Skip to content
UK GDPR

ICO Fines 2024–2025: Lessons for Growing Companies

4 min readUpdated 2 September 2026

The ICO's enforcement register for 2024–2025 provides a clear picture of what violations lead to fines and what the practical exposure is for growing companies. The pattern is consistent: direct marketing violations, inadequate security, and failure to respond to data subject requests account for the majority of enforcement actions.


Overview of ICO Enforcement in 2024–2025

The ICO issues three main types of enforcement outcomes:

  • Monetary Penalty Notices (MPNs): Financial fines
  • Reprimands: Public statements of non-compliance, no immediate financial penalty, but documented and reputationally damaging
  • Enforcement Notices: Orders to implement specific changes

In 2024–2025, the ICO issued approximately 70–90 MPNs and a significantly higher number of reprimands. Total fines issued exceeded £10 million across the enforcement year.


Top Fine Categories and Amounts

Direct Marketing Violations (PECR)

Direct marketing enforcement remains the ICO's highest-volume category. Common violations:

SMS and email marketing without consent:

  • Typical fine range: £30,000–£150,000 for SMEs
  • Higher for companies with large datasets or systematic violations

Cold calling without TPS checking:

  • Typical fine range: £10,000–£100,000
  • Multiple companies fined for ignoring TPS registrations entirely

Lead generation without adequate consent disclosure:

  • Companies that sold or passed leads without adequate consent to the receiving company
  • Both the lead generator and the marketing company receiving the leads can be fined

Selected 2024–2025 examples:

  • A financial services lead generation company: £120,000 for selling leads where the consent did not cover the receiving company's marketing
  • A SaaS marketing tool: £50,000 for enabling customers to send marketing without filtering against TPS
  • A health-related e-commerce company: £80,000 for SMS marketing using purchased lists without adequate consent verification

Inadequate Security — Data Breaches

Breaches caused by basic security failures:

  • Typical fine range for SMEs: £50,000–£250,000
  • No MFA on accounts, unencrypted data, unpatched vulnerabilities

Selected 2024–2025 examples:

  • An online retailer: £200,000 for a breach exposing customer financial data, where the root cause was an unpatched SQL injection vulnerability
  • A healthcare provider: £150,000 for a ransomware attack that exploited absence of MFA on remote access systems
  • A legal firm: £100,000 for a breach caused by an employee using an unencrypted USB drive

DSAR Non-Response

Ignoring or excessively delaying data subject access requests:

  • ICO action typically triggered by individual complaints
  • For SMEs: typically reprimands first, fines for repeated non-compliance
  • Fines in the £10,000–£50,000 range for persistent non-response

Cookie Consent Failures

The ICO conducted sector sweeps and issued several notices to companies running non-compliant cookie banners. Most were resolved through reprimands and required changes — not immediately financial. But reprimands are publicly listed and can affect due diligence processes for fundraising and enterprise sales.


What Drives the Fine Amount

Aggravating factors:

  • Large number of individuals affected
  • Special category or sensitive data involved
  • Wilful or deliberate violation (not accidental)
  • Previous ICO engagement on the same issue
  • Financial gain from the violation (marketing revenue from non-consented campaigns)
  • Failure to cooperate with the ICO investigation

Mitigating factors:

  • Prompt notification and cooperation
  • Evidence of attempting compliance (even if falling short)
  • Rapid remediation after discovery
  • No actual harm to individuals demonstrated
  • Small organisation with limited resources

The ICO explicitly considers company size and revenue. A fine that is significant for a 10-person company would be a rounding error for a large enterprise. The ICO's objective is deterrence — the fine must be meaningful in proportion to the organisation.


Reprimands: Not to Be Dismissed

Reprimands are published on the ICO's website and included in the ICO's enforcement register. For growing companies:

  • Due diligence in fundraising rounds increasingly includes ICO register checks
  • Enterprise customers conducting supplier qualification may flag ICO reprimands
  • A reprimand is a public record of a compliance failure

The ICO will often issue a reprimand as a first step, with a threat of financial penalties for non-compliance. Taking reprimands seriously and remedying the issue prevents escalation.


Practical Lessons from 2024–2025 Enforcement

Build a valid marketing consent database. The most common enforcement area. If you use purchased lists or generate leads, the consent must specifically cover your marketing.

Deploy MFA everywhere. Multiple fines linked to breaches where MFA was absent. This is now a basic hygiene standard — absence is indefensible.

Have a DSAR procedure and follow it. Set a calendar trigger for 28 days. Failure to respond is one of the most straightforward ICO complaints to investigate.

Get your cookie consent right. Run a cookie scan before the ICO does. Tools like Cookiebot Compliance Scanner will identify issues.

Document your compliance. Companies that can demonstrate a genuine compliance programme get more lenient treatment than companies that have done nothing. Documented effort, even if imperfect, matters.

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →