ICO reports a voluntary settlement and agreement to pay without appeal.
What happened
On 11 May 2026, the ICO announced a £963,900 fine against South Staffordshire Plc and South Staffordshire Water Plc. The regulator reported that information about 633,887 people had been extracted and published following a cyber attack. A voluntary settlement included an admission of the infringement and an agreement not to appeal. The published amount reflected a 40% reduction.
Source: ICO — original source ↗
What it means for your website
Website owners should not read this as a cookie-banner case. It is about protecting information and responding to access risks. Think about the accounts that can reach your website, hosting, backups and customer database. An old contractor account may be less visible than your public homepage but more consequential. Ask your technical provider how unusual access is detected and who receives alerts. A report that only tests the public website cannot prove those internal controls are working. Keep security reviews and consent testing as connected but distinct pieces of work.
Three useful next steps
- Review dormant and contractor accounts.
- Check who receives security alerts.
- Test the incident escalation route before an emergency.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.