The maximum fine for nuisance calls and spam texts rose thirty-five-fold in February, from half a million pounds to seventeen and a half million. The regulator's own guidance for the businesses it fines still quotes the old number.
Estimated reading time: 8 minutes
In short. Since 5 February 2026, the Information Commissioner has been able to fine a company up to £17.5 million, or 4% of global turnover, for breaking the PECR rules on nuisance calls, spam texts and cookies. The ICO's own live guidance for the businesses it regulates still says the maximum is £500,000, a figure the guidance has flagged as "under review" since June 2025 without ever being corrected. Even if it were corrected tomorrow, the law's own transitional rule means none of the ICO's three most recent PECR fines, all issued this year, could have tested the new number, and on the ICO's own pace from conduct to fine it will likely be 2027 before one does. Three documented mistakes: four stars.
Between April 2022 and May 2025, a Manchester company called KRA Consultancy Ltd sent 5,575,715 unlawful marketing texts to people already struggling with debt, some carrying fabricated bailiff threats warning that "an Enforcement agent will attend within 48 hours to remove your goods" [7]. More than 60,000 complaints followed. When the Information Commissioner's Office finally fined KRA on 23 June 2026, the penalty was £300,000 [7], comfortably inside a legal ceiling that, by the time the notice was signed, no longer existed.
That ceiling changed on 5 February 2026, when the Data (Use and Access) Act 2025 came into force for PECR enforcement, and the ICO's own guidance for organisations has not caught up.
What the law now actually allows
The Privacy and Electronic Communications Regulations 2003 (PECR) govern marketing calls, texts, emails and cookies. Until this year, a breach carried a maximum monetary penalty of £500,000, the figure the ICO's own guide states plainly: "The Information Commissioner can also serve a monetary penalty notice imposing a fine of up to £500,000 which can be issued against the organisation or its directors" [1].
The Data (Use and Access) Act 2025 changed that by applying the same penalty structure PECR uses to the one already built into the Data Protection Act 2018. Section 157 of that Act sets a "higher maximum amount" for the most serious contraventions of "£17,500,000 or 4% of the undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher" [2]. The ICO's own summary of the change confirms the effect in plain terms: the Act "brings the enforcement powers under PECR into line with UK GDPR, so that enforcement mechanisms and penalties are the same in most cases" [5]. The commencement regulations fix the date this took effect: "come into force on 5th February 2026" [3]. A £500,000 cap became a £17.5 million one, more than thirty-five times higher, seven months before this piece was written.
The guidance that never caught up
The ICO's own "What are PECR?" page, the guide a business would read to understand its exposure, still carries the £500,000 figure quoted above, unchanged. The same page does acknowledge that something is in motion, in a single caveated line: "Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change. The Plans for new and updated guidance page will tell you about which guidance will be updated and when this will happen" [1]. That sentence has sat on the page since the Act received royal assent on 19 June 2025, more than fourteen months ago, spanning both the Act's passage and the date the fine cap itself actually changed.
Follow the page's own link, and the promised timetable is not there. The ICO's "Our plans for new and updated guidance" page explains the process for developing guidance in general, but names no PECR marketing project and gives no date for one, stating only that "because of the Data (Use and Access) Act, we have started work on new guidance," which has meant the ICO has "had to deprioritise and withdraw some of the planned guidance you will have seen previously on this web page," restarting deprioritised projects only "if this happens" at some unstated future point [6]. A page that tells a business the fine it can face is thirty-five times smaller than the true figure now points, for a correction date, to a page that offers none.
Why no fine has tested the new number yet, and won't soon
Even a corrected guidance page would not answer the practical question: has anyone actually been fined more under the new regime? The answer is no, and the law's own drafting explains why it cannot yet be otherwise. The commencement regulations include a transitional and saving provision covering the Commissioner's enforcement powers, stating plainly that the power to investigate applies "regardless of when the conduct... occurred," but that this "does not authorise the imposition of any enforcement sanction in respect of an act or omission occurring before 5th February 2026" [4]. Conduct that happened before that date can only ever be fined under the old £500,000 cap, however late the fine arrives.
That bar covers every PECR fine the ICO has issued so far this year. KRA's 5.5 million unlawful texts ran from April 2022 to May 2025 [7], 13 months before its fine was signed. Elderly Aids Ltd made 758,053 unsolicited marketing calls targeting elderly people between May 2024 and February 2025 [8], 18 months before its £190,000 fine on 27 August 2026. Energy Prices Direct Limited made unsolicited calls from January 2024 to January 2025 [9], 16 months before its £160,000 fine on 20 May 2026. All three periods of conduct ended before 5 February 2026, so none of these penalties could legally have exceeded £500,000, and none did. On the ICO's own pace across these three cases, 13 to 18 months from the end of the conduct to a signed penalty notice, a company breaching PECR for the first time this month would not expect a fine before late 2027 at the earliest, whatever cap applies to it.
The claims, tested
| The document's own words | What the record actually shows | Verdict |
|---|---|---|
| ICO guidance: a PECR fine can go "up to £500,000" [1] | The real maximum has been £17.5 million or 4% of global turnover since 5 February 2026, per the Data Protection Act 2018 [2] as commenced for PECR [3] | A live guidance figure understated by a factor of 35 |
| The same guidance: "under review and may be subject to change," with a promised timetable elsewhere [1] | The linked "Plans for new and updated guidance" page names no PECR project and gives no date [6] | A caveat that points nowhere |
| The commencement regulations: enforcement sanctions cannot cover conduct "before 5th February 2026" [4] | The three most recent PECR fines all concern conduct that ended before that date [7] [8] [9] | The higher cap remains untested by design, not by chance |
The mistakes, counted
The ICO's own live guidance understates the maximum PECR fine by a factor of 35 (1). It states "up to £500,000" [1] more than seven months after the true maximum became £17.5 million or 4% of global turnover [2] [3].
The guidance's own "under review" caveat has sat unresolved for over fourteen months, and points to a page with no PECR date on it (2). The caveat dates to the Act's royal assent on 19 June 2025 [1]; the page it names as the source of a timetable lists no PECR guidance project and no date [6].
No fine has tested, or could yet test, the new cap (3). The law bars enforcement sanctions for conduct before 5 February 2026 [4], all three of the ICO's most recent PECR fines concern earlier conduct [7] [8] [9], and the ICO's own 13-to-18-month pace from conduct to penalty means a first test is unlikely before 2027.
Credit where due
The enforcement itself is real and specific, not vague. In four months this year the ICO named and fined three separate companies over nuisance calls and spam texts, publishing exact figures, exact call and text counts, and exact complaint numbers rather than a summary total [7] [8] [9]. The transitional bar on backdated sanctions [4] is not a design flaw; refusing to punish conduct retroactively under a penalty regime that did not exist at the time is ordinary, fair legislative drafting. And the underlying reform is a genuine one: raising a cap that critics had long treated as a cost of doing business to a level aligned with UK GDPR is a real increase in deterrence, once it starts being used.
Verdict
Four stars, from three documented mistakes. Parliament did the hard part: it closed the gap between PECR penalties and UK GDPR penalties, seven months ago, in law. The regulator that enforces PECR has not yet closed the much smaller gap between what its own guidance says and what the law now allows, and the page that promises a date for fixing that gives none. Anyone reading the ICO's own guidance to weigh the risk of ignoring the marketing rules is still being told a number that stopped being true in February.
Sources
- What are PECR?, Information Commissioner's Office
- Data Protection Act 2018, section 157: Maximum amount of penalty, legislation.gov.uk
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, regulation 2, legislation.gov.uk
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, regulation 8, legislation.gov.uk
- The Data (Use and Access) Act 2025 (DUAA): summary of the changes - Privacy and electronic communications, Information Commissioner's Office
- Our plans for new and updated guidance, Information Commissioner's Office
- Manchester firm fined £300,000 for bombarding people in debt with over 5.5 million unlawful texts, ICO, 23 June 2026
- ICO hits company selling call blockers with £190k fine for nuisance calls, ICO, 27 August 2026
- Glasgow-based energy company fined £160,000 for making unsolicited marketing calls, ICO, 20 May 2026