Company Brochure

Five Regulatory Actions, No Fines: What Gets You a Reprimand on the Isle of Man

A senior professional reading printed reports at a desk, colleagues working behind

Strengthen your compliance strategy

— with confidence. clarity. experts.

Book a
consultation

The Isle of Man Information Commissioner took five regulatory actions in the year covered by the Annual Report 2025/26, published on 8 July 2026. Four were reprimands; the fifth was a warning to a public sector organisation. No fine appears anywhere in the report. A reprimand is issued under Article 58(2)(b) of the Applied GDPR, and the Commissioner's own description places it deliberately low: it is issued "when the Information Commissioner believes there has been an infringement of the Applied GDPR, but the infringement is not serious enough to warrant a fine or enforcement notice". Low does not mean quiet. It names you, it is published, and "there is no appeal against the issue of a reprimand to the Data Protection Tribunal". The useful question for a controller here is not which rung a reprimand occupies but what has been putting organisations on it.

The ladder, in plain terms

The corrective powers run from a warning, through a reprimand and an enforcement notice, to a fine. Only the first two appear in the Island's record for last year.

ActionWhat it meansWhat the Commissioner has said about it
WarningThe lightest recorded action"A warning was also issued to a public sector organisation." Not named
ReprimandA published, named finding of infringementIssued under Article 58(2)(b): the power "to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation"
Enforcement noticeA step above a reprimandOne of the two more serious options named in the reprimand wording; none recorded in 2025/26
FineThe most serious stepNamed in the same wording; none recorded in 2025/26

Once a reprimand is issued there is nowhere to take it: there is no appeal to the Data Protection Tribunal, so your position can only change before the decision, where the Commissioner gives "full consideration of the Regulatory Policy" and weighs "both the aggravating and mitigating factors". There is a civil tail as well: "data subjects are entitled to seek compensation from the controller if they have suffered material or non-material damage as a result of any infringement of the Applied GDPR".

Publication is the norm. The Commissioner's office, which abbreviates itself "ICO", states: "The ICO lists all reprimands on our website, naming the organisations involved."

If you are unsure how your processing would read in a published finding, better to ask now.

An IT professional checking a tablet in a data centre aisle

What the 2025/26 numbers actually say

Measure2024/252025/26
Personal data breaches reported152200
People affected (estimated)4,91831,600
Data protection complaints2553
Freedom of Information decision noticesNot stated16, nearly double previous years
Oldest open caseMore than 11 monthsJust over six months

Read the two breach rows together. Reports rose by roughly a third; the people affected rose roughly sixfold. That is a statement about the kind of incident, not about carelessness spreading. Dr Alexandra Delaney-Bhattacharya, the Commissioner, puts it directly: "The increase reflects a rise in cyber incidents, which can affect large numbers of people in a single breach."

Complaints more than doubled while the office got faster: after a streamlined complaints system was introduced, the oldest open case fell from more than eleven months to just over six. The sixteen Freedom of Information decision notices are the same story on the public-authority side: see the 2026 FOI position for Isle of Man bodies and the governance lessons from information-rights decisions.

What actually triggered action

The Annual Report names the four organisations reprimanded in 2025/26: Shell Ship Management Ltd, Queen Elizabeth II High School, Payroll Partners Ltd and Manx Care. A warning also went to a public sector organisation, which is not named. Nothing further is recorded about any of them, and only one inference is available: two of the four are limited companies, so action here is not confined to government.

More detail is coming, by design: "to support transparency and share lessons learned, the ICO are increasing the amount of regulatory action we publish", with full infringement notices for the most serious cases and summary case studies elsewhere. The most recent is Reprimand 2026/003 of 10 August 2026, where a DPIA was produced, reviewed by the data protection officer and signed off but no longer described the processing that actually took place; five provisions of the Applied GDPR were infringed as a result, and we have set out what that reprimand shows about DPIA sign-off as the worked example.

A workplace desk with documents, a pen and a keyboard

Where the Island's risk is concentrating

One issue leads the complaints. They more than doubled to 53, "with handling of subject access requests the most common issue raised" — a process failure rather than a policy failure. How a subject access request should be handled on the Island is worth testing against what your team would actually do.

The Q1 2026 breach report, published on 8 August 2026 and covering April to June, shows a second concentration: five of the breaches that quarter involved schools. The causes named are "accessing systems with someone else's password, not using Bcc on emails, and medical information about all students attending a school trip detailed on a piece of paper stuck to the wall". In one of those reports, correspondence to estranged parents carried both addresses, "causing a potential safeguarding issue". The Commissioner's checklist for organisations handling children's data asks whether the information shared is necessary; whether sensitive information is visible to those who do not need access; whether recipient details have been checked before sending; whether known safeguarding considerations have been taken into account; and whether staff understand children's personal data may require additional protection. "A disclosure that appears minor on paper may have very different real-world consequences."

Two developments set the direction. The Island joined more than 60 regulators in raising concerns about the misuse of AI to create harmful or non-consensual imagery, one of the "new harms" the Commissioner sets alongside cyber incidents. The office also signed agreements with Dubai and Malta and joined cross-border investigations for the first time.

If your subject access process has not been reviewed since these reports, that is short work.

The two things that change your position after an incident

Reprimand 2026/003 records what counted in the organisation's favour, and the list is unglamorous: reporting the breach without undue delay and within 72 hours of first becoming aware; attempting to limit the damage; following the Commissioner's advice on public communications; and attending meetings and providing detailed information in a timely manner when requested.

Two are within anyone's control on the day. The 72-hour report runs from awareness, not from the end of your investigation. Cooperation, in the record, means datable things: you attended, you answered, you took the advice given on what to tell the people affected.

Mitigation is a record, not a tone of voice — dates, submissions and named attendees, built when nobody has time to build it. It buys no exemption: "There is no acceptable level of personal data breach. Even if the personal data is not thought to be particularly sensitive, the controller does not have the right to disclose it in an unauthorised manner."

A team meeting around a table in a modern office

Common mistakes we see

The most common is reading "not serious enough to warrant a fine or enforcement notice" as "not serious". A reprimand names you publicly, cannot be appealed, and sits on the record while data subjects remain entitled to seek compensation.

The second is treating UK material as a map of local exposure. Your regulator is the Isle of Man Information Commissioner and your framework is the Data Protection Act 2018 with the Applied GDPR; that the Island's own office uses the initials "ICO" makes the confusion easy.

The third is the artefact that no longer matches the activity: the assessment written for a process since changed, the request procedure naming someone who has left. Those pass an internal review and fail an investigation, because what the Commissioner examines is what you did.

Frequently asked questions

Is a reprimand from the Isle of Man Information Commissioner made public?

Yes. All reprimands are listed on the Commissioner's website naming the organisations involved, and some are published in detail. Consent is not required, though organisations are informed first.

Can we appeal a reprimand?

No. "There is no appeal against the issue of a reprimand to the Data Protection Tribunal." Your conduct tells during the investigation, where the Regulatory Policy and the aggravating and mitigating factors are considered.

Does a reprimand mean a fine will follow?

Not on the face of it. A reprimand is issued where an infringement is believed to have occurred but "is not serious enough to warrant a fine or enforcement notice", and none of the five actions of 2025/26 was a fine. What remains is a possible compensation claim.

Does this apply to private companies as well as public authorities?

Yes. The Article 58(2)(b) power is to issue reprimands "to a controller or a processor", and two of the four organisations reprimanded in 2025/26 are limited companies.

If you want a view on where your organisation sits, we are glad to look.

The file the Commissioner reads is written while you are still dealing with the incident, and what it says about you is settled by what you did in the first 72 hours.

Knight Consultancy
Knight Consultancy Limited
(Company No: 136669C)
Design House, Hills Meadow, Douglas,
Isle of Man ,IM1 5EB

© Knight Consultancy Limited {{Y}}. All Rights Reserved. Privacy Policy

Website and marketing partner: Yellowstone Accounts

Knight