is The Big Deal Limited
This Is The Big Deal Limited sent or instigated the sending of 41,417,889 unsolicited direct marketing messages (39,906,342 emails and 1,511,547 text messages) to individuals who had not consented to receiving such messages, in contravention of regulation 22 of PECR. 102,132 of the text messages were sent without the necessary opt-out information as required by regulation 23 of PECR. The company was fined £30,000.
London Borough of Lewisham
During the period of 3 January 2022 to 3 January 2023, 35% of subject access requests (SARs) that London Borough of Lewisham received were not responded to within the statutory deadlines of one and three months. A reprimand has therefore been issued to London Borough of Lewisham in relation to infringements of Article 12(3) and Article 15(1) of the UK General Data Protection Regulation (UK GDPR).
Swinburne, Snowball and Jackson
The Information Commissioner (the Commissioner) issues a reprimand to Swinburne, Snowball and Jackson in respect of infringements of Article 5(1)(f), which requires personal data is processed securely, and Article 32(1)(b) of the UK GDPR, which requires appropriate measures are in place to ensure a level of security appropriate to the risk and ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
Recruitment company reprimand
The Information Commissioner (the Commissioner) issues a reprimand to a recruitment company in respect of infringements of Article 5(1)(f) and 32(1)(b) of the UK GDPR. The organisation misconfigured a storage container, containing 12,000 records and relating to 3,000 workers, to be publicly accessible without any requirement to authenticate.
NHS Lanarkshire
The Information Commissioner (the Commissioner) issues a reprimand to NHS Lanarkshire in accordance with Article 58 (2)(b) of the UK General Data Protection Regulation (UK GDPR) for the sharing of personal data of patients via unauthorised means and secondly, a disclosure of personal data.
My Media World Limited t/a Brand New Tube
Reprimand has been issued to the above organisation in respect of Article 32 (1) and Article 32 (1) (d) of the GDPR. My Media World Limited failed to implement appropriate technical security and organisational measures to properly secure their systems, resulting in unauthorised access to their systems and the exfiltration of personal data relating to 345,000 UK Data Subjects.
Executive Office
On 22 May 2020, the Interim Advocate’s Office sent a newsletter by email to 251 subscribers on its mailing list using the ‘To’ field. The email addresses of the recipients were visible to all who received the email.
The Patient and Client Council
A reprimand has been issued to The Patient and Client Council in relation to infringements of Article 5 (1)(f) and Article 32 (1) of the UK GDPR. The infringements were identified following an investigation into the disclosure of special category due to an email sent to 15 individuals using carbon copy (CC) rather than blind carbon copy (BCC).
Fortis Insolvency Limited
Fortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent with 527,481 received by subscribers between 26 July 2020 and 26 July 2021 in contravention of regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice.
Fortis Insolvency Limited
Fortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent with 527,481 received by subscribers between 26 July 2020 and 26 July 2021 in contravention of regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice.
Nottinghamshire Police
The breach in this case was an unauthorised disclosure of the personal data of witnesses via a police officer’s unredacted statement on the CPS Digital Case Management system. The evidence has revealed that in this instance, the cause of the disclosure of the personal data of witnesses was the failure to ensure the adequate redaction of the data before disclosing this to the CPS.
Crown Glazing Ltd
The case was part of Operation Tinago which was formed to assess and analyse complaint trends in relation to the energy and home improvements sector. The organisation made 503,445 unsolicited calls to TPS registered numbers between 4 January to 11 November 2021. The calls were about energy products to reduce household bills and resulted in a total of 37 complaints.
Crown Glazing Ltd
The case was part of Operation Tinago which was formed to assess and analyse complaint trends in relation to the energy and home improvements sector. The organisation made 503,445 unsolicited calls to TPS registered numbers between 4 January to 11 November 2021. The calls were about energy products to reduce household bills and resulted in a total of 37 complaints.
Maxen Power Supply Limited
Maxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses in contravention of regulations 21 and 24 of PECR. The company was fined £120,000 and issued with an enforcement notice.
Maxen Power Supply Limited
Maxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses in contravention of regulations 21 and 24 of PECR. The company was fined £120,000 and issued with an enforcement notice.
Thames Valley Police
The Information Commissioner (the Commissioner) issues a reprimand to Thames Valey Police (TVP) in accordance with Schedule 13(2)(c) of the Data Protection Act 2018 (DPA 2018) in respect of certain infringements of the DPA 2018.
Parkside Community Primary School
A reprimand has been issued to Parkside Community Primary School in relation to the infringements of Article 5 (1)(f), Article 24 (1) and Article 32 of UK GDPR.
Ice Telecommunications Ltd
Ice Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022.
UK Direct Business Solutions Limited
UK Direct Business Solutions Limited made 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS between 1 March 2020 and 31 October 2021.
Ice Telecommunications Ltd
Ice Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022.
TikTok Information Technologies UK Limited and TikTok Inc (TikTok)
The Information Commissioner’s Office (ICO) has issued a £12,700,000 fine to TikTok Information Technologies UK Limited and TikTok Inc (TikTok) for a number of breaches of data protection law, including failing to use children’s personal data lawfully.
Shropshire Council
The Information Commissioner’s Office (ICO) has issued an enforcement notice to Shropshire Council for its poor handling of requests made under the Freedom of Information Act (FOIA) 2000.
Norfolk County Council
Norfolk County Council has only responded to 260 out of 511 SARs it received within the statutory timescales from 6 April 2021 to 6 April 2022.
Plymouth City Council
A reprimand has been issued to Plymouth City Council in relation to the infringements of Article 12 (3) and Article 15 of the UK GDPR. This case forms part of the ICO’s wider work into SAR compliance.
Ministry of Justice
14 bags of confidential waste were found in an unsecured holding area in the prison, which both prisoners and staff had access to.
University Hospitals Dorset NHS Foundation Trust
The Information Commissioner (the Commissioner) issues a reprimand to University Hospitals Dorset NHS Foundation Trust (the Trust) in accordance with Article 58(2)(b) of the UK General Data Protection Regulation in respect of certain infringements of the UK GDPR.
Join the Triboo Limited
Between 1 August 2019 and 19 August 2020, a confirmed total of 107 million direct marketing messages were sent by Join the Triboo Limited and from those messages 437,324 were received by distinct individuals. This means that each individual received on average 244 emails during the relevant period and that those messages contained direct marketing material for which subscribers had not provided valid consent.
Join the Triboo Limited
Between 1 August 2019 and 19 August 2020, a confirmed total of 107 million direct marketing messages were sent by Join the Triboo Limited and from those messages 437,324 were received by distinct individuals. This means that each individual received on average 244 emails during the relevant period and that those messages contained direct marketing material for which subscribers had not provided valid consent.
Surrey Police
In June 2020, the ICO became aware that staff members across both Sussex Police and Surrey Police had access to an app that recorded all incoming and outgoing phone calls. 1,015 staff members downloaded the app onto their work mobile phones and more than 200,000 recordings of phone conversations, likely with victims, witnesses, and perpetrators of suspected crimes, were automatically saved.
Sussex Police
In June 2020, the ICO became aware that staff members across both Sussex Police and Surrey Police had access to an app that recorded all incoming and outgoing phone calls. 1,015 staff members downloaded the app onto their work mobile phones and more than 200,000 recordings of phone conversations, likely with victims, witnesses, and perpetrators of suspected crimes, were automatically saved.
Achieving for Children
Due to communication failure and a lack organisational measures, Achieving for Children (AfC) inappropriately disclosed personal data, special category data and criminal conviction data in a report.
London Borough of Lewisham
The London Borough of Lewisham has been served with an Enforcement Notice as a result of the evidence seen by the Commissioner about its performance in relation to its statutory duties under the Freedom of information Act (FOIA). Specifically:
Gain Capital UK Limited
Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged an unpatched software vulnerability to access Gain Capital’s systems and exfiltrate personal data relating to 72,361 UK Data Subjects. Gain Capital had a support contract in place with a third party whom they believed were responsible for notifying Gain Capital about software security updates, however the contract stipulated that upgrades were Gain Capital’s responsibility.
NHS Highland
A formal reprimand has been issued to NHS Highland, which emailed 37 people likely to be accessing HIV services, inadvertently using CC (carbon copy) instead of BCC (blind carbon copy). The error meant recipients of the email could see the personal email addresses of other people receiving the email, with one person confirming they recognised four other individuals, one of whom was a previous sexual partner.
University Hospitals Bristol and Weston NHS Foundation Trust
Patient records were saved on to an Electronic Document Viewing System. The Trust decided to terminate the use of this system and the records on it were downloaded prior to allowing the system licence to expire. However this download was not fully successful but this was not investigated prior to the licence expiry and therefore a number of records became inaccessible and some permanently lost.
NHS Blood and Transplant
The Commissioner has decided to issue NHSBT with a reprimand in accordance with Article 58 of the GDPR, after they inadvertently released untested development code into a live system for matching transplant list patients with donated organs in August 2019.
Metropolitan Police Service
MPS was unable to ensure that sensitive criminal records were not able to be uploaded correctly to the Police National Database (PND), or amended, or deleted and that this situation had been in place, unknown to MPS for some considerable time. The consequences of this failure cannot be measured but had the potential to cause significant damage. Of particular concern was that, even though PND had been operational since 2011 MPS had not developed any automated system of checks to ensure that the vast number of criminal record files that were uploaded daily to PND were correctly loaded. In the response to enquiries, MPS described the system of checks at the time of the incident as “immature”. This is concerning given the length of time that PND had been operational when the incident was discovered.
Chartered Institute for Securities & Investment
An unauthorised third party exploited a known vulnerability in the Sitefinity software to leverage a bruteforce attack to upload a malicious code to the Chartered Institute for Securities & Investment (CISI)’s website checkout page. The code captured payment details of an estimated 3,883 UK Data Subjects, as well as other personal data including names and email addresses.
It's OK Limited
Between 1 July 2019 and 1 June 2020, It’s OK Limited engaged in the transmission of 1,752,149 unsolicited calls for direct marketing purposes to subscribers who had been registered with the TPS for not less than 28 days, and who had not notified It's OK Limited that they did not object to receiving such calls, contrary to regulation 21 of PECR.
It's OK Limited
Between 1 July 2019 and 1 June 2020, It’s OK Limited engaged in the transmission of 1,752,149 unsolicited calls for direct marketing purposes to subscribers who had been registered with the TPS for not less than 28 days, and who had not notified It's OK Limited that they did not object to receiving such calls, contrary to regulation 21 of PECR.
Monetise Media Limited
Between 28 July 2020 and 28 July 2021, Monetise Media Limited (MML) sent 3,506,157 direct marketing emails and text messages without valid consent, contrary to the regulation 22 of PECR.
Power Leisure Bookmakers Limited
The ICO has issued PLB with a reprimand, in accordance with Article 58 of the UK GDPR, following breaches reported to the ICO on 27 August 2021, 3 September 2021, 9 June 2022, and 7 July 2022.
Royal Free London NHS Foundation Trust
Hysteroscopy scans were saved on to a series of three USB sticks over a period of nine years from May 2013 until the remaining two encrypted USB sticks became inaccessible on 5 April 2018. It is unknown whether this inaccessibility was as a result of a technical failure of the USBs or human error from inputting the wrong password.
Department for Education
The DfE permitted third party access to the LRS database outside of the DfE and subsequent processing took place of some of that personal data (including children) for the purposes of age verification, without appropriate control or oversight. The investigation has found that therefore the personal data on the LRS database was processed in an insecure manner and for purposes that were not initially intended. Furthermore, the DfE failed to be transparent about that processing.
Department for Work and Pensions
A reprimand has been issued after the inappropriate disclosure of individuals personal data by Child Maintenance Appeals (CM Appeals) within the Department for Work and Pensions (DWP).
Secretary of State for the Home Department
On 5 September 2021 an envelope containing four documents classified 'Official Sensitive' (the Documents) was found at a venue in London, by venue staff. On 6 September 2021, the venue staff handed the documents in to the police and the police subsequently handed them to the Home Office on the same day.
Processing of special category biometric data
In November 2022, the Information Commissioner committed to publish all reprimands from 2022 onwards unless there is a good reason not to.
Actions by type
Read the chart values
| Action type | Actions |
|---|---|
| Monetary Penalty Notice | 63 |
| Enforcement Notice | 54 |
| Reprimand | 101 |
| Criminal Prosecution | 7 |
The ICO has taken 225 enforcement actions tracked here, including 63 monetary penalties and 101 reprimands. Total fines: £52,533,773.
Public bodies subject to ICO enforcement — NHS trusts, police forces, councils — can be cross-referenced with their inquiry recommendation delivery records to surface patterns between governance failures and accountability gaps.