PECR Fines and Enforcement: What the ICO Actually Cracks Down On
PECR enforcement has a very different pattern from GDPR enforcement, dominated for years by nuisance calls and texts, with cookie enforcement rising more recently. Here's what the ICO actually prioritizes.
If you only followed GDPR headlines, you’d expect PECR enforcement to look similar, big fines against recognizable companies for data misuse. It doesn’t. PECR enforcement has a genuinely different pattern, historically dominated by nuisance calls and texts rather than website cookie violations, though that’s shifted meaningfully in recent years. Understanding the actual pattern helps calibrate where your real exposure sits.
The historical center of gravity: nuisance calls and texts
For most of PECR’s enforcement history, the ICO’s largest and most frequent fines targeted:
- Claims management companies making unsolicited calls about PPI claims, accident claims, and similar services
- Automated marketing calls made without consent, at scale, often through outsourced call centers
- Unsolicited marketing texts, frequently tied to loan, insurance, or claims marketing
These enforcement actions frequently ran into the hundreds of thousands of pounds per case, and the common thread across nearly all of them was volume: businesses making tens of thousands to millions of unsolicited contacts without valid consent, not a single borderline email.
Why this category dominated for so long
Nuisance calls and texts generate direct, high-volume public complaints, people report unwanted calls to the ICO constantly, giving the regulator a steady, easily substantiated stream of enforcement leads. Cookie violations, by contrast, are largely invisible to an ordinary user unless they’re specifically checking dev tools, which historically made them harder to detect and prioritize at scale.
What’s changed more recently: rising cookie enforcement
The ICO has shifted meaningful attention toward cookie compliance in recent years, including public audits and warnings directed at major websites over non-compliant cookie banners, particularly around cookie walls and banners that made rejecting harder than accepting. This shift reflects both public pressure and the ICO’s own stated priorities around “conformance” campaigns targeting the most-visited UK websites first, then expanding scrutiny outward.
What this means for where your actual risk sits
- If you do outbound calling or SMS marketing, this remains the highest-enforcement-density category historically, and the bar for consent and Telephone Preference Service (TPS) screening is correspondingly strict.
- If you run a website with a cookie banner, your risk has risen relative to a few years ago, but enforcement still tends to start with warnings and corrective requests for first-time, non-systemic issues rather than jumping straight to a large fine, particularly for smaller sites without a pattern of complaints.
- Scale matters enormously either way. The consistent factor across nearly every large PECR fine is volume and repetition, a single mistaken send or one visitor’s complaint about a banner rarely triggers serious enforcement on its own; a systemic pattern, especially one continuing after a warning, is what escalates.
Usercentrics
Given that ICO cookie enforcement has shifted from spot-checks toward systematic sweeps of high-traffic sites, it's worth having an auditable record showing your consent controls were correctly configured over time, not just at the moment someone happens to check. Usercentrics' detailed consent reporting is built for exactly that kind of demonstrable compliance history.
What actually reduces enforcement risk in practice
- If you do any outbound marketing calls or texts, screen against the Telephone Preference Service and maintain documented consent records, this is the single highest-enforcement-density area historically.
- Fix known cookie banner gaps proactively, don’t wait for a complaint or a sweep to discover whether your reject button is genuinely equal to accept.
- Respond to ICO warnings immediately if you receive one. Continuing a flagged practice after a warning is one of the clearest aggravating factors across PECR enforcement history.
This analysis reflects general enforcement patterns and is not a guarantee about any regulator’s future priorities, and is not legal advice. Consult a privacy attorney for guidance on your specific risk profile.