Everyone seemingly is waiting for the ICO to show their teeth regarding GDPR. Until we start seeing monetary penalty notices, the worthy words from the regulator will be just that. To anticipate their potential approach, it’s worth revisiting their past actions – a brief history of enforcement if you will.

The Information Commissioners Office got the “power to penalise” in 2010. Prior to that there had been significant fines issued by other regulators – for example the £1m issued to Nationwide following the loss of unencrypted devices from the former FSA – but the ability for the ICO to take proper action was limited. Since 2010, the ICO has issued penalties to 174 data controllers – split roughly 50:50 between the Data Protection Act 1998 (DPA) and Privacy and Electronic Communication Regulations (PECR).

As an aside whilst £17.8m in penalties has been issued, only 54% of that money has been collected, if include non-payers, early payers and those in the middle who paid – on average – less than half of their penalty. 14 paid in full.

The fines under the DPA were issued for a number of offences broadly along loss of data, and consultants like the author have fond memories of the Northern Ireland Filing Cabinet, the skip in Brighton, the recycling centre in a Borders car park or tales of people using CC rather than BCC. It is ironic that the HMRC have received an enforcement notice for their poor management of customer consent regarding biometric data, when their two data discs lost somewhere between Middlesbrough and London with tens of millions of records on escaped any censure.

Anecdotal evidence suggests that the ICO towards the end of the DPA regime got a little punchier. For ages the maximum penalty issued was £325,000, then it went to £400,000 and finally the maximum of £500,000. And increasingly the focus changed from poor data handling to poor data management. Recently pregnancy club Bounty were fined £400,000 for sharing data outside of the reasonable expectations (or indeed informed knowledge) of the data subjects. Also Emma’s Diary were fined £140,000 for selling information to the Labour party, and True Visions Productions were fined £120,000 for not informing patients adequately around CCTVs and microphones used in the recording of a documentary on stillbirths.

Although there were still fines issued for loss of data – Royal Sun Alliance fined £150,000 for the loss of a network attached storage device with credit card customer names and numbers exposed, penalties increasingly dealt with more procedural matters. The charities sector came in for criticism – and fines – for their use of the Reciprocate scheme where data about donors would be shared with up to 40 charities. Higher Education institutions were investigated for the processing of personal data supporting fundraising, chiefly high net-worth alumni. Wiltshire police received an undertaking regarding their failure to provide staff with refresher training to staff.

And it is this diversity of offences which sees the ICO getting match fit for GDPR, with it’s plentiful number of hazards for organisations spread over two penalty tiers. That said it is likely that penalties under the DPA98 will still keep coming given the complexity of investigations around data breaches.

The first notice issued by the ICO under GDPR was to a Canadian data-analytics firm – one associated with the Facebook/Cambridge Analytica scandal. The processing in the EU lacked a lawful basis or appropriate transparency. This was addressed with an enforcement notice. The ICO has not had cause – as yet – to issue any financial penalty. And certainly not one to match the €50m fine issued to Google by the French regulator.

What happens next… who knows. Penalties need to be “effective, proportionate and dissuasive”. Whether they will be remains to be seen.