What the ICO has announced
The ICO has not published a single headline-grabbing announcement about cold calling rules. What it has done is more significant: it has set in motion a series of overlapping regulatory actions that, taken together, amount to a fundamental reset of how direct marketing compliance will be enforced in the UK.
Updated direct marketing and PECR guidance (spring 2026)
The ICO confirmed on its guidance planning page that its direct marketing and privacy and electronic communications guidance is currently being redrafted following a public consultation that has now closed. The final version is scheduled for publication in spring 2026.
This updated guidance will incorporate the amendments to PECR introduced by the Data (Use and Access) Act 2025, including the new fine regime, expanded definitions of "call" and "communication," and enhanced investigative powers. When published, it will be the definitive statement of the ICO's expectations for businesses making marketing calls, sending promotional texts, or running email campaigns.
Critically, the ICO is also updating its Direct Marketing Advice Generator, the interactive tool businesses use to determine which rules apply to their specific marketing activities. This tool is being rewritten to reflect the new legal framework.
New enforcement procedural guidance
In October 2025, the ICO launched a 12-week public consultation on draft enforcement procedural guidance, which closed in January 2026. This guidance sets out how the regulator intends to use both its existing and new enforcement powers under the amended legislation.
Of particular note for telemarketing businesses: the ICO has stated it plans to publish separate fining guidance for PECR, specifically to reflect the case law that has developed in the Tribunal in relation to direct marketing cases. This means the ICO is developing a distinct framework for calculating penalties for marketing call violations, informed by the precedents set in cases like Green Spark Energy, Outsource Strategies, and AFK Letters Co.
The draft enforcement guidance also introduces a structured settlement procedure for penalty notice cases, requiring admission of infringement details and agreement not to appeal. This is a new mechanism that could accelerate the resolution of PECR enforcement cases.
Sustained enforcement activity
The ICO has not paused enforcement while it drafts new guidance. If anything, the pace has intensified:
-
January 2026: Two companies fined a combined £225,000 for nuisance marketing messages. Allay Claims Ltd was fined £120,000 for sending over 4 million unsolicited SMS messages, and ZMLUK Limited was fined £105,000 for sending approximately 67.7 million marketing emails without valid consent.
-
February 2026: Two further convictions in what the ICO describes as its largest ever nuisance call investigation, bringing the total number of individuals prosecuted in the case to 13. This investigation involved the theft and sale of personal data obtained from over 400 garages and claims management companies, with criminal sentences imposed.
-
September 2025: Two energy companies fined a combined £550,000 for using avatar software to make nearly 12 million automated marketing calls, with the ICO issuing a public warning about the growing threat of robocalls.
For a comprehensive breakdown of recent ICO enforcement cases, see our article on TPS fines, enforcement, and real cases.
Why now: the regulatory context
The timing of the ICO's guidance overhaul is not coincidental. Three converging factors have created the conditions for a fundamental shift in how cold calling compliance is regulated and enforced.
1. The Data (Use and Access) Act 2025
The DUA Act received Royal Assent on 19 June 2025. Its PECR enforcement provisions came into force on 5 February 2026, just two weeks ago at the time of writing. This legislation:
- Raised maximum PECR fines from £500,000 to £17.5 million or 4% of annual global turnover
- Expanded the definition of "call" to include attempted calls, meaning dialling a TPS-registered number is a breach even if nobody answers
- Broadened "communication" to cover transmitted messages regardless of whether they are received
- Gave the ICO power to compel witness attendance at interviews, with criminal penalties for false statements
- Enabled the ICO to require organisations to commission technical reports at their own expense
- Applied the full range of Data Protection Act 2018 enforcement provisions to PECR breaches
Every enforcement case decided before February 2026 was subject to the old £500,000 cap. The new regime is now live, and the ICO's forthcoming guidance will set out how it intends to exercise these expanded powers. For a full analysis of the DUA Act's impact on TPS compliance, see our detailed article: How the Data Use and Access Act 2025 Changes TPS Compliance.
2. The ICO's growing concern about robocalls and AI-driven telemarketing
The September 2025 enforcement against Green Spark Energy and Home Improvement Marketing was accompanied by a pointed public warning. The ICO urged the public to be "on their guard against unlawful robo calls," noting that avatar software is "making it harder for the public to spot automated calls and report them to the ICO."
The ICO published tips for identifying robocalls, including watching for delayed responses between statements, limited flexibility in conversations, identical voices across multiple calls, and artificially polished audio quality. These are not the concerns of a regulator focused solely on traditional cold calling. They signal awareness that telemarketing technology is evolving faster than current guidance addresses.
This concern sits alongside the ICO's broader AI and biometrics strategy, launched in June 2025, which prioritises scrutiny of AI applications in three situations: where stakes are high, where there is clear public concern, and where regulatory clarity can provide immediate impact. AI-driven telemarketing ticks all three boxes.
3. The ICO's institutional transformation
The DUA Act does not just give the ICO new powers. It restructures the regulator itself. The Act establishes the Information Commission as a statutory corporate body to replace the current Information Commissioner's Office, introducing a board governance model with enhanced accountability mechanisms.
This restructuring means a regulator with broader institutional capacity and more formalised enforcement processes. The separate PECR fining guidance the ICO plans to publish is one manifestation of this more structured approach. For an overview of the full 2026 regulatory landscape, including what is coming next, see our regulations update.
Key changes businesses should prepare for
While the updated ICO guidance has not yet been published, the legislative changes are already in force, and the ICO's consultation documents and enforcement patterns make the direction of travel clear.
Attempted calls are now PECR breaches
This is the single most operationally significant change. Under the amended PECR definitions, a "call" includes any attempt to establish a connection, regardless of whether the recipient answers. If you load a TPS-registered number into an auto-dialler and the system dials it, that is a breach -- even if the call rings out, goes to voicemail, or is immediately disconnected.
For any business using predictive or automated dialling, this means every number must be screened against TPS and CTPS before it enters the dialler. Not after the first attempt. Not once an agent connects. Before the system makes any attempt at all.
The consent bar is higher in practice
The ICO's January 2026 enforcement against ZMLUK Limited reinforced a key principle: consent obtained through a list of 361 "partner" companies with no mechanism for individual selection is not valid consent. Andy Curry, the ICO's Head of Investigations, stated: "businesses must only send marketing messages to people who have freely and knowingly consented to receiving them."
If you are relying on third-party consent to call TPS-registered numbers, review those consent records now. The ICO is applying a strict standard: consent must name your organisation, must cover marketing calls specifically, and must represent a genuine, informed choice by the individual.
Separate PECR fining guidance is coming
The ICO's announcement that it will publish dedicated fining guidance for PECR, reflecting case law from direct marketing tribunal cases, signals a more systematic approach to penalty calculation. This is likely to produce more predictable but potentially larger fines, calibrated to the new £17.5 million ceiling.
The enforcement toolkit is broader
The ICO can now compel witnesses, demand technical reports, and issue information notices with the same force as in UK GDPR investigations. When the ICO investigates a suspected TPS violation, it can require your staff to attend interviews under caution, and providing false statements is a criminal offence. The days of half-hearted cooperation with ICO enquiries are over.
The new enforcement landscape
The numbers tell the story. Since April 2023, the ICO has issued more than £2.59 million in fines for nuisance calls, texts, and emails. Every one of those fines was imposed under the old £500,000 per-entity maximum. Under the new regime, the same conduct could attract penalties many times larger.
| Period | Old regime (pre-Feb 2026) | New regime (post-Feb 2026) |
|---|---|---|
| Maximum fine | £500,000 | £17.5 million or 4% of turnover |
| Increase | -- | 35x |
| Attempted calls | Not explicitly covered | A breach even if unanswered |
| Investigative powers | Limited | Compel witnesses, demand reports |
| PECR alignment | Standalone cap | Aligned with UK GDPR |
The ICO was already pushing against the old cap. In the Green Spark Energy case, two connected companies received combined penalties of £550,000, with the regulator effectively working around the per-entity limit by fining linked businesses separately. The new ceiling removes that constraint entirely.
No fine has yet been issued under the new £17.5 million regime, as the provisions only came into force on 5 February 2026. But the first cases will set the tone, and the ICO's track record leaves no reason to expect leniency.
Specific guidance on cold calling compliance
Whether or not you wait for the ICO's updated guidance document, the underlying legal requirements are already in force. Here is what PECR requires of every business making marketing calls in the UK.
TPS and CTPS screening
You must check every phone number against both the TPS and CTPS registers before making any unsolicited direct marketing call. This is a legal obligation under Regulation 21 of PECR, not a best practice suggestion. A single API call through TPSCheck checks both registers simultaneously.
For the full legal position on what constitutes a marketing call and when you can and cannot make one, see our guide: Are Cold Calls Illegal in the UK? What the Law Actually Says.
The 28-day re-check requirement
TPS registrations take up to 28 days to become active. The ICO recommends re-screening calling lists at least every 28 days to ensure you are not calling numbers where registrations have become active since your last check. After 28 days, you lose the statutory defence provided by Regulation 21.
With fines now reaching £17.5 million, the cost of working with stale data has increased dramatically. If your last TPS check is more than 28 days old, you are carrying significant and quantifiable compliance risk. For a detailed breakdown of this requirement, see The 28-Day TPS Re-Check Rule Explained.
Consent standards
If you are calling TPS-registered numbers on the basis of consent, that consent must be:
- Specific -- it must name your organisation explicitly
- Informed -- it must make clear that you will make marketing calls
- Freely given -- no pre-ticked boxes or bundled consent with 361 other companies
- Demonstrable -- you must be able to produce evidence if the ICO asks
- Current -- consent can be withdrawn at any time
The ICO's enforcement record shows that vague, third-party, or bundled consent is consistently rejected as a defence.
Record-keeping and audit trails
The ICO's enhanced investigative powers make audit trails more important than ever. You need timestamped records showing which numbers were checked, when, and what results were returned. "We check TPS" is not evidence. A timestamped audit log is.
TPSCheck's Pro plan and above log every check automatically with exportable compliance reports in CSV and PDF formats. See our documentation for details on how audit data is structured.
What this means for different sectors
The ICO's updated guidance will apply across all industries, but some sectors face heightened risk based on enforcement patterns and operational characteristics.
Call centres
Call centres are disproportionately represented in ICO enforcement actions. Volume multiplies exposure: a 1% screening failure rate at 5,000 calls per day means dozens of potentially unlawful calls daily. With attempted calls now counting as breaches, every number loaded into a dialler must be pre-screened.
The ICO's enforcement against Outsource Strategies Ltd demonstrated that having compliance procedures on paper is not enough. The company's own internal suppression systems flagged 141,914 numbers as "do not call," but the calls were made anyway. The ICO fined them £240,000.
For a complete compliance framework tailored to call centre operations, see TPS Compliance for Call Centres: A Practical Checklist.
Marketing agencies
Agencies face the dual challenge of managing compliance across multiple client accounts while bearing shared liability under PECR's instigator provisions. The ICO holds both the agency making the calls and the client who commissioned them responsible.
Data separation, per-client audit trails, and independent re-check schedules are not optional at agency scale. For detailed guidance on multi-client compliance workflows, see How Agencies Can Manage TPS Compliance for Multiple Clients.
B2B telemarketing
Businesses calling other businesses must screen against the CTPS register. The common misconception that B2B calls are exempt from TPS rules is wrong. Sole traders, partnerships, and small businesses are protected by both TPS and CTPS, and the ICO makes no enforcement distinction based on the nature of the called party.
High-risk sectors
The ICO's enforcement data shows clear patterns. Sectors most frequently subject to enforcement action include home improvements, energy, financial services, telecoms, and insurance. If your business operates in any of these sectors, you are already in the ICO's line of sight, and the updated guidance is likely to reflect continued focus on these areas.
Practical steps to prepare
The ICO's updated guidance is expected in spring 2026. But waiting for publication before acting would be a mistake. The legislative changes are already in force, the enforcement powers are already active, and the ICO is already issuing fines and securing criminal convictions. Here is what to do now.
Immediate actions
-
Audit your TPS/CTPS screening process. When was every number on your calling list last checked? If you cannot answer that question with a specific date for each number, you have a gap that needs closing.
-
Implement automated screening. Manual checking does not scale and creates gaps. Use an API-based TPS checking service that screens numbers in real time or in bulk before every campaign. TPSCheck's batch API processes up to 100 numbers per request.
-
Establish a 28-day re-check cycle. Set up automated re-screening of your active calling database at least every 28 days. Setting an internal deadline of 25 days provides a buffer for operational delays.
-
Review your consent records. If you are relying on consent to call TPS-registered numbers, verify that it meets the standard the ICO is enforcing: specific to your organisation, specific to marketing calls, demonstrable, and current.
-
Screen before loading diallers. With attempted calls now counting as breaches, no number should enter an auto-dialler or predictive dialler without a current TPS/CTPS check result.
Operational changes
-
Update your risk assessment. If your last PECR risk assessment was based on a £500,000 maximum fine, it is out of date. Recalculate your exposure under the £17.5 million ceiling.
-
Train your team. Everyone involved in outbound calling needs to understand that the maximum penalty has increased thirty-five-fold, that attempted calls count, and that the ICO can now compel witnesses and demand technical reports.
-
Review third-party data sources. If you purchase or receive calling lists from third parties, verify that TPS/CTPS screening was conducted within the last 28 days. Better yet, re-screen the data yourself before use. The ICO has consistently rejected the defence that a third party was responsible for screening failures.
-
Build audit trails into your workflow. Every TPS check should be logged automatically with a timestamp and result. TPSCheck does this on Pro plans and above, with retention periods from 90 days to 24 months depending on plan level.
Governance
-
Assign PECR compliance ownership. Someone in your organisation should be explicitly responsible for direct marketing compliance, with authority to halt campaigns that fail screening.
-
Prepare for the updated guidance. When the ICO publishes its spring 2026 guidance, review it against your current processes. The guidance will set the benchmark against which the ICO assesses compliance, and any gaps between your processes and the ICO's expectations will represent regulatory risk.
-
Monitor the first fines under the new regime. The ICO's initial penalties under the £17.5 million ceiling will establish the new baseline. Pay attention to the sectors targeted, the penalty calculation methodology, and the compliance failures that attracted enforcement action.
How TPSCheck helps
TPSCheck is built for the compliance environment the ICO is now enforcing. Every feature maps to a specific regulatory requirement.
- Instant TPS and CTPS screening -- check any UK phone number against both registers via a single API call, meeting the Regulation 21 screening obligation
- Batch checking -- screen up to 100 numbers per request, making pre-campaign and 28-day re-checks practical at any scale
- Automatic audit logs -- every check is timestamped and recorded without manual intervention, producing the evidence trail the ICO expects
- 28-day compliance tracking -- built-in dashboard on Growth plans and above that monitors when numbers are due for re-checking
- Compliance reports -- exportable PDF and CSV reports for ICO audits, client reporting, and internal compliance reviews
- Multiple API keys -- separate credentials per client or campaign for agencies and call centres managing multiple accounts
Plans start at £29/month for 10,000 checks, with a free tier offering 50 checks per month and full API access. No credit card required. Pay-as-you-go credit packs are available from £4 for 1,000 checks for one-off projects.
View all plans and start your free account or read the API documentation to see how TPS checking integrates with your existing systems.
Summary
The ICO is not making a single dramatic announcement about cold calling. It is doing something more consequential: systematically rebuilding the entire enforcement framework for direct marketing compliance. Updated PECR guidance due in spring 2026, separate PECR fining guidance in development, new enforcement procedural guidance following public consultation, and the full legislative weight of the Data (Use and Access) Act 2025 now in force.
The signals are clear:
- Maximum fines have increased from £500,000 to £17.5 million, a thirty-five-fold increase now in effect
- Attempted calls are now PECR breaches, with immediate implications for auto-dialler operations
- Updated ICO guidance on direct marketing and PECR is being redrafted and due in spring 2026
- Separate PECR fining guidance is planned, reflecting case law from direct marketing tribunal cases
- New enforcement powers allow the ICO to compel witnesses and demand technical reports
- Enforcement has not paused -- £225,000 in fines in January 2026, criminal convictions in February 2026
- AI-driven robocalls are on the ICO's radar, with public warnings and enforcement action against avatar software
The cost of compliance is negligible compared to the cost of getting it wrong. A TPS check costs pennies. A fine under the new regime could cost millions. The ICO's guidance refresh is your opportunity to get ahead of the new enforcement baseline rather than being caught behind it.
Start checking numbers for free -- 50 checks per month, no credit card required.
This article is for general information purposes and does not constitute legal advice. For specific guidance on your obligations under PECR and the Data (Use and Access) Act 2025, consult a qualified legal professional. TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).