Skip to content

As we approach the fourth anniversary of GDPR, we have analysed what causes the Information Commissioner’s Office (ICO) to issue fines following data security breaches. We hope that our findings assist in understanding areas to focus on in order to avoid attracting the ICO’s attention.

Read our analysis here

As you will see, we have carried out our research by reference to what we consider to be five key Monetary Penalty Notices (MPNs) issued by the ICO under the GDPR regime. Some of those MPNs are “blockbuster” fines like those for BA and Marriott. Others illustrate that no organisation is immune from sanctions (see those issued to the Cabinet Office and the charity Mermaids). We have taken each MPN and analysed it to extract what the ICO is really concerned about when a data security breach happens and what triggers the ICO to take enforcement action. This is all in the context of the ICO’s Five Step Regulatory Action Policy (RAP).

We will be holding a webinar to discuss these issues on 15 June. An invitation will follow shortly.

If you require further information about anything covered in this briefing, please contact Ian De Freitas, Kay Lubwika Bartlett or your usual contact at the firm on +44 (0)20 3375 7000.

This publication is a general summary of the law. It should not replace legal advice tailored to your specific circumstances.

© Farrer & Co LLP, May 2022

This site uses cookies to help us manage and improve the website and to analyse how visitors use our site. By continuing to use the website, you are agreeing to our use of cookies. For further information about cookies, including about how to change your browser settings to no longer accept cookies, please view our Cookie Policy. Click for more info

Back to top