Twelve Million Pounds. Zero Successful Appeals.
The ICO just locked in a fine of £12.7 million against TikTok. The company tried to fight it in court, but the preliminary appeal failed.
For most small business owners, that figure is an abstraction. You aren't fighting multi-million pound battles in high court. But you should care about the result. It proves that regulators are no longer satisfied with a "reasonable effort" defense if the actual outcome for the user (in this case, children's privacy) is broken.
Most firms without a compliance budget rely on what I call the Paper Shield. You pay a consultant a few hundred quid for a GDPR template, you slap your company name on it, and you file it in a folder that nobody ever opens. You've "implemented a policy."
I hate advice that tells you to "simply implement" a framework. Implementation isn't a checkbox; it's a habit. A policy is just a statement of intent. If your policy says you don't collect data from minors, but your sign-up flow doesn't actually check ages, the policy is worthless.
Paper doesn't stop fines.
The argument usually goes like this: "I'm too small for the ICO to notice, and I can't afford a full-time auditor."
That's true. You can't. But you also don't need one. The cheapest control is a manual spot check. Once a month, pick one process (like how you handle new customer emails) and actually follow the data. See where it goes. Check if it's sitting in an unencrypted spreadsheet on a laptop that stays in a car overnight. If the reality differs from your Paper Shield, fix the reality. It costs nothing but two hours of your time.
If you keep the policy and ignore the process, you aren't complying; you're just documenting your own negligence for the regulator to find later.
There is a second-order effect here that hits harder than a fine: insurance. Professional indemnity and cyber insurers are watching these ICO wins closely. When regulators successfully argue that "weak policies" aren't a defense, insurers stop paying out for "accidental" breaches. They start classifying them as systemic failures. You might find your premiums spiking or your coverage vanishing because you have the paperwork but no proof of testing.
The risk isn't just the regulator; it's the gap between what you told your insurer you do and what you actually do.
You can either spend a few hours a month verifying your own data flows, or you can spend years paying lawyers to argue that your template was "industry standard." I know which one fits a tight budget better.
One thing to check this week: Find the person in your office who handles the most customer data and ask them to show you exactly where they save it. Don't look at the policy; look at the folder.