Two-tier data protection enforcement: the public sector is effectively exempt from fines
The ICO's public sector approach, confirmed as permanent in November 2025, substitutes reprimands for fines. In December 2025 the Post Office received a reprimand rather than the £1.09m fine considered, for a breach exposing data of 502 Horizon scandal victims. One 2025 analysis estimated public-sector infringements would have attracted around £23m in fines absent the policy; reprimands went overwhelmingly to public bodies while all fines went to private firms. The Open Rights Group has formally urged revision. The Data (Use and Access) Act 2025 restructures the ICO into an Information Commission and creates no alternative sanction with force. The ICO's rationale, that fines recycle public money away from services, is real, and the result is no effective deterrent for state data misuse.
When the state breaches citizens' data the consequence is a reprimand, and private firms pay millions for equivalent failures. Deterrence disappears exactly where citizens cannot exit, and trust corrodes across an expanding public data estate spanning NHS data, One Login and police biometrics.
A statutory alternative-sanctions regime for public bodies: enforceable remediation orders with named-officer accountability, mandatory board-level reporting and publication, and escalation to fines paid into a redress fund for affected citizens. It fits as a DUAA follow-on or binding Information Commission policy, with DSIT responsible.
// State-led: Instrument: DUAA follow-on legislation or binding Information Commission policy; only Parliament or the regulator can create sanctions with teeth.
State data breaches draw only reprimands while firms pay millions, removing deterrence where citizens cannot exit; the Information Commission transition offers a legislative opening.