ICO Fines Pendant Alarm Company £100,000 for Unlawful Marketing Calls

Share this Article:

The Information Commissioner’s Office (ICO) has issued a £100,000 fine to a Birmingham-based pendant alarm company after serious breaches of marketing rules under PECR.

The company made over 260,000 unsolicited marketing calls over a seven-month period, targeting individuals registered with the Telephone Preference Service (TPS).

This case is a clear reminder that misuse of personal data for marketing purposes remains a key enforcement priority for the ICO and one where organisations have very little room for error.

What Happened?

The ICO’s investigation found that TMAC Ltd carried out large-scale unlawful marketing activity between February and September 2024.

The organisation:

  • Made over 260,000 marketing calls to TPS-registered numbers

  • Used misleading and false identities when speaking to individuals

  • Targeted vulnerable groups, including people aged over 60

  • Used second-hand data obtained from another company

Call transcripts revealed that employees claimed to be calling on behalf of crime prevention and fire safety initiatives, rather than identifying the company directly.

This was not a technical breach or oversight. The activity was deliberate, repeated and carried out at scale.

Why This Matters

The rules around marketing calls are well established. Under PECR, organisations must not contact individuals registered with the TPS unless they have clear and valid consent.

They must also:

  • Identify who they are when making a call

  • Provide accurate contact details

  • Check their data has been obtained lawfully

Failing to meet these requirements is a direct breach of the law.

The ICO has made it clear that where organisations ignore these rules, enforcement action will follow.

There Is Very Little Margin for Error

PECR has been in place since 2003, and the expectations on organisations are not new.

If your business is making marketing calls, you are expected to:

  • Screen data against the TPS

  • Understand where your data has come from

  • Ensure valid consent is in place

  • Be transparent about who is making the call

If you are found to be in breach, “not knowing” or relying on third-party data will not be accepted as a defence.

In most cases, organisations are held fully accountable for their marketing practices.

The Risk Has Increased

Recent changes introduced under the Data (Use and Access) Act 2025 (DUAA) have significantly increased the potential penalties for PECR breaches.

Fines are no longer capped at £500,000. They are now aligned with UK GDPR levels, meaning organisations could face penalties of up to £17.5 million or 4% of global annual turnover.

This brings marketing compliance into the same high-risk category as broader data protection obligations.

Key Lessons for Organisations

This case highlights several critical risks:

  • Using third-party or second-hand data does not remove your responsibility for compliance

  • Contacting TPS-registered individuals without consent is a clear breach

  • Misleading individuals about your identity significantly increases enforcement risk

  • High-volume activity increases both visibility and the scale of potential penalties

Put simply, if your marketing activity is not compliant, the risk is real and regularly enforced by the ICO.

Practical Questions for Organisations

If your organisation carries out marketing activity, you should be asking:

  • Do we have valid consent for all marketing communications?

  • Are we screening our data against the TPS register correctly?

  • Do we fully understand the source of our data?

  • Are we confident that any third-party data we use is compliant?

  • Are our teams trained to follow PECR requirements in practice?

If there is any uncertainty around these points, there is a clear risk of non-compliance.

Need Support Reviewing Your Approach?

For organisations that rely on marketing data, getting this right is essential.

At Privacy Helper, our consulting team includes specialists in marketing compliance who support call centres and data-driven organisations in operating with confidence.

We help businesses review data sources, assess consent mechanisms and implement compliant processes aligned with PECR requirements.

With enforcement increasing and penalties now significantly higher, taking action early is absolutely critical.

Contact us today to discuss how we can help you reduce risk and make sure your marketing practices are fully compliant.

About the Author:

Explore More Articles