emailmarketing.net

UK PECR — Electronic Mail Marketing

ICO guidance on direct marketing by electronic mail under PECR and UK GDPR: consent standard, the two soft opt-ins, individual vs. corporate subscribers, bought-in lists, and refer-a-friend.

Referencecompliancesender

The Privacy and Electronic Communications Regulations (PECR) set the UK rules for direct marketing by electronic mail; where personal information is used, the UK GDPR and Data Protection Act 2018 apply on top. The ICO (the UK regulator) publishes and enforces this guidance. Like Canada's CASL, and unlike US CAN-SPAM, PECR is an opt-in regime for individual subscribers — with two "soft opt-in" exceptions.

Not legal advice — verify penalties and thresholds against the primary source (below) and counsel before relying on them. See compliance/README.md.

Key definitions

Direct marketing (definition added into PECR from the DPA by the Data Use and Access Act, 20 August 2025): "the communication (by whatever means) of advertising or marketing material which is directed to particular individuals." It covers commercial marketing and the promotion of aims and ideals. Pure service/administrative messages are not direct marketing — but adding any promotional material to a service message makes it direct marketing.

Electronic mail: "any text, voice, sound or image message sent over a public electronic communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient and includes messages sent using a short message service." It covers:

  • email and SMS;
  • picture/video messages;
  • voicemail messages;
  • in-app messages;
  • social media direct (private) messages.

It does not cover online display/banner ads or social media feed ads (even targeted ones) — those are public, not stored for a specific recipient (other PECR rules, e.g. on storage and access technologies, may apply).

Solicited vs. unsolicited: marketing is solicited only when someone specifically asks for a particular message or type of information (e.g., "email me your summer brochure"). Everything else — including follow-ups to that person — is unsolicited. Solicited marketing needs no consent or soft opt-in.

Subscriber: the person or organisation named on the bill for the phone line, internet connection or other communications service. Two types:

  • individual subscribers — people, sole traders, ordinary partnerships;
  • corporate subscribers — organisations with their own legal personality (limited companies, LLPs, Scottish partnerships).

PECR applies even to generic or role-based addresses — knowing the recipient's name is not required. If personal information is used, data protection law also applies.

Which rules apply to whom (B2B vs. B2C)

Message Individual subscriber Corporate subscriber
Solicited marketing Allowed without consent Allowed without consent
Unsolicited marketing Requires consent or a soft opt-in Allowed without consent or soft opt-in
Identity disclosure Must not disguise/hide sender identity Same
Contact address for opt-out Required Required

Caution on "B2B": sole traders and ordinary partnerships count as individual subscribers, so the consent rules apply to them. And employees' business addresses at limited companies are still personal data, so UK GDPR (including the absolute right to object) applies even where PECR consent is not required.

Who must comply

PECR applies to anyone who sends or instigates electronic mail marketing. Instigating includes encouraging, inciting, incentivising or asking someone else to send it — if another organisation sends marketing on a brand's behalf, both are responsible (instigator + sender). A webmail service or bulk-email platform providing only technical delivery is normally not responsible. If a third party sends marketing using personal information on a sender's behalf, a written contract is required, plus appropriate compliance checks. A subscriber must also not allow others to use its line or connection to breach the rules.

Consent

PECR takes its consent standard from the UK GDPR: "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement."

Requirements when seeking consent:

  • Freely given — a free choice, refusable without detriment, kept separate from terms and conditions; making marketing agreement a condition of purchase or donation is unlikely to be valid.
  • Specific and informed — the request must name the organisation and make clear it covers electronic mail marketing; "I would like to receive marketing" without naming the channel is not specific enough. Ask separately per channel (email vs. SMS).
  • Unambiguous, clear affirmative action — no pre-ticked boxes, silence, or inactivity.
  • Recorded — keep who/when/how so validity can be demonstrated.
  • Not transferrable — consent is specific to the particular address or number given; it does not extend to the person's other addresses.
  • Withdrawable — must be easy to withdraw at any time; consent is "for the time being."

The soft opt-ins

Two limited exceptions allow unsolicited electronic mail marketing to individual subscribers without consent.

1. Products and services soft opt-in (any organisation, including charities)

All five conditions must be met:

  1. You obtained the recipient's contact details — directly. Not via a third party, not even another company in your own group. "There is no such thing as a third-party marketing list that is compliant with the soft opt-in."
  2. While selling or negotiating to sell a product or service — actual purchase not required; "negotiations" means active expression of buying interest (free-trial signup, quote request, product enquiry). Merely browsing a website, or a query unrelated to buying, does not qualify.
  3. You only market your similar products and services — test: based on previous interactions, would people reasonably expect this marketing? (Groceries buyer → other supermarket products: yes; → the chain's banking/insurance products: no.) Never covers other organisations' products. Charities, political parties and other not-for-profits must not use this soft opt-in for campaigning or fundraising, even to existing supporters.
  4. You offered a chance to refuse/opt out when collecting the details — a prominent opt-out box on the form (or verbally offered); an opt-out buried in a privacy policy, or offered only in a later confirmation email, does not qualify.
  5. You offer an opt-out in every subsequent message — a clear unsubscribe link or direct reply; SMS "text STOP to "; free of charge beyond normal message cost. Requiring a phone call, account creation, or login to a preference centre is not acceptable.

2. Charitable purposes soft opt-in (charities only) — commenced 5 February 2026

All six conditions must be met:

  1. You're a charity (per the statutory definition in each UK nation).
  2. You obtained the contact details directly — not via a trading subsidiary, third-party fundraising platform, or any other intermediary.
  3. Through the person expressing an interest in, or offering or providing support for, your charitable purposes — e.g., requesting information about the charity's work, donating money or property, or volunteering. Interactions that reveal nothing about interest in the charitable purposes (guest wifi signup, buying a coffee at a charity café, requesting emergency support) do not qualify. Some purchases clearly made as a supporter (annual membership, animal sponsorship, charity raffle, paid fundraising events) can qualify; incidental/convenience purchases do not.
  4. The sole purpose of the marketing is to further your charitable purposes — asking for donations (money or property), recruiting volunteers, or informing about mission-related programmes/projects/campaigns. It must not promote other organisations, including other charities or commercial sponsors.
  5. Opt-out offered at collection (same standard as above).
  6. Opt-out offered in every subsequent message (same standard as above).

Timing: this soft opt-in only applies to contact details obtained on or after 5 February 2026. Details collected earlier without consent cannot be used under it (unless collected again after that date with a compliant opt-out).

Using both soft opt-ins together

A charity may rely on both, but must: present separate opt-out boxes for each at collection (only where the collection conditions for that soft opt-in are met); provide a way to opt out of each type in every message; only include marketing content permitted by the soft opt-ins relied on; and keep records (flags/preference fields) of which legal basis applies per person.

Bought-in lists

To send electronic mail marketing to a purchased/rented/licensed list, everyone on it must have given valid consent naming your organisation specifically (not "trusted partners" or similar), covering the specific method (email/SMS), freely given, specific, informed, unambiguous, and recorded (who, when, how). If not — do not send. The soft opt-ins can never be used with bought lists, because they require direct collection.

Publicly available contact details

Public availability of an address (websites, social media, directories) is not consent. Unsolicited marketing to individual subscribers — including sole traders and ordinary partnerships — still requires consent or a soft opt-in. Scraping personal information also engages data protection law. (Contrast: CASL has a "conspicuous publication" implied-consent category; PECR does not.)

Refer-a-friend / viral marketing

Encouraging people to forward marketing makes the organisation an instigator — no incentive needed, active encouragement is enough. The soft opt-ins cannot be relied on for these messages; valid consent from the friend/family recipient would be required, which is unlikely to be obtainable in practice, so incentivised refer-a-friend email schemes generally breach PECR. An organisation is not responsible for messages people choose to send without its encouragement (organic recommendations, sharing a promotion, linking to a site, personal sponsorship requests).

Changing minds: withdrawal and opt-out

  • Consent can be withdrawn at any time; further marketing then requires fresh consent.
  • Opting out of a soft opt-in likewise stops further marketing under it; only fresh consent restores it.
  • Opt-outs apply per communication method if the wording makes that clear (unsubscribing from email need not stop SMS).
  • Under data protection law people have an absolute right to object to direct marketing — no grounds to refuse; not having opted out of a soft opt-in does not override it.
  • Maintain a "do not contact"/suppression list and check against it before sending.
  • A bounce-back confirming an unsubscribe and explaining how to re-subscribe is fine; preference reminders may be minor additions to messages already being sent, provided they don't encourage changing the choice.

PECR + UK GDPR interaction

Where personal information is used, both regimes apply. Processing must be fair, lawful and transparent (tell people at collection that marketing is intended). Of the seven UK GDPR lawful bases, consent and legitimate interests are usually relevant:

  • Relying on PECR consent → lawful basis is likely consent.
  • Relying on a soft opt-in → lawful basis is likely legitimate interests; carry out a legitimate interests assessment (purpose, necessity, balancing). Where recipients may be in vulnerable situations (the ICO's example: domestic-abuse support beneficiaries who could be harmed if a partner saw the email), the balancing test may fail and the soft opt-in should not be used.

Tracking pixels: the electronic mail marketing rules apply to the email itself, not to tracking pixels (open time, location, OS). Pixels fall under PECR's separate rules on storage and access technologies, which must also be complied with.

Deliverability relevance

PECR's consent and soft-opt-in conditions map directly onto deliverability best practice: directly-collected addresses with a recent purchase relationship, per-channel granular consent, prominent opt-outs, one-click unsubscribes, and suppression lists all reduce complaints and keep lists engaged — the core reputation inputs described in Foundations of Email Deliverability. The ICO's flat statement that no bought list can satisfy the soft opt-in mirrors the deliverability rule that purchased lists destroy sender reputation.

#compliance#legal#pecr#uk-gdpr#united-kingdom#consent#soft-opt-in