GDPR breaches are series. In this article we will discuss the penalties for Breaching the UK GDPR and Data Protection Act 2018. This includes the fines that can be applied, and a discussion of some of the criminal offences that can be committed for breaching the Act.
Contents
-
What is a data breach?
-
Breach notifications
-
Penalties for breaching GDPR
-
Enforcement notices
-
Criminal offences
-
Civil Action
-
Top 10 Questions Answered

Introduction to Breaching GDPR
The Data Protection Act 2018 (DPA 2018) brings the UK General Data Protection Regulation (UK GDPR) into UK law. The Act forms the legal framework for data protection in the United Kingdom. These regulations aim to safeguard individuals’ personal data, ensuring its fair and lawful processing. Violations of the UK GDPR and DPA 2018 can result in significant penalties for both organisations and individuals responsible for data breaches. In this article we explore what a personal data breach is, and the penalties associated with breaching these regulations. We also provide an overview of the criminal offenses detailed in the Data Protection Act 2018.
The UK GDPR is substantially the same as the EU GDPR.
What are GDPR Breaches?
A GDPR breaches, also knows as a data breach is defined as the accidental or deliberate destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
People and organisations have an obligation to take appropriate technical and organisational measures to prevent personal data breaches. This is especially important for high risk data processing like health related data for hospital patients.
It is also a breach of the GDPR to not comply with people’s data rights. For example, not responding to subject access requests (SAR) within statutory timescales.
Get More GDPR Information and Guidance Direct to Your Inbox
Actionable ideas, tools, and invites to expert sessions, direct to your inbox every month (and we won’t use your data for anything else)
Breach Notification
When a personal data breach occurs there may be obligations to report the breach to both individuals affected and the relevant supervisory authority, which in the UK is the Information Commissioner.
The threshold for reporting a personal data breach to the Information Commissioner is if the breach is likely to result in a risk to the rights and freedoms of individuals.
You only have to report to the Information Commissioner of a breach if it is likely to result in a risk to the rights and freedoms of individuals.
If a breach is likely to result in a high risk to the rights and freedoms of individuals, you have an obligation to inform those concerned directly without undue delay.
Penalties for GDPR Breaches
The UK GDPR empowers the Information Commissioner’s Office (ICO) to enforce compliance and impose penalties for non-compliance. The ICO can issue two types of penalty: administrative fines and enforcement notices.
In addition people and companies can be prosecuted for breaching the DPA 2018 and conviction could lead to an individual going to prison for up to two years.
GDPR Fines
Administrative fines are the most common penalties for breaching the UK GDPR and are classified into two tiers, depending on the severity of the violation:
Tier 1: Up to £8.7 million or 2% of annual global turnover (whichever is higher).
Tier 1 fines are typically applied for less severe infringements, such as not conducting data protection impact assessments, failing to maintain records of data processing activities, or inadequate data security measures. For example, a failure to report a data breach cold result in a Tier 1 fine.
Tier 2: Up to £17.5 million or 4% of annual global turnover (whichever is higher).
Tier 2 fines are reserved for more serious breaches, including significant violations of individuals’ rights, failure to obtain proper consent, or insufficient security measures leading to a data breach.
The specific amount of the fine within the given range depends on various factors, including the nature, gravity, and duration of the infringement, the organisation’s level of cooperation with the ICO, and the extent of the damage caused to individuals. Therefore the exact penalty will be decided on a case by case basis.
Enforcement Notices
In addition to fines, the ICO can issue enforcement notices to organisations to remedy non-compliance. These notices require organisations to take specific actions within a given timeframe to rectify GDPR breaches. Failure to comply with an enforcement notice can result in further penalties and potentially lead to criminal prosecution.
Sign Up Here:
Apart from administrative fines, the DPA 2018 also outlines several criminal offences related to data protection. These offences can result in criminal prosecution, leading to more severe penalties, including imprisonment and unlimited fines. Prosecution can happen to a company and an individual. The criminal offences under the DPA 2018 include: This offence involves intentionally obtaining, disclosing, or procuring personal data without the data controller’s consent. It also covers the sale, offering, or possession of unlawfully obtained personal data. Convictions for this offence can result in imprisonment for up to two years or an unlimited fine. The Act prohibits intentionally re-identifying de-identified personal data without the data controller’s consent. Re-identification involves linking anonymised or pseudonymised data with additional information to identify individuals. Convictions under this offence carry the penalty of imprisonment for up to two years or an unlimited fine. This offence pertains to intentionally altering personal data with the aim of preventing its disclosure. It is primarily aimed at preventing individuals from accessing their personal information. The penalty for this offence includes imprisonment for up to two years or an unlimited fine. As mentioned earlier, failure to comply with an enforcement notice issued by the ICO is a criminal offence. Organisations or individuals who fail to comply may face criminal prosecution. If convicted, the penalty can include an unlimited fine imposed by the court. Section 194 holds directors, managers, or officers of corporate bodies personally liable for offences committed by their organisations if the offence was committed with their consent, connivance, or neglect. Convictions under this section can lead to a prison terms of up to two years or an unlimited fine. It’s important to note that criminal offences under the DPA 2018 require proof of intent or recklessness. Mere negligence or accidental breaches typically fall under the scope of administrative fines rather than criminal prosecution. If someone has suffered a personal data breach they can bring a claim for compensation through the civil courts. Such claims could lead to awards for damages, and of course legal costs for both sides. The Information Commissioner cannot consider a claim for compensation. Can individuals be fined for GDPR breaches? Yes, they can, and they can also get a criminal record if they are prosecuted for one or more of the offences discussed above. How are GDPR fines calculated? The size of the fine depends on a number of factors and will be calculated on a case by case basis. Factors that are likely to be relevant include the number of people affected by the data breach, whether the data involved are sensitive in some way, and the extent of harm or distress causes by the people whose data were compromised. Who is liable for a data breach? Individuals, organisations and directors/managers or other senior people may be individually and jointly liable for a data breach. Data controllers may also be liable for data breaches caused by data processors. What is the fine for breaching GDPR? The maximum fine is £17.5 million or 4% of global turnover, whichever is greater. However the actual penalty will depend on the factors outlined in question 2, above. Can I get compensation for a breach of GDPR? The Information Commissioner will not give people compensation for a data breach, but people can make a compensation claim by starting a civil claim. How can I avoid a breach of GDPR? Understand and act on your responsibilities and statutory duties under the GDPR. Take a course like one of our five-star rated, expert led GDPR training. Find out more here. Who investigates GDPR breaches? Within a company the data protection officer or equivalent will investigate. For more serious breaches the Information Commissioner will investigate a GDPR breach. Are employees liable for GDPR breaches? Not unless they have been directly responsible for the breach that happened. Just being employed somewhere where a breach has happened does not make you liable. How do I report a data breach? You should contact the relevant organisation’s data protection officer, or you can contact the Information Commissioner here. Can GDPR be breached verbally? Yes, you can cause a data breach over the telephone or verbally. Compliance with the UK GDPR and the Data Protection Act 2018 is crucial to protect individuals’ personal data and maintain the trust of data subjects. Organisations and individuals should be aware of the severe penalties associated with breaching their statutory obligations. The Information Commissioner’s Office has the authority to impose administrative fines, which can range from a percentage of annual global turnover to millions of pounds. Additionally, the DPA 2018 sets out several criminal offences that can result in criminal prosecution, including imprisonment and unlimited fines. Alongside fines and a potential criminal case, there can be a civil claim for compensation for any personal data breach. It is therefore important that organisations and individuals handling personal data prioritise data protection and implement appropriate measures to ensure compliance with the law and avoid GDPR breaches. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.Criminal Offences under the Data Protection Act 2018
Unlawful Obtaining, Disclosure, or Procurement of Personal Data
Re-Identification of De-Identified Personal Data
Alteration of Personal Data to Prevent Disclosure
Failure to Comply with an Enforcement Notice
Offences by Directors, Managers, or Officers of Corporate Bodies
Claiming for GDPR Breaches and Compensation Options
GDPR Breaches: Top 10 Questions Answered
Conclusion: Understanding the Implications of GDPR Breaches
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: