UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement
UK GDPR, Arts. 82-83; Data Protection Act 2018 §169
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Expect the ICO to have jurisdiction and fining power, up to the higher of GBP 17,500,000 or 4 percent of global annual turnover, over your processing of personal data of a person in the United Kingdom.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under UK General Data Protection Regulation (GDPR) Article 82, but expect a UK representative claim to require proof of unlawful use and resulting damage for each individual claimant, not a bare loss-of-control theory, per Lloyd v Google.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
DPA 2018 s.157(1) sets the maximum administrative fine for an infringement of the UK GDPR at the amount specified in Art. 83 itself, or the standard maximum amount if Art. 83 specifies none. Section 157(5) defines the higher maximum amount, which Art. 83(5) applies to the gravest infringement categories (basic principles for processing including Art. 9, data-subject rights, the new Arts. 22B/22C automated-decision-making safeguards, and Chapter V transfers): the higher of £17,500,000 or 4% of worldwide annual turnover. Narrower provisions (breach notification, Arts. 33-34) attract the lower standard maximum amount under s.157(6) instead; see the article-scoped rows in this file.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- GBP
- Fixed cap
- 17,500,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.
Enforcement record
Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.
- As of
- 2 September 2026
- Source link
- https://ico.org.uk/action-weve-taken/enforcement/
- Actions per year
- 32
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Information Commissioner's Office (ICO) is the UK's single supervisory authority, unlike Germany's 17-authority structure, with UK GDPR Article 83 fines up to the greater of GBP 17.5 million or 4 percent of global turnover. Section 169 DPA 2018 supplies a private right of action for contravention of data protection legislation other than UK GDPR itself, while UK GDPR's own Article 82 covers contraventions of the Regulation directly; both cover material and non-material damage.
The UK's own Supreme Court has gone further than the CJEU in limiting what counts: Lloyd v Google LLC [2021] UKSC 50 (10 November 2021) unanimously rejected a representative claim brought on behalf of 4.4 million iPhone users, holding that compensation for a non-trivial data protection breach requires the individual to show tangible financial loss or distress, not a bare loss of control alone, and that such a claim cannot succeed without showing unlawful use and resulting damage for each individual claimant rather than the group as a whole.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
legislation.gov.uk, official consolidated text, verified directly
Lloyd v Google LLC [2021] UKSC 50
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.