Journey
Marketing compliance: PECR and UK GDPR
Learn how to send compliant marketing emails, texts, and make telephone calls. Covers PECR consent rules, the soft opt-in exception, TPS screening, cookie consent, and the increased penalties from 5 February 2026.
Why marketing compliance matters
Electronic marketing is one of the most heavily regulated areas of business communication. The Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR work together to protect people from unwanted marketing. Get it wrong and the Information Commissioner's Office (ICO) can fine you up to 17.5 million pounds.
This learning path covers the essential rules for email, text, telephone marketing, and website cookies.
Electronic marketing rules (PECR): the complete guide
Understand the full PECR framework before diving into specific channels. Covers consent requirements, soft opt-in, telephone screening, and ICO enforcement powers.
-
Understand email and text marketing rules
PECR treats email and SMS the same way. For individuals and sole traders, you need consent unless the soft opt-in exception applies. For companies and LLPs, the rules are more relaxed but you must still respect objections.
Email marketing compliance guide
Detailed guidance on compliant email marketing, including consent wording, unsubscribe mechanisms, and record-keeping requirements.
-
The soft opt-in exception
Soft opt-in lets you email existing customers without explicit consent, but only if you meet four strict conditions. All four must apply - fail any one and you need consent.
- Sale context: You obtained their details during a sale or negotiations
- Similar products: You are marketing your own similar products or services
- Opt-out given: You offered an opt-out when collecting details
- Easy unsubscribe: Every message includes a simple opt-out
Soft opt-in never applies to purchased lists or contacts obtained outside a sale context.
-
Telephone marketing and TPS screening
Live marketing calls have different rules to emails. You do not need consent, but you must screen against the Telephone Preference Service (TPS) and Corporate TPS (CTPS) at least every 28 days. Never call anyone who has asked not to be called.
Automated calls (robocalls) are different - you always need specific prior consent.
-
Cookies and website tracking
PECR also covers cookies and similar tracking technologies. Most cookies require consent before you set them. Strictly necessary cookies (essential for your site to work) are exempt, but analytics and marketing cookies are not.
Cookie consent compliance
How to implement compliant cookie consent, including banner design, consent management platforms, and the strictly necessary exemption.
-
Privacy notices for marketing
Your privacy notice must explain how you use personal data for marketing. People have the right to object to direct marketing at any time, and you must make it easy for them to do so.
Write a compliant privacy notice
How to write a privacy notice that covers your marketing activities, including what to say about third-party sharing, profiling, and automated decision-making.
-
Penalties for getting it wrong
PECR penalties were dramatically increased by the Data (Use and Access) Act 2025. From 5 February 2026, fines align with UK GDPR levels. The ICO actively enforces PECR - marketing violations are one of their most common enforcement areas.
-
Getting consent right under UK GDPR
When you do need consent, it must meet UK GDPR standards: freely given, specific, informed, and unambiguous. Pre-ticked boxes do not count. Bundled consent (tying marketing to a service) does not count. People must take clear affirmative action.
Data protection for businesses
Comprehensive guide to UK GDPR compliance, including the consent requirements that apply when soft opt-in is not available.
You have completed this learning path
You now understand the key rules for compliant marketing under PECR and UK GDPR. The essential points:
- Email and SMS to individuals require consent unless soft opt-in applies
- Email to companies and LLPs does not require consent but respect objections
- Screen telephone lists against TPS and CTPS every 28 days
- Automated calls always require specific prior consent
- Most cookies need consent before being set
- Penalties can reach 17.5 million pounds or 4% of turnover
For ongoing compliance, ensure you keep consent records, process opt-out requests promptly, and review your practices when the law changes.