Since 5 February 2026, the ICO can fine an organisation up to £17.5 million, or 4% of global turnover, for breaching PECR, the Privacy and Electronic Communications Regulations. Before the Data (Use and Access) Act 2025 took effect, the cap was £500,000. That is the same jump UK GDPR fines got back in 2018, now applied to the older, much less talked-about rules that actually govern cold email, cold calls, and marketing texts.
PECR has always been the quieter regulation. Most people who have heard of “GDPR fines” have never heard of PECR, even though PECR, not UK GDPR, is what decides whether you are allowed to email someone you have never spoken to. A regulator with real fining power behind a rule tends to enforce it more, not less.
The enforcement record so far
The ICO has said cookie compliance and direct marketing are renewed priorities now that it has this power, and its recent case history backs that up: a £225,000 penalty for nuisance marketing messages in January 2026, and a separate case in December 2025 against an organisation that sent around 80 million unsolicited marketing emails. None of that involved a small business anyone would recognise. That is the point. PECR does not scale its rules to company size, and a cap that used to top out at £500,000 was already more than most small businesses could absorb. One that can now scale with turnover changes the arithmetic for everyone, not only the large-scale spammers the ICO has gone after so far.
What does this mean for your business?
- Know which list rules actually apply to you. PECR restricts marketing to “individual subscribers”: consumers, sole traders, and partnerships. Limited companies are generally exempt from the consent requirement for B2B email, provided the message is genuinely relevant to the recipient’s role. If your list mixes company types, this distinction matters more than most people realise. A quick Companies House check settles it.
- Check you have real consent, or a genuine soft opt-in. Outside the corporate exemption, you need clear consent, or the recipient must be an existing customer, the message about a similar product or service, and they must have been given a clear chance to opt out both when you collected their details and in every message since. “I found their email on their website” is neither.
- Do not treat a bought or scraped list as ready to use. Purchased or scraped lists are one of the most common ways a small business ends up in breach without realising it. A list someone else compiled does not come with verified, current consent attached, whatever the seller claims.
- Make opting out actually work. An unsubscribe link that does not unsubscribe, or takes two weeks to take effect, is itself a compliance problem, not just a bad look.
- Write down your marketing lawful basis specifically. Most businesses can state a lawful basis for holding someone’s data. Fewer can state one for marketing them, which PECR asks separately from UK GDPR. Being able to say, for each list you hold, why you are allowed to be on it, is worth having in writing.
- Do not assume phone or text marketing is covered by the same check. Telephone marketing has its own layer, including the Telephone Preference Service and its corporate equivalent. “We checked the email rules” does not automatically cover a call or SMS campaign too.
None of this needs legal advice to get right for most small businesses. It needs actually checking, which is the part that tends to get skipped when a fine cap sounds abstract. It is a lot less abstract at £17.5 million. If you want the wider picture of what else the Act changed, see our plain-English guide to the DUAA.