Human resources at a click

ICO Fines – Don’t fall foul of the rules

html-coding-on-computer-screen

Back in March, Cathay Pacific were fined £500,000 for failing to protect the security of its customers’ personal data.  This used to be the largest fine that the ICO could impose under the Data Protection Act 1998 but the Data Protection Act 2018 now allows for a fine of anywhere up to 20 million euros or 4% of annual worldwide turnover, whichever is greater.

There have also been a number of fines imposed over recent months for unsolicited marketing emails and calls including two this month, namely:

  • £100,000 fine for Koypo Laboratories Limited for instigating 21,166,574 unsolicited marketing emails without consent
  • £80,000 fine for Rain Trading Limited for making 270,774 unsolicited marketing  calls to individuals without consent

Cathay Pacific were fined £500,000 for failing to protect the security of its customers’ personal data.

In the current economic crisis it would not be surprising if more businesses turned their attention to marketing but these fines are a stark warning to organisations to ensure they comply with data protection obligations in doing so.

Please do not hesitate to get in contact with our data protection team if you have any questions.

Disclaimer This information is for guidance purposes only and should not be regarded as a substitute for taking professional and legal advice. Please refer to the full General Notices on our website.
Louise_Keenan
Louise Keenan
Associate

Related Articles

The UK’s data protection framework is about to undergo its most significant change since the UK GDPR came into force....

On 6 May 2025, the SRA authorised the first law firm providing legal services through artificial intelligence. Garfield.Law will provide...

ICO Consultation and Draft Updated Guidance Where data breaches are easily achieved by human error, encryption not only offers a...

Related Resources

Request for access to personal data form

Employees should fill out this form if they want to request access to their personal data which the company may...

Bring your own device policy

This policy covers the use of employees’ own devices (e.g. smartphone, tablet, laptop) for companybusiness. This policy applies to the...

Surveillance impact assessment

Surveillance impact assessment form. Employee Monitoring Impact Assessment Considerations Suspected criminal activity or equivalent malpractice

...
Human resources at a click