Governance

    The ICO Issued £1.1m in PECR Fines. Marketing Consent Is Now a Balance-Sheet Item

    The ICO's 2024/25 annual report records £1.1 million in fines for PECR breaches, alongside tens of thousands of public reports about nuisance calls and spam email. UK direct marketing is being enforced, not just regulated.

    Written by

    Tiago Dias

    Co-Founder & COO

    2 Mar 2026 · 6 min read

    Market: United Kingdom

    Key figures

    £1.1m
    in PECR fines issued in 2024/25
    Source: ICO
    44,400
    public reports about nuisance calls in 2024
    Source: ICO
    28,969
    public reports about spam email in 2024
    Source: ICO

    The Information Commissioner's Office reports in its 2024/25 annual report that it issued £1.1 million in fines to companies for breaching the Privacy and Electronic Communications Regulations during the financial year. Its 2024 year in review adds the demand side of that enforcement: 44,400 reports from the public about nuisance calls and 28,969 about spam email.

    PECR is the rule that governs electronic marketing in the UK — calls, texts, email and cookies — and it sits alongside UK GDPR rather than inside it. Plenty of UK businesses have a privacy notice and a cookie banner and still run outbound programmes that would not survive a complaint, because the consent behind the list was never specific, never recorded, or never refreshed after a data purchase.

    The reports figure is the part to internalise. Regulatory attention here is largely complaint-driven, which means your exposure is a function of how irritating your marketing feels to the person receiving it. A campaign that generates volume and annoyance simultaneously is not merely inefficient; it is the mechanism by which you end up in front of the regulator.

    The same annual report shows enforcement is not confined to marketing: the ICO fined the Police Service of Northern Ireland £750,000 in October 2024 after a spreadsheet error exposed personal data for its entire workforce, and it fined software provider Advanced £3m following a 2022 ransomware attack, reduced from a provisional £6m. Data handling and security failures are being priced.

    Practically, three things carry most of the risk in the UK mid-market. First, consent evidence: you should be able to show, per contact, what they agreed to, when, and on which form. Second, the soft opt-in for existing customers, which is narrower than most teams assume and does not extend to purchased lists. Third, cookie and tag behaviour, where analytics and advertising scripts routinely fire before consent is given and nobody notices because it does not break the page.

    We build consent evidence into forms as a default now — timestamp, wording shown, and version — because reconstructing it after a complaint is impossible. It costs almost nothing at build time and it is the difference between answering the ICO in an afternoon and answering it with a lawyer.

    Sources

    1. 1.Information Commissioner's Annual Report and Financial Statements 2024/25Information Commissioner's Office · 2025
    2. 2.ICO 2024 – a year in reviewInformation Commissioner's Office · 2024

    Apply it

    Score your growth system

    Ten questions, a stage-by-stage score and your three highest-value priorities.
    Get your free Growth Audit