ICO fines & breach roundup — 23 September 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
The ICO's enforcement register has published no new fine, reprimand or enforcement notice since late August, and nothing new appeared in the week to 23 September. What the week did produce is a government department telling the regulator that its own staff had been reading files they had no reason to open, an academic audit of every licensed gambling site in the country that found most of them collecting data before anyone agreed to it, and a change of name at the regulator itself that is worth thirty seconds of your attention — mostly because of who will pretend to be it.
1. Court staff read files on the Southport attack victims — the access was authorised in the technical sense, which is exactly the problem
On 15 September the Ministry of Justice disclosed that court files relating to victims, survivors and families of the July 2024 Southport attack had been accessed by court staff without approval. Two details matter for anyone running a system that holds records about people. First, how it came to light: the MoJ says the unauthorised access was found during a review of its digital systems, not reported by a victim or spotted by an alarm. Second, how serious it was judged to be: the department says that for a limited number of people the material accessed was sensitive personal data assessed as likely to result in a high risk to their rights and freedoms — that is the legal threshold in Article 34 of the UK GDPR at which you must tell the individuals themselves, not just the regulator, and the MoJ says those affected are being contacted directly. The MoJ has referred the incident to the ICO and says there is no evidence any of the data was shared with third parties. An MoJ spokesperson said: "We are appalled that this happened and recognise the distress it will have caused victims, survivors, and their families", adding that "unauthorised access to court files is completely unacceptable." HM Courts & Tribunals Service and the Prison and Probation Service are both investigating, and the Prime Minister has asked the Lord Chancellor to oversee the work. Several things are genuinely unknown and should not be filled in: the MoJ has not said how many staff were involved, how many people's records were opened, over what period, or when the review took place. There is no ICO finding, no investigation outcome and no penalty — only a report the regulator is now holding. It is also not the first time records connected to this case have been opened inappropriately: reporting has previously covered a similar issue at North West Ambulance Service and nearly 50 staff at Aintree University Hospital found to have accessed victims' medical records.
What your business should learn: This is the breach category no firewall touches, because nobody broke in — the people who looked already had the login. Every small business has the same shape of risk sitting in its practice-management system, its CRM, its HR folder or its shared drive: a handful of staff with access to everything, because it was easier to set up that way, and no record of who opened what. Three cheap fixes, in order. Turn on the access logging you are probably already paying for — most cloud systems (Microsoft 365, Google Workspace, and nearly every industry SaaS product) keep an audit log and simply never show it to anyone; find out today whether yours does and who can read it. Then actually look at it, a sample, once a month, for ten minutes — both of the cases above were discovered by a routine review rather than by a complaint, and a log nobody ever opens deters nobody. And write the rule down in one line: looking at a record without a work reason is misconduct, not curiosity, and it applies to the owner too. Finally, know the trigger the MoJ hit: a breach likely to result in a high risk to people must be reported to the ICO within 72 hours and communicated to the individuals affected — so a snooping incident involving sensitive records is not something you can quietly handle in-house.
2. 86% of UK-licensed gambling sites are breaking the cookie rules, an academic audit found — and the rule they break applies to your website too
On 14 September Swansea University published research from its Gambling Research, Education and Treatment (GREAT) Centre which audited the cookie consent banners and network traffic of all 624 casino and sports betting websites licensed by the Gambling Commission. It found 86% operating in breach of data protection law. The individual numbers are the useful part: 67% began collecting personally identifiable data before the user had consented, sending unique identifiers to third-party analytics and marketing platforms; 24% offered no way to refuse tracking at all (including 2% that showed no banner whatsoever); and only 29% made rejecting as easy as accepting — on some sites it took 15 clicks to refuse. The banners leaned on so-called dark patterns: visual emphasis on the accept button (60%), the reject option hidden behind a second layer (47%), and privacy-unfriendly settings pre-selected (29%). A second, experimental part of the study put 615 UK online gamblers in front of a simulated betting site carrying one of six banner designs; the design most used across the industry made people three to four times more likely to accept tracking than a neutral one-click alternative, and those who accepted rated the choice as a much poorer reflection of their actual preferences than those who rejected (4.4 out of 10 against 7.9) — which is the researchers' evidence that the design, not the user, drove the outcome. The work was led by PhD student Jack McGarrigle, supervised by Professor Simon Dymond, Dr Martyn Quigley and Dr Jamie Torrance, and is published in Computers in Human Behavior Reports. Two things to be precise about. This is an academic audit, not a regulatory finding: no ICO investigation, finding or penalty against any named site exists here and none should be assumed. And the rule at issue in the UK is PECR — regulation 6 of the Privacy and Electronic Communications Regulations, which requires consent before non-essential cookies and similar technologies are set, with the UK GDPR supplying the standard that consent must meet. The press coverage calls it a GDPR breach; the regulation the ICO would actually enforce is PECR.
What your business should learn: Nothing about this is specific to gambling. The same consent platform, the same default settings and the same "accept is a button, reject is a link in a submenu" layout are on tens of thousands of ordinary UK small-business websites, usually because someone installed a banner plugin, accepted its defaults and assumed the job was done. The ICO's finalised guidance (Guidance on the use of storage and access technologies, April 2026) puts it in a checklist you can mark yourself against in five minutes: "Our consent mechanism makes it as easy to refuse consent as it is to accept", and it must require a positive action from the user before non-exempt technologies are set. It also says plainly that people must be able to withdraw consent with the same ease that they gave it — if your banner has no way back once it is dismissed, that alone fails. So do the test on your own site rather than trusting the plugin: open it in a private window, and before clicking anything open your browser's developer tools, look at Application → Cookies and Storage, and see what is already there. Then count the clicks to reject against the clicks to accept. Both problems are almost always a toggle in your consent tool's settings, not a developer job — which makes this the rare compliance fix that costs an afternoon and no money.
3. The ICO becomes the Information Commission on 30 September — nothing changes for you, which is precisely why scammers will say it does
On 15 September the ICO confirmed that government has set 30 September 2026 as the date it transitions to the Information Commission. It is a governance change made by the Data (Use and Access) Act 2025, brought into force by commencement regulations, and the ICO is explicit that it "maintains existing regulatory functions and responsibilities". The seven Non-Executive Members appointed to the new Information Commission Board in July take up their roles on the same date. The one practical point for the rest of us was added to the page on 17 September: "As the Information Commission's Office, we will continue to be known as the ICO." So the letters on the envelope do not change, and neither does anything you have to do — your registration, your data protection fee, the 72-hour breach report, the one-month deadline for a subject access request and every other obligation carry on exactly as before.
What your business should learn: Treat this as a phishing weather forecast. A publicised change of name at a regulator that can fine you is close to an ideal pretext, and the data protection fee is already one of the most impersonated things in UK small business — both by outright fraudsters and by "compliance agencies" that charge you three figures to fill in a form you could complete yourself in a quarter of an hour. Expect letters, emails and calls over the next few weeks telling you your registration must be renewed, revalidated or transferred to the new Information Commission. None of that is a thing. The fee is set by Parliament in three fixed tiers — £52 for micro organisations, £78 for small and medium ones and £3,763 for large — so any other figure is somebody's service charge or a scam. Pay it only by going to ico.org.uk yourself and typing the address in, never from a link, QR code or phone number in a message, and check your own renewal date while you are there rather than believing someone who tells you it has passed. And if your privacy notice names "the Information Commissioner's Office (ICO)" as your supervisory authority, it stays correct on 1 October: nobody needs to be paid to update it.
Sources
- The Register — Ministry of Justice apologizes after court staff accessed Southport victims' files
- LBC — Southport attack victims, survivors and families hit by 'completely unacceptable' data breach
- ICO — Personal data breach reporting
- Swansea University — Nine in 10 UK gambling websites breaching data privacy law, study finds
- ICO — Guidance on the use of storage and access technologies
- ICO — How do we manage consent in practice?
- ICO — ICO governance changes confirmed for 30 September 2026
- ICO — Guide to the data protection fee
- ICO — Enforcement action