UK Privacy Law United Kingdom

ICO Enforcement Trends: What the UK Regulator Actually Fines

Analysis of ICO enforcement patterns: the biggest UK GDPR fines, the PECR fining machine, the public sector approach, and current regulatory priorities.

Regulation

UK GDPR; DPA 2018; PECR

Max Penalty

GBP 17.5 million or 4% of global annual turnover

Enforcing Authority

Information Commissioner's Office (ICO)

Official Source

ico.org.uk

Executive Summary

  • The ICO's largest UK GDPR fines are British Airways (GBP 20 million, 2020), Marriott (GBP 18.4 million, 2020), TikTok (GBP 12.7 million, 2023), and Clearview AI (GBP 7.5 million, 2022), with 23andMe fined GBP 2.31 million in 2025 over its breach.
  • Both mega-fines were dramatically reduced from initial intent notices (BA from GBP 183 million, Marriott from GBP 99 million), establishing the ICO's pattern of negotiating down.
  • The volume of ICO fines is PECR spam enforcement: a steady stream of five- and six-figure penalties for unlawful calls, texts, and emails.
  • The ICO uses a public sector approach favoring reprimands over fines for public bodies, and publishes reprimands that carry reputational weight.
  • Current priorities: children's privacy and recommender systems, cookie banner compliance on top UK sites, AI and biometrics, and data broker practices.

Reading the ICO’s enforcement record tells you what UK data protection risk actually looks like, and it differs from the EU picture. The headline UK GDPR fines are few and heavily negotiated; the regulator’s daily output is PECR marketing penalties, reprimands, and enforcement notices. Knowing which failures draw which instrument is how you prioritize.

AuthorityInformation Commissioner’s Office
Max penaltyGBP 17.5M or 4% of turnover (UK GDPR); PECR ceilings raised by DUAA 2025
Largest fine to dateBritish Airways, GBP 20M (2020)
Enforcement recordico.org.uk enforcement action

The big fines and what they punished

British Airways (GBP 20 million, 2020): a Magecart-style attack redirected customer payment data; the ICO found inadequate security measures (no MFA on key access, weak monitoring). Intent notice: GBP 183 million. Marriott (GBP 18.4 million, 2020): the inherited Starwood breach, undetected for four years; due diligence and monitoring failures. Intent notice: GBP 99 million. The reductions taught two lessons: the ICO negotiates, and documented remediation plus cooperation materially moves the number.

TikTok (GBP 12.7 million, 2023): up to 1.4 million UK children under 13 using the platform against its own terms, without parental consent, connecting to the Children’s Code agenda. Clearview AI (GBP 7.5 million, 2022): scraping UK faces for biometric matching; the fine survived jurisdictional appeal skirmishes and marks the biometrics line. 23andMe (GBP 2.31 million, 2025): the credential-stuffing breach affecting UK users, a joint investigation with Canada’s OPC.

The volume business: PECR

Most months the ICO’s penalty page is spam enforcement: companies making unlawful marketing calls to TPS-registered numbers, blasting texts without consent, or emailing bought lists. Individual fines run tens to hundreds of thousands of pounds, directors can be personally liable for deliberate breaches, and the DUAA 2025 raises the ceilings toward UK GDPR levels. If your exposure includes outbound marketing, PECR is statistically your biggest UK fine risk.

Current priorities

The ICO has publicly committed resources to: cookie compliance on the UK’s most-visited sites (most conformed after warning letters; the sweep continues down the traffic rankings); children’s privacy, targeting recommender systems and age assurance; AI, biometrics, and facial recognition; and data brokers. Its public sector approach means private companies bear the fining risk. The pattern is consistent: visible, sector-wide sweeps announced in advance, then action against laggards. Being findable as a laggard, a non-compliant banner, trackers firing pre-consent, is the avoidable part; check your own pages with a free scan.

Frequently Asked Questions

What is the largest fine the ICO has issued?

British Airways, GBP 20 million in 2020, for security failures behind its 2018 breach affecting roughly 400,000 customers. The initial intent notice was GBP 183 million; COVID-era representations and mitigation brought it down. Marriott's GBP 18.4 million (from an intended GBP 99 million) followed the same arc.

Does the ICO fine as heavily as EU regulators?

No. There is no UK equivalent of the EUR 1.2 billion Meta fine; the ICO leans on reprimands, enforcement notices, and negotiated reductions, and has said fines are not its primary measure of impact. But PECR marketing fines are frequent, and the DUAA 2025 raises PECR ceilings substantially.

What does the ICO fine most often?

By count, PECR breaches: unlawful marketing calls, texts, and emails, typically GBP 50,000 to GBP 350,000 per case, month after month. Data protection fines are rarer and target security failures, children's data, and unlawful biometrics such as Clearview AI's scraping.

Does the ICO fine public bodies?

Rarely, by design. Its public sector approach, trialed from 2022 and made ICO policy since, prefers reprimands and enforcement notices so fines don't drain public budgets. High-harm cases can still draw penalties, and published reprimands name the organization.

What should compliance teams watch now?

The ICO's cookie banner sweep of top UK websites, its children's code strategy aimed at social media and video platforms, AI and biometric guidance and enforcement, and rising PECR penalties under the DUAA 2025. Security basics behind BA/Marriott-style fines remain the evergreen risk.

Regulatory Crosswalk

EU GDPRUK PECR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.