DLC Tech Solutions - IT Support for Small Business
    GDPR Compliance

    GDPR Breach Examples & Fines

    Real-world examples of GDPR breaches, ICO enforcement actions, and the fines organisations have faced for non-compliance.

    Book a Consultation

    What Is a GDPR Breach?

    A breach of GDPR — formally a "personal data breach" — is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. The UK GDPR recognises three distinct types:

    Confidentiality Breach

    Unauthorised or accidental disclosure of, or access to, personal data. This is the most commonly reported type — for example, sending personal data to the wrong recipient or a cyber attack exposing customer records.

    Integrity Breach

    Unauthorised or accidental alteration of personal data. An integrity breach in the context of GDPR means data has been changed without authorisation — potentially leading to incorrect decisions being made about individuals.

    Availability Breach

    Unauthorised or accidental loss of access to, or destruction of, personal data. A ransomware attack that encrypts patient records is a classic availability breach under GDPR, even if the data isn't exfiltrated.

    GDPR Fines: What Are the Penalties?

    The ICO can impose fines at two tiers under the UK GDPR:

    Lower Tier — Up to £8.7 Million

    Or 2% of annual global turnover. Applies to infringements relating to data protection by design, data processing records, cooperation with the ICO, and data breach notification obligations.

    Upper Tier — Up to £17.5 Million

    Or 4% of annual global turnover — whichever is higher. Applies to infringements of data processing principles, conditions for consent, data subject rights, and international data transfers.

    Real GDPR Breach Examples

    British Airways

    £20 million2020

    Personal and financial details of more than 400,000 customers were compromised through a web-skimming attack. The ICO found BA had poor security arrangements including insufficient monitoring and inadequate multi-factor authentication.

    Marriott International

    £18.4 million2020

    A breach affecting approximately 339 million guest records worldwide. The ICO found Marriott failed to undertake sufficient due diligence on IT systems when acquiring Starwood and did not do enough to secure them.

    Clearview AI

    £7.5 million2022

    The ICO fined Clearview AI for using images of people in the UK collected from the web and social media to create a global facial recognition database without consent or a lawful basis for processing.

    TikTok

    £12.7 million2023

    The ICO fined TikTok for processing personal data of children under 13 without appropriate parental consent, breaching UK GDPR requirements for special protections around children's data.

    How to Prevent a GDPR Breach

    Prevention is always more cost-effective than remediation. The organisations that avoid GDPR breaches and fines share common practices:

    • Conduct regular GDPR audits to identify and address compliance gaps
    • Implement strong access controls — especially Privileged Access Management (PAM)
    • Train staff on data protection responsibilities and breach reporting
    • Maintain accurate records of processing activities (ROPA)
    • Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing
    • Have a documented and tested breach response plan

    Protect Your Organisation

    A proactive approach to GDPR compliance significantly reduces your risk. Start with a GDPR audit to understand your current position, review your GDPR controls, and ensure your team understands individual rights under GDPR.

    For organisations handling special category data, additional safeguards are essential. Our GDPR compliance services help you build and maintain a robust data protection programme.

    Ready to Get Started?

    Contact us to discuss how we can support your organisation with practical, outcome-focused cyber security.

    Get in Touch