ICO Enforcement News: Latest UK Data Protection Fines & Actions

ICO-Enforcement

Written by

in

Recent ICO Enforcement shows a wider pattern than headline fines alone. The regulator is using monetary penalties, reprimands, enforcement notices, investigations, and criminal powers to address failures in how organisations collect, secure, and share personal information. In September 2026, the ICO also confirmed that it will become the Information Commission on 30 September, while keeping its existing regulatory functions.

For businesses tracking UK data protection fines, the more useful question is not simply how much an organisation was fined. Recent cases show what specific failures are attracting regulatory attention.

Latest ICO Enforcement News in September 2026

One of the newest developments is an ongoing investigation into Police Scotland’s handling of subject access requests. Announced on 11 September, the investigation is examining whether the force has complied with legal duties to respond to requests within the required time. The ICO stressed that the investigation is ongoing and does not mean a breach has been established.

This matters because enforcement is not limited to cyber attacks. Subject access requests are a basic data protection right, and organisations need systems that can record, manage, and answer them within the legal timeframe.

Metropolitan Police Receives Enforcement Notice and Reprimand

In August 2026, the ICO issued the Metropolitan Police Service an enforcement notice and reprimand after two serious data handling failures.

In one case, unredacted documents revealed a stalking victim’s new address and telephone number to the alleged stalker. In another, an email exposed the identities of 18 people connected to a sensitive investigation.

The ICO found wider weaknesses in training, monitoring, governance, and document handling. The enforcement notice requires the police service to improve its data protection training and controls.

The case is important because it shows that UK data protection fines are not the only enforcement risk. An organisation can face formal regulatory action without receiving a monetary penalty.

£963,900 Fine Follows Major Cyber Attack

South Staffordshire Plc and South Staffordshire Water Plc received a £963,900 fine after a cyber attack resulted in personal information belonging to 633,887 people being extracted and published on the dark web.

The attack began with a phishing email. Malicious software then remained undetected for about 20 months. The attacker later gained administrator-level access and extracted large amounts of data.

The ICO found that only about 5% of the IT environment was being monitored, limiting the organisation’s ability to detect the attack.

The companies admitted the infringement and agreed to a voluntary settlement. The final penalty included a 40% reduction for the early admission and cooperation.

For businesses, the case highlights why security monitoring, access controls, and detection systems can directly affect enforcement outcomes.

Reddit Faces £14.47 Million Children’s Privacy Fine

Children’s privacy remains another major enforcement area. In February 2026, the ICO fined Reddit £14.47 million after finding that it failed to use children’s personal information lawfully.

The ICO said Reddit did not have a robust age assurance mechanism and had not established a lawful basis for processing the personal information of children under 13 in the circumstances investigated.

The regulator also found that Reddit had failed to complete a required data protection impact assessment covering risks to children before January 2025. Reddit appealed the monetary penalty to the First-tier Tribunal in April 2026.

The practical point for online services is clear: age assurance, children’s privacy, and risk assessments can become enforcement issues, not just policy matters.

Another Police Scotland Case Shows How Sensitive Data Can Go Wrong

The ICO also fined Police Scotland £66,000 in March 2026 and issued a reprimand after sensitive information from a person’s mobile phone was extracted and later disclosed to a third party.

The regulator found that the entire contents of the phone had been extracted without sufficient safeguards to prevent access to irrelevant information. The information was later included in an unredacted disclosure bundle.

The ICO also found that the breach was not reported within the required 72-hour period.

This case adds another practical lesson for organisations: collecting too much information can create a second problem when that information is later shared.

ICO Enforcement Is Changing, But It Is Not Pausing

The ICO confirmed on 15 September that it will become the Information Commission on 30 September 2026 under the Data (Use and Access) Act 2025. The change affects the regulator’s governance structure, while its existing regulatory functions and responsibilities continue.

The ICO has also confirmed that it can use regulatory tools including warnings, reprimands, enforcement notices, and fines. The maximum fine can reach £17.5 million or 4% of worldwide annual turnover, whichever is higher, for applicable serious infringements.

The transition therefore does not remove the need for organisations to keep their privacy controls up to date.

What Recent UK Data Protection Fines Tell Businesses

Recent enforcement cases point to several areas worth checking:

  • Monitor systems properly: South Staffordshire’s case shows the risk of limited security monitoring.
  • Control sensitive disclosures: The Metropolitan Police case shows how one document or email can expose highly sensitive information.
  • Manage children’s data carefully: Online services should assess age-related privacy risks.
  • Respond to data rights on time: Subject access requests remain under regulatory attention.
  • Limit unnecessary data collection: Excess information can increase the impact of a later disclosure.
  • Keep evidence: Organisations should be able to show how privacy risks are identified and corrected.

The ICO’s enforcement action register is useful for tracking new cases by action type and sector.

Conclusion

The latest ICO Enforcement activity shows that UK data protection fines are only one part of the story. The South Staffordshire case highlights security failures, Reddit shows the growing focus on children’s privacy, and the Police Scotland investigation shows that everyday data rights can also attract regulatory attention.

For organisations, the most useful approach is to study the failure behind each enforcement action. That gives businesses a clearer way to identify weak controls before they become the subject of the next ICO investigation.

FAQ About UK Data Protection Fines

Does every ICO investigation lead to a fine?

No. The ICO can issue advice, warnings, reprimands, enforcement notices, or monetary penalties depending on the circumstances.

Can an organisation appeal an ICO fine?

Yes. Reddit, for example, appealed its 2026 monetary penalty to the First-tier Tribunal.

What is the biggest recent data protection fine covered here?

The largest example in this article is Reddit’s £14.47 million penalty, followed by South Staffordshire’s £963,900 fine. These cases concern different failures, so the amounts should not be treated as directly comparable.

Does the ICO only act after a data breach?

No. Recent activity also covers subject access requests, children’s privacy, data handling, governance, and other compliance failures.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *