惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threatpost
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
P
Privacy & Cybersecurity Law Blog
Cisco Talos Blog
Cisco Talos Blog
Blog — PlanetScale
Blog — PlanetScale
博客园 - 叶小钗
爱范儿
爱范儿
C
CERT Recently Published Vulnerability Notes
Hugging Face - Blog
Hugging Face - Blog
P
Proofpoint News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Know Your Adversary
Know Your Adversary
Latest news
Latest news
T
Tor Project blog
NISL@THU
NISL@THU
The Hacker News
The Hacker News
IT之家
IT之家
Last Week in AI
Last Week in AI
T
Tenable Blog
C
Cybersecurity and Infrastructure Security Agency CISA
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
D
Darknet – Hacking Tools, Hacker News & Cyber Security
V
Visual Studio Blog
Apple Machine Learning Research
Apple Machine Learning Research
T
Threat Research - Cisco Blogs
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 聂微东
T
The Exploit Database - CXSecurity.com
博客园 - 三生石上(FineUI控件)
Spread Privacy
Spread Privacy
S
Secure Thoughts
博客园 - 司徒正美
A
About on SuperTechFans
Attack and Defense Labs
Attack and Defense Labs
Microsoft Security Blog
Microsoft Security Blog
N
News and Events Feed by Topic
O
OpenAI News
V
V2EX
aimingoo的专栏
aimingoo的专栏
L
LangChain Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Security Affairs
MyScale Blog
MyScale Blog
S
Schneier on Security
宝玉的分享
宝玉的分享
Hacker News - Newest:
Hacker News - Newest: "LLM"
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations TikTok Faces Lawsuit Over Tracking Non-Users What’s the Digital Markets Act (DMA) and how will it affect you? | iubenda Simplifying Cookie Consent: The European Commission's Approach | iubenda Google Settles Landmark Privacy Lawsuit for $5 Billion | iubenda Navigate GDPR Compliance with Confidence: Lessons from Recent Fines in Italy Simplifying the Commission's New Reporting Template for Digital Market Gatekeepers | iubenda Understanding the GDPR Complaint Against X (Twitter) for Illegal MicroTargeting | iubenda Spanish Media Giants Take On Meta in a Groundbreaking $600 Million Lawsuit | iubenda DPO Newsletter: Data Protection & Privacy News (issue #126) | iubenda Belgian DPA Mandates Cookie Banner Changes for Major Media Websites | iubenda UK's Top Websites Warned by ICO to Revise Cookie Practices | iubenda Understanding the European Union's Data Act | iubenda Google Announces Consent Mode v2 – here’s what it means for your business and advertising Noyb Challenges EU Commission Over Controversial Ad Campaign | iubenda OECD Updates AI Definition: A Step Forward in Shaping EU’s AI Law Firefox To Introduce Simplified Global Privacy Control Berlin Court Cracks Down on LinkedIn’s Privacy Violations The YouTube Ad Blocker Controversy: A Test of the ePrivacy Directive? | iubenda DPO Newsletter: Data Protection & Privacy News (issue #125) Facebook and Instagram Subscription: Meta adds a paywall | iubenda GDPR Violation: Lack of Transparency in Data Processing via Google Fonts Amazon Introduces AWS European Sovereign Cloud to Address EU Regulations | iubenda Texas New Data Privacy Law TDPSA: Everything you need to know How to Make Money with a Website Without Selling Anything Oregon Consumer Privacy Act: Overview | iubenda Google’s Move to Disable Third-Party Cookies: What Advertisers Need to Know IMY Fines H&M for GDPR Violations: A Closer Look EU Commission Requests Information from X Under Digital Services Act: What You Need to Know | iubenda Understanding California’s “Delete Act” and Data Broker Regulations TCF v 2.2 Initial Layer (Banner) Requirements | iubenda Grindr Faces €5.8 Million Fine: A Reminder on the Importance of GDPR Compliance | iubenda Newly Enacted Iowa Consumer Data Protection Act (ICDPA) | iubenda The Witch’s Brew of Privacy: A Halloween Tale of Compliance and Consequences IAB TCF 2.2 – What you need to do DPO Newsletter: Data Protection & Privacy News (issue #124) Blog Ideas That Make Money: How To Make Money From Your Blog + Examples | iubenda Maximize your Growth with Online Presence Management | iubenda Meta's New Pivot in Europe: To Pay or Not to Pay for an Ad-Free Experience? | iubenda Consumer Reports Launches Free ‘Permission Slip’ App to Protect Your Data | iubenda DAZN’s Access Request Saga Personal Brand Logo: How to Stand Out in a Crowded Marketplace UK-US Data Bridge: A New Era for Secure Data Transfers 7 Ways How to Promote Affiliate Links Effectively (And Boost Commissions) | iubenda Mastering LinkedIn Personal Branding: A Guide to More Opportunities Meta's New Approach: Pay for Your Privacy? | iubenda No Return, No Refund Policy Template & Guide GDPR in the US: a GDPR Checklist for US Companies Crafting a Niche with Branding and Identity Design | iubenda The Online Safety Bill: A Leap Towards a Safer Digital United Kingdom Understanding Google's $93m Settlement over Consumer Location Data Accusations | iubenda CCPA vs CPRA: Key Differences You Need to Know | iubenda How To Use Ecommerce Retargeting to Grow Your Business | iubenda PECR: Everything you need to know | iubenda How Mobile Apps Illegally Share Your Personal Data: A Deep Dive | iubenda Legal Spotlight: Privacy Concerns Surrounding OpenAI’s ChatGPT and Microsoft’s Involvement Legal Scrutiny Looms Over Transatlantic Data Deal: French MEP Takes Action Understanding the Digital Markets Act: A Comprehensive Guide Block AI Crawlers: Here’s How To Stop Your Site From Being Used for AI Training (OpenAI and Google Bard Irish Regulator Slaps $368M Fine on TikTok DPO Newsletter: Data Protection & Privacy News (issue #123) | iubenda The Privacy Pitfalls of Vehicle Data Collection: What You Need to Know | iubenda Twitter customer’s data on the menu for xAI models Update: Revised Swiss Privacy Law Takes Effect Fitbit and the GDPR Hurdle: What You Need to Know About Your Data Privacy | iubenda Terms of Service Template for your site | iubenda Senators Urge FTC to Investigate YouTube and Google for Violating Children's Privacy: What You Need to Google AdSense Requirements: Here's What You Need to Know | iubenda Users can’t opt out from marketing emails: FTC fines Experian $650,000 | iubenda DPO Newsletter: Data Protection & Privacy News (issue #122) | iubenda 7 Ways Business Process Automation Can Increase Your Profits
Understanding the ICO's New Fining Guidance | iubenda
Jessica Ryder · 2024-04-16 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

A new detailed guidance from the UK’s Information Commissioner’s Office (ICO) has been published explaining the steps and criteria they will consider before imposing fines on businesses that violate data protection rules. The ICO’s new fining guidance will offer clear information and transparency on how the ICO will make decisions about penalties and how they are calculated.

Below we highlight the key findings from the guidance 👇

Key points for the ICO’s new fining guidance:

  1. Transparency and Fairness: The guidance aims to shed light on the fining process, particularly the considerations the ICO takes in imposing fines. It provides businesses with transparency and a clearer understanding of what leads to fines and penalties and how they may be able to avoid those fines through compliance.
    • Detailed Criteria: Provides specific criteria used in assessing fines, aiming for predictability in enforcement.
    • Decision-Making Process: Outlines the procedural steps taken from violation detection to the final fining decision, emphasizing the role of fair and impartial review.
    • Right to Respond: Details the opportunities businesses have to respond to allegations before fines are imposed, ensuring a fair hearing.
  2. Fining Criteria: It outlines the exact factors for calculating the fines. With the aim of making organizations fully aware of the financial consequences of noncompliance.
    • Severity and Duration: Takes into account both the severity and the duration of the breach, reflecting the extent of impact on data subjects.
    • Intentional or Negligent Breaches: Differentiates between breaches that are intentional or result from negligence, adjusting fines accordingly.
    • Mitigation Efforts: Considers whether the organization took steps to mitigate the damage, potentially reducing the fine.
  3. Maximum Fines: Confirming the potential severity of penalties, the guidance underscores that fines can escalate to as much as £17.5 million or 4% of an organization’s total worldwide annual turnover, whichever is greater. This aligns with the strict sanctions under the General Data Protection Regulation (GDPR), emphasizing the importance of adherence to data protection laws.
  4. Impact on Small and Medium-Sized Businesses (SMBs): Particularly relevant for SMBs, the guidance details a scaled approach to fines based on a company’s turnover. For businesses with a turnover of less than £2 million, such as micro enterprises, even minor infractions could result in fines up to £3,480. This tiered fining structure aims to balance the enforcement of data protection laws with the financial realities faced by smaller businesses, ensuring penalties are substantial yet fair.

How are the fines determined? 

The ICO now uses five steps to determine penalties:

  1. Evaluating the severity of the violation;
  2. Considering the financial turnover if the entity responsible is part of a larger business;
  3. Setting a preliminary fine based on the violation’s severity and, if applicable, the business’s turnover;
  4. Modifying the initial fine amount to reflect any exacerbating or alleviating factors; and
  5. Ensuring the penalty is substantial, fair, and serves as a deterrent.

The new guideline is a testimony to ICO’s efforts to enforce data protection laws stringently and calls on businesses to place importance on personal data security and privacy. For businesses, especially those under the SMB category, grasping the nuances of the guidelines can help massively when navigating the intricacies of compliance and avoiding fines.

Boost your compliance with the UK GDPR and key privacy regulations worldwide with iubenda’s comprehensive tools.

Start now