Skip to main content
UK GDPR Enforcement Tracker

UK ICO GDPR enforcement actions

A neutral, factual record of how the UK Information Commissioner's Office enforces data protection law. This tracker aggregates 150 published ICO actions — 50 monetary penalties totalling £41,682,773, plus 50 reprimands, 44 enforcement notices and 5 prosecutions — broken down by sector and year.

By the numbers

Totals computed directly from the published ICO actions in this dataset (8 Jun 2023 to 29 May 2026).

150
Total actions
50
Monetary penalties
£41,682,773
Total fines
£14,472,500
Largest fine
50
Reprimands
44
Enforcement notices

GDPR fine risk by sector

Pick a sector to see the ICO actions actually recorded against it. Every figure is a published outcome from the dataset — this is a factual lookup, not a predictive score.

See the ICO actions actually recorded against this sector in the dataset. All figures are published ICO outcomes — not a prediction.

20
Recorded actions
9
Monetary penalties
£855,000
Total fines
£95,000
Avg. per penalty
Share of this sector's actions that were monetary penalties
45%
Share of all recorded fines in this dataset
2%

Across the 150 actions in this dataset, the ICO recorded 50 monetary penalties totalling £41,682,773. Reprimands, enforcement notices and prosecutions carry no ICO fine and are counted as actions only. These are historical published outcomes and do not indicate the likelihood of any future action.

Most recent actions

The 25 most recently published ICO actions in this dataset. Each row links to the original ICO notice.

DateOrganisationActionFineSectorSource
29 May 2026Debbie Okparavero and Maliha Islam - Proceeds of Crime ActProsecutionICO notice
15 May 2026Rizwan Manjra - Proceeds of Crime ActProsecutionICO notice
7 May 2026South Staffordshire Plc and South Staffordshire Water PlcMonetary penalty£963,900UtilitiesICO notice
21 Apr 2026SA Assistance LtdEnforcement noticeGeneral businessICO notice
30 Mar 2026Energy Prices Direct LimitedMonetary penalty£160,000UtilitiesICO notice
23 Feb 2026Reddit, Inc.Monetary penalty£14,472,500Online technology and telecomsICO notice
20 Feb 2026The Commissioner of Police for the City of LondonReprimandCriminal justiceICO notice
11 Feb 2026Christopher Munro and William ChipomaProsecutionICO notice
4 Feb 2026MediaLab.AI, Inc.Monetary penalty£247,590Online technology and telecomsICO notice
3 Feb 2026TMAC LtdEnforcement noticeGeneral businessICO notice
3 Feb 2026TMAC LtdMonetary penalty£100,000General businessICO notice
15 Jan 2026Allay Claims LtdEnforcement noticeFinance insurance and creditICO notice
15 Jan 2026Allay Claims LtdMonetary penalty£120,000Finance insurance and creditICO notice
16 Dec 2025Staines Health GroupReprimandHealthICO notice
12 Dec 2025Police Service of ScotlandReprimandMonetary penalties, Criminal justiceICO notice
11 Dec 2025ZMLUK LimitedMonetary penalty£105,000MarketingICO notice
2 Dec 2025Post Office LimitedReprimandICO notice
20 Nov 2025LastPass UK LtdMonetary penalty£1,228,283Online technology and telecomsICO notice
6 Nov 2025Lead Pronto LtdMonetary penaltyMarketingICO notice
6 Nov 2025Lead Pronto LtdEnforcement noticeMarketingICO notice
15 Oct 2025Capita plc and Capita Pension Solutions LtdMonetary penalty£14,000,000ICO notice
9 Oct 2025South Wales PoliceEnforcement noticeCriminal justiceICO notice
8 Oct 2025Qonain HussainProsecutionICO notice
16 Sept 2025Bharat Singh ChandMonetary penalty£200,000ICO notice
16 Sept 2025Bharat Singh ChandEnforcement noticeICO notice

Source: ICO (Information Commissioner's Office) — Enforcement action. Contains public sector information licensed under the Open Government Licence v3.0. Showing 150 of 210 published actions, retrieved 2026-06-18. Figures are historical ICO outcomes presented neutrally and are not legal advice.

GDPR enforcement FAQ

What is the UK ICO and what enforcement powers does it have?
The Information Commissioner’s Office (ICO) is the UK’s independent data protection regulator. Under the UK GDPR, the Data Protection Act 2018 and PECR it can issue monetary penalties (fines), reprimands, enforcement notices requiring specific action, and bring prosecutions. Not every action carries a fine — reprimands, enforcement notices and prosecutions are recorded as actions without an ICO monetary penalty.
How large can a UK GDPR fine be?
Under the UK GDPR the maximum penalty for the most serious infringements is the higher of £17.5 million or 4% of total annual worldwide turnover. Less serious infringements are capped at the higher of £8.7 million or 2% of turnover. Actual fines published by the ICO vary widely with the facts of each case.
Which sectors see the most ICO enforcement action?
In this dataset, marketing, finance/insurance/credit, criminal justice, general business and local government appear most frequently. The by-sector pages show the exact recorded action count and total fines for each sector — see the breakdown below.
Where does this enforcement data come from?
Every action is taken from the ICO’s published "Action we’ve taken" enforcement listing and the linked Monetary Penalty Notices. Fine amounts are recorded only where the ICO confirms a monetary penalty figure. The data is licensed under the Open Government Licence v3.0 and presented neutrally.
How can a business reduce its GDPR fine risk?
The articles most cited in these notices — Article 5(1)(f) and Article 32 (security of processing) and PECR regulation 22 (direct marketing consent) — point to the same fundamentals: a lawful basis for every processing activity, demonstrable security controls, valid consent for marketing, and a tested breach-response process. A structured GDPR audit maps your data flows against these obligations and produces a prioritised remediation plan.

Stay off the ICO's enforcement list

GeraCompliance's fixed-scope GDPR sprint maps your data flows, finds your gaps against the same articles cited in these notices, and gives you a prioritised remediation plan — in days, not months.