header-logo header-logo

08 November 2018
Issue: 7816 / Categories: Legal News , Data protection
printer mail-detail

Data fines on the rise

The average value of fines issued for data breaches has doubled in the past year to September 2018, from £73,000 to £146,000, adding to fears of large companies post-GDPR.

The total value of penalties imposed by the Information Commissioner’s Office (ICO) rose 24% on the previous year to £4.98m. Businesses expect the introduction of the GDPR (General Data Protection Regulations), which came into effect on 25 May, to lead to higher penalties—fines of up to €20m or 4% of the organisation’s turnover can be imposed under the GDPR, compared to a maximum of £500,000 under previous legislation.

The UK’s first GDPR penalty notice was issued against AggregateIQ in September after it accessed the data of up to 87 million Facebook users. However, the ICO has said it will not be making early examples of businesses for minor infringements by issuing large fines.

Richard Breavington, partner at RPC, said: ‘A doubling in the average size of a fine should serve as a wake-up call to businesses.

‘Given that there seems to be no slowdown in the number of cyber-attacks today—businesses need to see how they can mitigate the risks to their customer when there is an attack. For example, businesses should ensure that they take out cyber insurance policies so that they can bring in experts to contain the impact of an attack and limit the exfiltration of data.’

Issue: 7816 / Categories: Legal News , Data protection
printer mail-details

MOVERS & SHAKERS

Foot Anstey—Jasmine Olomolaiye

Foot Anstey—Jasmine Olomolaiye

Investigations and corporate crime expert joins as partner

Fieldfisher—Mark Shaw

Fieldfisher—Mark Shaw

Veteran funds specialist joins investment funds team

Taylor Wessing—Stephen Whitfield

Taylor Wessing—Stephen Whitfield

Firm enhances competition practice with London partner hire

NEWS
The Supreme Court has delivered a decisive ruling on termination under the JCT Design & Build form. Writing in NLJ this week, Andrew Singer KC and Jonathan Ward, of Kings Chambers, analyse Providence Building Services v Hexagon Housing Association [2026] UKSC 1, which restores the first-instance decision and curbs contractors’ termination rights for repeated late payment
Secondments, disciplinary procedures and appeal chaos all feature in a quartet of recent rulings. Writing in NLJ this week, Ian Smith, barrister and emeritus professor of employment law at UEA, examines how established principles are being tested in modern disputes
The AI revolution is no longer a distant murmur—it’s at the client’s desk. Writing in NLJ this week, Peter Ambrose, CEO of The Partnership and Legalito, warns that the ‘AI chickens’ have ‘come home to roost’, transforming not just legal practice but the lawyer–client relationship itself
A High Court ruling involving the Longleat estate has exposed the fault line between modern family building and historic trust drafting. Writing in NLJ this week, Charlotte Coyle, director and family law expert at Freeths, examines Cator v Thynn [2026] EWHC 209 (Ch), where trustees sought approval to modernise trusts that retain pre-1970 definitions of ‘child’, ‘grandchild’ and ‘issue’
Fresh proposals to criminalise ‘nudification’ apps, prioritise cyberflashing and non-consensual intimate images, and even ban under-16s from social media have reignited debate over whether the Online Safety Act 2023 (OSA 2023) is fit for purpose. Writing in NLJ this week, Alexander Brown, head of technology, media and telecommunications, and Alexandra Webster, managing associate, Simmons & Simmons, caution against reactive law-making that could undermine the Act’s ‘risk-based and outcomes-focused’ design
back-to-top-scroll