Take note: new guidance on the ICO’s penalties and fines

Take note: new guidance on the ICO’s penalties and fines

On 18 March, the ICO published new Guidance on how it decides to issue penalties and calculate fines in relation to breaches of the UK GDPR and Data Protection Act 2018.  It replaces previous sections in the Regulatory Action Policy from back in 2018. The Guidance is substantial and details step by step what the ICO takes into consideration, whilst making it clear that it will always consider the particular circumstances of each breach. It will serve as a useful guide to organisations to better understand and quantify any monetary enforcement the ICO may take in a particular case

A few key points covered include:

  • Considerations when issuing a penalty notice may include the seriousness, nature and duration of the breach, what personal data is affected and whether there was any intention or negligence;
  • Details on the maximum fining amounts and clarity on what is classed as an undertaking (which is generally broad);
  • If there is more than one breach caused by the same processing activity then the overall fine is still subject to the maximum statutory amount that applies to the most serious breach; and
  • The methodology in which it’ll calculate a fine is a 5 step assessment of: (1) the seriousness of the breach; (2) considering turnover if an undertaking; (3) calculating the starting point based on (1) and (2); (4) taking into account aggravating or mitigating factors; and (5) finally, any adjustments to ensure it is effective, proportionate and dissuasive.

In setting out this Guidance the ICO fulfils its statutory obligation to provide information about how it issues penalties with the overall aim to provide greater certainty and clarity on how it reaches decisions.  We’ve seen increasing enforcement from the ICO and so this Guidance should be helpful to organisations to better understand the decision making and thought process behind  any potential enforcement.

If you would like to keep up to date on the latest in data protection, please get in touch to subscribe to our newsletter, The Data Download.

Recent posts

Previous
Next
AI Report
Read more
Baby Reindeer, internet sleuths and the perils of jigsaw identification
Read more
What businesses should consider before implementing monitoring
Read more
'Consent or pay’: the EDPB’s two cents on the right model
Read more
Labour’s proposed secondary ticketing reforms
Read more
The abolition of non-domicile in the Spring Budget
Read more
Content moderation: the ICO's guide
Read more
The Government moves to address unlawful immigration exemption under the Data Protection Act 2018
Read more
How can I get probate to sell my property?
Read more
Your reputation and AI
Read more

More from this author

Previous
Next
What businesses should consider before implementing monitoring
Read more
Content moderation: the ICO's guide
Read more
European Parliament issues negative opinion on the EU-US data transfer arrangement
Read more
ICO focusses on child protection in latest guidance to the games industry
Read more
Government to replace the UK GDPR
Read more

Share this page