What is the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025 (commonly referred to as the DUA Act or DUAA) is a wide-ranging piece of UK legislation that modernises data protection law, establishes a framework for digital identity verification, introduces smart data schemes, and reforms the regulatory structure of the Information Commissioner's Office.
The Act received Royal Assent on 19 June 2025 and is being brought into force in stages. The most significant tranche of provisions, including the main data protection and PECR amendments, came into force on 5 February 2026. Certain provisions around data subject complaints are expected to commence on 19 June 2026.
For businesses involved in telemarketing and direct marketing, the critical changes are found in Part 6 of the Act, which amends the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). These are the regulations that govern unsolicited marketing calls, texts, and emails in the UK, and that underpin the legal requirement to screen calling lists against the TPS and CTPS registers.
Key changes for telemarketing and TPS compliance
The DUA Act introduces several amendments to PECR that directly affect how businesses conduct direct marketing. Here are the changes that matter most.
1. Maximum PECR fines raised to £17.5 million
This is the single most consequential change for anyone making marketing calls in the UK.
Previously, the maximum penalty the ICO could impose for a PECR breach, including failure to screen against TPS and CTPS, was £500,000. That cap had been in place since 2003, and it was already looking outdated given the scale of modern telemarketing operations.
The DUA Act, through Schedule 13, brings PECR penalties into line with UK GDPR levels. The new maximum is:
- £17.5 million, or
- 4% of the organisation's total annual worldwide turnover in the preceding financial year
whichever is higher.
To put this in context: under the old regime, a large call centre operation might have calculated that a £500,000 fine, while painful, was an acceptable cost of business. That calculation no longer works. A company with £100 million in annual turnover now faces a theoretical maximum penalty of £4 million for the same offence.
It is worth noting that this increase applies specifically to breaches of PECR's direct marketing rules. It does not extend to the separate duty to notify the ICO of personal data breaches under PECR.
2. Expanded definitions of "call" and "communication"
Section 110 of the DUA Act amends the core definitions in PECR. These changes are technical but have real practical consequences.
"Call" now includes attempted calls. Previously, PECR applied to calls that were connected. Under the amended regulations, the definition of a "call" covers any attempt to establish a connection via a telephone call, regardless of whether the recipient answers. This means that an unsolicited marketing call to a TPS-registered number is a PECR breach even if the person never picks up.
"Communication" now covers transmitted messages. The definition has been broadened to encompass any information that is transmitted, regardless of whether it is received or read. A marketing text message sent to a TPS-registered number is a violation whether or not the recipient opens it.
"Recipient" now includes intended recipients. PECR protections now apply to the person you intended to contact, not just the person who actually received the communication.
For telemarketing operations, the practical implication is clear: you cannot defend a PECR breach by arguing that the call did not connect or the message was not received. The act of making the attempt is enough.
3. Enhanced ICO enforcement powers
The DUA Act does not just raise fines. It also gives the regulator significantly stronger tools to investigate and prosecute PECR breaches.
Under the new framework, the ICO (which will transition to become the Information Commission under the Act) can:
- Compel witness attendance at interviews, with criminal penalties for providing false statements
- Require organisations to commission technical reports from approved persons on specified matters, at the organisation's own expense
- Issue information notices demanding specific documents, including data protection impact assessments and risk evaluations
- Apply the full range of DPA 2018 enforcement provisions to PECR breaches, including assessment notices and enforcement notices
Most of the investigation and enforcement powers in Parts 5 to 7 of the Data Protection Act 2018 are now applied equally to PECR. This means the ICO can investigate a suspected TPS violation with the same procedural toolkit it uses for serious UK GDPR breaches.
4. Formal definition of "direct marketing"
Section 110 of the DUA Act incorporates the definition of "direct marketing" from the Data Protection Act 2018 into PECR: the communication of advertising or marketing material which is "directed to particular individuals."
While this largely codifies existing practice, it removes ambiguity and ensures consistency across UK data protection statutes. If you are directing promotional material at specific people, whether by phone, text, or email, you are conducting direct marketing, and PECR applies in full.
5. Structural changes to the ICO
The Act establishes the Information Commission as a statutory corporate body to replace the current Information Commissioner's Office. The chair of the new Commission will retain the title of Information Commissioner.
This restructuring introduces a board governance model, panel reviews of codes of practice, and enhanced accountability mechanisms. For regulated businesses, the practical effect is a regulator with broader institutional capacity and a more formalised approach to enforcement decisions.
Why this matters more than previous fine increases
It would be easy to dismiss the £17.5 million figure as a theoretical maximum that the ICO would never actually impose. That would be a mistake, for three reasons.
First, the ICO has been consistently active on PECR enforcement. In April 2024, the ICO fined two companies a combined £340,000 for making almost 1.43 million calls to TPS-registered numbers. In another case, two energy firms received combined penalties of £550,000 for unlawful automated marketing calls. A compensation firm was fined £90,000 in 2025 for 95,000 unsolicited calls to TPS-registered numbers. These fines were all imposed under the old £500,000 cap.
Second, the alignment with UK GDPR penalties signals regulatory intent. Parliament has deliberately placed PECR breaches on the same footing as serious data protection violations. The message to the regulator is clear: treat direct marketing non-compliance with the same gravity as data breaches.
Third, the ICO now has the investigative tools to build stronger cases. The power to compel witnesses, demand technical reports, and issue information notices means investigations can be more thorough and penalties more precisely calibrated to the scale of the offence.
What this means for your business
If your organisation makes outbound marketing calls, sends promotional text messages, or runs email marketing campaigns in the UK, the DUA Act raises the stakes across the board. Here is what you need to consider.
TPS and CTPS screening is no longer optional in practice
It never was, legally. But many businesses treated TPS compliance as a best-effort exercise, partly because the financial consequences of getting it wrong were capped at a level that large operations could absorb. That cushion no longer exists.
Under the new regime, a single sustained campaign of calls to TPS-registered numbers could expose your business to a fine that threatens its viability. Screening every number against the TPS and CTPS registers before making a marketing call is not just legally required under PECR. It is now an existential business risk to skip it.
The 28-day re-check rule carries more weight
ICO guidance has long stated that businesses should re-screen calling lists against TPS and CTPS at least every 28 days. People register with TPS continuously, and a number that was clear last month may not be clear today.
With fines potentially reaching £17.5 million, the cost of working with stale data has increased dramatically. If you checked a list six months ago and have been calling from it ever since, you are carrying significant compliance risk.
Attempted calls now count
The expanded definition of "call" under Section 110 means that dialling a TPS-registered number is a breach even if nobody answers. For businesses using auto-diallers, predictive diallers, or any form of automated calling, this has immediate implications. Every number loaded into your dialler should be pre-screened, because every attempt counts.
You need auditable compliance records
The ICO's enhanced investigative powers mean that when an investigation begins, you will be expected to demonstrate your compliance processes in detail. "We check TPS" is not sufficient. You need timestamped records showing which numbers were checked, when they were checked, and what results were returned.
If you cannot produce an audit trail showing that you screened a specific number within 28 days of calling it, you have limited defence against an enforcement action.
How to prepare: a compliance checklist
The DUA Act provisions affecting PECR came into force on 5 February 2026. If you have not already reviewed your compliance processes, now is the time. Here is a practical checklist.
Immediate actions
- [ ] Audit your current TPS/CTPS screening process. When was the last time every number on your calling list was checked? If you cannot answer that question with a specific date, you have a problem.
- [ ] Implement automated TPS/CTPS checking. Manual checking does not scale and creates gaps. Use an API-based service that can screen numbers in real time or in bulk before every campaign.
- [ ] Establish a 28-day re-check cycle. Set up automated re-screening of your entire active calling database at least every 28 days. Do not wait for a campaign to trigger a re-check.
- [ ] Review your record-keeping. Ensure every TPS check is logged with a timestamp, the number checked, and the result. You need this evidence if the ICO comes calling. Services like TPSCheck log every query automatically with exportable audit trails.
- [ ] Update your risk assessment. If your last PECR risk assessment was based on a maximum fine of £500,000, it is out of date. Recalculate your exposure under the new £17.5 million ceiling.
Operational changes
- [ ] Screen before loading diallers. With attempted calls now counting as breaches, no number should enter an auto-dialler without a current TPS/CTPS check result.
- [ ] Train your team. Make sure everyone involved in campaign management understands that the maximum penalty has increased 35 times over and that attempted calls count.
- [ ] Document your consent basis. If you are relying on consent rather than TPS screening, ensure your consent records are specific, informed, and current. The DUA Act's formal definition of direct marketing leaves no room for ambiguity.
- [ ] Review third-party data sources. If you purchase or receive calling lists from third parties, verify that TPS/CTPS screening was conducted within the last 28 days. Better yet, re-screen the data yourself before use.
- [ ] Consider compliance risk scoring. Going beyond a simple TPS yes/no result, risk scoring tools can help you assess the overall compliance risk of each number based on registration status, time since last check, and number validity.
Governance and oversight
- [ ] Assign PECR compliance ownership. Someone in your organisation should be explicitly responsible for direct marketing compliance, with authority to halt campaigns that fail screening.
- [ ] Schedule regular compliance reviews. Quarterly at minimum, reviewing call volumes, TPS check rates, complaint trends, and any ICO correspondence.
- [ ] Prepare an incident response plan. If you receive an ICO enquiry or enforcement notice, you need a documented process for responding, including who is responsible for gathering evidence and engaging legal counsel.
The bottom line
The Data (Use and Access) Act 2025 has fundamentally altered the risk equation for telemarketing compliance in the UK. Fines of up to £17.5 million, expanded definitions that capture attempted calls, and enhanced ICO enforcement powers mean that TPS and CTPS compliance is no longer something you can afford to treat casually.
The cost of a comprehensive TPS checking process is negligible compared to the potential consequences of getting it wrong. A single check costs pennies. A fine under the new regime could cost millions.
If you are not already using an automated, API-based TPS and CTPS checking service with built-in audit trails, now is the time to start. TPSCheck.uk provides real-time TPS and CTPS screening with every check logged and exportable, starting with a free plan that requires no credit card.
The law has changed. Your compliance processes need to change with it.
This article is for general information purposes and does not constitute legal advice. For specific guidance on your obligations under PECR and the Data (Use and Access) Act 2025, consult a qualified legal professional. TPSCheck is an independent commercial service and is not affiliated with the ICO, TPS Limited, or the Data & Marketing Association.