{"id":172251,"date":"2022-07-20T07:46:33","date_gmt":"2022-07-20T06:46:33","guid":{"rendered":"https:\/\/legalvision.co.uk\/?p=172251"},"modified":"2026-03-27T05:54:52","modified_gmt":"2026-03-27T05:54:52","slug":"biggest-fines-ico","status":"publish","type":"post","link":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/","title":{"rendered":"What Are the Biggest Fines Handed Down by the ICO in England?"},"content":{"rendered":"\n<p>The ICO has issued fines totalling nearly \u00a350m against some of the UK&#8217;s most recognisable organisations for breaching the GDPR, and no business is immune from scrutiny. Understanding what triggers an ICO fine and how to prevent a data breach is essential for protecting your business. This article will explore some of the largest fines the ICO has issued to organisations in recent years and the precautionary measures your business can implement to avoid a significant personal data breach.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When Will the ICO Issue Fines?<\/h2>\n\n\n\n<p>The <a href=\"https:\/\/legalvision.co.uk\/corporations\/complying-with-gdpr\/\">GDPR<\/a> is essential to UK law and data and privacy protection. Consequently, any severe breach should result in serious consequences. The Information Commissioner\u2019s Office (ICO) is the primary body responsible for investigating data breaches and handing down <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/data-breach-compensation-amounts\/\">fines<\/a>.&nbsp;<\/p>\n\n\n\n<p>The ICO may issue a fine against your company if it:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>commits a data breach involving the personal data of individuals;<\/li>\n\n\n\n<li>carries out unlawful monitoring of staff and third parties on your premises;<\/li>\n\n\n\n<li>stores <a href=\"https:\/\/legalvision.co.uk\/regulatory-compliance\/sensitive-data-information\/\">sensitive information<\/a> for too long without good reason;<\/li>\n\n\n\n<li>fails to answer or correctly process Subject Access Requests (SARs);<\/li>\n\n\n\n<li>fails to report a serious data breach to the ICO within 72 hours;<\/li>\n\n\n\n<li>fails to store personal information concerning staff and customers safely; or<\/li>\n\n\n\n<li>unlawfully leaks personal or sensitive information to others without the consent of the individuals it belongs to.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Largest Fines Awarded by the ICO&nbsp;<\/h2>\n\n\n\n<p>Currently, the five largest fines issued by the ICO for breach of data protection law add up to nearly \u00a350m. That is a sizeable proportion of the annual global turnover for the organisations affected. The ICO chose those figures to deter organisations from failing to take <a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/privacy-obligations\/\">sufficient security measures<\/a> concerning customer data in the future.<\/p>\n\n\n\n<p>Let us run through each fine and the nature of the UK GDPR breach below.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">British Airways Fine: \u00a320m<\/h3>\n\n\n\n<p>The ICO found that British Airways lacked adequate security measures to guard against cyber attacks. Eventually, this led to a cyber attack in 2018, which took British Airways over two months to find. Here, the fine was so significant because adequate IT security would have prevented the cyber attack, which subsequently leaked the personal and financial details of more than 425,000 customers.<\/p>\n\n\n\n<p>This currently stands as the ICO&#8217;s largest fine to date.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Marriott Hotels Fine: \u00a318.4m<\/h3>\n\n\n\n<p>In 2018, the ICO discovered that a 2014 cyber attack had leaked 339 million guest records worldwide. They concluded that Marriott Hotels failed to protect the stolen data adequately. Given that the stolen information contained names, phone numbers, email addresses and passport numbers, the ICO felt it essential to provide a considerable fine.<\/p>\n\n\n\n<p>In this case, the Information Commissioner said, <em>&#8220;Personal data is precious and businesses have to look after it.&#8221;<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Clearview AI Fine: \u00a37.5m (approx.)<\/h3>\n\n\n\n<p>The ICO fined Clearview AI just over \u00a37.5m for collecting images from the internet and social media for a global face recognition network. Clearview AI obtained the photos without the consent of individuals. Since their global database contained approximately 20 billion images, this was a significant breach of GDPR rules.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ticketmaster Fine: \u00a31.25m<\/h3>\n\n\n\n<p>The ICO found that Ticketmaster had failed to ensure appropriate security on its electronic payment page on its website. Consequently, hackers obtained sensitive financial information including names, credit card numbers and CVV&nbsp;relating to 1.5 million UK citizens.<\/p>\n\n\n\n<div  class=\"box box--icon box--info\">\n    <p>The Deputy Commissioner hoped that the \u00a31.25m fine would <em>&#8220;send a message to other organisations that looking after their customers&#8217; personal details safety should be at the top of their agenda&#8221;.<\/em><\/p>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Cabinet Office Fine: \u00a3500k<\/h3>\n\n\n\n<p>The ICO awarded this fine to the Cabinet Office for the well-publicised postal address leak of the 2020 New Year Honours recipients. Accordingly, the failure to protect this information led to the leaking of over 1000 home addresses online. Furthermore, many high-profile individuals were among the victims.<\/p>\n\n\n\n\n<a href=\"#content-next\"\n   class=\"block p-4 mt-10 text-xl font-bold text-center text-white no-underline bg-gray-800 rounded-t-xl\">\n    Continue reading this article below the form\n    <i class=\"text-xl fa-regular fa-arrow-down\"><\/i>\n<\/a>\n<div class=\"px-6 pt-10 pb-12 mb-10 text-center bg-gray-100 rounded-b-xl sm:px-12 test\">\n    <div class=\"mb-8 text-2xl font-bold text-orange\">\n        Need legal advice?\n        <br>\n        <span class=\"text-lg not-prose\">\n                            Call <a href=\"tel:+448081968584\" class=\"not-prose\">0808 196 8584<\/a> for urgent assistance.\n                <br>\n                Otherwise, complete this form, and we will contact you within one business day.\n                    <\/span>\n    <\/div>\n\n    \n\n<div class=\"not-prose flex justify-center text-left gform_input_bg_white    \">\n    <script>\nvar gform;gform||(document.addEventListener(\"gform_main_scripts_loaded\",function(){gform.scriptsLoaded=!0}),document.addEventListener(\"gform\/theme\/scripts_loaded\",function(){gform.themeScriptsLoaded=!0}),window.addEventListener(\"DOMContentLoaded\",function(){gform.domLoaded=!0}),gform={domLoaded:!1,scriptsLoaded:!1,themeScriptsLoaded:!1,isFormEditor:()=>\"function\"==typeof InitializeEditor,callIfLoaded:function(o){return!(!gform.domLoaded||!gform.scriptsLoaded||!gform.themeScriptsLoaded&&!gform.isFormEditor()||(gform.isFormEditor()&&console.warn(\"The use of gform.initializeOnLoaded() is deprecated in the form editor context and will be removed in Gravity Forms 3.1.\"),o(),0))},initializeOnLoaded:function(o){gform.callIfLoaded(o)||(document.addEventListener(\"gform_main_scripts_loaded\",()=>{gform.scriptsLoaded=!0,gform.callIfLoaded(o)}),document.addEventListener(\"gform\/theme\/scripts_loaded\",()=>{gform.themeScriptsLoaded=!0,gform.callIfLoaded(o)}),window.addEventListener(\"DOMContentLoaded\",()=>{gform.domLoaded=!0,gform.callIfLoaded(o)}))},hooks:{action:{},filter:{}},addAction:function(o,r,e,t){gform.addHook(\"action\",o,r,e,t)},addFilter:function(o,r,e,t){gform.addHook(\"filter\",o,r,e,t)},doAction:function(o){gform.doHook(\"action\",o,arguments)},applyFilters:function(o){return gform.doHook(\"filter\",o,arguments)},removeAction:function(o,r){gform.removeHook(\"action\",o,r)},removeFilter:function(o,r,e){gform.removeHook(\"filter\",o,r,e)},addHook:function(o,r,e,t,n){null==gform.hooks[o][r]&&(gform.hooks[o][r]=[]);var d=gform.hooks[o][r];null==n&&(n=r+\"_\"+d.length),gform.hooks[o][r].push({tag:n,callable:e,priority:t=null==t?10:t})},doHook:function(r,o,e){var t;if(e=Array.prototype.slice.call(e,1),null!=gform.hooks[r][o]&&((o=gform.hooks[r][o]).sort(function(o,r){return o.priority-r.priority}),o.forEach(function(o){\"function\"!=typeof(t=o.callable)&&(t=window[t]),\"action\"==r?t.apply(null,e):e[0]=t.apply(null,e)})),\"filter\"==r)return e[0]},removeHook:function(o,r,t,n){var e;null!=gform.hooks[o][r]&&(e=(e=gform.hooks[o][r]).filter(function(o,r,e){return!!(null!=n&&n!=o.tag||null!=t&&t!=o.priority)}),gform.hooks[o][r]=e)}});\n<\/script>\n\n                <div class='gf_browser_gecko gform_wrapper gravity-theme gform-theme--no-framework lawyer-form_wrapper gplaceholder_wrapper form-with-labels-no-asterisks_wrapper has-new-validation-error-styling_wrapper' data-form-theme='gravity-theme' data-form-index='0' id='gform_wrapper_2453' style='display:none'><div id='gf_2453' class='gform_anchor' tabindex='-1'><\/div><form method='post' enctype='multipart\/form-data' target='gform_ajax_frame_2453' id='gform_2453' class='lawyer-form gplaceholder form-with-labels-no-asterisks has-new-validation-error-styling' action='\/api\/wp\/v2\/posts\/172251#gf_2453' data-formid='2453' novalidate>\n                        <div class='gform-body gform_body'><div id='gform_fields_2453' class='gform_fields top_label form_sublabel_below description_below validation_below'><div id=\"field_2453_1000\" class=\"gfield gfield--type-honeypot gform_validation_container field_sublabel_below gfield--has-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_1000'>Company<\/label><div class='ginput_container'><input name='input_1000' id='input_2453_1000' type='text' value='' autocomplete='new-password'\/><\/div><div class='gfield_description' id='gfield_description_2453_1000'>This field is for validation purposes and should be left unchanged.<\/div><\/div><div id=\"field_2453_1\" class=\"gfield gfield--type-text gfield--input-type-text gf_left_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_1'>First Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_1' id='input_2453_1' type='text' value='' class='medium'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_12\" class=\"gfield gfield--type-text gfield--input-type-text gf_right_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_12'>Last Name<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_text'><input name='input_12' id='input_2453_12' type='text' value='' class='medium'     aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_2\" class=\"gfield gfield--type-email gfield--input-type-email gf_left_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_2'>Email Address<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_email'>\n                            <input name='input_2' id='input_2453_2' type='email' value='' class='medium'    aria-required=\"true\" aria-invalid=\"false\"  \/>\n                        <\/div><\/div><div id=\"field_2453_3\" class=\"gfield gfield--type-phone gfield--input-type-phone gf_right_half gfield--width-half gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_3'>Phone<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_phone'><input name='input_3' id='input_2453_3' type='tel' value='' class='medium'   aria-required=\"true\" aria-invalid=\"false\"   \/><\/div><\/div><div id=\"field_2453_14\" class=\"gfield gfield--type-select gfield--input-type-select gfield--width-full custom-select gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_14'>Number of Employees in Your Business<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_select'><select name='input_14' id='input_2453_14' class='large gfield_select'    aria-required=\"true\" aria-invalid=\"false\" ><option value='' selected='selected'>Select ...<\/option><option value='0' >0<\/option><option value='1' >1-5<\/option><option value='6' >6-20<\/option><option value='21' >21-50<\/option><option value='51' >51-250<\/option><option value='250' >250+<\/option><\/select><\/div><\/div><div id=\"field_2453_4\" class=\"gfield gfield--type-textarea gfield--input-type-textarea gfield_contains_required field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><label class='gfield_label gform-field-label' for='input_2453_4'>Tell us about your enquiry<span class=\"gfield_required\"><span class=\"gfield_required gfield_required_text\">(Required)<\/span><\/span><\/label><div class='ginput_container ginput_container_textarea'><textarea name='input_4' id='input_2453_4' class='textarea medium'     aria-required=\"true\" aria-invalid=\"false\"   rows='10' cols='50'><\/textarea><\/div><\/div><div id=\"field_2453_5\" class=\"gfield gfield--type-html gfield--input-type-html gfield_html gfield_html_formatted gfield_no_follows_desc field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  >By submitting this form, you agree to receive emails from LegalVision and can unsubscribe at any time. View our <a href=\"https:\/\/legalvision.co.uk\/privacy-notice\/\" target=\"_blank\">Privacy Policy<\/a>. <\/div><div id=\"field_2453_8\" class=\"gfield gfield--type-hidden gfield--input-type-hidden gform_hidden field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><div class='ginput_container ginput_container_text'><input name='input_8' id='input_2453_8' type='hidden' class='gform_hidden'  aria-invalid=\"false\" value='http:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172251' \/><\/div><\/div><div id=\"field_2453_13\" class=\"gfield gfield--type-hidden gfield--input-type-hidden gform_hidden field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><div class='ginput_container ginput_container_text'><input name='input_13' id='input_2453_13' type='hidden' class='gform_hidden'  aria-invalid=\"false\" value='generic_form' \/><\/div><\/div><fieldset id=\"field_2453_999\" class=\"gfield gfield--type-checkbox gfield--type-choice gfield__uk-marketo-opt-in field_sublabel_below gfield--no-description field_description_below field_validation_below gfield_visibility_visible\"  ><legend class='gfield_label gform-field-label screen-reader-text' ><\/legend><div class='ginput_container ginput_container_checkbox'><div class='gfield_checkbox ' id='input_2453_999'><div class='gchoice gchoice_2453_999_1'>\n\t\t\t\t\t\t\t\t<input class='gfield-choice-input' name='input_999.1' type='checkbox'  value='1'  id='choice_2453_999_1'   \/>\n\t\t\t\t\t\t\t\t<label for='choice_2453_999_1' id='label_2453_999_1' class='gform-field-label gform-field-label--type-inline'>By submitting this form, you agree to receive content and event invitations from us to help you grow your business. If you do not want to receive such messages, tick here.<\/label>\n\t\t\t\t\t\t\t<\/div><\/div><\/div><\/fieldset><\/div><\/div>\n        <div class='gform-footer gform_footer top_label'> <button type=\"submit\" id=\"gform_submit_button_2453\" class=\"gform_button button\" onclick=\"gform.submission.handleButtonClick(this);\" data-submission-type=\"submit\"><span class=\"gform_submit_button__text\">Submit Now<\/span><\/button> <input type='hidden' name='gform_ajax' value='form_id=2453&amp;title=&amp;description=&amp;tabindex=0&amp;theme=gravity-theme&amp;hash=ec2463697d0d9cef7b71236ae60964c7' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submission_method' data-js='gform_submission_method_2453' value='iframe' \/>\n            <input type='hidden' class='gform_hidden' name='gform_theme' data-js='gform_theme_2453' id='gform_theme_2453' value='gravity-theme' \/>\n            <input type='hidden' class='gform_hidden' name='gform_style_settings' data-js='gform_style_settings_2453' id='gform_style_settings_2453' value='' \/>\n            <input type='hidden' class='gform_hidden' name='is_submit_2453' value='1' \/>\n            <input type='hidden' class='gform_hidden' name='gform_submit' value='2453' \/>\n            \n            <input type='hidden' class='gform_hidden' name='gform_currency' data-currency='GBP' value='mjwHyfViU9Qd9xRkGbAm6ZBRJMzEb1wd\/yuFYO0CsG1l4gbDn1SLCyZCtgRvQea48NjjeNBm1gQU0fMzpZ4ey7g45vV4KLQWYNF4IgtrnjCdLho=' \/>\n            <input type='hidden' class='gform_hidden' name='gform_unique_id' value='' \/>\n            <input type='hidden' class='gform_hidden' name='state_2453' value='WyJ7XCIxNFwiOltcIjIyODY0N2ViMWU3NTcxZjA4YTY4NGJmMDcwMTk3Y2I0XCIsXCJiMzk3YmQ1MDBmMmFjNjk1ODE4MzdmNTBhYTA2MzQ0OFwiLFwiNGYyNGZkZGEwMzlkNDUxMWFhZGE1NGYwZmQwZmNiZTdcIixcIjUyMmJkMDE2M2I2ZmEwOTI3NDZhZjU5YTg0ZmM1NDk5XCIsXCIzODRlNjk1YjQxMTAzMWFiYmQ2ODEyMGYyZWFhMDYyNlwiLFwiYjkzNDcwNTE2MjkxOGRjZWViMjQzNzRjNmE0NGVmNTlcIixcIjQxMTliODZhMzVjYzJiMWViNDZiMmQ4NjRlNGUzZmNjXCJdfSIsIjQ3MjNiMzA2ZDIyZGVkODA2N2YyMjYyOThkYzI1ODVmIl0=' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_target_page_number_2453' id='gform_target_page_number_2453' value='0' \/>\n            <input type='hidden' autocomplete='off' class='gform_hidden' name='gform_source_page_number_2453' id='gform_source_page_number_2453' value='1' \/>\n            <input type='hidden' name='gform_field_values' value='' \/>\n            \n        <\/div>\n                        <\/form>\n                        <\/div>\n\t\t                <iframe style='display:none;width:0px;height:0px;' src='about:blank' name='gform_ajax_frame_2453' id='gform_ajax_frame_2453' title='This iframe contains the logic required to handle Ajax powered Gravity Forms.'><\/iframe>\n\t\t                <script>\ngform.initializeOnLoaded( function() {gformInitSpinner( 2453, 'https:\/\/legalvision.co.uk\/wp-content\/themes\/legalv-v6\/img\/spinner.svg', true );jQuery('#gform_ajax_frame_2453').on('load',function(){var contents = jQuery(this).contents().find('*').html();var is_postback = contents.indexOf('GF_AJAX_POSTBACK') >= 0;if(!is_postback){return;}var form_content = jQuery(this).contents().find('#gform_wrapper_2453');var is_confirmation = jQuery(this).contents().find('#gform_confirmation_wrapper_2453').length > 0;var is_redirect = contents.indexOf('gformRedirect(){') >= 0;var is_form = form_content.length > 0 && ! is_redirect && ! is_confirmation;var mt = parseInt(jQuery('html').css('margin-top'), 10) + parseInt(jQuery('body').css('margin-top'), 10) + 100;if(is_form){form_content.find('form').css('opacity', 0);jQuery('#gform_wrapper_2453').html(form_content.html());if(form_content.hasClass('gform_validation_error')){jQuery('#gform_wrapper_2453').addClass('gform_validation_error');} else {jQuery('#gform_wrapper_2453').removeClass('gform_validation_error');}setTimeout( function() { \/* delay the scroll by 50 milliseconds to fix a bug in chrome *\/ jQuery(document).scrollTop(jQuery('#gform_wrapper_2453').offset().top - mt); }, 50 );if(window['gformInitDatepicker']) {gformInitDatepicker();}if(window['gformInitPriceFields']) {gformInitPriceFields();}var current_page = jQuery('#gform_source_page_number_2453').val();gformInitSpinner( 2453, 'https:\/\/legalvision.co.uk\/wp-content\/themes\/legalv-v6\/img\/spinner.svg', true );jQuery(document).trigger('gform_page_loaded', [2453, current_page]);window['gf_submitting_2453'] = false;}else if(!is_redirect){var confirmation_content = jQuery(this).contents().find('.GF_AJAX_POSTBACK').html();if(!confirmation_content){confirmation_content = contents;}jQuery('#gform_wrapper_2453').replaceWith(confirmation_content);jQuery(document).scrollTop(jQuery('#gf_2453').offset().top - mt);jQuery(document).trigger('gform_confirmation_loaded', [2453]);window['gf_submitting_2453'] = false;wp.a11y.speak(jQuery('#gform_confirmation_message_2453').text());}else{jQuery('#gform_2453').append(contents);if(window['gformRedirect']) {gformRedirect();}}jQuery(document).trigger(\"gform_pre_post_render\", [{ formId: \"2453\", currentPage: \"current_page\", abort: function() { this.preventDefault(); } }]);        if (event && event.defaultPrevented) {                return;        }        const gformWrapperDiv = document.getElementById( \"gform_wrapper_2453\" );        if ( gformWrapperDiv ) {            const visibilitySpan = document.createElement( \"span\" );            visibilitySpan.id = \"gform_visibility_test_2453\";            gformWrapperDiv.insertAdjacentElement( \"afterend\", visibilitySpan );        }        const visibilityTestDiv = document.getElementById( \"gform_visibility_test_2453\" );        let postRenderFired = false;        function triggerPostRender() {            if ( postRenderFired ) {                return;            }            postRenderFired = true;            gform.core.triggerPostRenderEvents( 2453, current_page );            if ( visibilityTestDiv ) {                visibilityTestDiv.parentNode.removeChild( visibilityTestDiv );            }        }        function debounce( func, wait, immediate ) {            var timeout;            return function() {                var context = this, args = arguments;                var later = function() {                    timeout = null;                    if ( !immediate ) func.apply( context, args );                };                var callNow = immediate && !timeout;                clearTimeout( timeout );                timeout = setTimeout( later, wait );                if ( callNow ) func.apply( context, args );            };        }        const debouncedTriggerPostRender = debounce( function() {            triggerPostRender();        }, 200 );        if ( visibilityTestDiv && visibilityTestDiv.offsetParent === null ) {            const observer = new MutationObserver( ( mutations ) => {                mutations.forEach( ( mutation ) => {                    if ( mutation.type === 'attributes' && visibilityTestDiv.offsetParent !== null ) {                        debouncedTriggerPostRender();                        observer.disconnect();                    }                });            });            observer.observe( document.body, {                attributes: true,                childList: false,                subtree: true,                attributeFilter: [ 'style', 'class' ],            });        } else {            triggerPostRender();        }    } );} );\n<\/script>\n<\/div>\n<\/div>\n<div id=\"content-next\"><!-- scroll anchor --><\/div>\n<h2 class=\"wp-block-heading\">Are All ICO Fines Significant?<\/h2>\n\n\n\n<p>Not all ICO-issued fines will be significant. However, the examples above reflect the substantial harms caused by data breaches and the ICO\u2019s strict consequences for non-compliance. Accordingly, ensure your business has strong measures in place to store critical data and safely delete information if need be.<\/p>\n\n\n\n<p>For example, ensure your business has:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>protective passwords to secure information;<\/li>\n\n\n\n<li>anti-virus software against potential hackers;<\/li>\n\n\n\n<li>clear policies relating to how your business stores, manages and deletes information;<\/li>\n\n\n\n<li>procedures for individuals to request information relating to them; and<\/li>\n\n\n\n<li>other relevant measures that are reasonable to install.<\/li>\n<\/ul>\n\n\n\n<p>Data breaches can happen to any business, regardless of its size. On the whole, the surest way to protect yourself and avoid ICO-issued fines is by taking active steps to protect your data.<\/p>\n\n\n\n\n\n\n<div  class=\"box box--icon box--info\">\n    <p><strong>Key Statistics<\/strong><\/p>\n<ol>\n<li><strong>\u00a349.6 million:<\/strong> The combined total of the five largest ICO fines issued between 2018-2020, with British Airways (\u00a320m) and Marriott Hotels (\u00a318.4m) accounting for 77% of this amount.<\/li>\n<li><strong>2,562:<\/strong> The number of data breach reports received by the ICO in Q4 2024, representing a 15% increase from 2023, demonstrating growing regulatory scrutiny and enforcement activity.<\/li>\n<li><strong>72 hours:<\/strong> The mandatory timeframe for organisations to report serious data breaches to the ICO under UK GDPR, with failure to comply potentially resulting in fines of up to \u00a317.5m or 4% of global turnover.<\/li>\n<\/ol>\n<p><strong>Sources:<\/strong><\/p>\n<!-- wp:paragraph {\"fontSize\":\"small\"} -->\n<ol>\n<li>Information Commissioner&#8217;s Office, <em>Enforcement Action Database and Annual Reports<\/em>, 2018-2024.<\/li>\n<li>Information Commissioner&#8217;s Office, <em>Data Security Incident Trends Report<\/em>, Q4 2024.<\/li>\n<li>UK GDPR Article 33; and Information Commissioner&#8217;s Office, <em>Guide to the UK GDPR: Personal Data Breaches<\/em>, updated January 2025.<\/li>\n<\/ol>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Key Takeaways<\/h2>\n\n\n\n<p>The ICO stresses that it will use its powers of financial penalty when justified. The organisation is strict regarding failures in IT security or noticing cyber attacks. However, the ICO are generally lenient toward smaller companies and businesses they are investigating for the first time.<\/p>\n\n\n\n<p>The best advice to protect your commercial interests and avoid ICO-issued fines is to comply with all data protection rules. You can do this by reviewing the guidance documents on the ICO website, including the ICO Employment Practices Code.<\/p>\n\n\n\n<p>If you need help with data protection rules and ICO investigations into alleged breaches of the GDPR, LegalVision provides ongoing legal support for all businesses through our fixed-fee legal membership. Our experienced <a href=\"https:\/\/legalvision.co.uk\/it-lawyers-lp\/\">Data, Privacy and IT lawyers<\/a> help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee.\u00a0To learn more about LegalVision\u2019s legal membership, call <a href=\"tel:+448081968584\" class=\"AVANSERnumber dynamic-number\">0808 196 8584<\/a> or\u00a0<a href=\"https:\/\/legalvision.co.uk\/membership\/\" target=\"_blank\" rel=\"noreferrer noopener\">visit our membership page<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1658296290138\"><strong class=\"schema-faq-question\"><strong>What can my company put forward as mitigating circumstances within any ICO investigation?<\/strong><\/strong> <p class=\"schema-faq-answer\">Your business could stress that it provides annual staff training on data protection rules, always makes a genuine effort to comply with the GDPR and that the impact of any breach was minor. If true, the ICO may require remedial action or reduce the fine level.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1658296310967\"><strong class=\"schema-faq-question\"><strong>How often do the ICO award monetary penalties?<\/strong><\/strong> <p class=\"schema-faq-answer\">While it is rare for the ICO to award a maximum fine, they are not averse to punishing organisations for non-compliance with data protection principles. However, if the breach was minor and your company\u2019s first offence, the ICO may choose not to issue a fine.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1774590680473\"><strong class=\"schema-faq-question\">Are smaller businesses treated differently by the ICO?<\/strong> <p class=\"schema-faq-answer\">Generally yes, the ICO tends to be more lenient towards smaller companies and first-time offenders. However, all businesses regardless of size remain vulnerable to data breaches and should implement appropriate protective measures.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1774590688580\"><strong class=\"schema-faq-question\">What was the largest fine the ICO has ever issued?<\/strong> <p class=\"schema-faq-answer\">British Airways received the ICO&#8217;s largest fine to date &#8211; \u00a320m &#8211; after a 2018 cyber attack leaked personal and financial details of over 425,000 customers due to inadequate IT security measures.<\/p> <\/div> <\/div>\n<div class=\"not-prose m-feedback-prompt\">\n    <!-- Thumbs up\/down bar -->\n    <div class=\"m-feedback-prompt__main\">\n        <div class=\"m-feedback-prompt__title\">Was this article helpful?<\/div>\n        <div>\n            <!--span class=\"m-feedback-prompt__button--text\">Thanks!<\/span-->\n            <button type=\"button\" class=\"m-feedback-prompt__button m-feedback-prompt__button--yes\"\n                    data-analytics-link=\"feedback-prompt:yes\" aria-label=\"Agree\">\n                <i class=\"fa-regular fa-thumbs-up fa-3x\"><\/i>\n            <\/button>\n            <button type=\"button\" class=\"m-feedback-prompt__button m-feedback-prompt__button--no\"\n                    data-analytics-link=\"feedback-prompt:no\" aria-label=\"Disagree\">\n                <i class=\"fa-regular fa-thumbs-down fa-3x\"><\/i>\n            <\/button>\n        <\/div>\n    <\/div>\n\n    <!-- Feedback form -->\n    <div class=\"m-feedback-prompt__form\">\n        <div class=\"m-feedback-prompt__form--thanks \">\n            <div>Thanks!<\/div>\n            <p>\n                We appreciate your feedback \u2013 your submission has been successfully received.            <\/p>\n        <\/div>\n        <form id=\"contact-form\" class=\"m-feedback-prompt__form--form\" action=\"\" method=\"post\">\n            <input type=\"hidden\" id=\"authenticity_token\" name=\"authenticity_token\" value=\"9eb4f72322\" \/><input type=\"hidden\" name=\"_wp_http_referer\" value=\"\/api\/wp\/v2\/posts\/172251\" \/>            <input value=\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\" type=\"hidden\" name=\"currenturl\"\n                   id=\"currenturl\">\n            <input value=\"What Are the Biggest Fines Handed Down by the ICO in England?\" type=\"hidden\" name=\"currenttitle\"\n                   id=\"currenttitle\">\n            <label>\n                <!-- display on thumbs-up -->\n                <span class=\"m-feedback-prompt__feedback m-feedback-prompt__feedback--yes\">\n                    Can you tell us <span class=\"font-semibold\">why<\/span> you found it helpful?\n                <\/span>\n\n                <!-- display on thumbs-down -->\n                <span class=\"m-feedback-prompt__feedback m-feedback-prompt__feedback--no text-lg\">\n                    How can we better improve this article?\n                <\/span>\n                <textarea name=\"feedbackmessage\" id=\"feedbackmessage\" required><\/textarea>\n            <\/label>\n\n            <div class=\"m-feedback-prompt__form--error\" id=\"form-submit-error\"><\/div>\n            <button id=\"submit-contact-form-button\" type=\"submit\" name=\"commit\" class=\"m-feedback-prompt__form--submit\"\n                    data-analytics-link=\"feedback-prompt:submit\">\n                Submit            <\/button>\n        <\/form>\n    <\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The ICO has issued fines totalling nearly \u00a350m against some of the UK&#8217;s most recognisable organisations for breaching the GDPR, and no business is immune from scrutiny. Understanding what triggers an ICO fine and how to prevent a data breach is essential for protecting your business. This article will explore some of the largest fines<a href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\">Continue reading <span class=\"sr-only\">&#8220;What Are the Biggest Fines Handed Down by the ICO in England?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":13414,"featured_media":3104,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"1644,1489,3685,2170,1191,985","_relevanssi_noindex_reason":"","editor_notices":[],"footnotes":""},"categories":[27],"tags":[21,363,365,366,746,798],"class_list":["post-172251","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-privacy-it","tag-medium-business","tag-privacy-obligations","tag-gdpr","tag-data-privacy","tag-ico","tag-data-protection-rules"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Biggest Fines Issued by the ICO | LegalVision UK<\/title>\n<meta name=\"description\" content=\"This article explores the largest fines issued by the ICO for breaching data protection laws. The five biggest totaled almost \u00a350 million.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Biggest Fines Issued by the ICO | LegalVision UK\" \/>\n<meta property=\"og:description\" content=\"This article explores the largest fines issued by the ICO for breaching data protection laws. The five biggest totaled almost \u00a350 million.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\" \/>\n<meta property=\"og:site_name\" content=\"LegalVision UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/LegalVision\" \/>\n<meta property=\"article:published_time\" content=\"2022-07-20T06:46:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-27T05:54:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"775\" \/>\n\t<meta property=\"og:image:height\" content=\"517\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Saeidul Haque\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@LegalVision_law\" \/>\n<meta name=\"twitter:site\" content=\"@LegalVision_law\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Saeidul Haque\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\"},\"author\":{\"name\":\"Saeidul Haque\",\"@id\":\"https:\/\/legalvision.co.uk\/#\/schema\/person\/bfb2a4d49b5b6f7a78045a4c9d6a48bc\"},\"headline\":\"What Are the Biggest Fines Handed Down by the ICO in England?\",\"datePublished\":\"2022-07-20T06:46:33+00:00\",\"dateModified\":\"2026-03-27T05:54:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\"},\"wordCount\":1090,\"image\":{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg\",\"keywords\":[\"medium business\",\"privacy obligations\",\"gdpr\",\"data privacy\",\"ICO\",\"data protection rules\"],\"articleSection\":[\"Data, Privacy and IT Articles\"],\"inLanguage\":\"en-GB\"},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\",\"url\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\",\"name\":\"Biggest Fines Issued by the ICO | LegalVision UK\",\"isPartOf\":{\"@id\":\"https:\/\/legalvision.co.uk\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg\",\"datePublished\":\"2022-07-20T06:46:33+00:00\",\"dateModified\":\"2026-03-27T05:54:52+00:00\",\"author\":{\"@id\":\"https:\/\/legalvision.co.uk\/#\/schema\/person\/bfb2a4d49b5b6f7a78045a4c9d6a48bc\"},\"description\":\"This article explores the largest fines issued by the ICO for breaching data protection laws. The five biggest totaled almost \u00a350 million.\",\"breadcrumb\":{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296290138\"},{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296310967\"},{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590680473\"},{\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590688580\"}],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage\",\"url\":\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg\",\"contentUrl\":\"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg\",\"width\":775,\"height\":517,\"caption\":\"UCTA 1977: Legal Considerations for Small Businesses | LegalVision UK\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/legalvision.co.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data, Privacy and IT Articles\",\"item\":\"https:\/\/legalvision.co.uk\/category\/data-privacy-it\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"What Are the Biggest Fines Handed Down by the ICO in England?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legalvision.co.uk\/#website\",\"url\":\"https:\/\/legalvision.co.uk\/\",\"name\":\"LegalVision UK\",\"description\":\"LegalVision is a commercial law firm in the UK with a commitment to innovation\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legalvision.co.uk\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legalvision.co.uk\/#\/schema\/person\/bfb2a4d49b5b6f7a78045a4c9d6a48bc\",\"name\":\"Saeidul Haque\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/legalvision.co.uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/cropped-Saeidul-2612-scaled-e1714435464850-96x96.jpg\",\"contentUrl\":\"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/cropped-Saeidul-2612-scaled-e1714435464850-96x96.jpg\",\"caption\":\"Saeidul Haque\"},\"description\":\"Saeidul is a Senior Associate in LegalVision\u2019s UK Employment team. He advises on all aspects of employment law, both contentious and non-contentious. Saeidul has substantial experience in advising employers with day-to-day employment law and HR queries, including but not limited to discrimination, grievances, disciplinary matters, redundancies, tribunal claims and restrictive covenants.\",\"url\":\"https:\/\/legalvision.co.uk\/author\/saeidulhaque\/\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296290138\",\"name\":\"What can my company put forward as mitigating circumstances within any ICO investigation?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Your business could stress that it provides annual staff training on data protection rules, always makes a genuine effort to comply with the GDPR and that the impact of any breach was minor. If true, the ICO may require remedial action or reduce the fine level.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296310967\",\"name\":\"How often do the ICO award monetary penalties?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"While it is rare for the ICO to award a maximum fine, they are not averse to punishing organisations for non-compliance with data protection principles. However, if the breach was minor and your company\u2019s first offence, the ICO may choose not to issue a fine.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590680473\",\"name\":\"Are smaller businesses treated differently by the ICO?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Generally yes, the ICO tends to be more lenient towards smaller companies and first-time offenders. However, all businesses regardless of size remain vulnerable to data breaches and should implement appropriate protective measures.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"},{\"@type\":\"Question\",\"@id\":\"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590688580\",\"name\":\"What was the largest fine the ICO has ever issued?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"British Airways received the ICO's largest fine to date - \u00a320m - after a 2018 cyber attack leaked personal and financial details of over 425,000 customers due to inadequate IT security measures.\",\"inLanguage\":\"en-GB\"},\"inLanguage\":\"en-GB\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Biggest Fines Issued by the ICO | LegalVision UK","description":"This article explores the largest fines issued by the ICO for breaching data protection laws. The five biggest totaled almost \u00a350 million.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/","og_locale":"en_GB","og_type":"article","og_title":"Biggest Fines Issued by the ICO | LegalVision UK","og_description":"This article explores the largest fines issued by the ICO for breaching data protection laws. The five biggest totaled almost \u00a350 million.","og_url":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/","og_site_name":"LegalVision UK","article_publisher":"https:\/\/www.facebook.com\/LegalVision","article_published_time":"2022-07-20T06:46:33+00:00","article_modified_time":"2026-03-27T05:54:52+00:00","og_image":[{"width":775,"height":517,"url":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg","type":"image\/jpeg"}],"author":"Saeidul Haque","twitter_card":"summary_large_image","twitter_creator":"@LegalVision_law","twitter_site":"@LegalVision_law","twitter_misc":{"Written by":"Saeidul Haque","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#article","isPartOf":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/"},"author":{"name":"Saeidul Haque","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/bfb2a4d49b5b6f7a78045a4c9d6a48bc"},"headline":"What Are the Biggest Fines Handed Down by the ICO in England?","datePublished":"2022-07-20T06:46:33+00:00","dateModified":"2026-03-27T05:54:52+00:00","mainEntityOfPage":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/"},"wordCount":1090,"image":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage"},"thumbnailUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg","keywords":["medium business","privacy obligations","gdpr","data privacy","ICO","data protection rules"],"articleSection":["Data, Privacy and IT Articles"],"inLanguage":"en-GB"},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/","url":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/","name":"Biggest Fines Issued by the ICO | LegalVision UK","isPartOf":{"@id":"https:\/\/legalvision.co.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage"},"image":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage"},"thumbnailUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg","datePublished":"2022-07-20T06:46:33+00:00","dateModified":"2026-03-27T05:54:52+00:00","author":{"@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/bfb2a4d49b5b6f7a78045a4c9d6a48bc"},"description":"This article explores the largest fines issued by the ICO for breaching data protection laws. The five biggest totaled almost \u00a350 million.","breadcrumb":{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296290138"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296310967"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590680473"},{"@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590688580"}],"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#primaryimage","url":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg","contentUrl":"https:\/\/img.legalvision.com.au\/wp-content\/uploads\/sites\/4\/2022\/05\/24121449\/business-image-052244.jpg","width":775,"height":517,"caption":"UCTA 1977: Legal Considerations for Small Businesses | LegalVision UK"},{"@type":"BreadcrumbList","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legalvision.co.uk\/"},{"@type":"ListItem","position":2,"name":"Data, Privacy and IT Articles","item":"https:\/\/legalvision.co.uk\/category\/data-privacy-it\/"},{"@type":"ListItem","position":3,"name":"What Are the Biggest Fines Handed Down by the ICO in England?"}]},{"@type":"WebSite","@id":"https:\/\/legalvision.co.uk\/#website","url":"https:\/\/legalvision.co.uk\/","name":"LegalVision UK","description":"LegalVision is a commercial law firm in the UK with a commitment to innovation","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legalvision.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/bfb2a4d49b5b6f7a78045a4c9d6a48bc","name":"Saeidul Haque","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/legalvision.co.uk\/#\/schema\/person\/image\/","url":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/cropped-Saeidul-2612-scaled-e1714435464850-96x96.jpg","contentUrl":"https:\/\/legalvision.co.uk\/wp-content\/uploads\/sites\/4\/2024\/04\/cropped-Saeidul-2612-scaled-e1714435464850-96x96.jpg","caption":"Saeidul Haque"},"description":"Saeidul is a Senior Associate in LegalVision\u2019s UK Employment team. He advises on all aspects of employment law, both contentious and non-contentious. Saeidul has substantial experience in advising employers with day-to-day employment law and HR queries, including but not limited to discrimination, grievances, disciplinary matters, redundancies, tribunal claims and restrictive covenants.","url":"https:\/\/legalvision.co.uk\/author\/saeidulhaque\/"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296290138","name":"What can my company put forward as mitigating circumstances within any ICO investigation?","acceptedAnswer":{"@type":"Answer","text":"Your business could stress that it provides annual staff training on data protection rules, always makes a genuine effort to comply with the GDPR and that the impact of any breach was minor. If true, the ICO may require remedial action or reduce the fine level.","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1658296310967","name":"How often do the ICO award monetary penalties?","acceptedAnswer":{"@type":"Answer","text":"While it is rare for the ICO to award a maximum fine, they are not averse to punishing organisations for non-compliance with data protection principles. However, if the breach was minor and your company\u2019s first offence, the ICO may choose not to issue a fine.","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590680473","name":"Are smaller businesses treated differently by the ICO?","acceptedAnswer":{"@type":"Answer","text":"Generally yes, the ICO tends to be more lenient towards smaller companies and first-time offenders. However, all businesses regardless of size remain vulnerable to data breaches and should implement appropriate protective measures.","inLanguage":"en-GB"},"inLanguage":"en-GB"},{"@type":"Question","@id":"https:\/\/legalvision.co.uk\/data-privacy-it\/biggest-fines-ico\/#faq-question-1774590688580","name":"What was the largest fine the ICO has ever issued?","acceptedAnswer":{"@type":"Answer","text":"British Airways received the ICO's largest fine to date - \u00a320m - after a 2018 cyber attack leaked personal and financial details of over 425,000 customers due to inadequate IT security measures.","inLanguage":"en-GB"},"inLanguage":"en-GB"}]}},"_links":{"self":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172251","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/users\/13414"}],"replies":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/comments?post=172251"}],"version-history":[{"count":24,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172251\/revisions"}],"predecessor-version":[{"id":196605,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/posts\/172251\/revisions\/196605"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/media\/3104"}],"wp:attachment":[{"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/media?parent=172251"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/categories?post=172251"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legalvision.co.uk\/api\/wp\/v2\/tags?post=172251"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}