FineME

Jurisdictional Intelligence · GB

United Kingdom

Post-Brexit, the UK enforces UK GDPR and DPA 2018 independently via the ICO. The Online Safety Act 2023 adds major new duties for platforms; the DMCC Act gives the CMA gatekeeper powers over big tech.

Where regulatory precedent shapes global financial standards

Total Fines Tracked

€80.5M

EUR equivalent

Average Fine

€7.3M

per enforcement action

Top Sector

Technology

most-fined industry

Authorities

active regulators

Regulators

Authorities

No authority data yet.

Enforcement

Landmark Cases

View all

Advanced Computer Software Group Limited

cybersecurity
ICO-UKUK-GDPR-DPA20182024

Advanced Computer Software Group, supplier of NHS 111 and other critical healthcare IT services, was fined for an August 2022 ransomware attack that disrupted NHS services and compromised personal data of 82,946 patients. The ICO found Advanced had failed to implement multi-factor authentication across its systems, had inadequate vulnerability scanning, and had not conducted a DPIA for the health systems it managed — forcing NHS 111 to revert to paper records and disrupting ambulance dispatch across England. The fine was reduced from an initial notice of £6.09 million following representations.

€3.6M

London Borough of Hackney

cybersecurity
ICO-UKUK-GDPR-DPA20182023

The London Borough of Hackney was fined for a October 2020 ransomware attack that compromised personal data of a large number of council residents and staff, including housing benefit records, social care information, and sensitive data such as racial and ethnic origin. The ICO found Hackney had failed to patch known software vulnerabilities, had inadequate security monitoring, and had insufficient network segmentation — all of which contributed to the successful attack. The council took over two years to fully restore its systems, significantly disrupting public services.

€114,660.0

TikTok Information Technologies UK Limited

technology
ICO-UKUK-GDPR-DPA20182023

TikTok was fined for processing the personal data of an estimated 1.4 million children under 13 in the UK without appropriate parental consent between May 2018 and July 2020, and for allowing under-13s to create accounts on the platform despite claiming to prevent this. The ICO found TikTok also failed to use children's data in accordance with its own privacy policy and failed to ensure data accuracy. The investigation drew on the ICO's Age Appropriate Design Code (Children's Code), which came into force in September 2021 and sets out standards platforms must meet when processing children's data.

€14.9M

Interserve Group Limited

cybersecurity
ICO-UKUK-GDPR-DPA20182022

Interserve Group, a major UK government contractor, was fined for a 2020 phishing attack that compromised personal and special category data of up to 113,000 current and former employees, including health, financial, and immigration status information. The ICO found Interserve had failed to implement adequate anti-phishing controls, failed to follow its own security processes for flagging suspicious emails, had outdated and unpatched software across its systems, and provided insufficient staff security training. The company was also required to implement a formal remediation programme.

€5.1M

Easylife Group Limited

technology
ICO-UKUK-GDPR-DPA20182022

Easylife Group unlawfully profiled over 145,000 customers using purchase history to infer health conditions and then sold them related health products without their knowledge or consent — for example, inferring diabetes from purchases of compression socks and targeting those customers with diabetes medication products. The ICO found this constituted processing of inferred special category health data without explicit consent, as required by UK GDPR Art. 9. Easylife was simultaneously fined £130,000 by the ICO under PECR for related unlawful direct marketing calls.

€1.6M

Clearview AI Inc.

technology
ICO-UKUK-GDPR-DPA20182022

The ICO fined Clearview AI for unlawfully scraping and processing facial images of UK residents to build a database of over 20 billion images used to offer facial recognition services to law enforcement and commercial clients, without lawful basis, transparency, or any mechanism for UK residents to exercise data subject rights. The ICO coordinated its investigation with Australian and other privacy regulators as part of a joint international enforcement effort. The fine was reduced from an initial enforcement notice of £17.1 million following representations.

€8.8M

Marriott International Inc.

cybersecurity
ICO-UKUK-GDPR-DPA20182020

Marriott International was fined for a data breach originating from a compromise of the Starwood Hotels reservation system that dated to 2014, remained undetected until 2018, and ultimately exposed approximately 339 million guest records worldwide including around 7 million UK residents. The ICO found Marriott failed to conduct adequate due diligence when it acquired Starwood in 2016 and failed to implement adequate security measures on the inherited systems post-acquisition. The fine was reduced from an initial notice of £99.2 million following co-operation with the investigation.

€21.5M

British Airways plc

cybersecurity
ICO-UKUK-GDPR-DPA20182020

British Airways suffered a 2018 cyberattack in which attackers injected malicious JavaScript onto the BA website that harvested personal and payment card data of approximately 429,612 customers by redirecting users to a fraudulent site during the booking process. The ICO found BA's security measures were inadequate and that the attack could have been prevented with more robust controls including script integrity monitoring and multi-factor authentication. The fine was reduced from an initial notice of £183.39 million due in part to the economic impact of COVID-19 on the aviation sector.

€23.4M

Doorstep Dispensaree Ltd

technology
ICO-UKUK-GDPR-DPA20182020

Doorstep Dispensaree, a pharmacy delivering medication to care homes, was fined after ICO inspectors discovered approximately 500,000 documents — including patient names, addresses, dates of birth, NHS numbers, medical conditions, and prescription details — stored in unlocked caged trolleys in an external car park, exposed to the elements and accessible to anyone. The documents, some dating to 2016, had no document retention schedule or secure destruction procedures. The ICO found the pharmacy had failed to implement any of the basic physical security measures required for health records.

€321,750.0

Virgin Media Limited

cybersecurity
ICO-UKUK-GDPR-DPA20182020

Virgin Media Limited left a marketing database containing personal data of approximately 900,000 customers incorrectly configured and publicly accessible online for approximately ten months between April 2019 and February 2020. The ICO found Virgin Media failed to conduct a Data Protection Impact Assessment for the database, failed to apply basic access controls, and failed to maintain procedures for regular security testing — the misconfiguration was discovered not by Virgin Media's own monitoring but by a security researcher. The exposed data included names, home addresses, email addresses, and phone numbers.

€585,000.0

DSG Retail Limited (Currys PC World)

cybersecurity
ICO-UKUK-GDPR-DPA20182020

DSG Retail Limited (Currys PC World) was fined the maximum penalty under the Data Protection Act 1998 following a cyberattack between July 2017 and April 2018 in which attackers installed malware on point-of-sale terminals across hundreds of UK stores, compromising the payment card data of an estimated 14 million customers. The ICO found DSG had inadequate patch management, no vulnerability scanning programme, and failed to detect the nine-month compromise through absence of basic security monitoring. The violations predated GDPR but the fine was the maximum available under the applicable DPA 1998 regime.

€585,000.0

Legal Framework

Regulations by Domain

Technology

OSA 2023Active

Online Safety Act 2023

technology
Up to £18M or 10% of global annual qualifying revenue (higher figure); criminal prosecution for senior managers
DMCC ActActive

Digital Markets, Competition and Consumers Act 2024

technology
SMS firms: up to 10% of global annual turnover; consumer protection: up to £300,000 or 10% of global turnover
UK GDPR / DPA 2018Active

UK General Data Protection Regulation + Data Protection Act 2018

technology
Higher tier: £17.5M or 4% of global annual turnover; standard tier: £8.75M or 2%
PECRActive

Privacy and Electronic Communications Regulations 2003

technology
Up to £500,000 per violation standalone; UK GDPR fines (up to £17.5M / 4%) where personal data also involved

Finance

MLR 2017Active

Money Laundering Regulations 2017

finance
Unlimited fines; criminal prosecution for senior management; individual liability for systemic AML failures
FCA RulesActive

FCA Regulatory Framework (FSMA 2000 + FCA Handbook)

finance
Unlimited — fines are proportionate and revenue-based; criminal prosecution for market abuse and financial crime

Cybersecurity

NIS Regs 2018Active

NIS Regulations 2018 (Network and Information Systems)

cybersecurity
Up to £17M per violation; competent authorities include Ofcom, sector regulators, and NCSC

Marketplace

Regulatory Experts