ICO Fines Marketer £200,000 for PECR Breach

20th December 2025Photo by Lindsey LaMont on Unsplash

In September, the ICO issued a Monetary Penalty Notice against Mr Bharat Singh Chand for violating the PECR. Mr Chand is a sole trader who was responsible for distributing 1 million unsolicited ‘spam’ text messages. This case has several important lessons about marketing consent and compliance with data protection laws.

Case Details

The illegal activity of Mr Chand came to light during another ICO investigation into Daniel George Bentley, who was sending texts on behalf of Mr Chand. Bentley also provided advice to Mr Chand about using a SIM farm, or a device that contains multiple SIM cards and is capable of sending mass texts very quickly. Additionally, 19,138 complaints were made about Mr Chand’s spam texts to the 7726 spam reporting service.

Mr Chand is a sole trader operating out of Carmarthenshire who sent the text messages about debt solutions and energy saving grants, and had also been issued with an enforcement notice ordering him to stop sending marketing messages without consent. The text messages were sent anonymously, and stopping the messages was intentionally made difficult. The content of the text messages was also considered to be aggressive and disproportionately targeted towards vulnerable people in financial hardship. Here is an example of one such text message:

“Finding it hard to pay your Debts/Bills see if you can apply to write them off and freeze interest/ charges reply YES.” Source: Decision Marketing

These texts did not contain a website address or any information as to who the sender was. People who received these text messages and replied ‘YES’  then received phone calls from ‘The Debt Relief Team’, which they reported to the ICO and TPS.

The Investigation

The ICO was first alerted to Mr Chand’s activities during a previous investigation into Daniel George Bentley, who provided Mr Chand with advice on running a SIM farm, a device that can send hundreds of text messages at a time. On June 11th, 2024, the ICO carried out a search warrant on Mr Chand’s home address in Burry Port, Carmarthenshire, where he denied any involvement in marketing green energy schemes, even though a call script was out on display. The ICO found that Mr Chand was evading detection by giving fake business names. He also attempted to mislead the ICO during the course of their investigation, meaning that he likely knew that his actions were illegal. 

During the investigation, the ICO discovered that Mr Chand received a message advising him to lie to investigators following a letter sent by the ICO, saying:

“Ok pal, say you had an employee who was sourcing leads from an off shore centre without you knowing to get more commission but you sacked him when you found out”. Source: The ICO

Mr Chand was found to have sent 966,449 text messages between 3rd December 2023 and 3rd July 2024 without obtaining consent, which resulted in 19,138 complaints to the spam reporting service. He also used hundreds of unregistered prepaid SIM cards and did not identify the sender or instigator of the text messages. His actions violated Regulations 22 and 23 of PECR, and there is no evidence to suggest he took any steps to confirm that marketing consent had been properly obtained. He has subsequently been fined £200,000, which he is appealing at the time of writing, and also issued with an enforcement notice to cease his spam text activities- see the full enforcement notice from the ICO here.

The Law on Marketing Communications

Most individuals and organisations would not knowingly break the law in such an egregious manner as Mr Chand, but the lessons are still valid for all organisations that send electronic marketing communications, e.g. emails and texts. Regulations 22 and 23 of PECR state that:

“Except in the circumstances referred to in paragraph (3), a person shall neither transmit, nor instigate the transmission of, unsolicited communications for the purposes of direct marketing by means of electronic mail unless the recipient of the electronic mail has previously notified the sender that he consents for the time being to such communications being sent by, or at the instigation of, the sender.” Source: legislation.gov.uk

“A person shall neither transmit, nor instigate the transmission of, a communication for the purposes of direct marketing by means of electronic mail—

(a)where the identity of the person on whose behalf the communication has been sent has been disguised or concealed; F1…

(b)where a valid address to which the recipient of the communication may send a request that such communications cease has not been provided;

[F2(c)where that electronic mail would contravene regulation 7 of the Electronic Commerce (EC Directive) Regulations 2002; or

(d)where that electronic mail encourages recipients to visit websites which contravene that regulation.”

Source: legislation.gov.uk

It is worth noting that organisations can also rely on the ‘soft opt-in’ clause from Regulation 22(3)(c) of PECR, which allows for organisations to send marketing emails to existing customers about similar products or services without explicit consent. Organisations can also send B2B direct marketing emails or texts to generic corporate email addresses without consent under PECR, although in both cases, they must offer the option to unsubscribe.

Lessons from this case

It could be possible that Mr Chand thought that his status as a sole trader could exempt him from facing the full force of the ICO; however, the severity of the retribution incurred and the fine administered reflect not the size of the organisation, but the effects of their actions. The ICO’s enforcement notice and fine are due to the amount of texts sent illegally, Mr Chand’s repeated attempts at evading investigation, and the nature of the messages, i.e. they would disproportionately target vulnerable people who could be in debt or having money problems. 

Failing to respond to communications from the ICO or knowingly providing them with false information is a criminal offence, which Mr Chand was also guilty of in this case. In addition, while operating as a limited company removes certain personal liabilities from directors, they are still personally liable for sanctions and criminal offences.

This case reminds us to make sure that we have valid grounds for data processing and that we have valid consent from individuals to send them electronic marketing communications. If you have any questions about the legality of your marketing communications or want some support, please get in touch with us here at Griffin House Consultancy.

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founding directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting, and auditing requirements.

Sources

The ICO

The Register

Decision Marketing

 

 

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details