ICO Data Protection Register

Marketing emails, texts and calls: the maximum fine is now £17.5m

On 5 February 2026 the maximum fine for breaking the marketing rules in PECR rose from £500,000 to £17,500,000, or 4% of total annual worldwide turnover if that is higher. The rules on when you may send a marketing message did not change — with one exception, a new soft opt-in for charities.

Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.

The short version

The consent rules for marketing emails, texts and calls are the same as they were in January 2026. What changed is the penalty. The ceiling went from £500,000 to £17,500,000, or 4% of total annual worldwide turnover if higher. One genuine rule change landed on the same day: charities gained a new soft opt-in.

What the maximum fine is now, and which breaches attract it

Section 115(8) of the Data (Use and Access) Act 2025 replaced Schedule 1 to the Privacy and Electronic Communications Regulations 2003 (PECR) with the Schedule set out in Schedule 13 to that Act. The change came into force on 5 February 2026 under SI 2026/82.

The new Schedule 1, paragraph 18 applies section 157 of the Data Protection Act 2018 to PECR. That section sets the 'higher maximum amount' at £17,500,000 or 4% of an undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher. For anything that is not an undertaking, it is £17,500,000. The 'standard maximum amount', which applies to any PECR breach not on the list below, is £8,700,000 or 2%.

Before 5 February 2026 From 5 February 2026
Maximum PECR fine £500,000 £17,500,000, or 4% of worldwide turnover if higher
Where it comes from Data Protection Act 1998 penalty provisions applied by PECR Schedule 1 Data Protection Act 2018 s.157 applied by PECR Schedule 1 para. 18
ICO investigatory powers under PECR Audit power in PECR reg. 5B Assessment notices, interview notices, reports by approved persons

Paragraph 18 names the regulations that attract the higher maximum: 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23, 24 and 32B(4) and (5). In plain terms that is the entire direct marketing suite — automated calls (19), faxes (20), live calls (21), claims management calls (21A), pensions calls (21B), email and text (22), concealing your identity or failing to give an opt-out address (23), and failing to identify yourself on a call (24). It also covers regulation 6, the cookies and similar technologies rule, and regulation 5, security.

What the transitional saving does and does not do

Regulation 6 of SI 2026/82 saves the *old penalty notice procedure* where the ICO gave a notice of intent before 5 February 2026. It does that by disapplying the amendments made by section 101 of the Act. It is not a general saving of the £500,000 ceiling, and it does not say anything about conduct that happened before February.

Only the penalty, plus the charity change below. Regulation 22 still says you must not send unsolicited direct marketing by electronic mail to an individual subscriber unless they have consented or a soft opt-in applies. None of the following moved:

Section 110 of the Act tightened PECR's interpretation provisions from the same date. A 'call' now includes an *attempt* to establish a connection. A 'communication' now covers information *transmitted to* a party, rather than exchanged or conveyed between parties. And where information is sent but not received, 'recipient' means the intended recipient — so a text that never arrives can still be a breach. The same section writes a standalone definition of 'direct marketing' into PECR.

The soft opt-in, and when you can actually use it

The products and services soft opt-in lets you email or text an individual subscriber without consent. The ICO's position is that all of these must be true:

  1. You obtained the contact details yourself, directly from that person.
  2. You obtained them while selling, or negotiating to sell, a product or service.
  3. You are only marketing your own similar products or services.
  4. You gave a clear opportunity to opt out at the point you collected the details.
  5. You give an opportunity to opt out in every message you send afterwards.

'Negotiating a sale' means the person actively expressed an interest in buying — an enquiry about a product, a quote request, a free trial sign-up. Browsing your site is not enough. Nor is an enquiry about something other than buying. And the opt-out must be offered *when you collect the details*: putting it in the order confirmation is too late.

Bought-in lists never qualify

The soft opt-in requires that you collected the details. The ICO is explicit that there is no such thing as a third-party marketing list that is 'soft opt-in compliant'. To use a bought-in list you need consent that named your organisation and covered the exact channel.

Charities: a second soft opt-in, but check the collection date

Section 114 of the Act inserted a new regulation 22(3A). From 5 February 2026 a charity may send direct marketing by electronic mail — email, text or social media direct message — without prior consent, where all of the following apply: you are a charity within the relevant UK definition, which the Act ties to the Charities Act 2011, the Charities Act (Northern Ireland) 2008 or the Scottish Charity Register; you obtained the contact details in the course of the person expressing an interest in, or offering or providing support to further, your charitable purposes; the sole purpose of the marketing is to further those charitable purposes; you offered a simple, free means of refusal at collection; and you offer one in every later message.

The date trap

The ICO's final guidance, published 28 April 2026, states that the charitable purposes soft opt-in can only be used where you obtained the person's contact details on or after 5 February 2026. It does not unlock an existing supporter list. Historic supporters who gave consent can still be emailed on that consent, and an existing supporter who re-engages after that date and is given the required opt-out can be brought within it.

Two further limits. The charitable purposes soft opt-in cannot be used to promote other organisations, including other charities. And charities must not use the ordinary products and services soft opt-in to send electronic mail about campaigning or fundraising, even to existing supporters. Where both soft opt-ins apply, the ICO expects separate opt-out boxes for each, at collection and in every later message.

Cold emailing businesses, and where sole traders sit

PECR splits recipients into corporate subscribers and individual subscribers. Companies, LLPs, Scottish partnerships and some public bodies are corporate — and so is any other unincorporated body of persons in Scotland. Sole traders, ordinary partnerships and other unincorporated bodies outside Scotland are individual subscribers and get the same protection as private individuals.

Who you are contacting Marketing email or text Live marketing call
Limited company, LLP, Scottish partnership No PECR consent needed Screen against CTPS and TPS; stop if they object
Sole trader or ordinary partnership Consent, or a soft opt-in Screen against TPS; stop if they object
A private individual Consent, or a soft opt-in Screen against TPS; stop if they object

Cold B2B email to a limited company is therefore lawful under PECR without consent. But regulation 23 still applies to every message: identify yourself and give a valid opt-out address. And if the address identifies a person — j.smith@company.co.uk — you are processing personal data, so you need a lawful basis under the UK GDPR, you must provide privacy information, and the right to object to direct marketing is absolute. Where you cannot tell which type of subscriber an address belongs to, the ICO's advice is to take the cautious route and treat it as an individual subscriber.

New ICO powers, and what it is enforcing right now

The substituted Schedule 1 imports Data Protection Act 2018 enforcement machinery into PECR. The practical additions are the power to compel a witness to attend an interview, the power to require a report from an approved person, and assessment notices in place of the old PECR audit provision in regulation 5B, which was removed. The Data Protection Act 2018 penalty regime also contains no requirement to show substantial damage or substantial distress.

In a blog on 23 June 2026 the ICO said it is "currently developing separate guidance to cover these higher fines", while noting that the law has commenced and that it can and will use the new powers where necessary for the most serious cases.

Enforcement is active. On 29 July 2026 the ICO executed search warrants at residential and business premises linked to five companies in Bolton, Burnley, Liverpool, London and Swansea, over car finance claim texts. The ICO says it has received more than 12 million complaints about unwanted marketing texts linked to car finance claims since September 2025, at up to 100,000 a day, and that the five companies are believed responsible for a combined 170 million texts between September 2025 and May 2026. The action sits within a joint taskforce with the FCA, the ASA and the SRA. Andy Curry, the ICO's Head of Investigations, said: "This week's searches send a clear message to the claims management sector: comply with the law or expect to hear from us."

Fines are still landing at pre-February levels because the conduct predates the change. KRA Consultancy Ltd was fined £300,000 — a penalty notice dated 20 May 2026, announced on 23 June 2026 — for 5,575,715 unsolicited and fake bailiff texts sent between April 2022 and May 2025, under regulations 22 and 23. Jacksons Marketing Ltd was fined £130,000, announced on 8 July 2026, for more than 230,000 calls to TPS-registered numbers over an 11-month period. Treat these as evidence of what the ICO pursues, not of the new ceiling in use.

What to check in your marketing stack this quarter

  1. Step 1 Prove your permission, record by record For every contact on a marketing list, you should be able to say whether you rely on consent, the products and services soft opt-in, the charitable purposes soft opt-in, or corporate subscriber status — and show when and how you obtained the details.
  2. Step 2 Flag sole traders and partnerships They are individual subscribers. If your B2B list mixes limited companies with sole traders and you cannot tell them apart, the ICO's advice is to treat the whole list as individual subscribers.
  3. Step 3 Check the opt-out is offered at collection A prominent opt-out on the form or a verbal offer at the point of collection. An opt-out that first appears in the confirmation email does not meet the soft opt-in.
  4. Step 4 Check every send template A working unsubscribe link or STOP code, free of charge, in every message. No account login required to unsubscribe. A clear sender identity.
  5. Step 5 Charities: separate your lists by date Only details collected on or after 5 February 2026, through an expression of interest or offer of support, can sit on the charitable purposes soft opt-in. Keep separate preference flags for each basis.
  6. Step 6 Look at your cookie banner too Regulation 6 is on the higher-fine list. The exceptions added to PECR in February 2026 are narrow — statistical purposes, adapting appearance or functionality, software updates and emergency assistance — and none of them covers advertising or marketing tracking.

Common questions

Can the ICO really fine me £17.5 million for a marketing email?

That is the statutory ceiling, not a starting point. Section 157 of the Data Protection Act 2018, as applied to PECR from 5 February 2026, sets the maximum at £17,500,000 or 4% of total annual worldwide turnover, whichever is higher. Actual PECR fines announced in 2026 have been in the £130,000 to £300,000 range, for campaigns running into hundreds of thousands of calls or millions of messages. The ICO said in June 2026 that it was still developing separate guidance on the higher fines.

Do I need consent to send a cold marketing email to another business?

Not under PECR if the recipient is a corporate subscriber — a limited company, LLP, Scottish partnership or certain public bodies. You must still identify yourself and give a valid opt-out address under regulation 23. If the email address identifies a named person, the UK GDPR applies, so you need a lawful basis, must provide privacy information, and must honour any objection. Sole traders and ordinary partnerships outside Scotland are individual subscribers, so they need consent or a soft opt-in.

Our charity has a mailing list from before February 2026. Can we use the new charity soft opt-in on it?

No. The ICO's guidance says the charitable purposes soft opt-in may only be used where you obtained the recipient's contact details on or after 5 February 2026. For older contacts you need consent, or you need them to give you their details again in a way that meets the requirements.

Does the soft opt-in cover anyone who filled in a contact form?

Only if the enquiry was about buying your products or services. An enquiry asking whether you are opening a new branch does not count. The person must also have been given a clear opt-out at the moment you collected the details, and you must only market your own similar products or services.

We bought a list that the seller says is soft opt-in compliant. Can we email it?

No. The soft opt-in requires that you obtained the contact details directly from the person yourself. The ICO states there is no such thing as a third-party marketing list that is soft opt-in compliant. A bought-in list can only be used where the consent named your organisation and covered the exact channel you intend to use.

I keep getting spam texts. What can I do?

Forward the text to 7726, which is free on most UK networks. You can register your number with the Telephone Preference Service to stop marketing calls, and report unwanted calls, texts and emails to the ICO through its online reporting tool.

Sources

This page summarises the following primary sources. Where they disagree with this summary, they take precedence.

Related guidance