Chokey for receivers also
As it stands, the only people who can expect to attract the marshmallow like wrath of ICO are the data controller and the tea leaves. People who subsequently obtain data that has been leaked or stolen and then make use of it - the Graun publishing the BNP membership list, HMRC rifling through stolen bank records, etc - get away scot free.
Receiving personal data that aint yours should also be an offence, and one of strict liability, IMHO. Public interest exemptions for scumbag expense fiddlers, obviously, as there are in the current legislation.