UK Statutory Instrument 2003 United Kingdom

Privacy and Electronic Communications Regulations 2003

At a glance

Enforced by

ICO, Ofcom

What's here

25 compliance obligations, 26 practical guides across 5 topics · 11 journeys

Penalty landscape

10 of 25 obligations carry a fine up to £17,500,000. 15 have no criminal penalty — flagged in the list below.

Who this Act binds

Business-side actors with duties under this Act, ranked by how often they appear.

  • Any Person 12
  • Data Controller 5
  • Operator 2
  • Director or Officer 1

Plus 5 non-business duties on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

Step-by-step journeys using this legislation

Walkthroughs that take you from a real business situation to compliance.

Relevant guidance

Practical guides for businesses affected by this Act, ordered by how closely they engage with it.

Mentioned in related content

1 guides

Other Acts binding the same actors

For each actor bound by this Act, the other UK Acts that bind them most often. Useful for understanding the full compliance landscape facing each role.

Any Person also bound by 742 other Acts (top 5 shown)
Data Controllers also bound by 7 other Acts (top 5 shown)
Operators also bound by 124 other Acts (top 5 shown)
Directors and Officers also bound by 221 other Acts (top 5 shown)

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

Schedules

Browse 44 other Schedules — structural / supplementary
s.sch001

Provisions applied for enforcement purposes

s.sch001

Modification of section 148B (interview notices: restrictions)

s.sch001

Modification of section 149 (enforcement notices)

s.sch001

Modification of section 150 (enforcement notices: supplementary)

s.sch001

Modification of section 152 (enforcement notices: restrictions)

s.sch001

Modification of Schedule 15 (powers of entry and inspection)

s.sch001

Modification of section 155 (penalty notices)

s.sch001

Modification of Schedule 16 (penalties)

s.sch001

Modification of section 156 (penalty notices: restrictions)

s.sch001

Modification of section 157 (maximum amount of penalty)

s.sch001

Modification of section 159 (amount of penalties: supplementary)

s.sch001

General modification of references to the Data Protection Act 2018

s.sch001

Modification of section 160 (guidance)

s.sch001

Modification of section 162 (rights of appeal)

s.sch001

Modification of section 163 (determination of appeals)

s.sch001

Modification of section 180 (jurisdiction)

s.sch001

Modification of section 181 (interpretation of Part 6)

s.sch001

Modification of section 182 (regulations and consultation)

s.sch001

Modification of section 196 (penalties for offences)

s.sch001

Modification of section 200 (guidance about PACE codes of practice)

s.sch001

Modification of section 202 (proceedings in the First-tier Tribunal: contempt)

s.sch001

Modification of section 203 (tribunal procedure rules)

s.sch001

Modification of section 142 (information notices)

s.sch001

Interpretation

s.sch001

Modification of section 143 (information notices: restrictions)

s.sch001

Modification of section 145 (information orders)

s.sch001

Modification of section 146 (assessment notices)

s.sch001

Modification of section 146A (assessment notices: approval of person to prepare report)

s.sch001

Modification of section 147 (assessment notices: restrictions)

s.sch001

Modification of section 148A (interview notices)

s.sch002

In this Schedule “the 1999 Regulations” means the Telecommunications (Data...

s.sch002

(1) Regulation 18 of these Regulations shall not apply in...

s.sch002

(1) A notification of consent given to a caller by...

s.sch002

(1) A notification given by a subscriber pursuant to regulation...

s.sch002

In relation to times before an order made under section...

s.schedule a1 para.1

Interpretation

s.schedule a1 para.2

Consent

s.schedule a1 para.3

Transmission of a communication over an electronic communications network

s.schedule a1 para.4

Storage or access strictly necessary to provide an information society service

s.schedule a1 para.5

Collecting information for statistical purposes

s.schedule a1 para.6

Website appearance etc

s.schedule a1 para.7

Emergency assistance

s.005

Personal data breach

Fine up to £17,500,000
  • Notify the ICO and users of personal data breaches Operator
s.016

Emergency calls

Fine up to £17,500,000
  • Enable caller ID and location data for emergency 999/112 calls Any Person
s.018

Directories of subscribers

Fine up to £17,500,000
  • Obtain consent and inform individual subscribers before including them in directories Director or Officer
s.021

Calls for direct marketing of claims management services

  • Do not make unsolicited marketing calls for claims management services Any Person
s.029

(1) Where regulations 28 and 29 apply, communications providers must...

Fine up to £17,500,000
  • Maintain procedures for handling personal data access requests Data Controller
s.032

Accreditation of bodies monitoring compliance with codes of conduct

  • Accredited monitoring bodies must enforce codes of conduct and report suspensions Any Person
s.037

Review of implementation

Other duties (1) — Crown / regulator
  • Secretary of State must review the PECR regulations every five years Crown / Minister / Government department
Browse 26 other sections — procedural / definitional / commencement
s.001

Citation and commencement

s.002

Interpretation

s.calls for direct marketing in relation to pension

Calls for direct marketing in relation to pension schemes

s.codes of conduct

Codes of conduct

s.effect of codes of conduct

Effect of codes of conduct

s.emergency alerts

Emergency alerts

s.enforcement: appeals

Enforcement: appeals

s.enforcement: third party information notices

Enforcement: third party information notices

s.personal data breach: audit

Personal data breach: audit

s.personal data breach: enforcement

Personal data breach: enforcement

s.power to provide exceptions to regulation 6(1)

Power to provide exceptions to regulation 6(1)

s.storing information in the terminal equipment of a

Storing information in the terminal equipment of a subscriber or user

Official guidance

Authoritative sources published by regulators or government explaining this legislation.

Enforcement and responsible bodies

The regulators that administer or enforce this legislation.

ICO

Primary

Information Commissioner's Office

Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. …

Office of Communications

Regulates telecoms, TV, radio, video-on-demand, postal services, and online safety. Issues licences for telecoms providers, manages spectrum. Now enforces Online Safety Act …

Explore more

Browse legislation

Find other UK business legislation with related guidance.

Regulators

Learn more about the bodies that enforce this legislation.