ICO issues landmark fine for unlawful marketing messages

Published on 18 September 2026

The question

How does the Information Commissioner’s Office’s (ICO) largest ever nuisance marketing fine (£300,000) serve as a reminder to all organisations about the risks of using third-party data for large-scale direct marketing campaigns?

The key takeaway

Through its enforcement action, the ICO is seeking to remind organisations that they must adhere to the rules when it comes to ensuring that personal data is accurate and up to date and that valid consent from recipients has been obtained (unless an exception to the consent requirement applies). Particular care should be taken if using bought-in marketing lists to check they can lawfully be used for direct marketing.

The background

The ICO has fined KRA Consultancy (KRA) £300,000 and issued an enforcement notice against it for sending over 5.5 million unsolicited direct marketing texts between 2022 and 2025. The mass messaging operation (which promoted debt solutions) targeted people experiencing financial difficulty and who had previously been denied loans. Many of the texts were designed to intimidate recipients and coerce them into engaging with the company’s debt services, including by impersonating bailiffs. The texts (which disguised the sender’s identity) caused distress to some recipients and led to over 60,000 complaints.

The development

The ICO’s investigation into KRA revealed that:

  • the organisation had been using third-party data specifically to target individuals who had been refused loans
  • no attempt had been made to verify the accuracy of the information about these individuals or whether it was up to date (some of the information may have been three years old)
  • KRA did not have valid consent from the recipients to send the direct marketing messages to them and no attempt was made to check that the marketing lists it obtained could be used lawfully
  • KRA concealed its identity and failed to give its address in its marketing messages.

The ICO found that the campaign had sought to exploit vulnerable individuals and actively evade detection by sending texts which it sought to ensure were “completely untraceable”.

The £300,000 fine is one of the largest ever handed out by the ICO for nuisance marketing and is accompanied by an enforcement notice prohibiting KRA (unless it has a valid “soft opt-in”) from sending direct marketing messages without consent and from concealing its identity in marketing messages. It must also provide certain required details, including a valid address for KRA to enable recipients to withdraw consent to direct marketing.

Why is this important?

Businesses should be particularly alive to the risks of relying on third-party marketing lists for direct marketing messages at scale. They should carry out due diligence to ensure that such lists can be used lawfully and that “freely given, specific, informed” consent to direct marketing has been unambiguously given, that the consent was given sufficiently recently to validly be used and that the information being provided is accurate and up to date. In addition, messages should not be designed to cause alarm or coerce individuals into purchasing goods or services.

The ICO’s investigation into KRA began after information about it was obtained from search warrants executed during another investigation. The ICO’s use of search warrants in this investigation (of both business and residential premises) reflects a broader trend in its enforcement action, as seen in its recent investigation of car finance complaints.

Companies breaching the rules on direct marketing may face sanctions from the ICO, including enforcement orders (eg to prohibit use of the relevant marketing list) and fines of up to £17.5 million or 4% of global annual turnover (whichever is higher), as well as potential claims from individuals and, in certain circumstances, criminal liability.

Any practical tips?

Organisations should consider:

  • carrying out “rigorous checks” on marketing lists obtained from third party data providers to ensure they are accurate and up to date and that informed, specific consent for direct marketing has been given
  • providing their identity and a valid contact address in marketing messages
  • reviewing, and if necessary renegotiating, service contracts to ensure that third party data providers have given warranties in respect of compliance with direct marketing law, and
  • implementing internal policies requiring direct marketing campaigns to be proportionate and responsible, including considering the impact of direct marketing messages on vulnerable people.

Autumn 2026

Stay connected and subscribe to our latest insights and views 

Subscribe Here