
If You Need to know Marketing Rules Including, Emails, Cookies and Electronic Communications, You’re in the Right Place.
Practical advice on email marketing, consent, the soft opt-in, cookies and how your organisation communicates with customers and prospects.
We help organisations understand when they can contact customers and prospects, what consent or other permissions they need, and how PECR applies to email, SMS, telephone marketing, cookies and tracking technologies.
Marketing and PECR Rules for UK Organisations
The Data (Use and Access) Act 2025 significantly increased the ICO’s powers under PECR. The maximum fine can now reach £17.5 million or 4% of worldwide annual turnover, bringing PECR penalties into line with the highest UK GDPR penalty levels.
We review the practical customer journey and help you identify where consent, the soft opt-in, suppression lists, unsubscribe mechanisms or other PECR requirements apply.

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
Common issues
A common issue we find is that organisations do not always distinguish clearly between a service message and a marketing message. An email may begin as a genuine account update, renewal reminder or transactional communication, but promotional wording can change how that communication needs to be treated.
We also see organisations relying on consent obtained several years earlier without checking what people were actually told, or assuming that because someone is an existing customer they can automatically be marketed to under the soft opt-in.
Reviewing the full customer journey — from how contact details are collected through to how marketing preferences and opt-outs are recorded — often identifies issues that are not obvious when looking at an individual email in isolation.
Costing structure
Final pricing subject to discussion.
Marketing Review | Email Marketing & Soft opt-in Review | Full PECR Compliance Review |
From £500 | From £1,500 | From £3,000 |
Review of your current PECR position, including marketing emails, cookies or consent wording | Review of email marketing journeys, transactional emails, consent routes and soft opt-in use. | Wider review of email marketing, cookies, tracking tools, consent, unsubscribe processes and customer journeys |
Identification of obvious gaps, unclear consent options and risks | Assessment of whether emails are transactional, marketing or mixed-purpose communications | Review of website cookies, analytics tools, advertising pixels, CRM integrations and marketing platforms |
Practical recommendations for improvement | Recommendations on consent wording, unsubscribe wording, preference management and suppression lists | Alignment with privacy notices, cookie notices, consent records and wider UK GDPR documentation |
Suitable where you’re using consent for a new purpose. | Suitable where your main concern is email marketing compliance. | Suitable for organisations using several marketing channels, automation tools or tracking technologies |
Are you aware? Under the PECR, organisations generally need consent before sending unsolicited electronic marketing to individuals. However, there are exceptions, including the soft opt-in for certain existing customers. Different rules also apply when marketing to corporate subscribers.
PECR fines and enforcement
PECR covers electronic marketing, cookies and tracking technologies. The ICO can take enforcement action where organisations get this wrong, and The Data (Use and Access) Act 2025 has strengthened the ICO’s enforcement powers under PECR. Read more here.
Why organisations choose WDPS
We are a solicitor-led organisation with over 25 years’ experience in data protection and privacy law. We help organisations understand how PECR applies to their real marketing activity, including email campaigns, transactional messages, cookies, consent journeys and B2B communications.
We have worked with organisations across multiple sectors, including WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale, supporting privacy, data protection, marketing compliance and customer communication documentation.
Book an initial discussion
Speak directly with a data protection solicitor about your PECR, email marketing, cookie or consent issue. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4 pm). If you would like us to call or email you, please leave your details and a short summary of the issue. We will let you know whether we can help and what information we would need to review.
Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ
View our Privacy Policy here
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
Frequently asked questions
Do we always need consent to send marketing emails or texts?
Organisations generally need consent before sending unsolicited electronic marketing to individual subscribers, but the soft opt-in may apply to certain existing customers. Different PECR rules apply to corporate subscribers, although UK GDPR duties still apply when personal data is used.
When can the PECR soft opt-in be used?
Broadly, the contact details must have been obtained during a sale or negotiations for a sale, the marketing must concern your own similar products or services, and the person must have had a clear opt-out when their details were collected and in every later message.
How are corporate subscribers treated under PECR?
The electronic mail consent rule and soft opt-in do not apply to corporate subscribers in the same way as they do to individual subscribers. You should still identify the recipient correctly, respect objections and opt-outs, and comply with UK GDPR where a business contact can be identified.
Do non-essential cookies require consent?
Usually, yes. Cookies and similar technologies that are not strictly necessary generally require clear information and valid consent before they are set or accessed. Analytics, advertising and personalisation tools should be assessed rather than treated as automatically necessary.



