Search

How can we help?

Icon

ICO Fines – Don’t fall foul of the rules

Back in March, Cathay Pacific were fined £500,000 for failing to protect the security of its customers’ personal data.  This used to be the largest fine that the ICO could impose under the Data Protection Act 1998 but the Data Protection Act 2018 now allows for a fine of anywhere up to 20 million euros or 4% of annual worldwide turnover, whichever is greater.

There have also been a number of fines imposed over recent months for unsolicited marketing emails and calls including two this month, namely:

  • £100,000 fine for Koypo Laboratories Limited for instigating 21,166,574 unsolicited marketing emails without consent
  • £80,000 fine for Rain Trading Limited for making 270,774 unsolicited marketing  calls to individuals without consent

Cathay Pacific were fined £500,000 for failing to protect the security of its customers’ personal data.

In the current economic crisis it would not be surprising if more businesses turned their attention to marketing but these fines are a stark warning to organisations to ensure they comply with data protection obligations in doing so.

Please do not hesitate to get in contact with our data protection team if you have any questions.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 16 September 2026
  • Employment

Received an Employment Tribunal Claim? 6 Things Employers Should NOT Do

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 14 September 2026
  • Corporate and M&A

Key provisions found in a Shareholders’ Agreement – SHA Series Part 2 of 5

Discover the key provisions in a shareholders’ agreement, including ownership, decision-making, share transfers, exits and leaver clauses.

art
  • 11 September 2026
  • Privacy and Data Protection

Data Protection Breaches – Personal Liability for Employees

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.

Pub
  • 07 September 2026
  • Corporate and M&A

Frequently Asked Questions About Shareholders’ Agreements – Episode 1

Join Emma Docking and Jonathan Hayes as they explore some of the most frequently asked questions about shareholders’ agreements, including what they are, how they work alongside articles of association, and the risks of operating without one.

art
  • 03 September 2026
  • Employment

Employment Rights Act – October Changes

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 02 September 2026
  • Immigration

Mandatory MFA for Sponsor Management System Users: What Sponsors Need to Know

The Home Office is introducing a significant security change to the Sponsor Management System (SMS). From 3 September 2026, the Home Office will begin a phased rollout of mandatory Multi-Factor Authentication (MFA) for SMS users.