The Information Commissioner’s Office (ICO) has issued a £300,000 fine to a Manchester-based firm after it sent millions of unlawful marketing texts to people already struggling with debt. The messages included fake bailiff threats designed to frighten recipients into responding.
This is one of the largest fines for nuisance marketing in recent years. It is a stark reminder that targeting vulnerable individuals with unlawful marketing carries serious consequences, and it shows just how little room for error there is under PECR.
What Happened?
The ICO’s investigation found that KRA Consultancy Ltd (KRA) carried out large-scale unlawful marketing between April 2022 and May 2025. The company:
- Sent 5,575,715 unsolicited direct marketing texts promoting debt solutions
- Deliberately targeted people who had already been turned down for loans and were in financial difficulty
- Generated more than 60,000 complaints to the ICO and Mobile UK’s 7726 spam reporting service
- Sent fabricated bailiff threats under the sender ID ‘DEMAND’, warning recipients that enforcement agents would attend their homes to remove goods
- Made no attempt to check whether its data was accurate or whether recipients had consented to receive marketing
Internal messages uncovered during the investigation showed the conduct was deliberate. The company’s director referred to the fake threats as “coaching”, and sought assurances from an overseas telecoms provider that the mass texts would be “completely untraceable”. When concerns were raised that the data was three years old, the director made clear the priority was profit, not compliance.
This was not a technical breach or an oversight. The activity was calculated, repeated and carried out at scale, and it continued even after search warrants were executed at the company’s offices and the director’s home, leading to a further 161 complaints.
Why This Matters
The rules around marketing texts are well established. Under the Privacy and Electronic Communications Regulations 2003 (PECR), organisations may only send marketing text messages where the recipient has clearly agreed to receive them, or where there is a genuine,
existing relationship.
Alongside the £300,000 penalty, the ICO issued an enforcement notice ordering the company to stop sending marketing messages without consent within 30 days. The company was also found not to be registered with the Financial Conduct Authority, despite directing people towards debt solutions.
Andy Curry, Head of Investigations at the ICO, said the scheme “caused real fear and distress to people who were already struggling with debt”, adding that the fine “should leave no doubt that we will pursue any company that thinks it can evade the law and prey on the public.”
Targeting Vulnerable People Increases the Risk
This case is a clear example of how the ICO views the targeting of vulnerable individuals. Marketing to people known to be in financial difficulty, and using fear-based tactics to provoke a response, significantly increases both the seriousness of the breach and the likely penalty.
Where organisations exploit vulnerability, ignore consent, or attempt to evade detection, enforcement action will follow.
The Risk Has Increased
Recent changes introduced under the Data (Use and Access) Act 2025 (DUAA) have significantly increased the potential penalties for PECR breaches. Fines are no longer capped at £500,000. They are now aligned with UK GDPR levels, meaning organisations could face penalties of up to £17.5 million or 4% of global annual turnover.
This brings marketing compliance firmly into the same high-risk category as wider data protection obligations.
Key Lessons for Organisations
This case highlights several critical risks:
- Consent is non-negotiable, marketing texts may only be sent to people who have
genuinely agreed to receive them - Using third-party or second-hand data does not remove your responsibility for compliance
- Targeting vulnerable individuals dramatically increases enforcement risk
- Misleading or fear-based messaging is treated as a serious aggravating factor
- High-volume activity increases both visibility and the scale of potential penalties
Practical Questions for Organisations
If your organisation carries out marketing activity, you should be asking:
- Do we have valid, recorded consent for all marketing communications?
- Do we fully understand where our data has come from, and when it was collected?
- Are we confident any third-party data we use was lawfully obtained?
- Could any of our messaging be seen as misleading or pressurising?
- Are our teams trained to follow PECR requirements in practice?
If there is any uncertainty around these points, there is a clear risk of non-compliance.
Need Support Reviewing Your Approach?
For organisations that rely on marketing data, getting this right is essential. At Privacy Helper, our consulting team includes specialists in marketing compliance who support call centres and data-driven organisations in operating with confidence.
We help businesses review data sources, assess consent mechanisms and implement compliant processes aligned with PECR requirements. With enforcement increasing and penalties now significantly higher, taking action now is the surest way to protect your organisation.
Get in touch with the Privacy Helper team to discuss how we can support your marketing compliance.





