Close Menu
    What's Hot

    About Us

    Purchase Our Services

    Can personal data be processed outside of the UK and EU?

    LinkedIn X (Twitter)
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    • The ICO
    • About Us
    • Purchase
    LinkedIn X (Twitter)
    CONTACT
    • Home
    • Business

      Can personal data be processed outside of the UK and EU?

      Are there correct ways to respond to a GDPR subject access request?…

      When can a SAR be refused in full or in part?

      Do all businesses need to be compliant with the UK GDPR?

      Should you register your company with the ICO?

    • Personal

      Will the UK police respond to a GDPR subject access request?

      What does the UK GDPR mean for individuals?

      I don’t live in the UK or EU, what are my rights under GDPR?

      A company has not responded to my GDPR subject access request, what can I do?

      Dealing with unwanted and nuisance calls…

    • Technology

      A faulty server could be considered a breach of the GDPR…

      A glossary and explanation of GDPR terms

      Significant fines and breaches in the news…

      Why IT Security is at the core of good GDPR practice…

    • Purchase Our Services
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    Home » The ICO has the power to prosecute directors…
    GDPR News

    The ICO has the power to prosecute directors…

    Martin Kayes, CISSPBy Martin Kayes, CISSPUpdated:April 15, 20241 Min Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    It is quite broadly known that for serious infringements of the data protection principles, the enforcement body (for the UK this will be the ICO) has the power to issue fines of up to £17.5 million or 4% of a company’s annual worldwide turnover, whichever is higher.

    What is not so well know is that the UK GDPR sits alongside both the Data Protection Act (DPA 2018) and the Privacy and Electronic Communications Regulations (PECR), each of which are also enforced by the ICO.

    Previously, some company directors have been known to put their company in to liquidation to try and avoid paying the fines.

    However, since early 2017 amendments to the PECR legislation made it possible for such directors to be held personally liable and forced to pay fines of up to half a million pounds in addition to the fine imposed on their companies. In addition, the ICO can bring criminal prosecution against such directors.

    Here are some of the recent enforcement actions taken by the ICO:

    • United Lincolnshire Teaching Hospitals NHS Trust
      Source: ICO Enforcement Notices Published on 2024-12-19
    • Money Bubble Ltd EN
      Source: ICO Enforcement Notices Published on 2024-12-12
    • Money Bubble Ltd MPN
      Source: ICO Enforcement Notices Published on 2024-12-12
    • Breathe Services Ltd
      Source: ICO Enforcement Notices Published on 2024-12-12
    • Breathe Services Ltd
      Source: ICO Enforcement Notices Published on 2024-12-12
    • DPG Professional Services Ltd
      Source: ICO Enforcement Notices Published on 2024-11-25
    • City of London Police
      Source: ICO Enforcement Notices Published on 2024-11-20
    • Southend-on-Sea City Council
      Source: ICO Enforcement Notices Published on 2024-10-17
    • Quick Tax Claims Limited
      Source: ICO Enforcement Notices Published on 2024-10-15
    • Quick Tax Claims Limited
      Source: ICO Enforcement Notices Published on 2024-10-15
    • National Debt Advice Limited
      Source: ICO Enforcement Notices Published on 2024-10-14
    • National Debt Advice Limited
      Source: ICO Enforcement Notices Published on 2024-10-14
    • Levales Solicitors LLP
      Source: ICO Enforcement Notices Published on 2024-10-11
    • WerepairUK Ltd
      Source: ICO Enforcement Notices Published on 2024-10-10
    • WerepairUK Ltd
      Source: ICO Enforcement Notices Published on 2024-10-10
    News
    Martin Kayes, CISSP
    • Website

    Related Posts

    What you shouldn’t do when responding to a SAR…

    How to submit a SAR that will achieve what you need

    Significant fines and breaches in the news…

    Don't Miss
    Business

    Can personal data be processed outside of the UK and EU?

    By Martin Kayes, CISSP

    Yes, data can be processed internationally under the UK GDPR (General Data Protection Regulation). Under…

    Are there correct ways to respond to a GDPR subject access request?…

    When can a SAR be refused in full or in part?

    Will the UK police respond to a GDPR subject access request?

    Stay In Touch
    • LinkedIn
    • Twitter
    Specialist Investigations
    About Us
    About Us

    A trading style of Cobalt ICT Limited

    Providing affordable, professional help with GDPR, Subject Access Requests, Data Privacy and Cyber Essentials.

    Offering services and consultancy with PAYG and Monthly Retainer options

    Based in London

    We are based in London but for security reasons we do not publish our physical address.

    Our registered office is:
    c/o Kinnair & Company
    Aston House, 21 Redburn Road
    Newcastle Upon Tyne
    NE5 1NB

    A registered company in England and Wales. Registration Number 05484135

    Business Hours

    Monday - Friday
    9am - 5pm
    Terms and Conditions

    LinkedIn X (Twitter)
    • Home
    • Business
    • Personal
    • Technology
    • Fines & Breaches
    • GDPR News
    • Privacy Policy
    © 2025 Cobalt ICT Limited.

    Type above and press Enter to search. Press Esc to cancel.