KRA Consultancy Ltd – €351,000 Fine (United Kingdom, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
KRA Consultancy Ltd sent out a lot of unwanted SMS messages promoting debt services without getting permission from the recipients. The UK's Information Commissioner's Office found this practice troubling, especially since it targeted vulnerable people. This case highlights the importance of obtaining consent before sending marketing messages.
What happened
KRA Consultancy Ltd sent unsolicited SMS messages promoting debt-related services without valid consent from recipients.
Who was affected
Individuals who received unsolicited marketing SMS messages about debt solutions from KRA Consultancy Ltd.
What the authority found
The Information Commissioner's Office determined that KRA Consultancy Ltd did not have valid consent to send marketing messages, which is a violation of privacy rules.
Why this matters
This case shows that companies must get clear permission before sending marketing messages, especially to vulnerable individuals. Small businesses should review their consent processes to avoid similar issues.
National Law Articles
The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services. The case was initially connected to investigations into other companies and individuals involved in mass SMS marketing. During these investigations, the DPA identified links between the controller, debt advice websites, bulk SMS platforms, short URLs and complaints submitted by subscribers to the 7726 spam reporting service. The controller was found to have used different trading names, websites and bulk messaging services to send large volumes of SMS messages to subscribers. These messages promoted debt write-off or debt solution services and invited recipients to click links leading to websites operated by, or connected to, the controller. The DPA also found evidence that the controller used personal data obtained from loan decline datasets and other third-party sources. The controller did not demonstrate that the subscribers had provided valid consent to receive marketing SMS messages about debt solutions. The DPA further found that the controller used so-called “fake bailiff messages” to pressure individuals into responding. These messages suggested that enforcement agents or bailiffs would attend the recipient’s address. The DPA considered that these messages targeted financially vulnerable individuals and were likely to cause distress. During the investigation, the DPA executed search warrants and seized electronic devices. The evidence included WhatsApp messages, SMS messages, access to bulk SMS platforms, customer communications, call recordings and internal group chats. These showed that the controller was involved in the transmission or instigation of the SMS messages and had sought to make the messages difficult to trace. The DPA held that the controller infringed Regulation 22 PECR by transmitting or instigating the transmission of unsolicited direct marketing SMS messages wit
Related Enforcement Actions (0)
No other enforcement actions found for KRA Consultancy Ltd in UK
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
20 May 2026
Authority
Information Commissioner's Office
Fine Amount
€351,000
300,000 GBP
GDPRhub ID
gdprhub-10085About this data
Cite as: Cookie Fines. KRA Consultancy Ltd - United Kingdom (2026). Retrieved from cookiefines.eu
Last updated: