The Information Commissioner’s Office has fined a company selling call-blocking devices £190,000 for making unlawful marketing calls, alongside an enforcement notice ordering it to stop and to fix its caller ID practices. The fine itself isn’t the story. The story is what’s changed underneath it: since February this year, the maximum penalty the ICO can issue for this kind of breach jumped from £500,000 to £17.5 million, or 4% of global turnover, whichever is higher, the same ceiling that applies to serious UK GDPR breaches. A £190,000 fine under the old cap was already painful. Under the new one, it’s a reminder of how much further the ICO can now go.

The rules in question are PECR, the Privacy and Electronic Communications Regulations, which cover marketing calls, texts, and emails separately from general data protection law. They’ve existed for years, but the Data (Use and Access) Act, which came into force in February 2026, quietly aligned PECR’s penalty cap with UK GDPR’s. That’s a roughly 35-fold increase in the ICO’s maximum firepower for exactly the kind of marketing breaches that plenty of ordinary SMEs, not just cold-calling operations, can stumble into without meaning to.

Why this catches ordinary businesses out

Most SMEs aren’t running call centres. But PECR also covers marketing texts and emails, and the rules that catch businesses out are often mundane: emailing a customer who bought something once, years ago, without a live opt-in; texting a lapsed client list bought from a third party; or a member of staff making follow-up calls to old leads without checking consent records first. None of that looks like the deliberate nuisance-calling this fine targeted, but PECR doesn’t distinguish intent from carelessness when it comes to whether consent existed.

It’s also worth knowing the ICO doesn’t need a mountain of complaints to act. A relatively small number of reports through its dedicated nuisance calls and messages reporting channels can be enough to trigger an investigation, particularly where a pattern emerges across a short period. Businesses sometimes assume enforcement only follows large-scale, obviously abusive campaigns, but the regulator’s own enforcement history this year shows otherwise, smaller and mid-sized operators have featured repeatedly alongside the bigger names.

What to check now

Audit who’s actually on your marketing lists and why. If you can’t point to clear, recorded consent for calls, texts, or emails to a given contact, that’s the gap PECR enforcement targets. This doesn’t need to be a big compliance project, it needs an honest look at your CRM’s opt-in data and a plan to fix any obvious holes.

Check your caller ID and sender information is accurate and not misleading. Part of this fine specifically covered caller identification failures, businesses appearing as something other than what they are when they call. If your outbound calls or texts don’t clearly identify your business, that’s a fixable, specific risk.

Don’t assume small size protects you. The ICO’s enforcement pattern in 2026 has consistently included smaller operators, not just household names. KeepSafe monitors for the kind of incidents and regulatory exposure that catch SMEs off guard, precisely because “we’re too small to be a target” is rarely true for either cyberattacks or regulatory attention.

Write down where your consent records actually live. If proving lawful consent for a given contact would mean digging through old spreadsheets, a previous member of staff’s inbox, or a CRM nobody has cleaned up in years, that’s a practical gap worth closing regardless of whether the ICO ever comes calling. A simple, current record of who opted in, when, and how, is the single most useful thing to have ready if a complaint is ever raised.

The takeaway

A £190,000 fine is a genuine event for most SMEs, but the more useful number here is £17.5 million, the ceiling that’s now legally available if a marketing breach is serious or repeated enough. If your business does any calling, texting, or emailing to customers or prospects, it’s worth five minutes checking your consent records actually hold up, before the ICO decides to check for you.