UK's information regulator fines Carphone Warehouse £400K over preventable 2015 breach that exposed 3M+ customer details
Context & Ripple Effects
The ICO's £400K penalty closes a two-and-a-half-year arc that began when the [[a:831705|2015 hack exposed personal data of 2.4M customers alongside 90K encrypted credit card records]] — a figure the regulator now puts above 3M, with the breach judged preventable. The fine lands just months before GDPR replaces the UK's old regime, under which penalties were capped at £500K.
The timing matters: this penalty sits at the top of the pre-GDPR scale, alongside the maximum £500K Equifax fine for its 2017 breach affecting ~15M Britons and the maximum £500K Facebook fine over Cambridge Analytica later that year.
First-order effects
- Carphone Warehouse pays £400K for a breach the ICO deems preventable, with the final exposure tally revised up from the initially reported 2.4M customers to 3M+.
- The ICO signals it will pursue retailers, not just tech platforms, as the Equifax and Facebook cases show it doing across sectors in the same window.
Second-order effects
- Retailers holding payment-adjacent customer data face the same enforcement template — inadequate security plus a large UK customer base draws a near-maximum fine regardless of industry.
- The £500K statutory cap becomes visibly out of step with breach scale, setting up the post-GDPR regime where the ICO initially assessed British Airways at ~£184M before settling at £20M.
Third-order effects
- If the pattern holds, UK data protection shifts from symbolic half-million-pound penalties to turnover-linked fines, making breach-prevention spend a board-level cost of holding UK customer data rather than an IT line item.
The trend: UK data protection enforcement is transitioning from the capped £500K-penalty era into GDPR-scale fines, with the ICO applying consistent maximum-level penalties across retail, credit reporting, and social platforms in the interim.