Cybersecurity Policy Report, U.K. Agency Fines Energy Company Over Solicitation Calls, (May 26, 2026)
By Tony Foley
The United Kingdom’s Information Commissioner’s Office has fined Energy Prices Direct Ltd. (EPDL) 160,000 pounds sterling ($215,000) for violations of the U.K.’s Privacy and Electronic Communications Regulations 2003 (PECR) related to unsolicited marketing calls.
EPDL made more than 700,000 unsolicited marketing sales calls to individuals and businesses between January 2024 and January 2025, the ICO said in a news release, adding that 30 complaints were filed with the Telephone Preference Service (TPS) and Corporate Telephone Preference Service (CTPS). The ICO’s investigation found that, in some cases, employees failed to identify themselves as being from the company when making the calls. In addition, the ICO discovered that the data used to make the calls had been purchased without establishing whether the numbers had been screened through the TPS and CTPS and that there were instances EPDL could not identify the source of the data they were using. Accordingly, the ICO issued a monetary penalty notice finding serious violations of regulations 21 and 24 of the PECR.
“This case highlights the importance of robust compliance checks when buying and using marketing data and we expect all organisations to have proper systems in place to prevent this level of unlawful marketing activity,” said Ann Curry, the ICO’s head of investigations. “Compliance with TPS and CTPS requirements is a legal obligation for all organisations conducting marketing calls.”
News: InternationalLegislation LitigationEnforcement DataPrivacy