Hazard

By root cause

How UK organisations actually fail

The ICO does not publish a cause field. We derive one from the text of every notice, so you can ask what a given failure mode has cost across the whole register.

113 Unlawful direct marketing Nuisance calls, spam texts or emails sent without valid consent — enforced under PECR rather than UK GDPR. £3.52m in penalties 40 Other or unclassified The published notice did not contain enough detail to classify a single root cause. £13.03m in penalties 21 Failure on individual rights Subject access requests ignored or answered late, or people prevented from exercising their data rights. £5,440 in penalties 12 Cyber attack An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead. £18.50m in penalties 10 Unlawful disclosure Personal data published or shared with people who had no right to see it, including failures to redact. no penalties 6 Misdirected communication Personal data sent to the wrong recipient — the bcc field, the wrong attachment, the wrong address. Mundane, common, and expensive. £7,500 in penalties 4 Insider misuse A member of staff accessed or took personal data they had no business reason to touch. Frequently prosecuted under the Computer Misuse Act. £476,732.42 in penalties 3 Children's data Processing children's personal data without age assurance, parental consent or a lawful basis — the ICO's most active enforcement front against large platforms. £14.87m in penalties 3 Unpatched or unsupported software A known vulnerability was left unfixed, or the software was past end of support. The most directly preventable cause on this list. no penalties 2 Excessive collection or retention Data kept longer than necessary, or gathered without a lawful basis in the first place. no penalties 2 Ransomware An attacker encrypted or stole data and demanded payment. Usually the visible end of a chain that started with an unpatched service or a stolen credential. £3.07m in penalties 1 Lost device or paper record Physical loss — an unencrypted laptop, a memory stick, a file left behind. no penalties

Classification is automated from the published notice text and reviewed against the ICO's own wording. Where a notice is too brief to classify, it lands in “other”. How this works.