Artifact GuideUKPenalties and Fines

UK GDPR Penalties and Fines

The two main UK GDPR ceilings are £8.7 million or 2% of worldwide annual turnover and £17.5 million or 4%, using the higher figure for an undertaking.

Those statutory maximums do not set automatic tariffs. The ICO decides whether to issue a penalty notice and sets the amount from the infringement, seriousness, turnover where relevant, and aggravating or mitigating factors.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ICO enforcement can include warnings about intended processing, reprimands for infringements, orders, processing restrictions, fines, or a combination permitted by law. The and are ceilings; they do not set default penalties. The ICO must assess the individual case, and the turnover percentage applies to an only when it produces a higher ceiling than the fixed sterling amount.

Section 1

What should teams understand about UK GDPR penalties and fines?

Article 83 and section 157 DPA 2018 create two main ceilings. The standard band is £8.7 million or, for an , the higher of £8.7 million and 2% of total worldwide annual turnover in the preceding financial year. The higher band is £17.5 million or, for an undertaking, the higher of £17.5 million and 4% of that turnover.

The percentage does not automatically apply to every business. It produces the statutory ceiling only when it exceeds the fixed amount. The ICO gives the crossover figures as worldwide turnover above £435 million for the 2% band and above £437.5 million for the 4% band.

For example, an with £300 million in preceding-year worldwide turnover still has an £8.7 million standard ceiling because 2% is £6 million. At £500 million, the standard ceiling is £10 million and the higher ceiling is £20 million. These calculations identify only the maximum; they do not estimate the fine.

A statutory maximum does not predict the fine. The Commissioner must ensure that a fine is effective, proportionate, and dissuasive, and must consider the Article 83(2) factors that are relevant to the case. Article 83 and the DPA 2018 are binding law. The ICO's fining guidance explains its current evaluative approach but does not replace the statutory test or make the five steps a tariff.

  • Standard band: specified controller and processor duties in Articles 8, 11, 25 to 39, 42, and 43, plus specified certification-body and code-monitoring duties.
  • Higher band: processing principles and consent in Articles 5, 6, 7, and 9; rights in Articles 12 to 21; specified automated-decision safeguards in Articles 22B and 22C; international-transfer duties; specified DPA 2018 obligations; and non-compliance with certain ICO orders or access powers.
  • Separate DPA 2018 powers also cover failures involving information notices, assessment notices, enforcement notices, and data-protection charges; the applicable provision determines the penalty route and maximum.
  • Controllers, processors, certification providers, monitoring bodies, and other persons can face fines where the cited provisions apply. Identify the legal role before selecting a band.
  • A fine is one possible corrective measure. The ICO may also use warnings, reprimands, orders to comply, rectification or erasure orders, processing restrictions, or suspension of data flows where its powers and the case permit.
Section 2

Which facts can increase or reduce a UK GDPR fine?

Article 83(2) directs the Commissioner to consider the nature, gravity, and duration of the infringement; the processing purpose and scope; the number of people affected and their damage; whether conduct was intentional or negligent; mitigation; responsibility for technical and organisational measures; previous infringements; cooperation; data categories; how the ICO learned of the issue; compliance with earlier measures; approved codes or certification; and other aggravating or mitigating factors such as financial benefit or avoided loss.

Prompt remediation and cooperation can matter, but they do not erase the infringement or guarantee a reduced fine. Evidence should show what the organisation knew, what control failed, how quickly it contained and corrected the issue, how it protected people, and whether it complied with notification and ICO requests.

  • Scope and impact: affected processing, duration, data categories, number and types of people affected, and evidence of actual or potential damage.
  • State of mind and responsibility: decision records, risk assessments, warnings, budgets, control ownership, training, testing, and whether conduct was intentional or negligent.
  • Response: containment, mitigation for people, correction, regulator and individual notifications, preservation of evidence, and recurrence prevention.
  • Regulatory history: previous infringements, earlier ICO measures, compliance with those measures, and the completeness and timing of cooperation.
  • Financial context: benefit gained or loss avoided, the legal-entity and group structure, economic activity, autonomy, and the preceding financial year's worldwide turnover.
Section 3

How does the ICO calculate a fine?

The ICO's fining guidance uses five steps: assess seriousness; account for turnover where the controller or processor is part of an ; calculate a starting point from seriousness and, where relevant, turnover; adjust for aggravating and mitigating factors; and check that the result is effective, proportionate, and dissuasive. The ICO says this is an evaluative process, not a mechanical formula.

Where the same or linked processing operations intentionally or negligently infringe several UK GDPR provisions, Article 83(3) caps the total at the maximum for the gravest infringement. That rule does not combine genuinely separate conduct into one ceiling. The ICO assesses whether operations are linked from the circumstances, including their purpose, affected people, and timing.

For example, the ICO guidance treats an Article 8 children's-consent failure and an Article 13 transparency failure arising from the same or linked processing as subject to the single gravest-infringement ceiling, even if separate amounts are identified. By contrast, a security failure involving employee salary and bank details and an unrelated transparency failure in direct marketing can be separate conduct, so each infringement has its own applicable maximum.

Financial hardship is not assumed from the size of a proposed fine. The ICO guidance says a reduction for inability to pay is available only in exceptional circumstances after the appropriate amount has been calculated.

  • Map each alleged infringement to the exact UK GDPR or DPA 2018 provision and its maximum band.
  • Separate the infringement decision from the seriousness assessment and the later calculation of amount.
  • Determine whether the controller or processor forms part of a wider before using turnover.
  • Identify whether multiple findings arise from the same or linked processing operations or from separate conduct.
  • Retain the source financial statements, group and control analysis, factual chronology, mitigation record, and submissions relied on.
Section 4

What should an organisation do when an infringement or ICO investigation is possible?

Contain continuing harm, preserve evidence, and identify the controller, processor, and before estimating exposure. Meet any separate breach-notification or rights-request deadline; responding to an investigation does not pause those duties.

Build a provision-by-provision record instead of multiplying turnover by a percentage. Include the alleged conduct, affected processing, dates, people and data, applicable maximum, Article 83 factors, remediation, regulatory correspondence, financial evidence, and unresolved factual or legal issues. Separate verified facts, the organisation's position, and assumptions. Obtain case-specific legal advice where liability, privilege, appeals, or representations on a proposed penalty are in issue.

Is the maximum UK GDPR fine always 4% of turnover?

No. The infringement determines the band. The standard ceiling is £8.7 million or, for an , the higher of £8.7 million and 2% of worldwide annual turnover in the preceding financial year. The higher ceiling is £17.5 million or, for an undertaking, the higher of £17.5 million and 4%. The final fine can be lower, and the ICO assesses each case.

Does a data breach automatically lead to a fine?

No. A security incident must first be assessed against the UK GDPR duties that apply, including security, processor escalation, ICO notification, affected-person communication, and recordkeeping. The ICO then decides which infringements, if any, are established and whether a is appropriate. Other corrective measures can be used instead of or alongside a fine where the law permits.

Is the turnover calculation based only on the UK company that committed the infringement?

Not necessarily. If the controller or processor is part of an , the ICO can calculate the statutory maximum from the undertaking's worldwide turnover as a whole. An undertaking can include a parent and subsidiary that form one economic unit. The result depends on autonomy, decisive influence, and the economic, organisational, and legal links in the specific group.

Can remediation prevent a UK GDPR fine?

Remediation can be relevant mitigation, but it does not erase an infringement or guarantee that the ICO will avoid or reduce a fine. The Commissioner considers mitigation alongside seriousness, intent or negligence, responsibility, prior infringements, cooperation, affected data, notification, compliance with earlier measures, and other aggravating or mitigating factors.

  • Stop or reduce continuing risk and keep a dated record of each containment and mitigation step.
  • Preserve logs, notices, policies, DPIAs, contracts, decisions, tickets, complaints, communications, and financial records without altering the originals.
  • Map each fact to the exact obligation, responsible role, maximum band, seriousness evidence, and aggravating or mitigating factor.
  • Coordinate accurate, timely responses to ICO information, assessment, or enforcement notices and track every stated deadline.
  • Keep public, customer, employee, insurer, board, and regulator communications consistent with the verified facts.
  • Record the outcome separately for each alleged infringement: not established, established without a , included in a penalty notice with the applicable maximum and amount, or addressed through another corrective measure.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Article 83(1) and (2) establish the effective, proportionate, and dissuasive requirement and the case-specific factors.
legislation.gov.uk
Referenced sections
  • Part 6 establishes the ICO's information, assessment, enforcement, and penalty-notice framework, together with appeal and enforcement provisions.
ico.org.uk
Referenced sections
  • Current ICO guidance confirms the £8.7 million or 2% and £17.5 million or 4% ceilings and explains when turnover produces the higher statutory maximum.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.