ICO Enforcement Actions
Information Commissioner's Office enforcement actions — monetary penalties, enforcement notices, reprimands, and undertakings for data protection and FOI failures.
211
Total Actions
58
Monetary Penalties
£51,139,873
Total Fines (£)
Actions by Type
Key Insights
The ICO has taken 211 enforcement actions tracked here, including 58 monetary penalties and 100 reprimands. Total fines: £51,139,873.
Public bodies subject to ICO enforcement — NHS trusts, police forces, councils — can be cross-referenced with their inquiry recommendation delivery records to surface patterns between governance failures and accountability gaps.
Showing 211 actions
Money Bubble Ltd MPN
It was found that between October – November 2022, the company made 168,852 spam calls resulting in several further complaints being made to the ICO and TPS. MBL did not …
12 Dec 2024
£120,000
British Library
ICO
Breathe Services Ltd
Breathe Services Ltd (BSL), a debt advice company based in Bolton, first came to the attention of the ICO as part of a wider investigation into complaints received about unsolicited …
12 Dec 2024
Environment Agency
ICO
ESL Consultancy Services Ltd
Between 15 September 2022 and 5 December 2023, a total of 37,977 complaints were received regarding direct marketing messages which were sent at the instigation of ESL. The company has …
05 Dec 2024
Independent Case Examiner
ICO
ESL Consultancy Services Ltd
Between 15 September 2022 and 5 December 2023, a total of 37,977 complaints were received regarding direct marketing messages which were sent at the instigation of ESL. The company has …
05 Dec 2024
£200,000
Independent Case Examiner
ICO
Quick Tax Claims Limited
An ICO investigation revealed that Quick Tax Claims Limited had sent 7,863,547 unlawful text messages over the course of a month, resulting in 66,793 complaints – 93% of these stating …
15 Oct 2024
ICO
Quick Tax Claims Limited
An ICO investigation revealed that Quick Tax Claims Limited had sent 7,863,547 unlawful text messages over the course of a month, resulting in 66,793 complaints – 93% of these stating …
15 Oct 2024
ICO
National Debt Advice Limited
National Debt Advice sent 129,902 unsolicited direct marketing text messages to individuals in breach of regulation 22 of PECR resulting in over 4,000 complaints to the 7726 spam reporting service. …
14 Oct 2024
BT
ICO
National Debt Advice Limited
National Debt Advice sent 129,902 unsolicited direct marketing text messages to individuals in breach of regulation 22 of PECR resulting in over 4,000 complaints to the 7726 spam reporting service. …
14 Oct 2024
£30,000
BT
ICO
Southend-on-Sea City Council
We issued a reprimand to Southend-on-Sea City Council in Essex after hidden data on a spreadsheet released as part of a freedom of information request revealed the sensitive personal details …
14 Oct 2024
Southend-on-Sea City Council
ICO
WerepairUK Ltd
WerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £80,000 and issued with an enforcement notice.
10 Oct 2024
ICO
WerepairUK Ltd
WerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £80,000 and issued with an enforcement notice.
10 Oct 2024
£80,000
ICO
Service Box Group Limited
Service Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £40,000 and issued with an enforcement notice.
10 Oct 2024
£40,000
Independent Case Examiner
ICO
Service Box Group Limited
Service Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The company has been fined £40,000 and issued with an enforcement notice.
10 Oct 2024
Independent Case Examiner
ICO
Police Service of Northern Ireland
The Police Service of Northern Ireland has been fined £750,000 for infringing Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024.
03 Oct 2024
£750,000
Police Service of Northern Ireland
ICO
Bonne Terre Limited t/a Sky Betting and Gaming
We issued a reprimand to Bonne Terre Limited, trading as Sky Betting and Gaming, for unlawfully processing people’s data through advertising cookies without their consent.
02 Sep 2024
ICO
The Labour Party
The Labour Party were issued with a reprimand for failing to respond to people’s request for their own personal data, also know as a subject access request, and for failing …
20 Aug 2024
Historic England
ICO
Coastal Windows & Conservatories (UK) Limited
Coastal Windows & Conservatories Limited made over 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous …
15 Aug 2024
Office for National Statistics
ICO
Coastal Windows & Conservatories (UK) Limited
Coastal Windows & Conservatories Limited made over 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous …
15 Aug 2024
Office for National Statistics
ICO
Chelmer Valley High School
Chelmer Valley High School have been issued a reprimand in respect of Article 35(1). The school failed to complete a Data Protection Impact Assessment (DPIA) prior to introducing facial recognition …
22 Jul 2024
CHELMER VALLEY HIGH SCHOOL
ICO
London Borough of Hackney
The Information Commissioner’s Office has issued the London Borough of Hackey with a reprimand following a cyber-attack in 2020 that led to hackers gaining access to and encrypting 440,000 files, …
05 Jul 2024
London Borough of Hackney
ICO
Levales Solicitors LLP
Reprimand issued to Levales Solicitors LLP (‘Levales’) in respect of Articles 32(1)(b) and 32(1)(d). A threat actor accessed Levales’ cloud-based server using legitimate credentials and subsequently published data on the …
21 Jun 2024
Crossrail International
ICO
The Electoral Commission
Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s …
09 May 2024
The Electoral Commission
ICO
Clyde Valley Housing Association
Clyde Valley Housing Association have received the following reprimand because of an infringement that occurred in July 2022 when they released a new customer portal. This portal included personal data …
09 Apr 2024
Crossrail International
ICO
University Hospital of Southampton NHS Foundation Trust
A reprimand is being issued to University Hospital of Southampton NHS Foundation Trust as they have only responded to 59% of incoming SARs within the statutory timeframe during the period …
25 Mar 2024
Defence Academy of the United Kingdom
ICO
Home Office
An enforcement notice and a warning have been issued to the Home Office for failing to assess the privacy risks posed by the electronic monitoring of people arriving in the …
21 Mar 2024
Home Office
ICO
Birmingham Children's Trust Community Interest Company
Reprimand issued to Birmingham Children’s Trust Community Interest company in respect of Article 5(1)(f) and 32(1)(b) and 2. A child protection plan containing inappropriate personal data, in the form of …
18 Mar 2024
Committee on Mutagenicity of Chemicals in Food, Consumer Products and the Environment
ICO
Dover Harbour Board
A reprimand is being issued to Dover Harbour Board in respect of the creation and use of a social media distribution group, initially created in WhatsApp but later migrated to …
15 Mar 2024
Architects Registration Board
ICO
Chief Constable of Kent Police
A reprimand is being issued to Kent Police in respect of an incident in February 2021 when a Kent Police officer took a photograph of an individual’s identity document using …
15 Mar 2024
British Library
ICO
Mayor’s Office for Policing and Crime (MOPAC)
Within the London.gov.uk website, there was a webform to contact the London Victims’ Commissioner as well as other webforms. Between 11-14 November 2022, a member of GLA intended to give …
13 Mar 2024
Crime
ICO
Pinnacle Life Limited
07 Mar 2024
ICO
Pinnacle Life Limited
07 Mar 2024
ICO
The Central Young Men’s Christian Association
The Central YMCA sent an email to individuals participating in a programme for people living with HIV using “CC” rather than “BCC”, revealing the email addresses to all recipients. 166 …
06 Mar 2024
£7,500
Crossrail International
ICO
The Central Young Men’s Christian Association
The Central YMCA sent an email to individuals participating in a programme for people living with HIV using “CC” rather than “BCC”, revealing the email addresses to all recipients. 166 …
06 Mar 2024
Crossrail International
ICO
Chief Constable West Midlands Police
A reprimand has been issued to West Midlands Police after the force repeatedly incorrectly linked and merged the records of two individuals with similar personal data. West Midlands Police failed …
01 Mar 2024
British Library
ICO
Penny Appeal
The Information Commissioner’s Office (ICO) has issued an Enforcement Notice to Penny Appeal, for sending 461,650 spam text messages over a ten day period. These messages were sent to a …
01 Mar 2024
Environment Agency
ICO
Ministry of Defence
The MOD sent emails inadvertently using the “To” field rather than the “BCC” field. 265 unique email addresses were disclosed in breach of GDPR Article 5(1)(f). The MOD were fined …
26 Feb 2024
£350,000
Ministry of Defence
ICO
Serco Leisure Operating Limited and relevant associated Trusts
Serco Leisure, Serco Jersey and seven associated community leisure trusts have been issued enforcement notices ordering them to stop using facial recognition technology and fingerprint scanning to monitor employee attendance. …
23 Feb 2024
Active Travel England
ICO
Dr Telemarketing
15 Feb 2024
ICO
Dr Telemarketing
15 Feb 2024
ICO
Chief Constable Dorset Police
Chief Constable Dorset Police have continuously infringed Article 12(3) of the UK GDPR and Part 3, Chapter 3, Section 54 of the DPA 2018 for over four years. In this …
02 Feb 2024
British Library
ICO
Chief Constable Devon and Cornwall Police
Chief Constable Devon and Cornwall Police have continuously infringed Article 12(3) of the UK GDPR and Part 3, Chapter 3, Section 54 of the DPA 2018 for over four years. …
02 Feb 2024
British Library
ICO
L.A.D.H Limited
L.A.D.H Limited sent 31,329 direct market text messages to individuals in breach of regulation 22 and 23 of PECR. The company was fined £50,000 and issued with an enforcement notice.
19 Jan 2024
£50,000
ICO
L.A.D.H Limited
L.A.D. H Limited sent 31,329 direct market text messages to individuals in breach of regulation 22 and 23 of PECR. The company was fined £50,000 and issued with an enforcement …
19 Jan 2024
ICO
Crown Prosecution Service
An Enforcement Notice has been issued to the Crown Prosecution Service in relation to a contravention of the sixth data protection principle in section 40 DPA 2018. The contravention was …
18 Jan 2024
Crown Prosecution Service
ICO
Skean Homes Ltd
16 Jan 2024
Environment Agency
ICO
Poxell Ltd
16 Jan 2024
The Pensions Ombudsman
ICO
Poxell Ltd
16 Jan 2024
The Pensions Ombudsman
ICO
Skean Homes Ltd
16 Jan 2024
Environment Agency
ICO
Grocery Delivery E-Services UK Ltd t/a HelloFresh
The Information Commissioner’s Office (ICO) has fined food delivery company HelloFresh £140,000 for a campaign of 79 million spam emails and 1 million spam texts over a seven-month period. The …
12 Jan 2024
£140,000
Historic England
ICO
South Tees Hospitals NHS Trust
The reprimand was issued as the South Tees Hospitals NHS Trust (the Trust) was found to have not ensured that its staff were fully trained and prepared to deal with …
20 Dec 2023
South Tees Hospitals NHS Foundation Trust
ICO