Source · Data protection & FOI enforcement
ICO Enforcement Actions
225 total actions
63 monetary penalties
£52,533,773 total fines
Information Commissioner's Office enforcement actions — monetary penalties, enforcement notices, reprimands, and undertakings for data protection and FOI failures.
Enforcement actions
London Borough of Lambeth has only responded to 74% of the SARs it has received within the statutory timescales from 1 August 2020 to 11 August 2021. This equates to 268 SARs. The council continues to have a backlog of SAR cases and, based on the updated figures, does not appear to be improving.
Chief Constable of Kent Police
From October 2020 to February 2021, Kent Police received over 200 SARs, 60% were completed during the statutory deadline. However, some of the remaining SARs are reported to have taken over 18 months to issue a response. As of May 2022, over 200 SARs remain overdue.
Wakefield Council
A reprimand was issued after the Council sent papers prepared as a Court bundle, in relation to Child Protection Legal Proceedings, to the parents of the child in question. The Court documents contained a Child Protection Medical Report which included the home address of the mother and her two children.
Secretary of State for the Home Department (Home Office)
A reprimand has been issued to the Home Office following investigations that showed between March 2021 and November 2021, they had a significant back log of SARs, amounting to just under 21,000 not being responded to during the statutory timeframe. Complaints to the ICO showed requesters suffered significant distress as a result. As of July 2022, there are just over 3,000 unanswered SARs outside of the legal time limit.
London Borough of Hackney
For the period of April 2020 to February 2021, London Borough of Hackney did not respond to over 60% of the SARs submitted to them in the statutory timeframe. The oldest SAR was over 23 months.
Virgin Media Limited
Over a 6 month period in 2021, Virgin Media received over 9500 SARs. 14% of these were not responded to during the statutory timeframe. However, their compliance in 2022 has seen improvements.
National Crime Agency
The exception reports were to highlight where the work of the RPA could not be completed and manual officer intervention was required in order to complete the necessary work on Interpol circulations. Due to this oversight the exception reports were not actioned and as a result the cancellation of the data subject’s extradition order was not actioned which led to the incorrect arrest of the data subject.
Ministry of Justice
A reprimand has been issued after an unauthorised disclosure of personal information.
South Wales Police
A reprimand has been issued after the disclosure of personal information by South Wales Police on two separate occasions, the first reported was for an incident in April 2020 (the first incident), and a second is an incident that actually predates the first, that occurred in February 2020 (the second incident).
Jackson Quinn
Jackson Quinn was representing two children in relation to step-parent adoption proceedings at the family court. The case was listed for a final hearing to take place on 13 February 2021. Two reports containing personal data which were prepared for the court by social workers from were disclosed to the birth father in error by Jackson Quinn.
Secretary of State for the Home Department (Home Office)
A Home Office employee contacted members of the public as part of the creation of an education programme for staff into the historical background and circumstances of individuals arriving into the UK which had led to the matter that became widely and collectively known as the “Windrush scandal” occurring. It is my understanding that interviews were conducted with individuals who had previously been affected by the ”scandal”; that the interviews were recorded on the employee’s personal mobile phone; and subsequently uploaded to her personal YouTube account, from where they were shared with other Home Office employees.
Crown Prosecution Service
A reprimand was issued after an investigation into three separate incidents involving the loss of personal data.
Ministry of Defence
The MoD has been issued with a reprimand following an identified SAR backlog dating back to March 2020. Despite setting up a recovery plan, this backlog has continued to grow, and currently stands at 9,000 SAR requests yet to be responded to. This has meant that, on average, people were typically waiting over 12 months for their information.
Grindr LLC
The ICO deemed that Grindr has failed to provide effective and transparent privacy information to its UK data subjects in relation to the processing of their personal data.
London Borough of Croydon
From April 2020 to April 2021, the London Borough of Croydon Council responded to less than half of their SARs within the statutory timescales. This meant that 115 residents did not receive a response in accordance with the UKGDPR. Additionally, since June 2021, the ICO has issued 27 decisions notices under FOIA related to the Council’s failure to respond to information requests. They were issued with a reprimand.
Direct Clothing Co. (UK) Limited
On 19 August 2021, Direct Clothing Co. (UK) Limited (DCCUK) were contacted by a customer who advised that their payment card had been defrauded after using DCCUK’s website. An investigation by DCCUK found that a malicious code had been introduced to the website which allowed an unknown third party to obtain the payment card details of website customers.
Department of Health and Social Care
The ICO has issued the DHSC with a reprimand in relation to data protection compliance matters under the General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UKGDPR) and the UK Data Protection Act 2018 (DPA).
Allied Health Professionals
Allied Health Professionals have been issued with a reprimand for accidentally making data accessible to health care providers when data subjects had not given consent for this data to be shared.
Bolton at Home
Bolton at Home has been issued with a reprimand for the inappropriate disclosure of personal data.
Warrington and Halton Hospitals NHS Foundation Trust
An appointments administrator uploaded a patient’s urgent referral form to the wrong patient’s notes.
Epsom and St Helier University Hospitals NHS Trust
incorrect test result data was passed by Epsom & St Helier University Hospitals NHS Trust (the Trust) to Public Health England (PHE) resulting in individuals erroneously being contacted via the NHS Test and Trace (NHS T&T) system and advised to isolate.
North Yorkshire County Council
An NYCC employee failed to accurately complete the print to post process and as a result two envelopes containing multiple letters were sent to two different recipients.
Chief Constable of North Yorkshire Police
North Yorkshire Police has been issued with a reprimand in accordance with Schedule 13 (2) of the DPA 2018.
NHS National Services Scotland (NHS NSS)
NHS National Services Scotland (NHS NSS) has been issued with a reprimand in accordance with Article 58(2)(b) of the UK General Data Protection Regulation.
Welsh Language Commissioner
The ICO have decided to issue the WLC with a reprimand in accordance with Article 58(2)(b) of the General Data Protection Regulation.
Actions by type
Read the chart values
| Action type | Actions |
|---|---|
| Monetary Penalty Notice | 63 |
| Enforcement Notice | 54 |
| Reprimand | 101 |
| Criminal Prosecution | 7 |
The ICO has taken 225 enforcement actions tracked here, including 63 monetary penalties and 101 reprimands. Total fines: £52,533,773.
Public bodies subject to ICO enforcement — NHS trusts, police forces, councils — can be cross-referenced with their inquiry recommendation delivery records to surface patterns between governance failures and accountability gaps.