ICO fines & breach roundup — 6 July 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. National ransomware warning — 323 UK organisations hit in a year, over half small businesses (campaign launched 29 June 2026)
On 29 June 2026, Report Fraud (the UK's national fraud and cyber-crime reporting service, run with police and the National Cyber Security Centre) launched a campaign warning that 323 organisations reported a ransomware attack to police between April 2025 and March 2026 — and more than half of those, 175 reports, came from small and medium-sized enterprises. Reported financial losses totalled around £270,000, a 50% increase on the year before, with manufacturing, scientific/technical services and education among the hardest-hit sectors. This isn't an ICO fine or a single named breach — it's a national advisory, and the real figures are almost certainly higher since businesses often under-report losses. But it's directly relevant here: it confirms that ransomware isn't just a large-company problem, and that UK authorities are actively telling SMEs to prepare and report.
What your business should learn: The advice from the National Cyber Security Centre and UK law enforcement is not to pay a ransom — paying doesn't guarantee you get your data back and funds the next attack. The cheap, practical preparation is a tested backup that's kept offline or otherwise unreachable by an attacker who's already inside your network, so a ransomware infection is an inconvenience rather than a catastrophe. Actually test that you can restore from it — a backup nobody has ever restored from is a hope, not a plan. And know in advance who you'd call (Report Fraud, your insurer, an IT contact) so a bad day doesn't start with a panicked search for a phone number.
2. Energy Prices Direct Limited — £160,000 (announced May 2026), 700,000+ unwanted marketing calls
The ICO fined Glasgow-based energy-buying consortium Energy Prices Direct Limited £160,000 after it made more than 700,000 unsolicited marketing calls over a roughly 12-month period (January 2024 to January 2025) to numbers registered with the Telephone Preference Service (TPS) and Corporate TPS — the official do-not-call lists — in breach of the Privacy and Electronic Communications Regulations (PECR). The ICO's investigation also found that in some calls, staff failed to properly identify themselves as calling on the company's behalf.
What your business should learn: PECR consent rules aren't just about email and text — they cover phone calls too. If your business (or a marketing agency or call centre acting for you) cold-calls prospects, you must screen numbers against the TPS/CTPS lists before dialling, and every caller should clearly identify who they're calling from. This is a cheap, mechanical check — a list-scrub before a campaign goes out — and it's exactly the kind of basic compliance step the ICO expects even from smaller outbound-sales operations.
3. MediaLab (Imgur owner) — £247,590 (February 2026), first fine under the Children's Code
The ICO fined MediaLab.AI, Inc., owner of the image-hosting site Imgur, £247,590 — its first financial penalty under the UK's Children's Code. Over a four-year period (September 2021 to September 2025), the ICO found MediaLab had no age-assurance measures in place, processed the personal data of children under 13 without parental consent or another lawful basis, and hadn't carried out a data protection impact assessment (DPIA) even though children were foreseeably using the platform and could be exposed to harmful content.
What your business should learn: If your website, app or online community could realistically be used by under-13s — a forum, a comments section, an image or video sharing feature, even a general-audience app with no age gate — you're in scope of the Children's Code, regardless of your size. Before you build or launch something like this, do a short DPIA (a one-page "what data do we collect, who might use this, what could go wrong" document is a legitimate start) and add basic age-assurance rather than treating age as self-declared and unchecked. It's a lot cheaper to think about this before launch than to retrofit it after four years of use.
Sources
- ICO — Enforcement action
- Report Fraud — Don't pay the ransom: warning to organisations to protect themselves from ransomware attacks
- CIR Magazine — Police launch ransomware reporting initiative as UK firms face rising attacks
- ICO — Glasgow-based energy company fined £160,000 for making unsolicited marketing calls
- STV News — Glasgow energy firm fined £160,000 for making 700,000 unsolicited calls in a year
- ICO — Imgur owner MediaLab fined over children's privacy failures
- DataGuidance — UK: ICO fines MediaLab £247,590 for children's privacy failures