The U.K.’s data regulator published guidance setting out how it decides to issue penalties against companies and calculate fines.

Last week, the Information Commissioner’s Office (ICO) issued its updated data protection fining guidance to provide companies with greater transparency and clarity about how and why the regulator would administer penalties for a breach of the U.K. General Data Protection Regulation (GDPR) or Data Protection Act 2018.

Neil Hodge is a freelance business journalist and photographer based in Nottingham, United Kingdom. He writes on insurance and risk management, corporate governance, internal audit, compliance, and legal...