Can't pay Information Commissioner's fine? No problem! Just liquidate your firm

UK data protection watchdog has a 54% cash recovery rate

The UK's data protection watchdog has recovered only about half the value of fines doled out to dodgy data controllers, and those handed to spam marketing firms are the most likely to remain unpaid.

According to figures released under the Freedom of Information Act, the Information Commissioner's Office has fined companies breaking data protection and marketing laws some £17.8m since 2010 – but just £9.7m has made its way into government coffers, a 54 per cent recovery rate.

The ICO can issue fines to organisations that it finds to be in breach of either the UK's Data Protection Act (DPA) or the Privacy and Electronic Communications Regulations (PECR), which governs marketing emails and calls.

The money is paid into the Treasury's Consolidated Fund (it does not feather the ICO's nest).

Broadly speaking, firms making millions of automated nuisance calls are mostly found to be in breach of PECR, while authorities that lose DVDs full of confidential information, or firms that leave themselves open to hacks, will get slapped with fines under the DPA.

Fines under the DPA tend to be higher than for PECR – the respective modes are £70,000 and £50,000, the median values £85,000 and £75,000.

Just 99.5 million nuisance calls... and KeurBOOM! A £400K megafine


But the highest fine given out under both is £400,000. The body can dish out a maximum penalty of £500,000, although this will increase to 4 per cent of global turnover or €20m under the General Data Protection Regulation (GDPR).

However, the results of the FOI throw the deterrent effect of these larger fines into question.

The requests – submitted by The Register and reader Robert Rijkhoff, who has a long-running campaign against junk mail – asked the ICO how many of the data controllers issued with fines between 2010 and April 2018 have paid up, in full or in part. It was based on the publicly available list of civil monetary penalties on the ICO's website (downloads CSV).

It revealed that some 43 of the 174 data controllers fined during that period have paid back half or less of their fines, and 38 of these have paid back nothing.

Just 14 paid back the full amount, with a further 115 taking advantage of the ICO's early-bird payment discount, where they get 20 per cent off for paying within 28 days. One controller has paid 81 per cent; another, 83.3 per cent.

Most of the unpaid fines were issued for breaches of PECR. Of the 84 fines issued under these rules, which had a total value of £8.5m, about half have not paid more than 80 per cent of the headline fine.

Of the bakers' dozen of companies handed a fine of £200,000 or more under these rules, just one has paid a substantial amount, Newday Ltd, which paid 80 per cent of its £230,000 fine this year.

In contrast, of the 90 DPA fines issued, which came to a total of £9.3m, all but three have been paid, and most of those that hand over the cash doing so within 28 days of being handed the fine.

Big fine? Businesses go Keurboom!

The ICO emphasised that there are a number of reasons for controllers not paying the full fines – an appeal can delay, negate or drop the cost. Christopher Niebel successfully appealed a £300,000 fine in October 2013. Moreover, some organisations choose to pay back in instalments, meaning the exact figures can change regularly.

But the figures clearly show a low recovery rate that goes beyond this, at the heart of which is a problem that has plagued the ICO for years. When faced with a big-bucks fine, some companies will simply choose to go into liquidation to avoid paying out.

This is particularly true of the nuisance call companies that tend to be fined under PECR. Keurboom Communications, which was fined £400,000 in 2017 for making 99.5 million nuisance calls, was in liquidation by the time the fine was announced.

Similarly, after Your Money Rights was fined £350,000 in 2017, the directors immediately sought to dissolve the firm and the fine remains unpaid, while ProDial Ltd was already seeking liquidation when the ICO formally handed down a £350,000 fine in 2016.

And Media Tactics appointed a liquidator in October last year after receiving a £270,000 fine six months earlier. Check Point Claims, which was fined £250,000 in 2016, was dissolved last year.

Neil Brown, tech lawyer at decoded:Legal, said that it was "no particular surprise that the recovery rate is low", especially given the commissioner's public acknowledgment that directors often liquidate their firm and restart under a new name.

ICO calls for director liability

In a bid to tackle this, the ICO has repeatedly asked for powers to hold directors of companies directly liable – something that the government promised the office back in 2016, but is yet to transpire.

"We welcomed the announcement by government in 2016 of a planned change in law to make directors themselves responsible for nuisance marketing," Elizabeth Denham said in a statement sent to The Register about the figures.

"It should have a real deterrent effect on those who deliberately set out to disrupt people with troublesome calls, texts and emails. We hope the law change will come to fruition soon to increase the tools we have to protect the public from this modern menace."

We asked the Department for Digital, Culture, Media and Sport if the plans were still on the table, but it did not give a direct answer, instead saying it was "committed to working with regulators to make sure firm directors are held to account if they breach the rules and will be announcing further detail shortly".

In its FOI response to The Register, the ICO noted that it "will usually attempt to recover assets", including by working with other regulators or the government to take enforcement action against directors.

This includes banning them from acting as a director of another company – an option used this year in the cases of Leah Kimberley Masters, director of Cold Call Elimination (fined £75,000 in 2015), and Tony Ray Abbott, director of Reactive Media Ltd, which was fined £50,000 in 2014.

However, the fact the data controllers still escape without paying the fine arguably undermines the ICO's powers to hand out fines – something that has been made more of in light of the increased fines it can wield under the GDPR.

"Although fines are just one of the mechanisms available to the ICO to encourage compliance with the data protection framework, if they can be dodged easily, they lose their deterrent value," Brown said.

"You can understand why the ICO has been pushing for directors to be personally liable." ®

Send us news

UK data watchdog wants six figures from N Ireland cops after 2023 data leak

Massive discount applied to save cop shop’s helicopter budget

UK and Canada's data chiefs join forces to investigate 23andMe mega-breach

Three-pronged approach aims to uncover any malpractice at the Silicon Valley biotech biz

UK's Total Fitness exposed nearly 500K images of members, staff through unprotected database

Health club chain headed for the spa on choose-a-password day

Blackbaud has to cough up a few million dollars more over 2020 ransomware attack

Four years on and it's still paying for what California attorney general calls 'unacceptable' practice

Student's flimsy bin bags blamed for latest NHS data breach

Confidential patient information found by member of the public

Snowflake denies miscreants melted its security to steal data from top customers

Infosec house claims Ticketmaster, Santander hit via cloud storage

SpiderOak One customers threaten to jump ship following datacenter upgrade

One tricky cluster is causing outrage among longstanding customers

NHS Digital hints at exploit sightings of Arcserve UDP vulnerabilities

When PoC code is released within a day of disclosure, it's only a matter of time before attacks kick off

UK public voice fear over security in NHS data systems

NHS England's own survey also reveals suspicions that it would sell data to third parties

Over a million Neighbourhood Watch members exposed through web app bug

Unverified users could scoop up data on high-value individuals without any form of verification process

Lawsuit accuses Grindr of illegally sharing users' HIV status

LGBTQ+ dating app's maker previously denied selling sensitive user data

White House tweaks HIPAA to shield medical files of those seeking reproductive care

In theory, this should make it harder for states to compel data-sharing to enforce anti-abortion laws