The Information Commissioner’s Office is not the same regulatory body it was five years ago. Under John Edwards, who took over as Information Commissioner in January 2022, the ICO has adopted a more interventionist posture: higher fine amounts, more frequent enforcement action against technology-sector organisations, and an explicit focus on systemic failures rather than one-off incidents. Security leaders who still model their ICO exposure on the pre-2022 baseline are working from outdated assumptions.
This briefing covers where the ICO’s enforcement focus has settled in 2025 and 2026, the patterns that attract regulatory attention, and the specific security controls that most directly reduce exposure.
The Enforcement Landscape in 2026
The ICO now regularly issues fines that reflect the statutory maximum: up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious infringements. The gap between what the ICO could fine and what it does fine has narrowed. Several factors have driven this:
Ransomware attacks on UK organisations have been the single biggest source of ICO enforcement action for the past three years. The pattern is consistent: a ransomware incident discloses personal data, the organisation notifies the ICO, the ICO investigates, and if the investigation finds that inadequate technical or organisational measures caused or materially contributed to the breach, a fine follows. The fine magnitude correlates with the sensitivity of the data, the number of records affected, and the quality of the organisation’s security controls.
Healthcare and social care remains the most heavily regulated sector, with the ICO maintaining ongoing audit programmes for NHS trusts and social care providers. A ransomware attack on a healthcare provider is near-certain to receive an ICO reprimand or financial penalty; the question is severity.
Technology sector enforcement has increased significantly. The ICO has shown willingness to fine technology companies for PECR (Privacy and Electronic Communications Regulations) violations, for failures in AI system transparency, and for inadequate security of personal data processed through third-party services.
Children’s data is a specific enforcement priority. The Children’s Code (Age Appropriate Design Code) has generated enforcement action against consumer-facing technology services, and the ICO has made clear that children’s data protection failures receive enhanced scrutiny.
What Triggers ICO Investigations
Understanding the investigation trigger is essential for calibrating internal response. The ICO opens formal investigations through four main routes:
Mandatory breach notification under UK GDPR Article 33. Controllers must notify the ICO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals’ rights and freedoms. This notification is frequently what opens an investigation: the ICO receives a notification, assesses its severity, and decides whether to investigate the underlying security failure. A well-handled notification (timely, complete, demonstrates proportionate response) reduces investigative scrutiny. A delayed or incomplete notification is itself an infringement and compounds the original breach.
Data subject complaints. Individuals have the right to complain to the ICO if they believe their personal data has been handled unlawfully. High volumes of complaints about a specific organisation, or complaints about a particularly sensitive matter, trigger proactive review.
Referrals from other regulators. The ICO operates in a regulatory ecosystem. FCA, CQC, Ofcom, and other sector regulators cross-refer matters where data protection dimensions are present. A financial services firm with a serious data breach may receive concurrent inquiries from both FCA and ICO.
Proactive audits and investigations. The ICO has formal audit powers under UK GDPR Article 57 and exercises them. Sector-specific investigations, technology assessments, and follow-up audits of previously sanctioned organisations are all legitimate enforcement routes. Organisations in the ICO’s target sectors (healthcare, financial services, public sector, children-facing technology) should not assume that absence of a breach means absence of regulatory contact.
The 72-Hour Rule: Where Security and Compliance Connect
The 72-hour breach notification requirement is the most direct intersection between security operations and regulatory compliance. Getting it wrong is a separate infringement from the underlying breach.
The clock starts from when the controller “becomes aware” of the breach. This is not from when the breach occurred, and not from when a forensic investigation confirms all the facts. It starts from when any part of the organisation has enough information to recognise that a breach of personal data has likely occurred. A SOC analyst who identifies a ransomware infection on systems holding personal data has started the 72-hour clock, even if the full scope isn’t yet known.
Operationally, this means:
- Incident classification procedures must explicitly flag when personal data is in scope and trigger the DPO or legal team immediately, not as a post-triage step
- The ICO notification can be partial (Article 33(4) permits phased notification when full information isn’t available within 72 hours), so the 72-hour deadline is for initial notification, not for a complete forensic picture
- Notification decisions must be made by someone with authority and understanding of UK GDPR, not by a technical responder alone
- Documentation of when the breach was discovered and when notification decisions were made is essential evidence in any subsequent investigation
Security Controls That Reduce ICO Exposure
The ICO’s enforcement decisions consistently distinguish between organisations that had reasonable controls in place and experienced an incident, and organisations that had inadequate controls. Article 32 of UK GDPR requires “appropriate technical and organisational measures” proportionate to the risk. In practice, the ICO applies a standard based on what a reasonable, competent organisation in the same sector would have in place.
Controls that the ICO specifically examines in ransomware cases:
Multi-factor authentication. The ICO has explicitly cited absence of MFA as an aggravating factor in enforcement decisions involving credential-based initial access. For any system holding personal data accessible over the internet, MFA is now effectively a baseline expectation.
Network segmentation. The ability of ransomware to propagate across environments without restriction is treated as an inadequacy in technical controls. Organisations where ransomware encrypted the entirety of their infrastructure face worse outcomes than those where segmentation contained the impact.
Backup adequacy. Backups that were themselves encrypted by ransomware, or that were insufficient to restore critical systems within a reasonable timeframe, are cited as failures of business continuity planning that compound the data protection failure.
Patching. Exploitation of known vulnerabilities to achieve initial access, where patches were available but not applied within a reasonable period, is consistently cited as a technical measure failure.
Access controls. Excessive privileged access, shared accounts, and inadequate access review processes appear repeatedly in enforcement decisions.
Third-Party Processor Risk
A controller remains responsible for the security of personal data processed by its processors. The ICO has made clear that “my supplier was breached” is not a complete defence: the controller’s obligations include due diligence in selecting processors, contractual requirements under Article 28, and ongoing oversight.
Security leaders should review:
- Whether Article 28 data processing agreements are in place with all significant processors
- Whether supplier security assessments include meaningful security control verification (not just a questionnaire response)
- Whether contractual terms include notification obligations that meet the 72-hour requirement for the controller
- Whether critical processors are subject to regular review and whether concentration risk is understood (a single supplier breach affecting multiple processed data categories is a common ICO case pattern)
What “Appropriate” Means in Practice
The ICO doesn’t publish a specific control framework as the compliance standard, but enforcement decisions reference Cyber Essentials, ISO 27001, and NCSC guidance as evidence of what a reasonable baseline looks like in the UK context. An organisation that has implemented Cyber Essentials and Cyber Essentials Plus is in a materially better position before the ICO than one that hasn’t engaged with any structured security framework.
For organisations in sectors with higher regulatory exposure, ISO 27001 certification provides a documented, audited baseline that demonstrates systematic approach to information security risk management. This is evidence-based and not a guarantee of no enforcement action, but it substantially changes the narrative in an investigation where the ICO is assessing whether appropriate measures were in place.