Insights

How the ICO actually calculates the £17.5 million penalty

6 May 2026

“£17.5 million, or 4% of global annual turnover, whichever is higher” is the figure most commonly cited for the most serious UK GDPR breaches. It is accurate, and it is also the ceiling, not the typical outcome. The ICO's own published fining guidance sets out how it actually gets from a breach to a number, and the methodology matters more than the headline.

A staged assessment, not a single number

The ICO's published approach starts from the seriousness of the infringement — its nature, gravity, duration, and the number of people affected — before considering aggravating and mitigating factors. Aggravating factors include intentional or negligent conduct and a poor history of compliance. Mitigating factors include the degree of cooperation with the regulator, steps taken to reduce harm to affected individuals, and voluntary self-reporting. The same underlying breach can produce very different outcomes depending on how an organisation responds once it becomes aware of the problem — which is a recurring theme across UK regulatory enforcement generally, not unique to data protection.

Why the maximum figure is still the right one to know

Citing the ceiling is not scaremongering; it establishes the scale of exposure that a board is accountable for understanding, even where the realistic outcome for a specific case is likely to be lower. What the methodology adds is the practical point: an organisation's own conduct after a problem is identified — whether it cooperates, self-reports, and can demonstrate genuine remedial steps — has a direct, documented bearing on where within that range a penalty actually lands.

This is general awareness content, not legal advice, and does not cover the specific circumstances of any organisation or sector.

Have a compliance challenge we should be solving?

How the ICO actually calculates the £17.5 million penalty | Workplace Compliance Co