ICO breaks £1m milestone as two councils fined
The ICO hands out two hefty fines, meaning it has now enforced penalties amounting to greater than £1 million.


The Information Commissioner's Office (ICO) is clamping down hard on data breaches, as two more councils were today served with hefty fines.
Croydon Council was handed a 100,000 penalty after a bag containing papers relating to the care of a child sex abuse victim was stolen from a pub.
Norfolk County Council was hit with an 80,000 penalty for sending data about allegations against a parent and the welfare of their child to the wrong recipient.
One of the most basic rules when disclosing highly sensitive information is to check and then double check that it is going to the right recipient.
The two fines mean the ICO has now handed out over 1 million in fines since being given the license to hit organisations with up to 500,000 in data breach penalties in April 2010.
"We appreciate that people working in roles where they handle sensitive information will like all of us - sometimes have their bags stolen. However, this highly personal information needn't have been compromised at all if Croydon Council had appropriate security measures in place," said Stephen Eckersley, head of enforcement at the ICO.
"One of the most basic rules when disclosing highly sensitive information is to check and then double check that it is going to the right recipient. Norfolk County Council failed to have a system for this and also did not monitor whether staff had completed data protection training."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The news came just three days after the ICO slapped five separate local authorities on the wrist for breaching the Data Protection Act.
In late January, the ICO handed out its biggest fine ever as Midlothian Council was told to pay 140,000.
Only one private organisation has been hit with a fine, but private bodies are not yet required by law to disclose data breaches.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott