ICO fines & breach roundup — 30 June 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. South Staffordshire Water — nearly £1 million (May 2026)
The ICO fined South Staffordshire Plc and South Staffordshire Water close to £1 million following a major cyber attack and data breach that exposed customer personal data. It's one of the first big enforcement actions of 2026 and continues the regulator's focus on security failures rather than paperwork slips.
What your business should learn: The ICO is fining organisations for how they were breached — the security that wasn't in place — not just the fact a breach happened. Holding customer data (even just names, addresses and bank details for billing) puts you in scope. The defences they look for are the ordinary ones: patching, access control, and monitoring.
2. Capita — £14 million (October 2025), the ICO's largest fine
Capita was fined £14 million (reduced from an intended £45 million) after a cyber attack exposed the personal data of around 6.6 million people. The ICO found security shortcomings that let attackers move through Capita's systems.
What your business should learn: Capita is an outsourcer — it held data on behalf of other organisations. If you hand customer or staff data to a supplier (payroll, IT, a marketing agency), their breach is your problem too. Ask suppliers what security they have, and put it in the contract. Scale doesn't equal safety: a household-name processor still got the basics wrong.
3. Advanced Software — £3 million (March 2025), a LockBit ransomware victim
Advanced (a major NHS IT supplier) was fined £3 million after the 2022 LockBit ransomware attack that disrupted NHS 111 and care services. The ICO highlighted that the attackers got in through an account without multi-factor authentication (MFA).
What your business should learn: This is the single most repeated finding in ICO security cases — a remote-access account with no MFA. Turning on MFA for email, remote access and admin accounts is free or near-free, and it's the one control that would have stopped a string of these incidents.
4. DPP Law — £60,000 (April 2025), a law firm hit by ransomware
The ICO fined criminal-defence firm DPP Law £60,000 after a ransomware attack led to highly sensitive client information appearing on the dark web. The regulator found the firm hadn't acted on the basics of securing privileged accounts.
What your business should learn: Small professional-services firms — solicitors, accountants, recruiters — hold exactly the sensitive data attackers want, and the ICO does fine businesses this size. You don't need an enterprise budget; you need MFA, patching, and a tested backup.
5. Levales Solicitors — public reprimand (late 2024)
A smaller law firm, Levales, received a public reprimand (not a fine) after hackers accessed client details. The ICO pointed to no MFA and weak password management, and the firm couldn't even establish how the attackers got the credentials.
What your business should learn: Same lesson, smaller firm: MFA and decent passwords. Note the second point — they couldn't tell how they were breached. Basic logging and knowing who can access what isn't bureaucracy; it's how you contain an incident and show the ICO you took care.
6. The rules just got sharper — DUAA in force, PECR fines up to £17.5m
The Data (Use and Access) Act 2025 took effect on 5 February 2026. Among the changes: the cap on fines for electronic marketing breaches (PECR) — unsolicited emails, texts and calls — rose from £500,000 to £17.5 million, in line with UK GDPR. Separately, from June 2026 people generally have to complain to the organisation first before escalating to the ICO.
What your business should learn: If you do any marketing by email, text or phone, sloppy consent just got far more expensive. Make sure you have a lawful basis and a working unsubscribe, and keep records of consent. And because complaints now come to you first, having a simple, responsive way to handle a data request or complaint is worth setting up now.
Sources
- ICO — Enforcement action
- ICO — Fine against South Staffordshire Plc and South Staffordshire Water (May 2026)
- ICO fines Capita £14m (Oct 2025)
- ICO fines Advanced £3m following 2022 LockBit ransomware attack
- ICO fines DPP Law £60,000 after ransomware incident
- ICO reprimands Levales Solicitors
- DUAA in force — ICO enforcement approach 2026