UK Statutory Instrument 2003 United Kingdom

Privacy and Electronic Communications Regulations 2003

At a glance

Enforced by

ICO, Ofcom

What's here

25 compliance obligations, 22 practical guides across 4 topics · 11 journeys

Penalty landscape

10 of 25 obligations carry a fine up to £17,500,000. 15 have no criminal penalty — flagged in the list below.

Who this Act binds

Business-side actors with duties under this Act, ranked by how often they appear.

  • Any Person 12
  • Data Controller 5
  • Operator 2
  • Director or Officer 1

Plus 5 non-business duties on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

Step-by-step journeys using this legislation

Walkthroughs that take you from a real business situation to compliance.

Relevant guidance

Practical guides for businesses affected by this Act, ordered by how closely they engage with it.

Mentioned in related content

1 guides

Other Acts binding the same actors

For each actor bound by this Act, the other UK Acts that bind them most often. Useful for understanding the full compliance landscape facing each role.

Any Person also bound by 749 other Acts (top 5 shown)
Data Controllers also bound by 7 other Acts (top 5 shown)
Operators also bound by 125 other Acts (top 5 shown)
Directors and Officers also bound by 224 other Acts (top 5 shown)

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

Schedules

Browse 2 other Schedules — structural / supplementary
s.016

Emergency calls

Fine up to £17,500,000
  • Enable caller ID and location data for emergency 999/112 calls Any Person
s.018

Directories of subscribers

Fine up to £17,500,000
  • Obtain consent and inform individual subscribers before including them in directories Director or Officer
s.037

Review of implementation

Other duties (1) — Crown / regulator
  • Secretary of State must review the PECR regulations every five years Crown / Minister / Government department
s.accreditation of bodies monitoring compliance with

Accreditation of bodies monitoring compliance with codes of conduct

  • Accredited monitoring bodies must enforce codes of conduct and report suspensions Any Person
s.calls for direct marketing of claims management se

Calls for direct marketing of claims management services

  • Do not make unsolicited marketing calls for claims management services Any Person
s.personal data breach

Personal data breach

Fine up to £17,500,000
  • Notify the ICO and users of personal data breaches Operator
s.(unknown)

(unknown)

Fine up to £17,500,000
  • Maintain procedures for handling personal data access requests Data Controller
Browse 24 other sections — procedural / definitional / commencement
s.calls for direct marketing in relation to pension

Calls for direct marketing in relation to pension schemes

s.codes of conduct

Codes of conduct

s.effect of codes of conduct

Effect of codes of conduct

s.emergency alerts

Emergency alerts

s.enforcement: appeals

Enforcement: appeals

s.enforcement: third party information notices

Enforcement: third party information notices

s.personal data breach: audit

Personal data breach: audit

s.personal data breach: enforcement

Personal data breach: enforcement

s.power to provide exceptions to regulation 6(1)

Power to provide exceptions to regulation 6(1)

s.storing information in the terminal equipment of a

Storing information in the terminal equipment of a subscriber or user

Official guidance

Authoritative sources published by regulators or government explaining this legislation.

Enforcement and responsible bodies

The regulators that administer or enforce this legislation.

ICO

Primary

Information Commissioner's Office

Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. …

Office of Communications

Regulates telecoms, TV, radio, video-on-demand, postal services, and online safety. Issues licences for telecoms providers, manages spectrum. Now enforces Online Safety Act …

Explore more

Browse legislation

Find other UK business legislation with related guidance.

Regulators

Learn more about the bodies that enforce this legislation.