Investigations

Inside the regulator's new approach to fines

The regulator has been overhauling how it decides fines, including offering discounts for settling early. Here is what the new approach means, and why cooperating quickly is now worth real money.

TheDutyDesk Editorial12 February 20263 min readReviewed 7 June 2026

Most businesses never think about how a data protection fine is actually calculated, right up until the day it might apply to them. It is worth a few minutes now, because the regulator has been reworking its approach to enforcement, and one change in particular rewards doing the right thing quickly.

What is changing

The regulator consulted in late 2025 on new guidance for how it investigates and fines.[5] The headline change is a formal settlement route: an organisation that accepts the findings and resolves matters early can receive a discount on the fine.[5]

This did not exist in a clear form before. Now there is an explicit incentive to cooperate, hold your hands up where you got something wrong, and settle rather than fight every point. The faster, more constructive path can cost you less.

Recent cases show the other side of the coin. In late 2025 and early 2026 the regulator issued substantial fines, including penalties of millions of pounds for serious data breaches and for failures around children's data.[9] The willingness to impose large fines is real. The new settlement route is the off-ramp for organisations that respond well.

Why this matters even if you are small

You may assume large fines are only for large companies. The structure still matters to you for one reason: how you behave when something goes wrong now affects the cost.

An organisation that detects a problem, reports it promptly, fixes it and engages openly is in a far better position than one that hides, delays or argues. The new approach puts a price on that difference.

What this means for you

The lesson is about behaviour, not just rules.

If you ever have a data breach or a serious complaint, the instinct to go quiet is the wrong one. Acting quickly, being honest with the regulator, and showing what you have done to fix things is now not only the right thing to do but the cheaper path.[5]

Keeping good records helps here too. The organisation that can show, in writing, what happened and how it responded is the one best placed to settle well.

Sources used in this article

  • [5]ICO enforcement consultation, October 2025
  • [9]ICO enforcement action register

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 12 August 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.