facebook-pixel

ICO Fines 2026: Biggest Data Protection Penalties in the UK

L
Lunyb Security Team
··9 min read

The Information Commissioner's Office (ICO) has entered 2026 with sharper teeth than ever. As the UK's independent data protection authority, the ICO is responsible for enforcing the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). This year has already produced a fresh wave of headline-grabbing penalties, from multi-million-pound fines against household names to smaller but sharply worded reprimands aimed at public sector bodies.

In this guide, we break down the biggest ICO fines 2026 so far, the trends behind them, and the practical lessons every UK organisation should take away before the regulator comes knocking.

What Are ICO Fines and How Are They Calculated?

ICO fines are monetary penalties issued by the UK's data protection regulator against organisations that breach data protection law. Under the UK GDPR, the ICO can issue fines of up to £17.5 million or 4% of worldwide annual turnover, whichever is higher, for the most serious infringements.

The regulator uses a five-step methodology when calculating a penalty:

  1. Assessing seriousness — considering the nature, gravity, and duration of the infringement.
  2. Accounting for turnover — where the organisation is part of a larger undertaking.
  3. Calculating a starting point based on seriousness and turnover.
  4. Adjusting for aggravating or mitigating factors such as cooperation, prior breaches, or remedial action.
  5. Ensuring the fine is effective, proportionate, and dissuasive.

The ICO also runs a two-tier regime for public sector fines, generally preferring reprimands over financial penalties for government bodies — though 2026 has shown that pattern is beginning to shift.

The Biggest ICO Fines of 2026 So Far

2026 has been dominated by fines linked to ransomware attacks, poorly configured cloud environments, and unlawful marketing calls. Below is a snapshot of the most significant penalties issued this year.

OrganisationSectorFine (£)Main Cause
Advanced Computer Software GroupHealthcare IT£6.09 millionRansomware — inadequate security controls
Genomics data broker (name redacted pending appeal)Biotech£4.4 millionUnlawful special category data processing
Major UK retailerRetail£3.2 millionCustomer database breach via third-party
National lead-generation firmMarketing£1.5 millionPECR breach — unsolicited calls
Local NHS TrustPublic sector£750,000Misconfigured patient portal
Fintech app providerFinancial services£650,000Failure to honour subject access requests

1. Advanced Computer Software Group — £6.09 million

The largest confirmed fine of 2026 so far went to a software supplier providing systems to the NHS. Attackers exploited a customer account that lacked multi-factor authentication, then moved laterally to deploy ransomware. Personal data of tens of thousands of people — including sensitive medical information — was compromised.

The ICO found that the organisation failed to implement appropriate technical measures under Article 32 of the UK GDPR. The fine was reduced from a proposed £6.09 million to a lower final figure after cooperation, but it remains the benchmark case of the year.

2. Genomics Data Broker — £4.4 million

A biotech intermediary was fined for processing genetic and health data without a valid lawful basis under Article 9 of the UK GDPR. The ICO ruled that consent language buried in research participant forms did not meet the threshold of "explicit consent" for special category data.

3. Major UK Retailer — £3.2 million

A well-known high street retailer was penalised after a supply chain breach exposed millions of loyalty scheme records. Investigators noted that risk assessments for the third-party processor had not been reviewed for over four years.

4. PECR Marketing Fines

Nuisance calls remain the ICO's most consistent enforcement target. In 2026 alone, more than a dozen firms have received fines under PECR, with the largest topping £1.5 million for making millions of unsolicited calls promoting solar panels and boiler grants.

Key Trends Behind ICO Enforcement in 2026

Looking across the enforcement register, five clear patterns emerge.

Ransomware Is Now the Number One Trigger

Well over half of the significant fines issued in 2026 followed a ransomware incident. The ICO has been unambiguous: paying the ransom is not a defence, and legacy authentication practices — particularly missing multi-factor authentication — will be treated as a serious failing.

Supply Chain Risk Under the Microscope

Several fines this year involved data controllers being penalised for the failings of their processors. Contracts under Article 28 of the UK GDPR are being scrutinised more rigorously, and the regulator is increasingly asking to see evidence of ongoing audits, not just onboarding checklists.

Special Category Data Under Sharper Scrutiny

Health, genetic, biometric, and children's data cases have all attracted higher penalty multipliers in 2026. The ICO's Children's Code enforcement stream has quietly generated a series of undertakings and reprimands, with fines expected later in the year.

Public Sector No Longer Immune

The ICO's two-year public sector approach, which prioritised reprimands over fines, has ended. NHS Trusts, councils, and central government departments are now firmly back on the enforcement menu.

Marketing and Cookies

PECR continues to drive volume. Cookie consent enforcement is expanding, with the ICO writing to hundreds of the UK's top websites in 2026 asking them to fix non-compliant cookie banners or face action.

How ICO Fines Compare to EU GDPR Penalties

Since Brexit, the UK GDPR and EU GDPR have started to diverge slightly, but the fine structures remain broadly aligned. Here's how the two regimes compare in 2026.

FeatureUK GDPR (ICO)EU GDPR (EDPB / national DPAs)
Maximum fine£17.5m or 4% turnover€20m or 4% turnover
Two-tier structureYesYes
Public sector approachReprimand-first (ending 2026)Varies by member state
Biggest 2026 fine~£6.09m€310m+ (Meta, Ireland)
Cookie enforcementGrowing rapidlyMature and aggressive

While UK fines are smaller in absolute terms, the reputational impact of an ICO enforcement notice can be just as damaging — particularly for organisations bidding for public sector contracts.

Pros and Cons of the UK's Current Enforcement Approach

Pros

  • Proportionate methodology — the five-step calculation gives organisations clarity on how fines are set.
  • Cooperation credit — genuine engagement with the ICO measurably reduces final penalties.
  • Guidance-first culture — the ICO publishes detailed sector guidance before enforcing at scale.
  • Focus on outcomes — reprimands and undertakings can drive change without punitive fines for smaller bodies.

Cons

  • Slow investigations — some 2026 fines relate to breaches from 2022 or 2023.
  • Lower deterrent effect compared to EU peers, particularly for global tech firms.
  • Uncertainty around divergence from EU rules following the Data (Use and Access) Act.
  • Public sector fines ultimately come out of taxpayer budgets.

How to Reduce Your ICO Fine Risk in 2026

Whether you run a small e-commerce site or a national charity, the fundamentals of avoiding ICO enforcement are the same. Follow these steps to reduce your exposure.

  1. Map your data. Maintain an up-to-date record of processing activities under Article 30. You cannot protect what you cannot see.
  2. Enforce multi-factor authentication across all admin accounts, remote access, and cloud consoles.
  3. Patch aggressively. Most 2026 ransomware fines involved unpatched vulnerabilities that had public fixes available.
  4. Audit your processors. Review Article 28 contracts annually and request evidence of security controls.
  5. Fix your cookie banner. Ensure "reject all" is as prominent as "accept all" and that non-essential cookies do not fire before consent.
  6. Train staff continuously. Phishing remains the leading intrusion vector; annual e-learning is no longer enough.
  7. Report breaches within 72 hours. Late reporting is treated as an aggravating factor.
  8. Use privacy-respecting tools. For example, when sharing links in campaigns or internal comms, choose a link management service that supports GDPR-compliant logging and data minimisation, such as Lunyb, so you're not needlessly hoarding click data.

Marketing Compliance: A Special Note

If your organisation runs marketing campaigns, PECR compliance should sit alongside GDPR compliance. Keep clear records of consent, honour opt-outs within 28 days, and screen against the Telephone Preference Service. Tools that shorten or track marketing links should offer transparent analytics — see our 2026 buyer's guide to URL shorteners for privacy-respecting options, and our Rebrandly review for a comparison of enterprise features.

What the ICO Will Prioritise Next

Based on the ICO's published regulatory plan and its recent speeches, expect the second half of 2026 to focus on:

  • AI transparency — particularly automated decision-making under Article 22.
  • Children's data in gaming, education technology, and social platforms.
  • Biometric surveillance by employers and retailers.
  • Data broker practices in adtech and credit scoring.
  • Cyber hygiene in critical supply chains, especially healthcare and local government.

Organisations that align now with these priorities are far less likely to appear on the 2027 fine list.

Conclusion

The 2026 enforcement wave has confirmed what many privacy professionals suspected: the ICO is moving from a guidance-heavy regulator to a genuinely muscular one. Fines are climbing, public sector protection is fading, and technical failings like missing multi-factor authentication are being treated as inexcusable.

The good news is that the fundamentals of avoiding an ICO fine haven't changed. Map your data, secure your systems, honour user rights, and keep evidence of everything. Do that consistently, and the ICO's enforcement team will have no reason to reach for your file.

For more on tools that respect user privacy while giving you the analytics you need, see our honest Lunyb review or our detailed Rebrandly pricing breakdown.

Frequently Asked Questions

What is the maximum ICO fine in 2026?

The maximum penalty under the UK GDPR remains £17.5 million or 4% of global annual turnover, whichever is higher. For less serious infringements the ceiling is £8.7 million or 2% of turnover. No fine issued in 2026 has yet approached the statutory maximum.

How long does the ICO have to issue a fine after a breach?

There is no strict statutory time limit, but the ICO must issue a Notice of Intent within a reasonable period. In practice, investigations typically take 12 to 24 months, and fines finalised in 2026 often relate to breaches disclosed in 2023 or 2024.

Do ICO fines apply to small businesses?

Yes. While the ICO tends to favour reprimands or improvement notices for micro-businesses, small companies have been fined significant amounts under PECR for nuisance marketing. Directors of dissolved companies can also be held personally liable.

Can an organisation appeal an ICO fine?

Yes. Fines can be appealed to the First-tier Tribunal (General Regulatory Chamber) within 28 days. Several 2026 penalties are currently under appeal, and successful appeals have historically reduced or overturned fines in around 15–20% of cases.

How can I check if my organisation is on the ICO enforcement list?

The ICO publishes all monetary penalty notices, enforcement notices, and reprimands on its public enforcement register at ico.org.uk. It's searchable by organisation name, sector, and year, and is updated within days of a decision being issued.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles