What changed in 2025-2026
The headline change is the Data (Use and Access) Act 2025, but it is worth understanding the full sequence of events that brought us here.
The Data (Use and Access) Act 2025
The Data (Use and Access) Act received Royal Assent on 19 June 2025. It is the most significant overhaul of UK data protection and electronic communications law since Brexit. While the Act covers a broad range of subjects -- digital identity, smart data schemes, ICO governance reform -- the provisions that matter most for telemarketing compliance sit in Part 6, which amends PECR directly.
The PECR-related provisions came into force on 5 February 2026 through the Commencement No. 6 Regulations. For a detailed analysis of every provision, see our article: How the Data Use and Access Act 2025 Changes TPS Compliance.
The new fine regime
This is the change that demands attention. Under the old regime, the maximum fine the ICO could impose for a PECR breach was £500,000. That cap had been in place since 2003. It was widely regarded as insufficient, particularly for larger organisations that could absorb a six-figure penalty as a cost of doing business.
The new maximum penalty for PECR breaches, including failure to screen against TPS and CTPS, is:
- £17.5 million, or
- 4% of annual global turnover
Whichever is higher. This aligns PECR enforcement with UK GDPR penalties. Parliament has deliberately placed telemarketing non-compliance on the same footing as serious data protection violations.
Expanded definitions
The Data (Use and Access) Act did not just raise fines. It also tightened the definitions that underpin PECR. Three changes stand out:
"Call" now includes attempted calls. Under the old wording, PECR applied to calls that were connected. The amended definition captures any attempt to establish a connection via a telephone call, regardless of whether the recipient answers. Dialling a TPS-registered number is now a breach even if nobody picks up. For businesses using auto-diallers or predictive diallers, this has immediate operational implications.
"Communication" now covers transmitted messages. A marketing text sent to a TPS-registered number is a violation whether or not the recipient opens it.
"Recipient" now includes intended recipients. PECR protections apply to the person you intended to contact, not just the person who actually received the communication.
Enhanced ICO enforcement powers
The ICO has gained significantly stronger investigative tools under the new framework. It can now compel witness attendance at interviews with criminal penalties for false statements, require organisations to commission technical reports at their own expense, and apply the full range of Data Protection Act 2018 enforcement provisions to PECR breaches. The investigation of a suspected TPS violation can now be conducted with the same procedural toolkit used for serious UK GDPR breaches.
The ICO itself is also being restructured. The Act establishes the Information Commission as a statutory corporate body to replace the current Information Commissioner's Office, introducing a board governance model with enhanced accountability mechanisms. The practical effect is a regulator with broader institutional capacity and more formalised enforcement processes.
The current regulatory framework
Understanding TPS compliance in 2026 requires knowing how three pillars of regulation work together.
PECR: the foundation
The Privacy and Electronic Communications (EC Directive) Regulations 2003 remain the primary legislation governing marketing calls in the UK. Regulation 21 is the provision that matters: it makes it unlawful to make unsolicited direct marketing calls to numbers listed on the TPS register, unless the subscriber has given specific prior consent to be called by your organisation.
PECR also requires you to display a calling number, identify yourself to the person you are calling, and maintain your own suppression list of people who have asked you directly not to call. For a full breakdown of what PECR does and does not say about cold calling, see Are Cold Calls Illegal in the UK? What the Law Actually Says.
The Data (Use and Access) Act 2025: the enforcement upgrade
The DUA Act does not replace PECR. It amends it. The core obligations remain the same -- screen against TPS, do not call registered numbers without consent, maintain records. What has changed is the weight behind those obligations. Fines are higher, definitions are broader, and the regulator has more tools to investigate and prosecute breaches.
ICO guidance: the practical standard
The ICO publishes detailed guidance on how it interprets and enforces PECR's marketing rules. This guidance is not legislation, but it represents the regulator's expectations and is the benchmark against which your compliance processes will be assessed.
Critically, the ICO is currently redrafting its direct marketing and PECR guidance to incorporate the amendments from the Data (Use and Access) Act. The updated guidance is scheduled for publication in spring 2026. When it arrives, it will be the definitive statement of the ICO's enforcement approach under the new regime. Until then, existing guidance remains in force, supplemented by the Act itself.
Key requirements for businesses
If your organisation makes direct marketing calls in the UK, here is what the law requires of you in 2026. These are not recommendations or best practices. They are legal obligations under PECR, and failing to meet them can now attract penalties of up to £17.5 million.
1. Screen every number against TPS and CTPS before calling
This is the fundamental obligation. Before making any unsolicited direct marketing call, you must check the number against both the Telephone Preference Service (for individual consumers) and the Corporate Telephone Preference Service (for business numbers). If a number is registered, you must not call it unless you hold specific prior consent from that subscriber.
A single API call through TPSCheck checks both registers simultaneously, returning TPS and CTPS status alongside phone intelligence data. See the API documentation for integration details.
2. Re-screen at least every 28 days
People register with the TPS continuously. A number that was clear when you last checked it may have been registered since. The ICO recommends re-screening your calling lists at least every 28 days. This is based on the fact that TPS registrations can take up to 28 days to become active -- and Regulation 21 provides a statutory defence only for calls made to numbers listed for fewer than 28 days.
After that window, you are exposed. Setting an internal deadline of 25 days provides a safety buffer. For a full explanation of where the 28-day figure comes from and how to implement automated re-checking, see The 28-Day TPS Re-Check Rule Explained.
3. Hold valid consent if calling TPS-registered numbers
If you intend to call someone who is registered on the TPS, you need their specific prior consent. That consent must:
- Name your organisation -- generic third-party consent is not sufficient
- Cover marketing calls specifically -- not just "contact" or "communications"
- Be demonstrable -- you must be able to produce evidence if challenged
- Be current -- consent can be withdrawn at any time
The ICO has repeatedly penalised businesses that relied on vague or third-party consent statements. The AFK Letters Co case is a textbook example: the company was fined £90,000 because its consent records did not specifically name it as a caller, and it could not produce evidence even within its own data retention window.
4. Maintain your own suppression list
In addition to screening against TPS and CTPS, you must keep an internal record of individuals who have asked you directly not to call. This is a separate obligation under PECR Regulation 21. Even if someone is not on the TPS, if they have told you to stop calling, you must stop.
5. Keep auditable records
Log when you checked each number, what the result was, and what action you took. The ICO's enhanced investigative powers under the DUA Act mean that when an investigation begins, you will be expected to demonstrate your compliance processes in detail. A verbal assurance that "we check TPS regularly" is not evidence. Timestamped audit logs are.
TPSCheck's Pro plan and above include audit logs with exportable compliance reports for exactly this purpose.
6. Identify yourself and display your number
PECR requires that when you make a marketing call, you must display a calling number (or an alternative contact number), identify yourself promptly, and provide a contact address or freephone number if asked. Hiding your identity or using spoofed numbers is not just a PECR breach -- it is the kind of conduct that triggers the ICO's most aggressive enforcement responses.
The new penalty regime: what £17.5 million really means
It would be easy to dismiss the new maximum as a theoretical figure. That would be a mistake.
How it compares to the old regime
| Old regime (pre-Feb 2026) | New regime (post-Feb 2026) | |
|---|---|---|
| Maximum fine | £500,000 | £17.5 million or 4% of global turnover |
| Increase factor | -- | 35x |
| Alignment | Standalone PECR cap | Aligned with UK GDPR |
Every enforcement case decided before February 2026 was subject to the old cap. Under the new regime, the same conduct could attract penalties many times larger.
What enforcement looked like under the old regime
The ICO has a consistent track record of fining businesses for TPS violations. These cases, all decided under the old £500,000 maximum, illustrate the scale of enforcement that was already happening:
- Green Spark Energy and Home Improvement Marketing -- fined a combined £550,000 for instigating nearly 12 million automated marketing calls using pre-recorded messages and avatar software
- Outsource Strategies and Dr Telemarketing -- fined a combined £340,000 for 1.43 million calls to TPS-registered numbers, with deliberate targeting of elderly individuals
- Poxell and Skean Homes -- fined a combined £250,000 for 3.2 million unsolicited calls, with Poxell deliberately purchasing multiple phone lines to evade detection
- AFK Letters Co -- fined £90,000 for 95,277 calls without demonstrable consent
For a comprehensive breakdown of these cases and the ICO's fine calculation methodology, see What Happens If You Ignore TPS? ICO Fines, Enforcement, and Real Cases.
The January 2026 enforcement wave
Even in the final weeks of the old regime, the ICO remained active. In January 2026, two companies were fined a combined £225,000 for nuisance marketing messages. These fines were issued under the old cap -- but they signal clearly that the ICO's appetite for enforcement has not diminished as the new regime takes effect.
Why the new ceiling matters
Three factors make the £17.5 million maximum more than a theoretical number.
First, the ICO was already pushing against the old cap. In the Green Spark Energy case, two connected companies received combined penalties of £550,000 -- exceeding the per-entity maximum through the device of fining two linked businesses separately. The ICO was clearly constrained by the £500,000 limit and was finding ways to work around it.
Second, aligning PECR with UK GDPR signals parliamentary intent. The message to the regulator is explicit: treat direct marketing non-compliance with the same gravity as data protection violations. The ICO now has political cover to issue larger fines.
Third, the enhanced investigative powers allow stronger cases. The ability to compel witnesses, demand technical reports, and issue information notices means investigations can be more thorough and penalties more precisely calibrated to the scale of the offence.
No fine has yet been issued under the new regime -- the provisions only came into force on 5 February 2026. But the first cases will set the tone, and there is every reason to expect a step change in penalty levels.
What is coming next
The regulatory environment is not standing still. Here is what to watch for over the remainder of 2026.
Updated ICO guidance (spring 2026)
The ICO is currently redrafting its direct marketing and PECR guidance to incorporate the amendments from the Data (Use and Access) Act. Publication is targeted for spring 2026. This will be the first comprehensive guidance update since the new fine regime came into force, and it will set out the ICO's enforcement approach under the amended legislation. When it is published, review it carefully -- it will be the definitive reference for compliance expectations.
Remaining DUA Act provisions (June 2026)
Not all provisions of the Data (Use and Access) Act came into force on 5 February. Certain provisions around data subject complaints are expected to commence on 19 June 2026. While these are primarily data protection provisions rather than PECR-specific, they form part of the broader regulatory ecosystem that governs how you handle personal data in your marketing operations.
First enforcement actions under the new regime
The ICO's first fines under the £17.5 million ceiling will be closely watched by the industry. They will establish the new baseline for penalty levels and indicate how aggressively the ICO intends to use its expanded powers. If your compliance processes are not already in order, do not wait for these cases to provide motivation.
Potential PECR reform
The DUA Act amended PECR significantly, but it did not replace it. PECR dates from 2003 and was originally designed to implement an EU directive. There have been ongoing discussions about whether a more fundamental overhaul of electronic communications privacy regulation is needed. While no specific reform legislation has been announced, the topic remains on the policy agenda, particularly as the ICO and Ofcom have publicly flagged concerns about AI-driven telemarketing and robocalls.
How to stay compliant: a practical checklist
Compliance with TPS regulations in 2026 is not complicated. It requires consistent processes, not expensive technology. Here is what every business making marketing calls should have in place.
Immediate priorities
- Audit your current screening process. When was the last time every number on your calling list was checked against TPS and CTPS? If you cannot answer that with a specific date, you have a problem.
- Implement automated TPS/CTPS checking. Manual checking does not scale and creates gaps. Use an API-based service that screens numbers in real time or in bulk before every campaign.
- Establish a 28-day re-check cycle. Set up automated re-screening of your entire active calling database at least every 28 days. Do not wait for a campaign to trigger a re-check.
- Update your risk assessment. If your last PECR risk assessment was based on a £500,000 maximum fine, it is out of date. Recalculate your exposure under the new £17.5 million ceiling.
Operational essentials
- Screen before loading diallers. With attempted calls now counting as breaches, no number should enter an auto-dialler without a current TPS/CTPS check result.
- Review your consent records. If you are relying on consent to call TPS-registered numbers, ensure it meets the standard: specific to your organisation, specific to marketing calls, demonstrable, and current.
- Check your third-party data. If you purchase or receive calling lists from third parties, verify that TPS/CTPS screening was conducted within the last 28 days. Better yet, re-screen the data yourself.
- Train your team. Make sure everyone involved in outbound calling understands the new penalty levels and the expanded definition of "call."
Building an evidence base
- Log every check with a timestamp and result. TPSCheck's Pro plan and above do this automatically.
- Export compliance reports before and after campaigns.
- Assign compliance ownership. Someone in your organisation should be explicitly responsible for PECR compliance, with authority to halt campaigns that fail screening.
The cost of screening is negligible compared to the consequences of getting it wrong. A single TPS check costs pennies. A fine under the new regime could cost millions. The arithmetic has never been clearer.
For guidance specific to your operational context, see our articles on TPS compliance for call centres and managing TPS compliance across multiple clients.
Summary
The TPS regulatory landscape in 2026 looks fundamentally different from even a year ago. Here are the key points:
- The Data (Use and Access) Act 2025 came into force on 5 February 2026, bringing the most significant changes to PECR enforcement since the regulations were introduced in 2003
- Maximum fines increased from £500,000 to £17.5 million or 4% of global turnover, a thirty-five-fold increase
- The definition of "call" now includes attempted calls, meaning dialling a TPS-registered number is a breach even if nobody answers
- The ICO has enhanced investigative powers, including the ability to compel witnesses and demand technical reports
- Updated ICO guidance incorporating the DUA Act changes is expected in spring 2026
- All previous enforcement cases were decided under the old cap -- the new regime makes equivalent conduct significantly more expensive
- The core PECR obligations have not changed: screen against TPS and CTPS, re-check within 28 days, hold valid consent where required, maintain audit trails
The law has changed. If your compliance processes have not changed with it, now is the time.
Start your free TPSCheck account -- 50 checks per month, no credit card required. Or explore our API documentation to integrate TPS checking into your existing systems.
This article is for general information purposes and does not constitute legal advice. For specific guidance on your obligations under PECR and the Data (Use and Access) Act 2025, consult a qualified legal professional. TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).