For years, the rules on cookies and marketing emails carried a maximum fine of £500,000. That was the ceiling no matter how badly an organisation behaved. The Data (Use and Access) Act has removed that ceiling and replaced it with a much higher one.
The maximum is now up to £17.5m, or 4% of worldwide annual turnover, whichever is higher.[1] That is the same level as the main data protection fines. The thing many businesses treated as a minor compliance chore now sits in serious-money territory.
What the rules cover
These rules govern two everyday activities. The first is cookies and similar tracking on your website. The second is electronic marketing: the texts, emails and calls you send to promote your business.[20]
The classic mistakes are familiar. A cookie banner that drops tracking cookies before anyone clicks anything. Marketing emails sent to people who never agreed to receive them. A "consent" that was really just a pre-ticked box. None of these are new mistakes. What is new is the price of making them.
It is worth knowing that some cookie rules also got easier at the same time, with new exceptions for low-risk cookies. The relaxation and the bigger fines arrived together, which is exactly why getting the line right now matters.
What this means for you
You do not need to spend money to remove most of this risk. You need to check three things.
First, your cookie banner: does anything track visitors before they say yes? If so, fix it. Second, your marketing lists: can you show that the people on them agreed to hear from you? If not, clean the list. Third, your unsubscribe: does every marketing message offer an easy way out, and does it actually work?
These are small, practical checks. The reason to do them now is straightforward. The behaviour that used to risk a modest fine can now, in a bad case, risk a very large one. A morning spent tidying your banner and your lists is cheap insurance against that.