Metaluxo
← Blog

ICO Fines in 2024: What Changed and What It Means for SMEs

ICO Fines in 2024: What Changed and What It Means for SMEs

The UK Information Commissioner’s Office issued 12 enforcement notices and over £15 million in fines in 2024. The headline cases involved big names — a social media platform, a major retailer, a healthcare provider — but the patterns that triggered fines are relevant to every SME.

At Metaluxo we review ICO enforcement actions quarterly to identify the compliance gaps that regulators are actually targeting. Here is what 2024 taught us.


Pattern 1: Repeat offenders

Three of the largest fines went to companies that had already been warned. The ICO sent letters, conducted audits, and issued guidance. The companies acknowledged the findings but did not implement the recommended changes.

The lesson: An ICO warning letter is not the end of the process. It is the beginning of a countdown. If you receive one, treat it as a formal enforcement notice and act immediately.


Pattern 2: Untested backups

Two fines involved ransomware incidents where the company had backups — but the backups were encrypted or corrupted. The companies could not restore operations and lost customer data.

The lesson: Backups are not a compliance control until they are tested. The ICO expects evidence of tested recovery procedures, not just backup schedules.


Pattern 3: Missing or absent Data Protection Officers

Four enforcement actions noted that the company either had no DPO or had appointed someone without the necessary independence or expertise. The ICO’s guidance is clear: if you process personal data at scale, you need a named, trained, and independent DPO.

The lesson: For SMEs, a DPO does not need to be full-time. A virtual DPO arrangement with an external consultant is valid — but it must be documented, the consultant must have access to senior management, and their advice must be followed.


The £5,000 fine that should worry you most

Not every fine was headline-grabbing. One £5,000 fine went to a 12-person company that had lost a laptop containing customer data. The laptop was not encrypted. There was no remote wipe capability. The company had no incident response plan.

The ICO’s message is that size does not excuse basic controls. A 12-person company is expected to encrypt laptops and know what to do when one goes missing.


At Metaluxo we help SMEs avoid ICO enforcement by building proportionate compliance programmes. If you are unsure whether your data protection measures meet the ICO’s expectations, book a free 30-minute consultation and we will assess your gaps.

Roberto Arias — founder of Metaluxo. Virtual CISO work, ISO 27001 and incident response for small and medium businesses across the EU. Ask him a question →

Send us a message
Message us Book now