ICO Fines and Enforcement: What Small Businesses Should Know
The ICO can issue fines of up to £17.5m or 4% of global annual turnover, but for most small businesses that is not the reality. Reprimands, enforcement notices and orders to fix problems are far more common. This guide explains what the ICO actually does, what triggers action, and how to stay on the right side of it.
The reality behind the headlines
The Information Commissioner’s Office (ICO) is the UK’s independent regulator for data protection. If your business handles personal information — customer names, email addresses, payroll, booking records, health details — the ICO is the body that can hold you to account under UK GDPR and the Data Protection Act 2018.
The news tends to focus on enormous fines against household-name companies. That is understandable, but it paints a misleading picture of what enforcement looks like for a typical small business in Leeds or anywhere else in Yorkshire. In reality, the ICO uses a range of tools, and a large fine is one of the least common outcomes. This article explains what the ICO can actually do, what triggers action, and how to keep on the right side of it — without the scare tactics.
What the penalties look like on paper
UK GDPR sets two tiers of maximum fine. These are ceilings, not typical amounts.
- Standard tier: up to £8.75 million or 2% of your global annual turnover, whichever is higher. This covers failings such as poor record-keeping or not carrying out a required assessment.
- Higher tier: up to £17.5 million or 4% of your global annual turnover, whichever is higher. This covers the most serious matters, such as breaching the core data protection principles or ignoring people’s rights.
Those figures are real, and they are why data protection is worth taking seriously. But it is important to understand the word maximum. The ICO decides any penalty based on how serious the failing is, whether it was deliberate or negligent, how many people were affected, and what you did to put things right. A small business is not going to be fined tens of millions of pounds for a genuine, well-handled mistake.
What enforcement usually looks like
A fine is only one item in the ICO’s toolkit, and for small organisations it is rarely the first one reached for. The more common outcomes include:
- Reprimands. A formal, published telling-off that sets out what went wrong and what you must fix. No money changes hands. This is one of the ICO’s most-used tools.
- Enforcement notices. A legal order to do something, or stop doing something, by a deadline — for example, to respond to outstanding data requests or delete data you should not hold.
- Assessment notices and audits. The ICO can inspect how you handle data and make recommendations.
- Advice and guidance. For many small businesses, the first contact is educational rather than punitive.
The pattern is clear: the ICO’s priority is usually to get the problem fixed and to protect the public, not to bankrupt a small firm. Cooperation and remediation go a long way.
A small business is not going to be fined tens of millions of pounds for a genuine, well-handled mistake.
What actually triggers ICO action
Enforcement does not appear out of nowhere. For a small business, action is most often prompted by one of the following:
- A complaint from an individual. Someone asks to see or delete their data and you ignore them, or you send marketing they never agreed to.
- A personal data breach. You lose a laptop, suffer an account takeover, or email a spreadsheet of customers to the wrong person — and it puts people at risk.
- Failure to report, or over-reporting. Not reporting a serious breach within 72 hours when you should have, or a pattern of careless reporting.
- Ignoring the rules repeatedly. A one-off slip handled well is very different from a business that has been warned and does nothing.
What rarely triggers a heavy penalty is an honest mistake that you own up to, contain quickly, and learn from. Regulators reward good faith and evidence that you take the issue seriously.
How to stay on the right side of the ICO
You do not need a compliance department to be in a strong position. A handful of sensible habits cover most of what a small business needs:
- Know what data you hold and why. Keep a simple record of the personal data you collect, where it lives, and how long you keep it. This is the foundation of everything else.
- Have a lawful reason for using it. Every use of personal data needs a lawful basis. Our guide to the six lawful bases breaks this down in plain English.
- Respond to people’s requests. If someone asks for a copy of their data or asks you to delete it, respond within a month. Ignoring these is a common cause of complaints.
- Protect the data properly. Strong passwords, multi-factor authentication, reliable backups and up-to-date software prevent most breaches in the first place.
- Have a plan for when things go wrong. Know who decides whether a breach is reportable, and keep the ICO’s 72-hour deadline in mind.
If you want the broader picture of your obligations, start with our GDPR basics for UK small business.
Where DACROS fits in
Most ICO problems are really IT and process problems in disguise: weak security, no record of what you hold, no plan when something breaks. As a managed IT and cyber-security provider in Leeds, DACROS helps small businesses put the practical protections in place — access controls, backups, breach readiness and staff awareness — so a bad day never becomes a regulatory one.
If you are not sure where you stand, get in touch for a straightforward conversation. No jargon, no fear-selling — just a clear view of what matters for a business your size.
Frequently asked questions
Can the ICO really fine my small business £17.5 million?
In theory the higher tier maximum is £17.5m or 4% of your global annual turnover, whichever is greater. In practice, fines of that scale are reserved for the most serious failings by very large organisations. For a typical small business, the ICO is far more likely to issue a reprimand or an order to fix the problem than a headline fine.
What usually triggers ICO enforcement against a small business?
Common triggers include complaints from individuals (for example, ignoring a request to access or delete their data), a personal data breach you report or fail to report, sending marketing without consent, or a pattern of ignoring the rules. A single honest mistake that you handle well rarely leads to a fine.
Is a reprimand the same as a fine?
No. A reprimand is a formal telling-off that sets out what you did wrong and what to fix, but it does not involve paying a penalty. The ICO publishes many reprimands, and they are one of its most-used tools for small and medium organisations. A fine (a 'penalty notice') is a separate, more serious step.
Do I have to report every data breach to the ICO?
You must report a personal data breach to the ICO within 72 hours only if it is likely to result in a risk to people's rights and freedoms. Many minor incidents do not meet that bar, but you should still record them internally. If in doubt, the ICO's self-assessment tool can help you decide.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.