Journey

Marketing compliance: PECR and UK GDPR

Learn how to send compliant marketing emails, texts, and make telephone calls. Covers PECR consent rules, the soft opt-in exception, TPS screening, cookie consent, and the increased penalties from 5 February 2026.

Running a Business Updated 15 September 2026
7 milestones references 5 guides

Why marketing compliance matters

Electronic marketing is one of the most heavily regulated areas of business communication. The Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR work together to protect people from unwanted marketing. Get it wrong and the Information Commissioner's Office (ICO) can fine you up to 17.5 million pounds.

This learning path covers the essential rules for email, text, telephone marketing, and website cookies.

Electronic marketing rules (PECR): the complete guide

Understand the full PECR framework before diving into specific channels. Covers consent requirements, soft opt-in, telephone screening, and ICO enforcement powers.

  1. Understand email and text marketing rules

    PECR treats email and SMS the same way. For individuals and sole traders, you need consent unless the soft opt-in exception applies. For companies and LLPs, the rules are more relaxed but you must still respect objections.

    Email marketing compliance guide

    Detailed guidance on compliant email marketing, including consent wording, unsubscribe mechanisms, and record-keeping requirements.

  2. The soft opt-in exception

    Soft opt-in lets you email existing customers without explicit consent, but only if you meet four strict conditions. All four must apply - fail any one and you need consent.

    • Sale context: You obtained their details during a sale or negotiations
    • Similar products: You are marketing your own similar products or services
    • Opt-out given: You offered an opt-out when collecting details
    • Easy unsubscribe: Every message includes a simple opt-out

    Soft opt-in never applies to purchased lists or contacts obtained outside a sale context.

  3. Telephone marketing and TPS screening

    Live marketing calls have different rules to emails. You do not need consent, but you must screen against the Telephone Preference Service (TPS) and Corporate TPS (CTPS) at least every 28 days. Never call anyone who has asked not to be called.

    Automated calls (robocalls) are different - you always need specific prior consent.

  4. Cookies and website tracking

    PECR also covers cookies and similar tracking technologies. Most cookies require consent before you set them. Strictly necessary cookies (essential for your site to work) are exempt, but analytics and marketing cookies are not.

    Cookie consent compliance

    How to implement compliant cookie consent, including banner design, consent management platforms, and the strictly necessary exemption.

  5. Privacy notices for marketing

    Your privacy notice must explain how you use personal data for marketing. People have the right to object to direct marketing at any time, and you must make it easy for them to do so.

    Write a compliant privacy notice

    How to write a privacy notice that covers your marketing activities, including what to say about third-party sharing, profiling, and automated decision-making.

  6. Penalties for getting it wrong

    PECR penalties were dramatically increased by the Data (Use and Access) Act 2025. From 5 February 2026, fines align with UK GDPR levels. The ICO actively enforces PECR - marketing violations are one of their most common enforcement areas.

  7. Getting consent right under UK GDPR

    When you do need consent, it must meet UK GDPR standards: freely given, specific, informed, and unambiguous. Pre-ticked boxes do not count. Bundled consent (tying marketing to a service) does not count. People must take clear affirmative action.

    Data protection for businesses

    Comprehensive guide to UK GDPR compliance, including the consent requirements that apply when soft opt-in is not available.

You have completed this learning path

You now understand the key rules for compliant marketing under PECR and UK GDPR. The essential points:

  • Email and SMS to individuals require consent unless soft opt-in applies
  • Email to companies and LLPs does not require consent but respect objections
  • Screen telephone lists against TPS and CTPS every 28 days
  • Automated calls always require specific prior consent
  • Most cookies need consent before being set
  • Penalties can reach 17.5 million pounds or 4% of turnover

For ongoing compliance, ensure you keep consent records, process opt-out requests promptly, and review your practices when the law changes.