Site navigation

Public Sector Leads 2024 ICO GDPR Fines

Elizabeth Greenberg

,

uk public sector gdpr ICO fines
The UK public sector faced more regulatory scrutiny in 2024 for GDPR violations than their private sector counterparts. 

The public sector outperformed the private sector, in terms of raking up more UK GDPR reprimands, new analysis has found.

URM Consulting analysed the top GDPR fines and repirmands issued by the UK’s data protection watchdog, the Information Commissioner’s Office, over 2024.

The findings also highlighted the UK’s different approach to GDPR violations, as the ICO typically opts for more reprimands, in contrast to the EU’s penchant for hefty fines.

Overall in 2024, the public sector faced 16 reprimands compared to just two issued to the private sector. 27 total UK public sector firms faced some type of action by the ICO for GDPR violations.

The public sector was also issued the highest GDPR fines from the ICO, with three GDPR fines in 2024. While private sector organisations also faced fines from the ICO in 2024, these were in violation of the Privacy and Electronic Communications Regulations (PECR) rather than GDPR.

Total GDPR violations in the UK reached around £1.1m, while PECR violations reached roughly £1.6m across more overall fines.

The three GDPR fines in 2024 include:

  • £750,000 to the Police Service of Northern Ireland (PSNI) for the leak of a spreadsheet containing personal information of nearly 1,000 officers and staff.
  • £350,000 to the Ministry of Defence for exposing the identities of Afghan citizens via email who worked with the UK government during the war in Afghanistan.
  • £7,500 to the Central YMCA for exposing via email personally identifiable details of people who have HIV.

All of these leaks were accidental, and involved personal sensitive information, which may have put people’s lives at risk if the details were exposed.

The egregious nature of the violations explains why the ICO parted with their normal temperament to issue reprimands to public bodies as opposed to fines.

The Information Commissioner John Edwards has previously explained that he believes fines to be counterintuitive to progress and were not effective in keeping tech firms in line with data protection.


Recommended reading


Other GDPR enforcement actions taken against the public sector include 18 reprimands and 11 enforcement notices.

While a reprimand is a formal warning to a firm about non-compliance, an enforcement notice is more severe, and requires organisations to take specific actions to fix any data protection issues the ICO found.

Elizabeth Greenberg

Staff Writer

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far