What happened
The UK's data protection watchdog fined Elderly Aids £190,000 ($258,000) for making 758,053 unsolicited direct marketing calls to phone numbers registered with the Telephone Preference Service. All of the calls went to people who had not given that company consent to contact them, which is illegal under UK direct marketing rules.
The company sold devices meant to block nuisance calls, and the irony was not lost on regulators. The ICO and the TPS received 20 complaints during the period, with complainants citing aggressive and misleading sales tactics and callers failing to identify themselves. The ICO's head of investigations said the company targeted vulnerable people who had explicitly asked not to be called, then harassed them to sell a product intended to stop such calls. Public Companies House filings show the company attempted to strike itself off the register three months after starting the calls, a move that was suspended following an objection.
Why this is a GRC story
Direct marketing compliance is a real part of privacy governance, and this case is a clean example of the basics being ignored. The Telephone Preference Service exists so people can control who contacts them, and the rule is simple: no calls to registered numbers without explicit consent to that specific company. Screening lists against the TPS and Corporate TPS registers is a basic control, and the Data & Marketing Association's director of preference services made exactly that point, saying people register because they want greater control, and cases like this demonstrate why the protections matter.
The case also shows that enforcement reaches small companies, not just big platforms. The fine is modest by GDPR standards, but the conduct was persistent, targeted at elderly people, and the company's attempted strike-off suggests it knew the exposure was building. For compliance teams, the takeaway is that consent and preference records need to be auditable: if a regulator asks who you called and why, the answer should be in your files, not reconstructed later.
What to watch
Watch whether the fine is paid or appealed, and whether the ICO's continued push on nuisance calls extends to the wider supply chain of outsourced call operations, which is where much of this activity actually runs. The DMA's advice to screen against TPS and CTPS registers is the standard every marketing operation should already meet.
For any business doing outbound calling, the durable question is simple: does your campaign process check the preference registers before every dial, and can you prove it? This case is the reminder that the penalty for skipping that step can arrive with a regulator's letterhead.
Attribution: Analysis based on The Register's reporting, the ICO announcement and related public reporting. This article is original commentary, not a repost of the source material.
