Skip to main content
TPSCheck Blog
What Happens If You Ignore TPS? ICO Fines, Enforcement, and Real Cases

What Happens If You Ignore TPS? ICO Fines, Enforcement, and Real Cases

Every day, UK businesses make marketing calls to phone numbers registered on the Telephone Preference Service. Some do it knowingly. Many do it by accident. Either way, the Information Commissioner's Office does not distinguish between the two.

The consequences are the same: investigations, monetary penalties, enforcement notices, and public naming. And as of February 2026, the maximum fines have increased thirty-five-fold.

This article sets out what the ICO can actually do when businesses ignore TPS rules, what has happened to companies that got it wrong, and what you should be doing to avoid joining that list.

Why TPS compliance matters

The Telephone Preference Service (TPS) is the UK's official register of people who have opted out of receiving unsolicited marketing calls. Its corporate equivalent, the CTPS, covers business numbers. Together, they represent millions of UK phone numbers that are legally off-limits to cold callers.

Under Regulation 21 of the Privacy and Electronic Communications Regulations 2003 (PECR), it is unlawful to make unsolicited direct marketing calls to individuals who are registered with the TPS, unless you have their specific, informed prior consent.

This is not guidance. It is the law. And the regulator responsible for enforcing it is the ICO.

For a more detailed overview of TPS and CTPS obligations, see our product guide.


What the ICO can do

The ICO has a range of enforcement tools available when it finds that a business has breached PECR's marketing rules. These include:

Monetary penalties

The ICO can issue fines to organisations that make unsolicited marketing calls to TPS-registered numbers without valid consent. Until recently, the maximum fine under PECR was £500,000 -- already enough to threaten the viability of most small and medium-sized businesses.

The new regime: fines up to £17.5 million

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Its enforcement provisions for PECR came into force on 5 February 2026, bringing maximum fines into line with the UK GDPR regime.

The new maximum penalty for PECR breaches is now:

  • £17.5 million, or
  • 4% of annual global turnover

Whichever is higher.

This is a fundamental shift. Every enforcement case discussed in this article was decided under the old £500,000 cap. Under the new regime, the same conduct could result in penalties many times larger.

Enforcement notices

Alongside fines, the ICO can issue enforcement notices that legally compel a business to stop specific activities, such as making marketing calls to TPS-registered numbers. Breaching an enforcement notice is a criminal offence.

Public disclosure

All ICO enforcement actions are published on its website. The company name, the fine amount, and the details of what went wrong are all made public. For businesses that rely on trust and reputation, the reputational damage can be as costly as the fine itself.

Criminal prosecution

In the most serious cases, the ICO can pursue criminal prosecution. While this is rare for PECR breaches alone, it remains an option, particularly where companies have deliberately evaded detection or breached enforcement notices.


Real enforcement cases: what actually happened

The following cases are all drawn from published ICO enforcement actions. The fines, call volumes, and company details are a matter of public record.

It is important to note that every fine listed below was issued under the old £500,000 maximum. Under the new regime that came into force in February 2026, the same conduct could attract penalties of up to £17.5 million.


Outsource Strategies Ltd and Dr Telemarketing Ltd -- £340,000 (April 2024)

What happened: Between February 2021 and March 2022, these two connected companies made almost 1.43 million unwanted marketing calls to people registered with the TPS.

  • Outsource Strategies Ltd (Cardiff) made 1,346,503 calls and received 74 complaints
  • Dr Telemarketing Ltd (London) made 80,240 calls and received 2 complaints

What went wrong: The ICO found that both companies used aggressive sales tactics and specifically targeted elderly and vulnerable individuals. Outsource Strategies still made 141,914 calls to numbers flagged as "do not call" on its own internal systems -- meaning even their own suppression processes were either ignored or inadequate.

The penalties: Outsource Strategies was fined £240,000. Dr Telemarketing was fined £100,000. Both received enforcement notices.

Aftermath: Outsource Strategies appealed the decision. Dr Telemarketing refused to engage with the ICO and has not paid its fine. The ICO is pursuing financial recovery.

Andy Curry, then Head of Investigations at the ICO, stated: "All the people targeted by these nuisance calls should not have been called in the first place."


Poxell Ltd and Skean Homes Ltd -- £250,000 (January 2024)

What happened: Between March and July 2022, these two home improvement companies made a combined 3.2 million unsolicited marketing calls to TPS-registered numbers.

  • Poxell Ltd made over 2.6 million calls, generating 413 complaints
  • Skean Homes Ltd made over 614,000 calls, generating 31 complaints

What went wrong: Poxell deliberately purchased multiple telephone lines to obscure its identity and evade detection. Its communications provider eventually terminated its account. The company promoted energy-saving products such as double glazing and resin driveways using aggressive tactics. Complainants reported being called repeatedly despite asking to be removed from lists.

Skean Homes used false company names including "Eco Hub," "Driveway Solutions," and "Eco Driveways," and falsely claimed affiliation with local councils. When challenged, it blamed a third-party lead generation provider. The ICO found no evidence to support that claim.

The penalties: Poxell was fined £150,000. Skean Homes was fined £100,000. Both received enforcement notices.


Green Spark Energy Ltd and Home Improvement Marketing Ltd -- £550,000 (September 2025)

What happened: Green Spark Energy (Durham) instigated the transmission of 9.5 million automated marketing calls between May 2023 and May 2024. Home Improvement Marketing (Pembrokeshire) made 2.4 million calls. Combined, that is nearly 12 million unlawful calls.

What went wrong: Both companies used avatar software with pre-recorded voice actors who introduced themselves as "Jo," "Helen," and "Ian," giving recipients the impression they were speaking to a real person in the UK. In reality, the calls were activated by agents abroad.

The recordings contained misleading statements designed to alarm homeowners, including claims that their existing loft insulation was likely to cause serious health problems. Nearly 500 people contacted the ICO or TPS to complain, including elderly and vulnerable individuals.

Both companies shared a common director.

The penalties: Green Spark Energy was fined £250,000. Home Improvement Marketing was fined £300,000. Both received enforcement notices.


WerepairUK Ltd and Service Box Group Ltd -- £120,000 (October 2024)

What happened: WerepairUK (Tonbridge) made 42,688 unsolicited calls to TPS-registered numbers. Service Box Group (East Sussex) made 5,361 calls.

What went wrong: Both companies targeted vulnerable populations, particularly older adults, with repeated calls selling white goods warranties and boiler policies. The ICO's investigation found evidence that individuals with dementia were called and sold policies they neither needed nor understood.

The penalties: WerepairUK was fined £80,000. Service Box Group was fined £40,000. These fines brought the total penalties in this particular enforcement wave to £1.57 million.

Andy Curry described the conduct as "deeply exploitative" and emphasised the ICO's "commitment to protecting the public, especially those who may not be in a position to defend themselves."


AFK Letters Co Ltd -- £90,000 (April 2025)

What happened: AFK made 95,277 unsolicited marketing calls to TPS-registered individuals between January and September 2023.

What went wrong: AFK could not demonstrate valid consent for any of the calls. The third-party consent statements it relied on did not specifically name AFK as a company that would contact people. Its own privacy policy mentioned only email contact, not phone calls.

When challenged, AFK claimed it deleted customer data after three months, which conveniently prevented the ICO from verifying consent records. However, the company was unable to produce consent evidence even for calls made within that three-month window.

The penalty: AFK was fined £90,000.

Andy Curry's response was direct: "If you cannot demonstrate valid consent for people on the TPS, you should not be contacting people. Consent must be absolutely clear about what it is for."


The pattern: how complaints become investigations

A common misconception is that the ICO proactively monitors businesses for TPS compliance. It does not. Investigations typically begin through one of these routes:

  1. Public complaints. When consumers report unwanted calls through the ICO's online reporting tool or to the TPS itself, those complaints accumulate against specific phone numbers and companies.

  2. Complaint trend analysis. The ICO analyses complaint data to identify patterns, particularly in high-risk sectors such as energy, home improvements, and financial services.

  3. Cross-referrals. A company may come to the ICO's attention during an investigation into another business. Several of the cases above involved connected companies or shared directors.

  4. Telecommunications provider reports. In extreme cases, providers themselves flag suspicious calling patterns.

The process is not instant. Investigations can take months. But when the ICO does act, the fines are substantial and the records are permanent.

Here is what is worth noting: the cases above involved complaint volumes ranging from just 2 complaints (Dr Telemarketing) to 497 complaints (Green Spark Energy). There is no safe number of complaints below which you are invisible to the regulator. Even a small number of complaints, combined with evidence of systemic non-compliance, can trigger enforcement action.


How fines are calculated

The ICO considers several factors when determining the size of a monetary penalty:

  • Volume of calls made to TPS-registered numbers
  • Whether vulnerable people were targeted (this is treated as an aggravating factor)
  • Whether the company took deliberate steps to evade detection, such as using multiple phone lines or false business names
  • The number of complaints received by the ICO and TPS
  • Whether the company cooperated with the investigation
  • Whether the company had adequate compliance procedures in place
  • The company's financial position and ability to pay

Under the old regime, fines ranged from tens of thousands of pounds to the £500,000 maximum. The new £17.5 million ceiling gives the ICO significantly more headroom, particularly when dealing with larger organisations.

The argument "we did not know" has never worked as a defence. Ignorance of TPS obligations is not a mitigating factor. The ICO expects every organisation that makes marketing calls to be aware of its legal responsibilities under PECR and to have processes in place to screen numbers before calling.


Sectors most at risk

While any business that makes marketing calls can fall foul of TPS rules, ICO enforcement data shows clear patterns. The sectors most frequently targeted by enforcement action include:

  • Home improvements (double glazing, insulation, driveways)
  • Energy (green energy, boiler installations)
  • Financial services (claims management, pensions, debt solutions)
  • Telecoms (broadband, mobile contracts)
  • Insurance (warranties, appliance cover)

If your business operates in any of these sectors, you are already in the ICO's line of sight.


How to protect your business

TPS compliance is not complicated. It requires consistent processes, not expensive technology. Here are the practical steps every business making marketing calls should follow:

1. Screen every number before calling

Check all phone numbers against both TPS and CTPS registers before making marketing calls. This is a legal requirement, not a best practice suggestion. Services like TPSCheck let you verify numbers individually or in bulk via API, making it straightforward to integrate screening into your existing workflows.

2. Re-check at least every 28 days

TPS registrations change daily. ICO guidance is clear: you must re-screen your calling lists at least every 28 days. A number that was safe to call last month may not be safe today.

3. Maintain consent records

If you are relying on consent to call TPS-registered numbers, that consent must be specific, informed, and demonstrable. It must name your organisation. It must cover phone calls specifically. And you must be able to produce evidence of it when asked. The AFK case above shows exactly what happens when you cannot.

4. Keep audit trails

Record when you checked each number, what the result was, and what action you took. If the ICO ever investigates, you will need to demonstrate that you had proper procedures in place and followed them. Compliance reports and audit logs are your evidence. TPSCheck's Pro plan and above include audit logs and downloadable compliance reports for exactly this purpose.

5. Train your team

Everyone involved in marketing calls needs to understand TPS obligations. This includes call centre staff, marketing managers, and any third parties making calls on your behalf. You are responsible for calls made in your name, even if outsourced.

6. Do not rely on third-party excuses

The ICO has repeatedly rejected the defence that a third-party lead generator or dialler platform was responsible for TPS breaches. If calls are made on your behalf, you are the instigator, and you bear the regulatory risk.

7. Take complaints seriously

If someone complains about receiving an unwanted call, treat it as an early warning. Investigate how the call was made, whether the number was screened, and whether your processes failed. A single complaint can be the start of an ICO investigation.


The cost of compliance vs. the cost of a fine

To put the numbers in perspective:

  • A TPS check through TPSCheck costs as little as £0.0015 per number on high-volume plans
  • Checking 10,000 numbers costs £29 per month on a Starter plan
  • The lowest fine in the cases above was £40,000
  • The highest was £300,000 -- under the old regime
  • Under the new regime, the maximum is £17.5 million

The maths is straightforward. Screening your call lists is not just a legal obligation. It is the cheapest insurance policy your business will ever buy.

View TPSCheck pricing to find a plan that fits your volume.


Summary

The ICO has issued millions of pounds in fines to UK businesses for calling TPS-registered numbers. The companies penalised range from small operations making a few thousand calls to larger organisations making millions. The common thread is not scale -- it is negligence.

Since 5 February 2026, the stakes have risen dramatically. Maximum fines have increased from £500,000 to £17.5 million or 4% of global turnover. The ICO now has the same enforcement teeth for PECR breaches as it does for UK GDPR violations.

The law is clear. The enforcement record is public. The tools to comply are accessible and affordable. The only real question is whether you choose to use them.


TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).