GDPR Breaches: Offences and Penalties

GDPR breaches are series. In this article we will discuss the penalties for Breaching the UK GDPR and Data Protection Act 2018. This includes the fines that can be applied, and a discussion of some of the criminal offences that can be committed for breaching the Act.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

  • What is a data breach?

  • Breach notifications

  • Penalties for breaching GDPR

  • Enforcement notices

  • Criminal offences

  • Civil Action

  • Top 10 Questions Answered

Periodic Table of the GDPR

Introduction to Breaching GDPR

The Data Protection Act 2018 (DPA 2018) brings the UK General Data Protection Regulation (UK GDPR) into UK law. The Act forms the legal framework for data protection in the United Kingdom. These regulations aim to safeguard individuals’ personal data, ensuring its fair and lawful processing. Violations of the UK GDPR and DPA 2018 can result in significant penalties for both organisations and individuals responsible for data breaches. In this article we explore what a personal data breach is, and the penalties associated with breaching these regulations. We also provide an overview of the criminal offenses detailed in the Data Protection Act 2018.

The UK GDPR is substantially the same as the EU GDPR.

What are GDPR Breaches?

A GDPR breaches, also knows as a data breach is defined as the accidental or deliberate destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

People and organisations have an obligation to take appropriate technical and organisational measures to prevent personal data breaches. This is especially important for high risk data processing like health related data for hospital patients.

It is also a breach of the GDPR to not comply with people’s data rights. For example, not responding to subject access requests (SAR) within statutory timescales.

Get More GDPR Information and Guidance Direct to Your Inbox

Actionable ideas, tools, and invites to expert sessions, direct to your inbox every month (and we won’t use your data for anything else)

 

Breach Notification

When a personal data breach occurs there may be obligations to report the breach to both individuals affected and the relevant supervisory authority, which in the UK is the Information Commissioner.

The threshold for reporting a personal data breach to the Information Commissioner is if the breach is likely to result in a risk to the rights and freedoms of individuals.

You only have to report to the Information Commissioner of a breach if it is likely to result in a risk to the rights and freedoms of individuals.

If a breach is likely to result in a high risk to the rights and freedoms of individuals, you have an obligation to inform those concerned directly without undue delay.

Penalties for GDPR Breaches

The UK GDPR empowers the Information Commissioner’s Office (ICO) to enforce compliance and impose penalties for non-compliance. The ICO can issue two types of penalty: administrative fines and enforcement notices.

In addition people and companies can be prosecuted for breaching the DPA 2018 and conviction could lead to an individual going to prison for up to two years.

GDPR Fines

Administrative fines are the most common penalties for breaching the UK GDPR and are classified into two tiers, depending on the severity of the violation:

Tier 1: Up to £8.7 million or 2% of annual global turnover (whichever is higher).

Tier 1 fines are typically applied for less severe infringements, such as not conducting data protection impact assessments, failing to maintain records of data processing activities, or inadequate data security measures. For example, a failure to report a data breach cold result in a Tier 1 fine.

Tier 2: Up to £17.5 million or 4% of annual global turnover (whichever is higher).

Tier 2 fines are reserved for more serious breaches, including significant violations of individuals’ rights, failure to obtain proper consent, or insufficient security measures leading to a data breach.

The specific amount of the fine within the given range depends on various factors, including the nature, gravity, and duration of the infringement, the organisation’s level of cooperation with the ICO, and the extent of the damage caused to individuals. Therefore the exact penalty will be decided on a case by case basis.

Enforcement Notices

In addition to fines, the ICO can issue enforcement notices to organisations to remedy non-compliance. These notices require organisations to take specific actions within a given timeframe to rectify GDPR breaches. Failure to comply with an enforcement notice can result in further penalties and potentially lead to criminal prosecution.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Criminal Offences under the Data Protection Act 2018

Apart from administrative fines, the DPA 2018 also outlines several criminal offences related to data protection. These offences can result in criminal prosecution, leading to more severe penalties, including imprisonment and unlimited fines. Prosecution can happen to a company and an individual. The criminal offences under the DPA 2018 include:

Unlawful Obtaining, Disclosure, or Procurement of Personal Data

This offence involves intentionally obtaining, disclosing, or procuring personal data without the data controller’s consent. It also covers the sale, offering, or possession of unlawfully obtained personal data. Convictions for this offence can result in imprisonment for up to two years or an unlimited fine.

Re-Identification of De-Identified Personal Data

The Act prohibits intentionally re-identifying de-identified personal data without the data controller’s consent. Re-identification involves linking anonymised or pseudonymised data with additional information to identify individuals. Convictions under this offence carry the penalty of imprisonment for up to two years or an unlimited fine.

Alteration of Personal Data to Prevent Disclosure

This offence pertains to intentionally altering personal data with the aim of preventing its disclosure. It is primarily aimed at preventing individuals from accessing their personal information. The penalty for this offence includes imprisonment for up to two years or an unlimited fine.

Failure to Comply with an Enforcement Notice

As mentioned earlier, failure to comply with an enforcement notice issued by the ICO is a criminal

offence. Organisations or individuals who fail to comply may face criminal prosecution. If convicted, the penalty can include an unlimited fine imposed by the court.

Offences by Directors, Managers, or Officers of Corporate Bodies

Section 194 holds directors, managers, or officers of corporate bodies personally liable for offences committed by their organisations if the offence was committed with their consent, connivance, or neglect. Convictions under this section can lead to a prison terms of up to two years or an unlimited fine.

It’s important to note that criminal offences under the DPA 2018 require proof of intent or recklessness. Mere negligence or accidental breaches typically fall under the scope of administrative fines rather than criminal prosecution.

Claiming for GDPR Breaches and Compensation Options

If someone has suffered a personal data breach they can bring a claim for compensation through the civil courts. Such claims could lead to awards for damages, and of course legal costs for both sides. The Information Commissioner cannot consider a claim for compensation.

GDPR Breaches: Top 10 Questions Answered

  1. Can individuals be fined for GDPR breaches? Yes, they can, and they can also get a criminal record if they are prosecuted for one or more of the offences discussed above.

  2. How are GDPR fines calculated? The size of the fine depends on a number of factors and will be calculated on a case by case basis. Factors that are likely to be relevant include the number of people affected by the data breach, whether the data involved are sensitive in some way, and the extent of harm or distress causes by the people whose data were compromised.

  3. Who is liable for a data breach? Individuals, organisations and directors/managers or other senior people may be individually and jointly liable for a data breach. Data controllers may also be liable for data breaches caused by data processors.

  4. What is the fine for breaching GDPR? The maximum fine is £17.5 million or 4% of global turnover, whichever is greater. However the actual penalty will depend on the factors outlined in question 2, above.

  5. Can I get compensation for a breach of GDPR? The Information Commissioner will not give people compensation for a data breach, but people can make a compensation claim by starting a civil claim.

  6. How can I avoid a breach of GDPR? Understand and act on your responsibilities and statutory duties under the GDPR. Take a course like one of our five-star rated, expert led GDPR training. Find out more here.

  7. Who investigates GDPR breaches? Within a company the data protection officer or equivalent will investigate. For more serious breaches the Information Commissioner will investigate a GDPR breach.

  8. Are employees liable for GDPR breaches? Not unless they have been directly responsible for the breach that happened. Just being employed somewhere where a breach has happened does not make you liable.

  9. How do I report a data breach? You should contact the relevant organisation’s data protection officer, or you can contact the Information Commissioner here.

  10. Can GDPR be breached verbally? Yes, you can cause a data breach over the telephone or verbally.

Conclusion: Understanding the Implications of GDPR Breaches

Compliance with the UK GDPR and the Data Protection Act 2018 is crucial to protect individuals’ personal data and maintain the trust of data subjects. Organisations and individuals should be aware of the severe penalties associated with breaching their statutory obligations. The Information Commissioner’s Office has the authority to impose administrative fines, which can range from a percentage of annual global turnover to millions of pounds. Additionally, the DPA 2018 sets out several criminal offences that can result in criminal prosecution, including imprisonment and unlimited fines. Alongside fines and a potential criminal case, there can be a civil claim for compensation for any personal data breach.

It is therefore important that organisations and individuals handling personal data prioritise data protection and implement appropriate measures to ensure compliance with the law and avoid GDPR breaches.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial