ICO fines in 2026: recent UK cases and how amounts are set
Compare recent UK ICO fines for a water utility and unlawful marketing texts, then follow the five steps used to calculate a data protection penalty.

Quick Answer: Recent ICO fines: South Staffordshire Plc and South Staffordshire Water Plc received £963,900 for security infringements affecting approximately 633,887 people; KRA Consultancy Ltd received £300,000 for over 5.5 million unlawful marketing texts. For data protection fines, the ICO assesses seriousness, turnover, a starting point and adjustments, then proportionality1,2,3.
Summary in a mind map
ICO fines in 2026: recent UK cases and how amounts are set │ ├─ Security penalty │ ├─ South Staffordshire: £963,900 │ ├─ UK GDPR Articles 5(1)(f) and 32(1) │ └─ About 633,887 UK data subjects │ ├─ Marketing penalty │ ├─ KRA Consultancy: £300,000 │ ├─ PECR regulations 22 and 23 │ └─ Over 5.5 million unlawful texts │ └─ Data protection fine ├─ Seriousness, turnover and starting point ├─ Aggravating and mitigating factors └─ Effective, proportionate, dissuasive
Which 2026 ICO monetary penalties should a smaller UK organisation compare?
Start with the activity, not the headline amount. A regional utility's customer and employee data call for a security review. A business sending promotional texts needs a marketing permissions review. Both may face ICO enforcement, but these examples concern different conduct and legal provisions1,2.
| 2026 notice | ICO finding | Scale recorded in the notice | Penalty |
|---|---|---|---|
| South Staffordshire Plc and South Staffordshire Water Plc, 7 May | UK GDPR Articles 5(1)(f) and 32(1), after a cyber incident | Approximately 633,887 UK data subjects | £963,900 1 |
| KRA Consultancy Ltd, 20 May | PECR regulations 22 and 23, unsolicited direct marketing and fake bailiff texts | More than 5.5 million texts | £300,000 2 |
For a firm with 50–500 staff, the comparison suggests two separate entries in a risk register. One concerns the protection of information already held. The other concerns the basis on which communications are sent. A single generic “privacy compliance” check would hide that operational distinction1,2.
South Staffordshire: a 2026 ICO data security penalty
The ICO's monetary penalty notice dated 7 May 2026 names South Staffordshire Plc and South Staffordshire Water Plc. The penalty is £963,900. The identified infringements are Article 5(1)(f), the integrity and confidentiality principle, and Article 32(1), the security of processing duty, under the UK GDPR. The incident involved approximately 633,887 UK data subjects1.
That combination matters. The notice is about the organisation's obligations in handling personal data, assessed against a particular cyber incident. It is not a statement that a cyber attack alone creates a fine. A smaller organisation reading it should ask which systems hold comparable categories of data, who can access them and what evidence shows security measures were reviewed1.
At Step 1, the approximately 633,887 UK data subjects recorded in the notice form part of what happened and the people affected, which the ICO weighs when assessing seriousness1,3.
KRA Consultancy: a 2026 PECR marketing penalty
The notice dated 20 May 2026 fines KRA Consultancy Ltd £300,000. The ICO identifies more than 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of the Privacy and Electronic Communications Regulations. The volume is a count of texts, not a count of unique recipients supplied by this article2.
This example belongs in a marketing workflow review. Before a campaign is dispatched, the responsible team needs to know which rule applies to that channel and why each group of recipients may lawfully be contacted. The case is especially relevant where a third party supplies leads or sends messages on a firm's behalf; the notice must be read for the actual facts before any conclusion about a different arrangement. The linked guide on emailing businesses without consent in the UK addresses a different channel and must not be mistaken for permission to send texts2.
The title of a message and its apparent urgency do not change the underlying PECR question. Here, the ICO expressly described fake bailiff texts. A manager should preserve sample messages and approval records so the marketing decision can be tested against what recipients actually saw2.
The five steps in the ICO data protection fine calculation
The ICO's published data protection fining guidance sets out five steps. They are a sequence of judgments rather than a public calculator that guarantees a result. The guidance addresses data protection fines; KRA Consultancy's PECR notice must be understood under its own legal basis2,3.
| Step | Question for the ICO | Evidence a business should locate |
|---|---|---|
| 1. Seriousness | How serious is the infringement? | What happened, the processing involved and the people affected 3 |
| 2. Turnover | What is the relevant turnover? | Reliable turnover evidence 3 |
| 3. Starting point | What amount should anchor the assessment? | The case's particular circumstances 3 |
| 4. Adjustment | What aggravates or mitigates the case? | A record of relevant responses and circumstances 3 |
| 5. Final check | Is the amount effective, proportionate and dissuasive? | Reasons supporting a fair outcome 3 |
In words, the tree branches like this: identify whether the conduct is a UK GDPR data protection infringement, such as the South Staffordshire security failure, or a PECR marketing infringement. The UK GDPR branch leads to the ICO's five-step data protection assessment. The PECR branch leads back to the particular marketing notice and the applicable PECR rules. The legal route determines which notice and guidance to read1,2,3.
Seriousness, turnover and adjustments in the amount
At Step 2, the ICO considers turnover where the controller or processor is part of an undertaking. At Step 3, it sets the starting point having regard to the seriousness of the infringement and, where relevant, the turnover of that undertaking. Aggravating or mitigating circumstances then affect the amount before the final effectiveness, proportionality and deterrence check3.
The ordering matters for a board discussion. If a board begins with the final £963,900, it may overlook why the ICO identified Articles 5(1)(f) and 32(1) in the first place. If it begins with £300,000, it may overlook that the other case is a PECR marketing matter. Document the infringement and the affected activity first; discuss financial exposure only after the factual and legal route is clear1,2,3.
What the two cases cannot determine for another business
They identify concrete questions for a review, not the fine another organisation would receive. The South Staffordshire notice gives a specific UK GDPR security finding and an approximate count of UK data subjects. The KRA notice gives a specific PECR finding and message volume. The ICO's data protection guidance explains the calculation stages. None of those sources proves that a different firm with 50, 250 or 500 staff would receive the same penalty1,2,3.
The cases also do not resolve an organisation's processor and controller roles. That depends on the actual processing relationship; the controller or processor guide explains the role test. Nor does a tool used in order processing automation by itself establish the security measures or marketing permissions required here. The UK and EU AI governance comparison is relevant if the same systems introduce an AI governance question, but it does not replace the notice-specific analysis.
Next steps for a smaller UK organisation
Use two short review records. For systems containing personal data, record the owner, the types of information held, the current security review and the decision on any gap exposed by the South Staffordshire facts. For a text campaign, record the audience, the message, the relevant PECR basis, who approved the send and the evidence retained. Assign a date to revisit each decision after a system or campaign changes1,2.
When discussing potential exposure, work through the five ICO stages for a data protection infringement and label the assumptions. Keep PECR marketing analysis separate. The useful output is an evidenced decision about a control or campaign, not a guessed fine. If the organisation faces a real investigation, use the actual notice and guidance as the starting sources for professional advice2,3.
Frequently Asked Questions
Which UK organisation received a 2026 ICO data security fine?
Which recent ICO fine concerned unsolicited marketing texts?
Does the ICO start with a company's turnover when calculating a fine?
Are PECR and UK GDPR penalties calculated under the same five-step guidance?
What should a smaller UK organisation take from these ICO fines?
Sources
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.