UK Data Protection

How the ICO Calculates a UK GDPR Fine: The Five Steps in Its Data Protection Fining Guidance

Key Takeaways

  • Section 157 of the DPA 2018 and Article 83 of the UK GDPR set a higher maximum of £17.5 million or 4% of worldwide turnover, and a standard maximum of £8.7 million or 2%, whichever is higher for an undertaking
  • Step 1 places an infringement in a seriousness band with a starting point of 0% to 10%, 10% to 20% or 20% to 100% of the relevant maximum
  • Step 2 lets the ICO scale that starting point by turnover, down to 0.2% to 0.4% of it for undertakings with turnover up to £2 million, with no adjustment above £435 million or £437.5 million
  • Turnover is that of the undertaking in the competition law sense, so a parent's figures count where it exercises decisive influence, presumed where it holds all or nearly all voting shares
  • Since 5 February 2026 the ICO must follow a notice of intent with a penalty notice, or a decision not to issue one, within six months or as soon as reasonably practicable after

Where the Fining Power Comes From

The power to fine is statutory, and the guidance is the regulator's account of how it will use it. Section 155 of the Data Protection Act 2018 provides for penalty notices, and for a notice concerning a matter to which the UK GDPR applies it points to "the matters listed in Article 83(1) and (2)" of the UK GDPR. Article 83 sets out those matters and the two fine ceilings. Section 156 then restricts penalty notices in four situations the guidance lists: processing for the special purposes of journalism, academic, artistic or literary expression without a court's leave, processing determined by either House of Parliament, the Crown Estate Commissioners and controllers acting for the Royal Household and the Duchies of Lancaster and Cornwall, and certain joint controller arrangements in law enforcement and intelligence processing.

The Data Protection Fining Guidance states that it is published under the section 160 duty to issue guidance about penalty notices, that it has been presented to Parliament under section 160(11), and that it replaces the penalty sections of the Regulatory Action Policy published in November 2018. By its own description it covers penalty notices for infringements of the UK GDPR, Part 3 of the 2018 Act (law enforcement processing) and Part 4 (intelligence services processing), and for failures to comply with information, assessment and enforcement notices. The ICO announced it on 18 March 2024, after consulting on a draft the previous year.

Two Ceilings, and the Turnover at Which Each Switches

Section 157 and Article 83(4) and (5) set a standard maximum and a higher maximum. The standard maximum is £8,700,000 or, for an undertaking, 2% of total annual worldwide turnover in the preceding financial year if that is higher. The higher maximum is £17,500,000 or 4% on the same basis. Article 83(6) applies the higher figure to non-compliance with an order under Article 58(2), and section 157(4) applies it to failures to comply with an information notice, an assessment notice, an enforcement notice and, since 5 February 2026, an interview notice added by the Data (Use and Access) Act 2025. A new subsection (4A), in force from 19 June 2026, applies the standard maximum to infringements of section 164A or regulations under section 164B.

The guidance converts those formulas into break-points. The percentage governs only where turnover exceeds £435 million for the standard maximum or £437.5 million for the higher maximum, because 2% of £435 million is £8.7 million and 4% of £437.5 million is £17.5 million. Below those figures the fixed sums are the ceiling.

Turnover Belongs to the Undertaking, Not the Company Fined

Neither the UK GDPR nor the 2018 Act defines "undertaking" for fining purposes. The guidance relies on Recital 150, which ties the term to Articles 101 and 102 of the Treaty on the Functioning of the European Union, and on UK competition case law. An undertaking is "any entity that is engaged in economic activity, regardless of its legal status or the way in which it is financed," which the ICO says can include public authorities, state-controlled enterprises and charities carrying on economic activity, and it may comprise several legal or natural persons forming a "single economic unit."

Where a controller is a subsidiary, the maximum is calculated on the turnover of the undertaking as a whole. Whether a parent belongs to that unit depends on decisive influence, judged by economic, organisational and legal links such as shareholding and board representation. Where a parent owns "all, or nearly all, the voting shares" in a subsidiary there is a rebuttable presumption of decisive influence, and the burden falls on the parent to show the subsidiary acts independently. The guidance adds that the Commissioner may hold a parent jointly and severally liable for payment, citing its 4 April 2023 TikTok decision.

One Cap for Linked Processing

Article 83(3) provides that where a controller or processor infringes several provisions "for the same or linked processing operations," the total fine may not exceed the amount specified for the gravest infringement. The guidance treats operations as linked where they serve a particular purpose or the same means of processing, relate to the same or a similar group of data subjects, and take place concurrently, sequentially or close in time. Its example is an information society service fined for infringing both Article 8 and Article 13, where the combined fines cannot exceed the higher maximum that attaches to Article 13. Infringements arising from separate conduct, such as a security breach and unrelated marketing transparency failures, are each capped separately even if they appear in one penalty notice. The 2018 Act has no equivalent of Article 83(3), and the ICO says it applies the same approach to Parts 3 and 4 for consistency.

The Five Steps

Step 1: seriousness

Step 1 assigns a starting point as a percentage of the relevant statutory maximum, reflecting the nature, gravity and duration of the infringement, whether it was intentional or negligent, and the categories of personal data affected. The guidance says there is "no pre-set 'tariff'" and uses three bands:

  • lower degree of seriousness: between 0% and 10% of the relevant legal maximum
  • medium degree of seriousness: between 10% and 20%
  • high degree of seriousness: between 20% and 100%

For an undertaking above the £435 million or £437.5 million line, the percentage applies to the turnover-based maximum; otherwise it applies to the fixed sum. The guidance's illustration is a high-seriousness starting point of 40% of the higher maximum, which for a controller subject to the fixed amount equals £7 million.

Step 2: turnover

Step 2 lets the Commissioner reduce the starting point to reflect the size of the undertaking, using turnover for the financial year before the penalty notice, generally from consolidated audited accounts. The indicative ranges, expressed as a percentage of the Step 1 figure, are:

Annual turnover of the undertakingAdjustment range applied to the Step 1 figure
Up to £2 million (micro-enterprise)0.2% to 0.4%
£2 million to £10 million (small enterprise)0.4% to 2%
£10 million to £50 million (medium enterprise)2% to 10%
£50 million to £100 million10% to 20%
£100 million to £250 million20% to 50%
£250 million to £435 million or £437.5 million50% to 100%
Above £435 million or £437.5 millionNo adjustment

The ranges are "only indicative," and the Commissioner "retains the discretion to impose a fine up to the applicable statutory maximum." Where a controller or processor is not an undertaking and has no turnover, the ICO may look instead at indicators such as assets, funding or administrative budget.

Step 3: the starting point in pounds

Step 3 combines the first two. Where the maximum is a fixed sum, the fixed maximum is multiplied by the seriousness percentage and then by the turnover adjustment; where it is turnover-based, turnover is multiplied by the statutory percentage and then by the seriousness percentage. In the guidance's Example A, a medium-seriousness infringement set at 16% of the higher maximum by a business with £30 million turnover, adjusted at 5%, gives £17.5 million multiplied by 16% and by 5%, a starting point of £140,000. In Example B, a high-seriousness infringement set at 40% by an undertaking with £800 million turnover, with no Step 2 adjustment, gives £800 million multiplied by 4% and by 40%, or £12.8 million.

Steps 4 and 5: factors and a final check

Step 4 applies aggravating or mitigating factors, which may take the figure above or below the indicative range. Step 5 tests whether the result is effective, proportionate and dissuasive, considering specific and general deterrence, and may raise or lower it. For several infringements from linked processing, the ICO assesses both each fine and the combined total. The guidance states that a controller or processor responsible for a serious infringement "should not avoid a fine solely on the basis of its financial position," and a final check keeps the amount within the statutory maximum.

A financial hardship reduction is available only in exceptional circumstances, on a claim the organisation or individual must prove, and only on objective evidence that the fine "would irretrievably jeopardise an organisation's economic viability or bankrupt an individual." A loss-making position alone is not enough, and the ICO may instead agree extra time to pay or payment by instalments.

How the ICO Reads the Article 83(2) Factors

The guidance's treatment of aggravating and mitigating factors follows Article 83(2) and section 155(3), but narrows several of them:

  • the ordinary duty of cooperation with the Commissioner "is required by law" and is not mitigation; cooperation counts where it concludes enforcement significantly more quickly or effectively or significantly limits harm, and persistent delay can aggravate
  • a breach notification the law requires is not mitigation "even if made promptly"; bringing an infringement the ICO did not already know about to its attention can be
  • the absence of previous infringements is not a mitigating factor "because compliance with the UK GDPR and DPA 2018 is expected"
  • the degree of responsibility for technical and organisational measures is more likely to be aggravating or neutral, and mitigation requires showing the controller or processor "has gone over and above its obligations"
  • failing to comply with an approved code of conduct or certification mechanism relevant to the infringement may aggravate and may be evidence of intent or negligence

On seriousness, the guidance describes an infringement as intentional where the controller or processor "wilfully ignored the known risk of its conduct infringing the law," and as negligent where it breached the duty of care the legislation requires, with examples including a failure to adopt data protection policies and human error by staff without adequate training. It may give more weight to processing involving children or other vulnerable people, a clear imbalance of power, or large-scale and systematic profiling.

Notice of Intent, Representations and Appeal

The procedure sits in Schedule 16 to the 2018 Act. Before a penalty notice, the Commissioner must give a notice of intent that sets out the reasons and "an indication of the amount of the penalty the Commissioner proposes to impose, including any aggravating or mitigating factors," allows at least 21 days for written representations, and offers oral representations where the Commissioner considers that appropriate. A penalty notice cannot be given before the representation period ends, and any representations must be considered.

The time limit changed on 5 February 2026. As originally enacted, paragraph 2(2) barred giving a penalty notice in reliance on a notice of intent after six months, and paragraph 2(3) allowed that period to be extended by agreement. Section 101 of the Data (Use and Access) Act 2025 omitted both and inserted paragraph 4(A2), under which, within six months of the notice of intent "or as soon as reasonably practicable thereafter," the regulator must give either a penalty notice or written notice that it has decided not to give one.

A penalty notice must allow at least 28 days for payment. A penalty variation notice cannot increase the amount or shorten the payment period, and recovery action cannot begin until any appeal has been decided or the time for appealing has ended. Under section 162, a person given a penalty notice may appeal to the Tribunal against the notice and also "against the amount of the penalty specified in the notice, whether or not the person appeals against the notice."

PECR Penalties Now Run Through the Same Machinery

The fining guidance addresses the UK GDPR and the 2018 Act. Penalties under the Privacy and Electronic Communications Regulations follow a separate statutory route that the 2025 Act redrew. Section 115 of the Data (Use and Access) Act 2025, fully in force since 5 February 2026, substituted regulation 31 so that Schedule 1 to the Regulations applies provisions of Parts 5 to 7 of the 2018 Act "with modifications" for enforcement, and replaced Schedule 1 with the text in Schedule 13 to the 2025 Act.

That schedule applies section 155 and Schedule 16, section 156, section 157 and section 159, among others, each subject to the modifications it sets out. Its paragraph 15 provides that no penalty notice may be given for a failure to comply with regulation 5A, and allows a penalty notice to an officer of a body penalised for breaching any of regulations 19 to 24 in the circumstances it specifies. Section 115 also retains the fixed monetary penalty in regulation 5C for personal data breach notification failures and gives the Secretary of State a power to change its amount by regulations. The modified maxima for PECR are set out in paragraph 18 of Schedule 13 and are not restated here.

Frequently Asked Questions

What is the maximum fine the ICO can impose under the UK GDPR?
For infringements subject to the higher maximum, £17.5 million or 4% of an undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher; for those subject to the standard maximum, £8.7 million or 2%. The percentage figures exceed the fixed sums only above turnover of £437.5 million and £435 million respectively.
Does the ICO use a parent company's turnover when fining a subsidiary?
Where the parent exercises decisive influence over the subsidiary, the guidance calculates the maximum on the turnover of the whole undertaking. Decisive influence is presumed, subject to rebuttal by the parent, where the parent owns all or nearly all of the subsidiary's voting shares, and the ICO may hold the parent jointly and severally liable for payment.
What starting point does the ICO use for a high-seriousness infringement?
Between 20% and 100% of the relevant statutory maximum at Step 1, compared with 10% to 20% for medium seriousness and 0% to 10% for lower seriousness. That figure may then be reduced at Step 2 to reflect the undertaking's turnover.
Is reporting a personal data breach to the ICO a mitigating factor?
Not where the report is required by law. The guidance states that notifications required by law are not mitigating even if made promptly, while voluntarily bringing to the ICO's attention an infringement it did not already know about may be.
Can an organisation appeal the amount of an ICO fine?
Yes. Section 162(3) of the Data Protection Act 2018 allows a person given a penalty notice or penalty variation notice to appeal to the Tribunal against the amount of the penalty, whether or not it also appeals against the notice itself.
How long does the ICO have between a notice of intent and a penalty notice?
Since 5 February 2026, paragraph 4(A2) of Schedule 16 requires the ICO to give a penalty notice, or written notice that it has decided not to, within six months of the notice of intent or as soon as reasonably practicable after that. The original paragraph 2(2) had barred a penalty notice after six months unless the period was extended by agreement.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. ICO, Data Protection Fining Guidance (March 18, 2024) agency guidance
  2. ICO, Data Protection Fining Guidance: the maximum amount of a fine under UK GDPR and DPA 2018 (March 18, 2024) agency guidance
  3. ICO, Data Protection Fining Guidance: the concept of an undertaking (March 18, 2024) agency guidance
  4. ICO, Data Protection Fining Guidance: fines where there is more than one infringement (March 18, 2024) agency guidance
  5. ICO, Data Protection Fining Guidance: seriousness of the infringement (March 18, 2024) agency guidance
  6. ICO, Data Protection Fining Guidance: relevant aggravating or mitigating factors (March 18, 2024) agency guidance
  7. ICO, Data Protection Fining Guidance: Step 1, assessment of the seriousness of the infringement (March 18, 2024) agency guidance
  8. ICO, Data Protection Fining Guidance: Step 2, accounting for turnover (March 18, 2024) agency guidance
  9. ICO, Data Protection Fining Guidance: Step 3, calculation of the starting point (March 18, 2024) agency guidance
  10. ICO, Data Protection Fining Guidance: Step 4, aggravating and mitigating factors (March 18, 2024) agency guidance
  11. ICO, Data Protection Fining Guidance: Step 5, adjustment to ensure the fine is effective, proportionate and dissuasive (March 18, 2024) agency guidance
  12. ICO, Data Protection Fining Guidance: financial hardship (March 18, 2024) agency guidance
  13. ICO, ICO publishes new fining guidance (March 18, 2024) agency release
  14. Data Protection Act 2018, section 155 (penalty notices) (September 13, 2026) statute
  15. Data Protection Act 2018, section 157 (maximum amount of penalty) (September 12, 2026) statute
  16. Data Protection Act 2018, section 162 (rights of appeal) (September 12, 2026) statute
  17. Data Protection Act 2018, Schedule 16 (penalties), latest available version (September 14, 2026) statute
  18. Data Protection Act 2018, Schedule 16 (penalties), as enacted (May 23, 2018) statute
  19. UK GDPR, Article 83 (general conditions for imposing administrative fines) (September 13, 2026) statute
  20. Data (Use and Access) Act 2025, section 115 (Commissioner's enforcement powers under the PEC Regulations) (February 5, 2026) statute
  21. Data (Use and Access) Act 2025, Schedule 13 (privacy and electronic communications: Commissioner's enforcement powers) (February 5, 2026) statute

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.