Take note: new guidance on the ICO’s penalties and fines

Take note: new guidance on the ICO’s penalties and fines

On 18 March, the ICO published new Guidance on how it decides to issue penalties and calculate fines in relation to breaches of the UK GDPR and Data Protection Act 2018.  It replaces previous sections in the Regulatory Action Policy from back in 2018. The Guidance is substantial and details step by step what the ICO takes into consideration, whilst making it clear that it will always consider the particular circumstances of each breach. It will serve as a useful guide to organisations to better understand and quantify any monetary enforcement the ICO may take in a particular case

A few key points covered include:

  • Considerations when issuing a penalty notice may include the seriousness, nature and duration of the breach, what personal data is affected and whether there was any intention or negligence;
  • Details on the maximum fining amounts and clarity on what is classed as an undertaking (which is generally broad);
  • If there is more than one breach caused by the same processing activity then the overall fine is still subject to the maximum statutory amount that applies to the most serious breach; and
  • The methodology in which it’ll calculate a fine is a 5 step assessment of: (1) the seriousness of the breach; (2) considering turnover if an undertaking; (3) calculating the starting point based on (1) and (2); (4) taking into account aggravating or mitigating factors; and (5) finally, any adjustments to ensure it is effective, proportionate and dissuasive.

In setting out this Guidance the ICO fulfils its statutory obligation to provide information about how it issues penalties with the overall aim to provide greater certainty and clarity on how it reaches decisions.  We’ve seen increasing enforcement from the ICO and so this Guidance should be helpful to organisations to better understand the decision making and thought process behind  any potential enforcement.

If you would like to keep up to date on the latest in data protection, please get in touch to subscribe to our newsletter, The Data Download.

Recent posts

Previous
Next
Unable to row the distance: No copyright in a rowing machine as a work of artistic craftsmanship (WaterRower v Liking)
Read more
The wait is over – Sky v SkyKick decision handed down today
Read more
Autumn Budget 2024: Headlines
Read more
The Final Word
Read more
The UK's new Data (Use and Access) Bill has been introduced into Parliament
Read more
New reforms but a long wait for change: government publishes Employment Rights Bill draft
Read more
The UK's Data Protection Regulator begins its modernisation plans
Read more
A cautionary tale of lessons learnt in cases involving crypto fraud from D'Aloia v Persons Unknown Category A & Ors [2024]
Read more
‘This is a true story’: A lesson learnt from ‘Baby Reindeer’ for shows dramatising the lives of real people
Read more
Tougher protection on its way for victims of revenge porn
Read more

More from this author

Previous
Next
What businesses should consider before implementing monitoring
Read more
Content moderation: the ICO's guide
Read more
European Parliament issues negative opinion on the EU-US data transfer arrangement
Read more
ICO focusses on child protection in latest guidance to the games industry
Read more
Government to replace the UK GDPR
Read more

Share this page