FineMeFine Intelligence
🇬🇧
UKGB

United Kingdom

Where regulatory precedent shapes global financial standards

Information Commissioner's Office·ICO

UK GDPRData Protection Act 2018PECRNIS Regulations 2018
Big Ben
3/5
Enforcement
1–3%
Penalty basis
22 mo
Avg investigation
178
Cases tracked
£189M
Total fines

Enforcement profile

The ICO is a well-established authority that has signalled a more proportionate post-Brexit approach. It reduced several large provisional fines (British Airways originally faced £183M before reduction to £20M). ICO is particularly active on data breaches, PECR cookie compliance, and children's data. It publishes detailed enforcement guidance.

Post-Brexit, ICO enforces UK GDPR separately — not bound by EU DPA decisions
ICO has explicitly adopted a more "pragmatic" approach than EU counterparts since 2022
PECR (cookie rules) enforcement is a major focus alongside UK GDPR

Notable enforcement decisions

British AirwaysGDPR Art. 5, 322020

Insufficient security measures led to breach exposing 400,000 customer records including payment data.

£20M
Marriott InternationalGDPR Art. 5, 322020

Failure to implement adequate security following acquisition of Starwood hotel group systems.

£18.4M
TikTokUK GDPR Art. 5, 62023

Processing personal data of children under 13 without parental consent.

£12.7M
Clearview AIUK GDPR Art. 6, 92022

Unlawful collection and use of facial recognition data of UK residents.

£7.5M

Active regulations

UK GDPR
Data Protection Act 2018
PECR
NIS Regulations 2018
Big Ben

The Gothic clock tower at the north end of the Palace of Westminster — synonymous with London and British governance.

Enforcement data is based on publicly available decisions and may not reflect every action, appeal, reduction, or subsequent court ruling. Fine amounts are shown as reported at the time of the decision. This information is for intelligence purposes and does not constitute legal advice.