ICO Enforcement Lessons You Can’t Ignore

19/09/2025

Running a care home is never simple. Staffing, CQC inspections, family expectations… and somewhere in the mix, the law on personal data. It often slips down the priority list – until it bites back.

The Information Commissioner’s Office (ICO) has recently reminded the sector that data protection isn’t optional. Here are three real cases every care home manager should know about, and the lessons to take away.

1. Ignoring Subject Access Requests – Criminal Offence

In 2025, the ICO prosecuted the director of a Yorkshire care home (Bridlington Lodge) for flat-out refusing to respond to a Subject Access Request (SAR) from a resident’s daughter, who had lasting power of attorney. The home held incident reports, CCTV and care notes, all within the scope of the lawful request.

Instead of complying, the director concealed and withheld information. The result? A fine of £1,100 plus costs of £5,440. More damaging than the money was the reputational hit: a public prosecution and ICO press release.

Every SAR must be taken seriously. You have one calendar month to respond, and “we’re too busy” is not a defence. Staff need to know what a SAR looks like and who to escalate it to.

2. Cybersecurity Failures – Multi-Million Pound Fine

In a high-profile case, the ICO fined Advanced Computer Software Group (an NHS software supplier) £3.07 million after a ransomware attack. The core issue? Basic security was missing including no multi-factor authentication (MFA) on critical accounts and weak technical controls.

Care homes increasingly use electronic care planning and medication systems. If your supplier doesn’t have strong security in place, or if your own staff log in with weak passwords (or passwords on Post Its…) and no MFA, you’re vulnerable. The ICO, patients and their families expect reasonable technical and organisational measures under Article 32 GDPR.

3. Unencrypted Devices – Data Theft

A care home in Northern Ireland was fined £15,000 after an employee took an unencrypted laptop home, which was stolen in a burglary. The device contained sensitive health records of residents and staff.

Portable devices are high-risk. If you allow staff to work remotely, laptops must be encrypted, and sensitive information should not be stored locally at all unless absolutely necessary. Do you have a remote working policy in place?

What This Means for Care Homes

These aren’t abstract examples. They’re real-world cases showing that care homes are firmly on the ICO’s radar. Whether it’s mishandling a SAR, neglecting security basics, or failing to protect devices, the consequences are fines, prosecutions, and public reputational damage.

And remember: under CQC’s Well-Led and Safe key lines of enquiry, inspectors are looking closely at confidentiality, records management and information governance. Poor data protection practices will impact your ratings.

How I Can Help

At JH Data Protection Ltd, I work with independent care homes to make compliance practical, not painful. That includes:

  • SAR processes that actually work in real life
  • UK GDPR/DSPT audits and action plans
  • Staff training (short, scenario-based sessions)
  • Policy updates (privacy, retention, CCTV, breach response)
  • Support with DPIAs for electronic care records, visitor systems, and more

I offer a free 30-minute mini-audit for care homes. You’ll walk away with clear, actionable steps to reduce risk and confidence that if the ICO or CQC come knocking, you’re ready.


Next Step

Get in touch at dpo@jhdataprotection.com. Don’t wait for a complaint, breach or ICO letter to make data protection your priority.

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…