Site navigation

Average Fine for UK Data Breaches Doubled to £146,000 in Past Year

Duncan MacRae

,

bank notes

The total value of penalties issued by the Information Commissioner’s Office rose to £4.98 million last year, up 24% from £4 million the previous year.

The average value of fines issued by the the UK’s data watchdog to organisations deemed to have failed to adequately protect customer data has doubled to £146,000 in the past year.

This has risen from £73,000 in September 2017, according to a report by law firm RPC.

The total value of penalties issued by the Information Commissioner’s Office (ICO) for data breaches rose to £4.98 million last year, up 24% from £4 million the previous year.

Greater fines

Under the EU’s General Data Protection Regulation (GDPR), introduced on 25th May 2018, the ICO can impose fines of up to €20m (£17.8m), or 4% of annual global turnover – whichever is highest. Previously, the maximum fine was £500,000. This means it is likely that ICO’s data breach fines will be even greater in the future.

The ICO has said, however, that it does not plan on making examples of companies by issuing hefty fines for minor infringements, and that any penalty must be proportionate to the risk posed by a data breach.

Last week, the ICO recently issued the UK’s first GDPR enforcement notice against AggregateIQ, in relation to an incident that saw data of almost 87 million Facebook users accessed. The data breach had taken place before GDPR kicked in.

Other large fines issued by the ICO over the past year include:

  • Carphone Warehouse being fined £400,000 for failing to adequately protect employee and customer data.
  • Equifax being fined £500,000 for failing to protect the personal details of 15 million Brits during a 2017 cyber attack.
  • The British and Foreign Bible Society being fined £100,000 after a cyber attack that compromised personal information of 417,000 people.

Richard Breavington, Partner at RPC, said: “A doubling in the average size of a fine should serve as a wake-up call to businesses. However, political pressure is mounting.

“Given that there seems to be no slowdown in the number of cyber-attacks today – businesses need to see how they can mitigate the risks to their customer when there is an attack.

“For example, businesses should ensure that they take out cyber insurance policies so that they can bring in experts to contain the impact of an attack and limit the exfiltration of data.”

https://www.digitexpo.uk/

Duncan MacRae

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data