- GDPR
- 8th Sep 2026
- 1 min read
UK GDPR Fines in 2026: Enforcement Trends and Penalties
- Written by
In Short..
TLDR: 4 Key Takeaways
- Enforcement has real financial teeth: Reddit’s £14.47 million fine and MediaLab’s £247,590 penalty show the ICO acting on age assurance and DPIA failures.
- PECR fines jumped 35-fold: the flat cap rose from £500,000 to £17.5 million under the DUAA, live since 5 February 2026, and climbs further still for larger organisations where 4% of global turnover exceeds that ceiling.
- Three priorities drive 2026 enforcement: AI and biometrics, the Children’s Code, and new procedural powers modelled on the FCA’s investigative approach.
- Complaint handling rules are already live: since 19 June 2026, organisations must provide a formal complaints mechanism and acknowledge every complaint within 30 days.
- Self-declaration has a defined limit: Ofcom and the ICO jointly confirmed in March 2026 that proportionate age assurance requires genuine verification methods, and MediaLab's fine is what that position costs in practice.
The ICO fined Reddit £14.47 million for unlawfully processing children’s personal data, part of a coordinated Children’s Code enforcement programme. That penalty is a signal: ICO enforcement has become deliberate, coordinated, and expensive, pairing guidance with targeted fines, binding commitments, and new powers under the Data (Use and Access) Act 2025 (DUAA). For compliance teams, the operative question now is whether you’re already in scope.
This article breaks down the enforcement cases that defined 2026, the three strategic priorities driving ICO action, what changed under the DUAA, and the practical lessons your team needs to act on now. PECR fine caps alone rose from £500,000 to £17.5 million or 4% of global annual turnover, reframing the risk calculus for every UK organisation running electronic marketing or tracking technologies.
Expert View
Matt Davies Chief Product Officer, SureCloud |
What our experts say about proving safeguards match actual practice
"Both the Reddit and MediaLab notices cite the same gap: a DPIA written once at launch and left untouched as the product changed underneath it. We see it constantly. The ICO is testing whether your risk assessment reflects what the product actually does today." |
The Enforcement Cases That Defined 2026
Children’s data and security failures dominate the headline enforcement numbers from 2026.
Reddit: £14.47 million for children’s data violations
As the largest penalty the ICO issued in 2026, the case sits within a coordinated enforcement programme targeting social media platforms (SMPs) and video sharing platforms (VSPs). The Children’s Code strategy, launched in April 2024, had affected close to five million child users across multiple platforms by July 2026.
Reddit had no lawful basis for processing under-13s’ personal data. It hadn’t implemented effective age assurance or secured parental consent, and it hadn’t carried out a data protection impact assessment for that processing until 1 January 2025, a separate breach of Article 35 UK GDPR.
MediaLab (Imgur): £247,590 for age assurance failures
MediaLab, owner of the image-hosting platform Imgur, was fined £247,590 for unlawfully processing children’s data between September 2021 and September 2025. The ICO found that Imgur’s terms of service allowed under-13s to use the platform with parental supervision, but the company had no age assurance measures to verify that claim, no completed DPIA, and no controls stopping children under 13 from reaching potentially harmful content.
The fine is modest against Reddit’s, but the ICO’s language alongside it carries more weight than the number. The regulator called this decision part of a wider intervention. MediaLab’s case sends the same signal to every platform relying on self-declaration or terms-of-service disclaimers as a substitute for genuine age assurance.
The pattern across both cases
Both cases turn on whether an organisation’s technical and organisational measures actually match its public assurances, and both fines landed because the gap between the two was easy for an investigator to find.
The ICO’s Three Enforcement Priorities for 2026
The ICO’s 2026 work programme runs on three interconnected workstreams, and each carries direct enforcement consequences for compliance teams.
1. AI and biometrics
The ICO’s AI and biometrics strategy update, published 17 March 2026, sets out the ICO’s expectations for automated decision-making (ADM) as Section 80 of the Data (Use and Access) Act 2025 takes effect. That section inserted Articles 22A to 22D into the UK GDPR on 5 February 2026, restructuring the ADM rules.
The ICO’s position is direct. Show how each decision was made, and prove the safeguards are proportionate to the risk, because there's no grace period for getting the documentation in order after the fact.
That translates into four requirements:
- ADM processes that affect individuals require documented safeguards
- Biometric data processing faces heightened scrutiny
- The ICO expects controllers to evidence their decision-making logic with documented records
- SI 2026/425, in force since 12 May 2026, places the Commissioner under a statutory duty to prepare a code of practice on AI development and automated decision-making
The draft guidance on ADM and profiling has closed for consultation, with final guidance due summer 2026. Organisations that haven’t mapped their ADM processes against Articles 22A to 22D are already behind.
2. Children’s Code
The Children’s Code, formally the Age-Appropriate Design Code under Section 123 of the Data Protection Act 2018, has applied since 2 September 2021. Its 15 standards cover any information society service likely to be accessed by children under 18, deliberately broader than services aimed at children specifically.
The ICO’s strategy has moved through social media and video sharing platforms and is now expanding into mobile gaming. A monitoring programme covering 10 popular mobile games is underway, assessing default privacy settings, geolocation controls, and targeted advertising practices.
In March 2026, Ofcom and the ICO published a joint statement on age assurance, confirming that "self-declaration alone is not an effective means to determine the age or age range of users and prevent access by underage users." For services enforcing a minimum age of 13, the regulators point to methods including facial age estimation, digital ID, and one-time photo matching, provided they guard against fake input and bind the proof of age to the user presenting for the check.
For organisations in scope, the minimum expectation now is proportionate age assurance, a completed DPIA, and design decisions that put children’s best interests first. The ICO has also written directly to six high-risk services, including TikTok, Snapchat, Facebook, Instagram, YouTube, and X, asking them to demonstrate how their age assurance measures meet these expectations.
3. Enforcement procedural guidance
The ICO consulted on draft enforcement procedural guidance between 31 October 2025 and 23 January 2026. Once finalised, this guidance replaces the 2018 Regulatory Action Policy and governs how the ICO uses its expanded powers under the DUAA: interview notices that give the ICO new investigative reach, approved-person reports broadly comparable to the FCA’s Section 166 skilled-person regime, and the recalibrated PECR fine caps at £17.5 million or 4% of global annual turnover.
The FCA comparison is deliberate. The ICO is signalling that it intends to operate with the same investigative rigour and accountability expectations as a financial regulator, and organisations used to its historically restrained approach to fines would be wrong to assume that continues.
What Changed Under the Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 (DUAA) marks the most significant change to the UK’s data protection framework since the UK GDPR itself. Its Part 5 provisions took effect on 5 February 2026. Compliance teams need the specifics behind that date.
Key amendments to UK GDPR
- Recognised legitimate interests: A new lawful basis covering processing purposes more likely to qualify as legitimate interest, including national security, crime detection, safeguarding vulnerable people, and defined public interest processing. This reduces friction for that processing; the balancing test still applies.
- Automated decision-making: Articles 22A to 22D replace the previous Article 22. The new provisions narrow the prohibition to apply specifically where special category data is involved, while adding new safeguards and documentation requirements.
- Cookie exemptions: New exemptions apply to statistical, appearance, and emergency-assistance cookies, reducing the consent burden for genuinely low-risk analytics. Advertising cookies and profiling stay outside the exemption.
- Soft opt-in extension: Charities can now use the soft opt-in for electronic marketing, a route previously limited to commercial organisations.
The PECR fine cap: a step change in risk
The PECR fine cap uplift carries the most immediate commercial impact of any DUAA change, and it’s already live. The previous PECR maximum was £500,000. Since 5 February 2026, that ceiling is the higher of £17.5 million or 4% of global annual turnover.
An organisation with £500 million in global revenue now faces a theoretical maximum PECR fine of £20 million, since 4% of turnover overtakes the flat £17.5 million ceiling at that scale, against a previous cap of £500,000 for the same breach. That’s a 40-fold increase in exposure for a single direct marketing or cookie violation.
The ICO has historically used PECR enforcement against nuisance calls and spam texts. The new cap extends that same enforcement logic to any organisation running tracking technologies, digital advertising, or electronic marketing at scale.
Complaint handling obligations
Since 19 June 2026, organisations have been required to give individuals a formal mechanism for raising data protection complaints, acknowledge receipt within 30 days, and investigate without undue delay.
Organisations without a structured complaint intake and tracking process are exposed to both regulatory and reputational risk under this rule. The ICO has indicated further guidance on complaint handling will follow.
Five Lessons Compliance Teams Should Act On Now
The 2026 enforcement picture points to specific, closeable gaps. Here’s what the cases and regulatory changes tell you to fix.
1. Stop treating terms of service as age assurance
The MediaLab case settled the ambiguity. Stating in your terms that under-13s need parental supervision doesn’t count as age assurance. The ICO expects proportionate technical measures: documented age verification or estimation methods, a DPIA, and design decisions that default to the most protective settings for any service children are likely to access.
Self-declaration and checkbox consent haven’t counted as proportionate since the Children’s Code came into force in 2021. The 2026 enforcement action just made the consequences concrete.
2. Treat your DPIA programme as a live control
Both the Reddit and MediaLab cases involved failures that a properly conducted DPIA should have caught. The ICO’s expectation is a DPIA that reflects your current processing activities and gets reviewed every time those activities change.
Practical action: audit your DPIA register against your current data flows. Identify processing activities that have changed since the last review, and prioritise high-risk areas: children’s data, biometrics, automated decision-making, and any third-party integrations added in the past 12 months.
3. Document your AI decision-making before the ICO asks
Articles 22A to 22D are in force, and the ICO’s final ADM guidance is due. For every organisation using AI to influence decisions about individuals, the test is whether your documentation can withstand scrutiny.
The ICO applies the same test across all three 2026 priorities: can you show how each decision was made, and are the safeguards proportionate to the risk? That test applies to AI-driven credit decisions, automated screening tools, marketing profiling, and any other process where personal data feeds a system that affects real people.
4. Reassess your PECR exposure under the new fine caps
If your organisation runs cookie-based advertising, deploys tracking pixels across your site, or sends electronic marketing at scale, the PECR uplift has already grown your maximum regulatory exposure materially, whether or not anyone has run the numbers yet.
Start the review here:
- Cookie consent mechanisms and whether they meet the current ICO standard
- Email and SMS marketing consent records and how you maintain them
- Third-party tracking technologies embedded in your digital estate
- Whether your legitimate interests assessments reflect the new DUAA provisions
5. Close the gap on complaint handling infrastructure
The formal complaint handling obligations took effect on 19 June 2026. Organisations without a structured intake, acknowledgement, and investigation process are already out of step with the requirement, facing both regulatory risk and the practical problem of managing complaints reactively as volume grows.
A complaint handling process doubles as a risk intelligence tool. Patterns in complaints surface the processing activities individuals find opaque or unfair, exactly what the ICO looks for when it assesses accountability.
A complaint log that nobody's read in six months tells the ICO the same thing an unreviewed DPIA does: nobody's actually watching this process day to day, whatever the policy document says on paper.
What Good UK GDPR Compliance Looks Like in 2026
Across security, children’s privacy, AI decision-making, and direct marketing alike, the ICO’s enforcement approach tests whether your stated commitments on data protection match your actual practice.
Organisations that pass that test share the same characteristics. They maintain live records of their processing activities, review DPIAs when things change, and can produce evidence of their decision-making on demand.
The accountability standard
UK GDPR's accountability principle demands proof, in a form the ICO can inspect, not just a policy document asserting that compliance work happens. Here's what that looks like in practice:
- Records of processing activities (RoPA) that reflect current reality and get updated as processing changes
- DPIAs reviewed on a defined cycle and triggered by material changes to processing
- Consent records that are maintained, auditable, and granular enough to evidence individual choices
- AI documentation that maps ADM processes, the data inputs, the logic applied, and the human oversight in place
- Incident response with a documented, tested procedure for notifying the ICO within 72 hours of a qualifying breach
The role of continuous monitoring
One of the biggest gaps in most data protection programmes is missing continuous monitoring. Compliance status gets assessed at a single point in time, while processing activities keep changing continuously. Enforcement risk lives in that gap.
Continuous monitoring of controls, automated evidence collection, and integrated privacy management have become the operational baseline for organisations that want to demonstrate accountability under the ICO’s current expectations. Inside SureCloud’s Data Privacy Management module, a dedicated Compliance Persona from Gracie AI Agents with Personas and Skills checks your DPIA register against live processing activity and flags the specific assessments that have gone stale, rather than leaving that discovery for whoever runs the next audit.
Reddit’s fine alone runs to £14.47 million, PECR exposure has moved from hundreds of thousands into the tens of millions, and the regulator now carries FCA-equivalent investigative powers, including interview notices it didn’t have before 2026. Weigh that against the cost of a DPIA programme that actually gets reviewed.
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
Turn Your DPIA Register Into Live Evidence
FAQ’s
What is the maximum fine for a UK GDPR breach in 2026?
The maximum fine under UK GDPR is the higher of £17.5 million or 4% of global annual turnover. This applies to the most serious violations: unlawful processing of special category data, failures to implement appropriate technical and organisational measures, and breaches of the fundamental principles of data protection. PECR fines were uplifted to the same ceiling under the Data (Use and Access) Act 2025, live since 5 February 2026, a major change from the previous £500,000 cap.
What is the ICO’s enforcement focus in 2026?
The ICO has three stated enforcement priorities for 2026: AI and biometrics, the Children’s Code, and enforcement procedural guidance. On AI and biometrics, organisations using automated decision-making need to evidence how decisions are made and show their safeguards are proportionate to risk. On the Children’s Code, the ICO is enforcing the Age-Appropriate Design Code across social media, video sharing platforms, and increasingly mobile gaming, while its procedural guidance work finalises the framework governing its expanded powers under the DUAA, including FCA-equivalent investigative rigour such as interview notices and approved-person reports.
What did the ICO fine Reddit for in 2026?
The ICO fined Reddit £14.47 million for unlawfully processing children’s personal data on its platform, as part of its coordinated Children’s Code enforcement strategy. Reddit had no lawful basis for processing under-13s’ data: it hadn’t implemented effective age assurance or secured parental consent, and it hadn’t carried out a DPIA for that processing until 1 January 2025. Both failures breach the UK GDPR directly, the first under Articles 5(1)(a), 6, and 8, the second under Article 35.
What is the Children’s Code and who does it apply to?
The Children’s Code, formally the Age-Appropriate Design Code, is a statutory code under Section 123 of the Data Protection Act 2018. It applies to any information society service likely to be accessed by children under 18, deliberately broader than services aimed at children specifically. Its 15 standards cover default privacy settings, data minimisation, geolocation controls, profiling, and targeted advertising. The ICO’s enforcement programme began with social media and video sharing platforms and has expanded to mobile gaming in 2026; organisations relying on terms-of-service disclaimers instead of genuine age assurance face direct enforcement risk.
What changed under the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025 introduced several changes to the UK data protection framework, most taking effect on 5 February 2026: a new recognised legitimate interests lawful basis, Articles 22A to 22D replacing the previous automated decision-making rules, narrower cookie consent requirements for low-risk analytics, a PECR fine cap raised to £17.5 million or 4% of global turnover, and a soft opt-in extension letting charities use it for electronic marketing. A separate complaint handling obligation, requiring organisations to acknowledge complaints within 30 days, took effect on 19 June 2026.
What counts as “proportionate” age assurance under the ICO’s 2026 guidance?
Self-declaration and a checkbox no longer meet the bar. Ofcom and the ICO's March 2026 joint statement points to methods including facial age estimation, digital ID, and one-time photo matching for services enforcing a minimum age of 13, provided the method guards against fake input and binds the proof of age to the person actually presenting for the check. Terms-of-service disclaimers relying on parental supervision, the approach MediaLab used, don't meet that standard either.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
Esavian House 181A High Holborn, London, WC1V 7QX, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.