By root cause
How UK organisations actually fail
The ICO does not publish a cause field. We derive one from the text of every notice, so you can ask what a given failure mode has cost across the whole register.
113
Unlawful direct marketing
Nuisance calls, spam texts or emails sent without valid consent — enforced under PECR rather than UK GDPR.
£3.52m in penalties
40
Other or unclassified
The published notice did not contain enough detail to classify a single root cause.
£13.03m in penalties
21
Failure on individual rights
Subject access requests ignored or answered late, or people prevented from exercising their data rights.
£5,440 in penalties
12
Cyber attack
An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead.
£18.50m in penalties
10
Unlawful disclosure
Personal data published or shared with people who had no right to see it, including failures to redact.
no penalties
6
Misdirected communication
Personal data sent to the wrong recipient — the bcc field, the wrong attachment, the wrong address. Mundane, common, and expensive.
£7,500 in penalties
4
Insider misuse
A member of staff accessed or took personal data they had no business reason to touch. Frequently prosecuted under the Computer Misuse Act.
£476,732.42 in penalties
3
Children's data
Processing children's personal data without age assurance, parental consent or a lawful basis — the ICO's most active enforcement front against large platforms.
£14.87m in penalties
3
Unpatched or unsupported software
A known vulnerability was left unfixed, or the software was past end of support. The most directly preventable cause on this list.
no penalties
2
Excessive collection or retention
Data kept longer than necessary, or gathered without a lawful basis in the first place.
no penalties
2
Ransomware
An attacker encrypted or stole data and demanded payment. Usually the visible end of a chain that started with an unpatched service or a stolen credential.
£3.07m in penalties
1
Lost device or paper record
Physical loss — an unencrypted laptop, a memory stick, a file left behind.
no penalties
Classification is automated from the published notice text and reviewed against the ICO's own wording. Where a notice is too brief to classify, it lands in “other”. How this works.