All news
Rules & compliance
5 November 2024

ICO enforcement: the small-business mistakes that get penalised

Most UK enforcement action against smaller organisations comes from unsolicited marketing and avoidable data losses, not sophisticated breaches.

What this means for your business

Marketing lists, old data nobody deleted, and unencrypted laptops are the common threads. All three are fixable in a week.

Looking through Information Commissioner's Office enforcement against smaller UK organisations, the same causes come up repeatedly — and none of them involve advanced attackers.

The recurring themes

Unsolicited marketing. Texts and calls to people who never consented, or to lists bought from a broker with vague provenance. PECR fines here are routine and land on small companies.

Keeping data forever. Ten years of customer records, old CVs, ex-employee files. If you don't need it, holding it is only risk.

Unencrypted devices. A laptop left on a train becomes a reportable breach if the disk isn't encrypted, and doesn't if it is. BitLocker is free and takes minutes.

No process for subject access requests. The deadline is one month and complaints about missed deadlines get looked at.

A short list that covers most of it

  1. Turn on disk encryption everywhere and record the recovery keys centrally.
  2. Write a retention schedule, however simple, and actually delete things.
  3. Check your marketing consent basis before the next campaign.
  4. Know who reports a breach, and that the clock is 72 hours.

We cover encryption and device control as part of managed support, and our GDPR page walks through the rest.

Need help staying compliant?

Practical GDPR and data protection support for small and medium businesses.

GDPR support

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.