UK Statutory Instrument SI 2003 United Kingdom

Privacy and Electronic Communications Regulations 2003

These Regulations implement Articles 2, 4, 5(3), 6 to 13, 15 and 16 of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) …

Enforced by
ICO, Ofcom
Status
In Force
Penalty ceiling
Prosecution 10 of 25 obligations carry a fine up to £17,500,000. 15 have no criminal penalty — flagged in the list below.

Does it bind you?

Business-side roles with duties under this instrument.

Any Person12 Data Controller5 Operator2 Director or Officer1

Plus 5 duties on the regulator, Crown ministers and public bodies — folded into the section list below.

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Any Person — also bound by 2340 other Acts
Data Controller — also bound by 35 other Acts
Operator — also bound by 746 other Acts
Director or Officer — also bound by 429 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

s.005 Personal data breach Prosecution
  • Notify the ICO and users of personal data breachesOperator

Fine up to £17,500,000

s.005 Security of public electronic communications services (opens in a new tab) Prosecution
  • Safeguard the security of public electronic communications servicesOperator

Fine up to £17,500,000

s.006 Storing information in the terminal equipment of a subscriber or user (opens in a new tab) Prosecution
  • Obtain consent before using cookies or similar tracking technologiesAny Person

Fine up to £17,500,000

s.007 Restrictions on the processing of certain traffic data (opens in a new tab) Prosecution
  • Erase or anonymise communications traffic data when no longer neededData Controller

Fine up to £17,500,000

s.009 Itemised billing and privacy (opens in a new tab) Regulated
  • Provide non-itemised bills upon subscriber requestData Controller
s.010 Prevention of calling line identification – outgoing calls (opens in a new tab) Regulated
  • Provide callers with a way to hide their phone numberAny Person
s.011 Prevention of calling or connected line identification – incoming calls (opens in a new tab) Prosecution
  • Provide callers with privacy options for incoming callsData Controller

Fine up to £17,500,000

s.012 Publication of information for the purposes of regulations 10 and 11 (opens in a new tab) Prosecution
  • Inform the public about caller ID and privacy optionsData Controller

Fine up to £17,500,000

s.013 Co-operation of communications providers for the purposes of regulations 10 and 11 (opens in a new tab) Regulated
  • Cooperate with telecoms providers regarding caller ID servicesAny Person
s.016 Emergency calls (opens in a new tab) Prosecution
  • Enable caller ID and location data for emergency 999/112 callsAny Person

Fine up to £17,500,000

s.017 Termination of automatic call forwarding (opens in a new tab) Regulated
  • Stop automatic call forwarding upon subscriber requestAny Person
s.018 Directories of subscribers (opens in a new tab) Prosecution
  • Obtain consent and inform individual subscribers before including them in directoriesDirector or Officer

Fine up to £17,500,000

s.019 Use of automated calling systems (opens in a new tab) Regulated
  • Obtain consent before making automated marketing callsAny Person
s.020 Use of facsimile machines for direct marketing purposes (opens in a new tab) Regulated
  • Do not send unsolicited direct marketing faxes without consentAny Person
s.021 Calls for direct marketing of claims management services Regulated
  • Do not make unsolicited marketing calls for claims management servicesAny Person
s.023 Use of electronic mail for direct marketing purposes where the identity or address of the sender is concealed (opens in a new tab) Prosecution
  • Identify your business and provide a valid opt-out address in marketing emailsAny Person

Fine up to £17,500,000

s.024 Information to be provided for the purposes of regulations 19 to 21A (opens in a new tab) Regulated
  • Identify yourself when sending direct marketing communicationsAny Person
s.025 Register to be kept for the purposes of regulation 20 (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must maintain and provide access to the Fax Preference Service registerStatutory regulator
s.026 Register to be kept for the purposes of regulation 21 (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must maintain a register of people who opt out of marketing callsStatutory regulator
s.029 (1) Where regulations 28 and 29 apply, communications providers must... Prosecution
  • Maintain procedures for handling personal data access requestsData Controller

Fine up to £17,500,000

s.030 Proceedings for compensation for failure to comply with requirements of the Regulations (opens in a new tab) Regulated
  • Pay compensation for damages caused by privacy breachesAny Person
s.032 Accreditation of bodies monitoring compliance with codes of conduct Regulated
  • Accredited monitoring bodies must enforce codes of conduct and report suspensionsAny Person
s.032 Request that the Commissioner exercise his enforcement functions (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must investigate alleged PECR breaches upon requestStatutory regulator
s.033 Technical advice to the Commissioner (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Ofcom must provide technical advice to the Information CommissionerStatutory regulator
s.037 Review of implementation (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • Secretary of State must review the PECR regulations every five yearsCrown / Minister / Government department
26 other provisions — procedural and definitional
s.001 Citation and commencement
s.002 Interpretation
s.calls for direct marketing in relation to pension Calls for direct marketing in relation to pension schemes
s.codes of conduct Codes of conduct
s.effect of codes of conduct Effect of codes of conduct
s.emergency alerts Emergency alerts
s.enforcement: appeals Enforcement: appeals
s.enforcement: third party information notices Enforcement: third party information notices
s.personal data breach: audit Personal data breach: audit
s.personal data breach: enforcement Personal data breach: enforcement
s.power to provide exceptions to regulation 6(1) Power to provide exceptions to regulation 6(1)
s.storing information in the terminal equipment of a Storing information in the terminal equipment of a subscriber or user
Schedules

Schedules

0 of 44 shown
44 other schedules
s.sch001 Provisions applied for enforcement purposes
s.sch001 Modification of section 148B (interview notices: restrictions)
s.sch001 Modification of section 149 (enforcement notices)
s.sch001 Modification of section 150 (enforcement notices: supplementary)
s.sch001 Modification of section 152 (enforcement notices: restrictions)
s.sch001 Modification of Schedule 15 (powers of entry and inspection)
s.sch001 Modification of section 155 (penalty notices)
s.sch001 Modification of Schedule 16 (penalties)
s.sch001 Modification of section 156 (penalty notices: restrictions)
s.sch001 Modification of section 157 (maximum amount of penalty)
s.sch001 Modification of section 159 (amount of penalties: supplementary)
s.sch001 General modification of references to the Data Protection Act 2018
s.sch001 Modification of section 160 (guidance)
s.sch001 Modification of section 162 (rights of appeal)
s.sch001 Modification of section 163 (determination of appeals)
s.sch001 Modification of section 180 (jurisdiction)
s.sch001 Modification of section 181 (interpretation of Part 6)
s.sch001 Modification of section 182 (regulations and consultation)
s.sch001 Modification of section 196 (penalties for offences)
s.sch001 Modification of section 200 (guidance about PACE codes of practice)
s.sch001 Modification of section 202 (proceedings in the First-tier Tribunal: contempt)
s.sch001 Modification of section 203 (tribunal procedure rules)
s.sch001 Modification of section 142 (information notices)
s.sch001 Interpretation
s.sch001 Modification of section 143 (information notices: restrictions)
s.sch001 Modification of section 145 (information orders)
s.sch001 Modification of section 146 (assessment notices)
s.sch001 Modification of section 146A (assessment notices: approval of person to prepare report)
s.sch001 Modification of section 147 (assessment notices: restrictions)
s.sch001 Modification of section 148A (interview notices)
s.sch002 In this Schedule “the 1999 Regulations” means the Telecommunications (Data...
s.sch002 (1) Regulation 18 of these Regulations shall not apply in...
s.sch002 (1) A notification of consent given to a caller by...
s.sch002 (1) A notification given by a subscriber pursuant to regulation...
s.sch002 In relation to times before an order made under section...
s.schedule a1 para.1 Interpretation
s.schedule a1 para.2 Consent
s.schedule a1 para.3 Transmission of a communication over an electronic communications network
s.schedule a1 para.4 Storage or access strictly necessary to provide an information society service
s.schedule a1 para.5 Collecting information for statistical purposes
s.schedule a1 para.6 Website appearance etc
s.schedule a1 para.7 Emergency assistance

Help complying

Guvnor’s practical routes through this instrument.

Marketing compliance: PECR and UK GDPR

Learn how to send compliant marketing emails, texts, and make telephone calls. Covers PECR consent rules, the soft opt-in exception, TPS screening, …

Respond to a cyber attack

Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data …

Prepare for the Data Use and Access Act 2025 changes

A step-by-step guide to understanding and adapting to the Data (Use and Access) Act 2025. Covers the 8 key reforms now in …

Meet your data protection obligations

Ensure your business complies with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful basis for processing, data subject …

Data protection compliance checklist

Quick compliance check for UK GDPR and Data Protection Act 2018. Verify your ICO registration, lawful basis documentation, privacy notice, data subject …

Accommodation compliance for hotels, B&Bs, and holiday lets

Compliance journey for accommodation providers covering tourist registration, fire safety for sleeping accommodation, legionella management, VAT on accommodation, short-term lets regulation, HMO …

Cookie consent: comply with PECR requirements

How to comply with cookie consent rules under the Privacy and Electronic Communications Regulations 2003 (PECR). Covers consent banners, strictly necessary exemptions, …

Data Use and Access Act 2025: what changed for businesses

What the Data (Use and Access) Act 2025 means for UK businesses. Explains the eight key reforms now in force, including recognised …

Email marketing: PECR and UK GDPR requirements

How to send compliant marketing emails under PECR and UK GDPR. Covers consent requirements, the soft opt-in exception for existing customers, unsubscribe …

24 more guides that reference this instrument

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.