PECR fines just quadrupled to £17.5M -- what the DUAA changes mean for cleansing a UK B2B database

The Data (Use and Access) Act 2025 raised the maximum fine under the UK's Privacy and Electronic Communications Regulations from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher -- the same ceiling that applies under UK GDPR. That change has been in force since 5 February 2026, and for any company running B2B email or calling campaigns off a UK contact database, it turns PECR from a regulation with a fine most companies could absorb into one with the same exposure as a full GDPR breach.
PECR has always drawn a distinction that GDPR doesn't: Regulation 22 treats individual subscribers and corporate subscribers differently, and B2B marketing has historically leaned on that distinction to justify a lighter consent standard for a role-based business email address than for a personal one. That distinction hasn't disappeared under the DUAA, but the stakes for getting the lawful basis wrong on a corporate record are now high enough that a legitimate interest assessment documented at the point a contact enters the database -- not retrofitted after the fact -- is worth the time it takes.
The DUAA's second change is the one most UK data-cleansing processes aren't built for yet: PECR's scope now extends to "intended recipients," not just contacts who actually received a message. A dead, bounced, or unreachable record sitting uncleaned in the database used to be treated purely as a deliverability drag -- wasted sends, a dented sender reputation. Under the expanded scope, that same stale record is now a direct compliance exposure in its own right, whether or not a message ever successfully reached it.
That reframes what a cleansing cycle is actually checking for. A process built around deliverability metrics alone -- bounce rate, open rate, spam complaints -- misses records that are technically deliverable but sitting on a stale or undocumented consent basis, which is exactly the gap the DUAA's expanded scope now penalizes. A cleansing cycle built for the post-February-2026 rules has to verify consent basis and currency together, not treat "the email still delivers" as evidence the record is fine.
We treat UK database cleansing as a compliance control now, not a hygiene task -- documenting the lawful basis behind every corporate record at the point of entry, and re-verifying both deliverability and consent currency on the same recurring cycle, because under a 35-fold increase in maximum exposure, the cost of getting this wrong changed more than the cost of doing it right.
Want help putting this into practice?
Our team runs these exact strategies for B2B clients every day, at a 94% success rate.
Talk to our team


