The Information Commissioner's Office (ICO) has shifted enforcement posture in 2025–2026. After years of action primarily against large organisations, the ICO has increased its focus on practices that affect large numbers of individuals — including SME failures in cookie consent, marketing databases, and data breach response. This article covers what the ICO is prioritising and what it means for growing companies.
ICO Enforcement Priorities in 2025–2026
The ICO's strategic priorities have consistently focused on:
1. Nuisance calls and direct marketing The ICO issues more fines in the direct marketing space than any other category. Violations include:
- SMS and email marketing without valid consent
- Cold calling without checking the Telephone Preference Service (TPS)
- Buying lead lists from data brokers without adequate due diligence on consent
SMEs and startup-stage companies have featured regularly in ICO enforcement for marketing violations. Fines have ranged from tens of thousands to hundreds of thousands of pounds.
2. Data breaches and inadequate security The ICO has enforced against organisations that suffered preventable breaches — particularly where basic security measures (encryption, access controls, patch management) were absent.
For SMEs, the enforcement focus has been on breaches that affect large numbers of individuals, particularly where:
- Sensitive personal data (health, financial, special category) was involved
- Basic security practices were clearly absent
- The organisation failed to notify the ICO within 72 hours
3. Cookie compliance The ICO has been publicly active on cookie consent practices. In 2024–2025, the ICO conducted a series of cookie sweeps — systematic reviews of the top websites by category. Websites using non-compliant banners (pre-ticked boxes, accept-all more prominent than reject, cookies setting before consent) received formal notices.
4. Data retention and deletion Several enforcement actions have addressed organisations retaining data far beyond reasonable periods — particularly in HR, marketing, and customer service contexts. The ICO does not accept indefinite retention.
ICO's SME Enforcement Approach
The ICO has published guidance emphasising that compliance does not require large budgets — it requires the right practices. The ICO's enforcement approach against SMEs:
Proportionate fines: SME fines are substantially lower than fines against large organisations. The £17.5 million maximum is reserved for serious violations by large companies. SME fines in the hundreds of thousands are more typical for significant violations.
Reprimands as an alternative to fines: For less serious violations or first incidents, the ICO increasingly issues reprimands — public statements of non-compliance — rather than financial penalties. These are publicly listed on the ICO register and can reputational impact.
Monetary penalties for serious or repeat violations: Direct marketing without consent, inadequate security leading to significant breaches, and repeat violations attract fines regardless of company size.
Audit powers: The ICO can audit organisations for compliance. Audits can be consensual or (for public sector) statutory. Following a significant incident, an audit is likely.
Most Common SME Violations
Email marketing without valid consent. Sending marketing emails to individuals who did not specifically opt in to receive marketing from your company. Purchased lists are a common source — the vendor's consent may not cover your marketing.
Cookie banners that set cookies before consent. Google Analytics, Facebook Pixel, and similar tools firing before the user accepts cookies. This has been enforced repeatedly.
No response to data subject access requests. Ignoring or missing the one-month DSAR deadline. The ICO routinely receives complaints from individuals who received no response.
Inadequate security — particularly no MFA or encryption. Breaches involving accounts that had no MFA, or data stored unencrypted.
Retaining data of former employees or customers indefinitely. No data deletion policy or automated retention enforcement.
Reporting a Breach to the ICO
For SMEs, breach reporting is often the first significant ICO interaction. Key requirements:
72-hour deadline. From the point you became aware of a breach, not when you completed an investigation. Notify with what you know — partial notification is acceptable; late notification is not.
What to include:
- Nature of the breach (how it happened)
- Categories of personal data involved
- Approximate number of individuals affected
- DPO or contact person details
- Likely consequences
- Measures taken
Where to report: The ICO's online self-reporting tool at ico.org.uk.
What happens next: The ICO assesses the notification and may contact you for further information. Most notifications result in no further action if the breach was handled well and is unlikely to cause significant harm.
What You Can Do to Stay Off the ICO's Radar
- Cookie consent: Implement a consent management platform (Cookiebot, CookieYes, OneTrust) that blocks non-essential cookies before consent and records consent
- Marketing lists: Audit your marketing database — confirm valid consent for each contact
- DSAR procedure: Assign responsibility, set a calendar reminder for 28-day follow-ups
- Security basics: MFA on all company accounts, encryption for any sensitive data, patch management
- Data retention policy: Define and enforce retention periods — automate deletion where possible
- Breach procedure: Have a documented procedure and know how to report before you need to