Earlier quoted context omitted.
They've been failing to even issue fines, let alone enforce them. Both for competence reasons (see also: the collapse of the AIQ enforcement, and the climb-downs in Mariot and BA cases) and for... I don't know why in the adtech case. The ICO has evidence of wide-scale criminal behaviour in the adtech industry. And yet they flat-out refuse to take enforcement action . They're even proud of the fact they're refusing to…
They did, however, appear to do a good job with the recent Experian and Equifax enforcement.
If so, we seem to have a major disagreement about the definition of a "good job". The ICO, by its own admission, found that:
> The investigation found how the three CRAs were trading, enriching and enhancing people’s personal data without their knowledge. This processing resulted in products which were used by commercial organisations, political parties or charities to find new customers, identify the people most likely to be able to afford goods and services, and build profiles about people.
> The ICO found that significant ‘invisible’ processing took place, likely affecting millions of adults in the UK. It is ‘invisible’ because the individual is not aware that the organisation is collecting and using their personal data. This is against data protection law.
The ICO was clearly aware that a large-scale GDPR breach was being committed for profit for several years by a large company who should know better (and has the resources to comply should they want to), and the best they could muster is an "enforcement notice" as opposed to a fine?