Vote Leave fined £40,000 for unlawful text messages
It's the latest fine in a string of penalties for unlawful political advertising


The Information Commissioner's Office (ICO) has fined the Vote Leave campaign 40,000 for sending unlawful and unsolicited text messages prior to the 2016 EU referendum.
The ICO's investigation found that the campaign sent 196,154 text messages to people which included campaign propaganda and in most cases, links to the campaign's website where recipients could find out more.
Vote Leave was unable to provide the ICO with evidence to show recipients of the messages had given their consent which is a key component of electronic marketing law, as set out by the Data Protection Act 2018.
ICO fines Leave.EU and Arron Banks' insurance £120,000 over marketing law breaches General Data Protection Regulation (GDPR)
"Spam texts are a real nuisance for millions of people and we will take action against organisations who disregard the law," said Steve Eckersley, ICO director of investigations. "Direct marketing is not just about selling products and services, it's also about promoting an organisation's aims and ideals".
"Political campaigns and parties, like any other organisations, have to comply with the law," he added.
Vote Leave responded to the investigation by saying it had acquired people's details from enquiries originating from its website, from individuals who had responded via text to promotional leaflets and from entrants to its football competition which promised at 50 million cash prize.
The prize could be won if entrants correctly guessed the result of all 51 matches in the 2016 Euro Tournament hosted in France, the chances of which were placed at one in 5,000,000,000,000,000,000,000 (five sextillions). For reference, the odds for winning the UK lottery are placed at one in 14 million.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Vote Leave said that after the referendum ended, the organisation deleted all evidence of the consent it relied upon to lawfully distribute the text messages. Details of the phone numbers from which the messages were sent and the volume of messages sent and received were also deleted.
IT Pro tried to contact Vote Leave for a statement but communication channels to the organisation seemed to have been abandoned.
This is the latest fine in an ICO crackdown on misuse of data in political advertising. In February 2019, Leave.EU was fined on two separate occasions on the same day. Firstly, similarly to Vote Leave, it was fined 45,000 for sending unsolicited direct marketing emails without consent and then a further 15,000 for sending almost 300,000 unsolicited communications in a single day without required consent.
On the same day as the Leave.EU fines, 1 February 2019, Eldon Insurance was fined 60,000 for instigating the sending of unsolicited direct marketing emails without consent - we're sensing a theme here.
The ICO publishes detailed guidance on political campaigning and direct marketing explaining the legal obligations organisations have to comply with the Privacy and Electronic Communications Regulations (PECR).

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott Published
-
Data sovereignty a growing priority for UK enterprises
News Many firms view data sovereignty as simply a compliance issue
By Emma Woollacott Published
-
Elevating compliance standards for MSPs in 2025
Industry Insights The security landscape is set to change significantly in the years to come with new regulations coming into effect next year, here's how the channel needs to adapt
By Ross Brewer Published
-
How ready is your company for NIS2?
Supported Content The EU’s latest cybersecurity legislation raises the stakes for enterprises and IT leaders - and ensuring compliance can be a daunting task
By Ross Kelly Published
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro Published
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly Published
-
Conquering technology risk in banking
Whitepaper Five ways leaders can transform technology risk into advantage
By ITPro Published
-
Advancing your risk management maturity
Whitepaper A roadmap to effective governance and increase resilience
By ITPro Published