Law / United Kingdom

UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement

UK GDPR, Arts. 82-83; Data Protection Act 2018 §169

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Expect the ICO to have jurisdiction and fining power, up to the higher of GBP 17,500,000 or 4 percent of global annual turnover, over your processing of personal data of a person in the United Kingdom.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under UK General Data Protection Regulation (GDPR) Article 82, but expect a UK representative claim to require proof of unlawful use and resulting damage for each individual claimant, not a bare loss-of-control theory, per Lloyd v Google.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

DPA 2018 s.157(1) sets the maximum administrative fine for an infringement of the UK GDPR at the amount specified in Art. 83 itself, or the standard maximum amount if Art. 83 specifies none. Section 157(5) defines the higher maximum amount, which Art. 83(5) applies to the gravest infringement categories (basic principles for processing including Art. 9, data-subject rights, the new Arts. 22B/22C automated-decision-making safeguards, and Chapter V transfers): the higher of £17,500,000 or 4% of worldwide annual turnover. Narrower provisions (breach notification, Arts. 33-34) attract the lower standard maximum amount under s.157(6) instead; see the article-scoped rows in this file.

Rule
Higher of
As of
2 September 2026
Currency
GBP
Fixed cap
17,500,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.

Enforcement record

Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.

As of
2 September 2026
Source link
https://ico.org.uk/action-weve-taken/enforcement/
Actions per year
32

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Information Commissioner's Office (ICO) is the UK's single supervisory authority, unlike Germany's 17-authority structure, with UK GDPR Article 83 fines up to the greater of GBP 17.5 million or 4 percent of global turnover. Section 169 DPA 2018 supplies a private right of action for contravention of data protection legislation other than UK GDPR itself, while UK GDPR's own Article 82 covers contraventions of the Regulation directly; both cover material and non-material damage.

The UK's own Supreme Court has gone further than the CJEU in limiting what counts: Lloyd v Google LLC [2021] UKSC 50 (10 November 2021) unanimously rejected a representative claim brought on behalf of 4.4 million iPhone users, holding that compensation for a non-trivial data protection breach requires the individual to show tangible financial loss or distress, not a bare loss of control alone, and that such a claim cannot succeed without showing unlawful use and resulting damage for each individual claimant rather than the group as a whole.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

legislation.gov.uk, official consolidated text, verified directly
Lloyd v Google LLC [2021] UKSC 50

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app