- Status
- In Force
- Penalty ceiling
- Prosecution 10 of 25 obligations carry a fine up to £17,500,000. 15 have no criminal penalty — flagged in the list below.
Does it bind you?
Business-side roles with duties under this instrument.
Plus 5 duties on the regulator, Crown ministers and public bodies — folded into the section list below.
Other Acts binding the same actors
If a role above is yours, these are the other instruments that most often bind it.
Any Person — also bound by 2340 other Acts
Data Controller — also bound by 35 other Acts
Operator — also bound by 746 other Acts
Director or Officer — also bound by 429 other Acts
What it requires
Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.
- Notify the ICO and users of personal data breachesOperator
Fine up to £17,500,000
- Safeguard the security of public electronic communications servicesOperator
Fine up to £17,500,000
- Obtain consent before using cookies or similar tracking technologiesAny Person
Fine up to £17,500,000
- Erase or anonymise communications traffic data when no longer neededData Controller
Fine up to £17,500,000
- Provide non-itemised bills upon subscriber requestData Controller
- Provide callers with a way to hide their phone numberAny Person
- Provide callers with privacy options for incoming callsData Controller
Fine up to £17,500,000
- Inform the public about caller ID and privacy optionsData Controller
Fine up to £17,500,000
- Cooperate with telecoms providers regarding caller ID servicesAny Person
- Enable caller ID and location data for emergency 999/112 callsAny Person
Fine up to £17,500,000
- Stop automatic call forwarding upon subscriber requestAny Person
- Obtain consent and inform individual subscribers before including them in directoriesDirector or Officer
Fine up to £17,500,000
- Obtain consent before making automated marketing callsAny Person
- Do not send unsolicited direct marketing faxes without consentAny Person
- Do not make unsolicited marketing calls for claims management servicesAny Person
- Identify your business and provide a valid opt-out address in marketing emailsAny Person
Fine up to £17,500,000
- Identify yourself when sending direct marketing communicationsAny Person
Other duties (1) — Crown / regulator
- ICO must maintain and provide access to the Fax Preference Service registerStatutory regulator
Other duties (1) — Crown / regulator
- ICO must maintain a register of people who opt out of marketing callsStatutory regulator
- Maintain procedures for handling personal data access requestsData Controller
Fine up to £17,500,000
- Pay compensation for damages caused by privacy breachesAny Person
- Accredited monitoring bodies must enforce codes of conduct and report suspensionsAny Person
Other duties (1) — Crown / regulator
- ICO must investigate alleged PECR breaches upon requestStatutory regulator
Other duties (1) — Crown / regulator
- Ofcom must provide technical advice to the Information CommissionerStatutory regulator
Other duties (1) — Crown / regulator
- Secretary of State must review the PECR regulations every five yearsCrown / Minister / Government department
26 other provisions — procedural and definitional
Schedules
0 of 44 shown44 other schedules
Help complying
Guvnor’s practical routes through this instrument.
Marketing compliance: PECR and UK GDPR
Learn how to send compliant marketing emails, texts, and make telephone calls. Covers PECR consent rules, the soft opt-in exception, TPS screening, …
Respond to a cyber attack
Emergency guidance for businesses experiencing a cyber attack. Immediate containment steps, who to report to, and what to do if personal data …
Prepare for the Data Use and Access Act 2025 changes
A step-by-step guide to understanding and adapting to the Data (Use and Access) Act 2025. Covers the 8 key reforms now in …
Meet your data protection obligations
Ensure your business complies with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful basis for processing, data subject …
Data protection compliance checklist
Quick compliance check for UK GDPR and Data Protection Act 2018. Verify your ICO registration, lawful basis documentation, privacy notice, data subject …
Accommodation compliance for hotels, B&Bs, and holiday lets
Compliance journey for accommodation providers covering tourist registration, fire safety for sleeping accommodation, legionella management, VAT on accommodation, short-term lets regulation, HMO …
Cookie consent: comply with PECR requirements
How to comply with cookie consent rules under the Privacy and Electronic Communications Regulations 2003 (PECR). Covers consent banners, strictly necessary exemptions, …
Data Use and Access Act 2025: what changed for businesses
What the Data (Use and Access) Act 2025 means for UK businesses. Explains the eight key reforms now in force, including recognised …
Email marketing: PECR and UK GDPR requirements
How to send compliant marketing emails under PECR and UK GDPR. Covers consent requirements, the soft opt-in exception for existing customers, unsubscribe …
24 more guides that reference this instrument
Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.