The draft Bill proposes strengthened enforcement with maximum penalties of £17 million or 4% of worldwide turnover, whichever is higher.
Compare It With The Incidents In This Database
JLR booked £196 million against a single quarter at 25-0902, in an incident whose wider economic cost has been estimated at £1.9 billion. M&S reported a nine-figure impact at 25-0430. Coinbase estimated $180–400 million at 25-0530.
The fixed ceiling is an order of magnitude below what a serious incident costs the affected organisation directly. For a large company, the regulator is not the most expensive consequence of a failure — the failure is.
Which Means The Fine Is Not The Deterrent
That sounds like criticism and mostly is not. Where an incident is already ruinous, a penalty adds little marginal deterrence, and the turnover-based alternative exists precisely to bite where the fixed sum would not.
The place a penalty regime does real work is on organisations whose own losses would be survivable — the ones holding other people’s data while bearing little of the consequence. Marquis at 25-0814, Chain IQ at 25-0613, the servicing platform at 25-0701. For those, the regulator may genuinely be the largest consequence available.
And A Maximum Is Not A Distribution
Headline ceilings are quoted constantly and imposed rarely. What determines behaviour is the penalty an organisation expects, which is the ceiling multiplied by the probability of enforcement and discounted by everything a regulator weighs.
This corpus has no data on that for a regime not yet in force, and the accountability files at 26-0419 and 26-0223 record how little consequence has historically attached. The ceiling is the least informative number in the Bill.
Built on published legal analysis of the draft Bill, listed below. Comparisons with incident costs are our arithmetic on separately reported figures. Corrections: corrections@forensicpost.com.