# UK PECR — Electronic Mail Marketing

> ICO guidance on direct marketing by electronic mail under PECR and UK GDPR: consent standard, the two soft opt-ins, individual vs. corporate subscribers, bought-in lists, and refer-a-friend.

Source: emailmarketing.net — https://emailmarketing.net/learn/compliance/uk-pecr-email-marketing

If you send marketing email or SMS to people in the UK, you generally need their consent, unless one of two "soft opt-in" exceptions applies. The rules are set by the Privacy and Electronic Communications Regulations (PECR). Where personal information is used, the UK GDPR and the Data Protection Act 2018 also apply.

The Information Commissioner's Office (ICO), the UK regulator, publishes and enforces this guidance. Like [Canada's CASL](https://emailmarketing.net/learn/compliance/casl), and unlike [CAN-SPAM](https://emailmarketing.net/learn/compliance/can-spam) in the US, PECR is an **opt-in** regime for individual subscribers, with the two soft opt-in exceptions.

This is not legal advice. Check penalties and thresholds against the primary source (below) and with a lawyer before you rely on them. See the [compliance notice](https://emailmarketing.net/learn/compliance).

## Key definitions

**Direct marketing.** The Data (Use and Access) Act added this definition to PECR from the Data Protection Act (DPA), with effect from 20 August 2025: "the communication (by whatever means) of advertising or marketing material which is directed to particular individuals." It covers commercial marketing **and the promotion of aims and ideals**. Messages that are purely about service or administration are not direct marketing, but adding any promotional material to a service message makes it direct marketing.

**Electronic mail**: "any text, voice, sound or image message sent over a public electronic communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient and includes messages sent using a short message service." It covers:

- email and SMS;
- picture and video messages;
- voicemail messages;
- in-app messages;
- direct (private) messages on social media.

It does **not** cover online display or banner ads, or ads in social media feeds (even targeted ones), because those are public and not stored for a specific recipient. Other PECR rules, such as those on storage and access technologies, may apply to them.

**Solicited and unsolicited marketing.** Marketing is *solicited* only when someone specifically asks for a particular message or type of information (for example, "email me your summer brochure"). Everything else, including follow-up messages to that person, is *unsolicited*. Solicited marketing needs no consent and no soft opt-in.

**Subscriber**: the person or organisation named on the bill for the phone line, internet connection or other communications service. There are two types:

- **individual subscribers**: people, sole traders and ordinary partnerships;
- **corporate subscribers**: organisations with their own legal personality (limited companies, limited liability partnerships (LLPs), Scottish partnerships).

PECR applies **even to generic or role-based addresses**, so you do not need to know the recipient's name for it to apply. If personal information is used, data protection law applies as well.

## Which rules apply to whom (B2B vs. B2C)

| Message | Individual subscriber | Corporate subscriber |
|---|---|---|
| Solicited marketing | Allowed without consent | Allowed without consent |
| Unsolicited marketing | Requires **consent** or a **soft opt-in** | Allowed without consent or a soft opt-in |
| Identity disclosure | Must not disguise or hide the sender's identity | Same |
| Contact address for opting out | Required | Required |

Be careful with "B2B". Sole traders and ordinary partnerships count as **individual** subscribers, so the consent rules apply to them. Employees' business addresses at limited companies are still personal data, so the UK GDPR, including the absolute right to object, applies even where PECR does not require consent.

## Who must comply

PECR applies to anyone who **sends or instigates** electronic mail marketing. Instigating includes encouraging, inciting, offering an incentive to, or asking someone else to send it. If another organisation sends marketing on a brand's behalf, **both** are responsible: the instigator and the sender. A webmail service or bulk email platform that only provides technical delivery is normally **not** responsible.

If a third party sends marketing that uses personal information on a sender's behalf, a written contract is required, along with appropriate compliance checks. A subscriber must also not let others use its line or connection to break the rules.

## Consent

PECR takes its standard of consent from the UK GDPR: "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement."

When you ask for consent, it must be:

- **Freely given.** A free choice that people can refuse without any disadvantage, kept separate from the terms and conditions. Making agreement to marketing a condition of a purchase or donation is unlikely to be valid.
- **Specific and informed.** The request must name the organisation and make clear that it covers electronic mail marketing. "I would like to receive marketing", without naming the channel, is not specific enough. Ask separately for each channel (email and SMS).
- **Unambiguous, through a clear affirmative action.** Pre-ticked boxes, silence and inactivity do not count.
- **Recorded.** Keep a record of who consented, when and how, so that you can show the consent is valid.
- **Not transferable.** Consent applies to the particular address or number given, and does not extend to the person's other addresses.
- **Possible to withdraw.** It must be easy to withdraw at any time; consent lasts only "for the time being."

## The soft opt-ins

Two limited exceptions allow unsolicited electronic mail marketing to individual subscribers without consent.

### 1. Products and services soft opt-in (any organisation, including charities)

All five conditions must be met:

1. **You obtained the recipient's contact details** directly: not through a third party, and not even through another company in your own group. "There is no such thing as a third-party marketing list that is compliant with the soft opt-in."
2. **You obtained them while selling, or negotiating to sell, a product or service.** A purchase is not required. "Negotiations" means the person actively showed an interest in buying (signing up for a free trial, asking for a quote, asking about a product). Merely browsing a website, or asking a question unrelated to buying, does not qualify.
3. **You market only your own similar products and services.** The test is whether, based on earlier interactions, people would reasonably expect this marketing. Someone who buys groceries can be sent marketing for other supermarket products, but not for the chain's banking or insurance products. It never covers other organisations' products. Charities, political parties and other not-for-profit organisations must **not** use this soft opt-in for campaigning or fundraising, even to existing supporters.
4. **You gave people a chance to refuse, or opt out, when you collected the details.** A prominent opt-out box on the form, or an opt-out offered verbally, qualifies. An opt-out buried in a privacy policy, or offered only in a later confirmation email, does not.
5. **You offer an opt-out in every later message.** This means a clear unsubscribe link or a direct reply, or for SMS "text STOP to [code number]", free of charge apart from the normal cost of a message. Requiring a phone call, the creation of an account, or a login to a preference centre is not acceptable.

### 2. Charitable purposes soft opt-in (charities only), in force from 5 February 2026

All six conditions must be met:

1. **You are a charity**, as defined by law in each UK nation.
2. **You obtained the contact details directly**, not through a trading subsidiary, a third-party fundraising platform or any other intermediary.
3. **You obtained them because the person expressed an interest in, or offered or gave support for, your charitable purposes**: for example, by asking for information about the charity's work, donating money or property, or volunteering. Interactions that show nothing about an interest in the charitable purposes do not qualify, such as signing up for guest wifi, buying a coffee at a charity café, or asking for emergency support. Some purchases clearly made by a supporter, in that capacity, can qualify (an annual membership, sponsoring an animal, a charity raffle, paid fundraising events). Purchases made incidentally or for convenience do not.
4. **The only purpose of the marketing is to further your charitable purposes**: asking for donations (money or property), recruiting volunteers, or informing people about programmes, projects and campaigns related to the mission. It must not promote other organisations, including other charities or commercial sponsors.
5. **You offered an opt-out when you collected the details** (to the same standard as above).
6. **You offer an opt-out in every later message** (to the same standard as above).

**Timing.** This soft opt-in applies only to contact details obtained **on or after 5 February 2026**. Details collected earlier without consent cannot be used under it, unless they are collected again after that date with a compliant opt-out.

### Using both soft opt-ins together

A charity may rely on both. To do so, it must:

- show **separate opt-out boxes** for each one when it collects the details (and only where the collection conditions for that soft opt-in are met);
- provide a way to opt out of each type in every message;
- include only the marketing content that the soft opt-ins it relies on allow;
- keep records (flags or preference fields) of which legal basis applies to each person.

## Bought-in lists

To send electronic mail marketing to a list you bought, rented or licensed, everyone on it must have given valid consent that **names your organisation specifically** (not "trusted partners" or similar). The consent must cover the specific channel (email or SMS), and must be freely given, specific, informed, unambiguous and recorded (who, when and how). If it is not, do not send. The soft opt-ins can **never** be used with bought lists, because they require the details to be collected directly.

## Publicly available contact details

The fact that an address is publicly available (on websites, social media or directories) is **not** consent. Unsolicited marketing to individual subscribers, including sole traders and ordinary partnerships, still requires consent or a soft opt-in. Scraping personal information also brings in data protection law. By contrast, CASL has a category of implied consent for "conspicuous publication"; PECR does not.

## Refer-a-friend / viral marketing

An organisation that encourages people to forward its marketing becomes an **instigator**. No incentive is needed: active encouragement is enough. The soft opt-ins cannot be used for these messages. Valid consent from the friend or family member who receives the message would be required, and that is unlikely to be obtainable in practice, so refer-a-friend email schemes with incentives generally breach PECR.

An organisation is not responsible for messages that people choose to send without its encouragement, such as spontaneous recommendations, sharing a promotion, linking to a site, or personal requests for sponsorship.

## Changing minds: withdrawal and opt-out

- Consent can be withdrawn at any time. After that, further marketing requires new consent.
- Opting out of a soft opt-in also stops further marketing under it, and only new consent restores it.
- An opt-out applies to one channel if its wording makes that clear (unsubscribing from email does not have to stop SMS).
- Under data protection law, people have an **absolute right to object** to direct marketing. It cannot be refused on any grounds, and not having opted out of a soft opt-in does not override it.
- Keep a **"do not contact" list (a suppression list)** and check it before sending.
- A reply confirming an unsubscribe and explaining how to subscribe again is fine. Reminders about preferences may be small additions to messages you are already sending, provided they do not encourage people to change their choice.

## How PECR and the UK GDPR interact

Where personal information is used, both sets of rules apply. Processing must be fair, lawful and transparent, so tell people when you collect their details that you intend to send marketing. Of the seven lawful bases in the UK GDPR, **consent** and **legitimate interests** are usually the relevant ones:

- If you rely on consent under PECR, your lawful basis is likely to be consent.
- If you rely on a soft opt-in, your lawful basis is likely to be **legitimate interests**. Carry out a legitimate interests assessment (purpose, necessity, balancing). Where recipients may be in vulnerable situations, the balancing test may fail and the soft opt-in should not be used. The ICO's example is people receiving support after domestic abuse, who could be harmed if a partner saw the email.

**Tracking pixels.** The electronic mail marketing rules apply to the email itself, not to tracking pixels (which record the time of opening, the location and the operating system). Pixels fall under PECR's separate rules on **storage and access technologies**, which you must also comply with.

## Deliverability relevance

PECR's conditions for consent and the soft opt-in match deliverability best practice closely. Addresses collected directly from people with a recent purchase, granular consent for each channel, prominent opt-outs, one-click unsubscribes and suppression lists all reduce complaints and keep lists engaged, and those are the core inputs to reputation described in [Foundations of Email Deliverability](https://emailmarketing.net/learn/foundations/foundations-of-email-deliverability). The ICO's plain statement that no bought list can satisfy the soft opt-in mirrors the deliverability rule that purchased lists destroy a sender's reputation.
