Skip to main content

URM

Cybersecurity reports and statistics published by URM

0 categories1 reports

Recent Statistics & Reports

There were 62 instances of enforcement action against 47 organisations by the Information Commissioner’s Office (ICO) in 2024, including 8 law enforcement agencies. 32 of these actions related to breaches of the UK GDPR and were brought against 31 organisations, with 27 in the public sector and 4 in the private sector.

2/1/2025

In 2024, 3 public organisations were fined by the Information Commissioner’s Office (ICO): The Police Service of Northern Ireland (PSNI) was fined £750,000, the Ministry of Defence (MOD) was fined £350,000 (reduced from £1m), and the Central YMCA was fined £7,500.

2/1/2025

Fines for breaches of PECR exceeded those for UK GDPR violations, with roughly £1.6m compared to around £1.1m.

2/1/2025

The ICO imposed 18 monetary penalties in 2024, nearly the same as the 17 in 2023.

2/1/2025

The average fine by the Information Commissioner’s Office (ICO) in the UK in 2024 was £153,722, which is less than a fifth of the 2023 average of £816,471 (skewed by a large fine to TikTok).

2/1/2025

The majority of fines by the Information Commissioner’s Office (ICO) in 2024 were for breaches of the Privacy and Electronic Communications Regulations (PECR), but the proportion of fines for UK GDPR breaches rose to one sixth of the total in 2024, compared to one seventeenth in 2023.

2/1/2025

The average fine by the Information Commissioner’s Office (ICO) in the UK in 2024 was £153,722, which is less than a fifth of the 2023 average of £816,471 (skewed by a large fine to TikTok).

2/1/2025

Top Categories