Reading the ICO’s enforcement record tells you what UK data protection risk actually looks like, and it differs from the EU picture. The headline UK GDPR fines are few and heavily negotiated; the regulator’s daily output is PECR marketing penalties, reprimands, and enforcement notices. Knowing which failures draw which instrument is how you prioritize.
| Authority | Information Commissioner’s Office |
|---|---|
| Max penalty | GBP 17.5M or 4% of turnover (UK GDPR); PECR ceilings raised by DUAA 2025 |
| Largest fine to date | British Airways, GBP 20M (2020) |
| Enforcement record | ico.org.uk enforcement action |
The big fines and what they punished
British Airways (GBP 20 million, 2020): a Magecart-style attack redirected customer payment data; the ICO found inadequate security measures (no MFA on key access, weak monitoring). Intent notice: GBP 183 million. Marriott (GBP 18.4 million, 2020): the inherited Starwood breach, undetected for four years; due diligence and monitoring failures. Intent notice: GBP 99 million. The reductions taught two lessons: the ICO negotiates, and documented remediation plus cooperation materially moves the number.
TikTok (GBP 12.7 million, 2023): up to 1.4 million UK children under 13 using the platform against its own terms, without parental consent, connecting to the Children’s Code agenda. Clearview AI (GBP 7.5 million, 2022): scraping UK faces for biometric matching; the fine survived jurisdictional appeal skirmishes and marks the biometrics line. 23andMe (GBP 2.31 million, 2025): the credential-stuffing breach affecting UK users, a joint investigation with Canada’s OPC.
The volume business: PECR
Most months the ICO’s penalty page is spam enforcement: companies making unlawful marketing calls to TPS-registered numbers, blasting texts without consent, or emailing bought lists. Individual fines run tens to hundreds of thousands of pounds, directors can be personally liable for deliberate breaches, and the DUAA 2025 raises the ceilings toward UK GDPR levels. If your exposure includes outbound marketing, PECR is statistically your biggest UK fine risk.
Current priorities
The ICO has publicly committed resources to: cookie compliance on the UK’s most-visited sites (most conformed after warning letters; the sweep continues down the traffic rankings); children’s privacy, targeting recommender systems and age assurance; AI, biometrics, and facial recognition; and data brokers. Its public sector approach means private companies bear the fining risk. The pattern is consistent: visible, sector-wide sweeps announced in advance, then action against laggards. Being findable as a laggard, a non-compliant banner, trackers firing pre-consent, is the avoidable part; check your own pages with a free scan.