The ICO exists to empower you through information.

Standard maximum amount

UK GDPR provision 103 Part 3 DPA: Law Enforcement processing 104 Part 4 DPA: Intelligence Services processing 105
Obligations of controller and processor Articles 8, 11, 25-39, 42 Sections 64-65 and Sections 67-68 Section 108
Obligations of the certification body Articles 42 and 43 N/A N/A
Obligations of the monitoring body Article 41(4) N/A N/A

Higher maximum amount

UK GDPR provision 106 Part 3 DPA: Law Enforcement processing 107 Part 4 DPA: Intelligence Services processing 108
The basic principles for processing, including conditions for consent Articles 5,6,7 and 9 Sections 35-37, Section 38(1), Section 39(1), Section 40 Sections 86-91
Data subject rights Articles 12-22 Sections 44-49 and Sections 52-53 Sections 93-94 and Section 100
Transfers of personal data to a recipient in a third country or an international organisation Articles 44-49 Section 73 and Sections 75-78 Section 109
Non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the Commissioner Article 58(2)(f) and Article 58(2)(j) Section 157(4) Section 157(4)
Failure to comply with an information notice, assessment notice or enforcement notice Article 58(5)(e) and Article 58(6) 109 Section 157(4) Section 157(4)


103 Art 83(4)

104 s157(2)

105 s157(3)

106 Art 83(5)

107 s157(2)

108 s157(3)

109 See also section 157(4) DPA 2018.