What is PECR? UK Privacy and Electronic Communications Regulations Explained
PECR stands for the Privacy and Electronic Communications Regulations. They are UK rules governing electronic marketing, cookies and similar tracking technologies, and certain aspects of electronic communications.
For most businesses, PECR becomes relevant when sending marketing emails or text messages. It also covers making marketing calls or using cookies, pixels and other technologies on a website or app.
It sits alongside the UK GDPR and the Data Protection Act 2018. This means an organisation may need to comply with both PECR and data protection law when carrying out the same activity.
For organisations, PECR commonly affects:
Email and SMS marketing – and whether you can send unsolicited marketing and whether consent or a soft opt-in is required.
It also affects Telephone marketing – including the rules surrounding live and automated marketing calls.
As well as Cookies and tracking technologies – including cookies, tracking pixels, scripts, tags, local storage and device fingerprinting.
And Electronic communications services – including particular requirements relating to security, traffic data, location data, billing and communications privacy.
For many ordinary businesses, however, marketing and website technologies are the areas where PECR is most likely to arise in day-to-day operations.
What does PECR stand for?
As mentioned, PECR stands for the Privacy and Electronic Communications (EC Directive) Regulations 2003. Although the Regulations date from 2003, they remain an important part of UK privacy law and have been amended several times.
Most recently, the Data (Use and Access) Act 2025 made significant changes to PECR, including changes to storage and access technologies, charitable marketing and the Information Commissioner’s enforcement powers.
What are the rules for email marketing?
The rules depend partly on who you are sending the marketing to and whether the message is solicited or unsolicited. For unsolicited electronic marketing to an individual subscriber, consent or an applicable soft opt-in will normally be required.
For unsolicited electronic marketing sent to an individual subscriber, an organisation will normally need either:
valid consent, or to satisfy all the conditions of an applicable soft opt-in.
Individual subscribers include consumers, but can also include sole traders and some partnerships.
The position is different when sending electronic mail marketing to a corporate subscriber. PECR does not require prior consent or use of the soft opt-in in the same way.
That does not mean that business-to-business marketing is unregulated. If you are using the personal data of an identifiable employee or business contact, such as clara.westbrook@wdps.co.uk the UK GDPR will still apply. You must also respect objections to direct marketing and include an opt out in each and every communication.
Whatever type of subscriber you contact, PECR also prohibits disguising or concealing the sender’s identity and requires a valid address through which the recipient can opt out or unsubscribe.
What counts as consent under PECR.
Consent needs to be freely given, specific, informed and unambiguous, and there must be a clear positive action from the person concerned.
A pre-ticked box is not sufficient enough and is no longer legal under UK law. Neither is bundling marketing wording inside a privacy notice and assuming that the individual has agreed to receive marketing. We have also seen hidden pre ticked consent buttons. These are also not legal under the law.
A consent request should be unambiguous, such as:
☐ I would like to receive marketing emails from Westbrook Data Protection Services Limited about its products and services.
If you intend to use more than one marketing channel, you should consider whether people need meaningful choices between them.
For example, someone may be happy to receive email marketing but not SMS marketing. Defining each one gives clarity.
You should also be able to demonstrate what the person agreed to, when they agreed and how their consent was obtained. If you recieved a DSAR, you will be required to show this.
What records should you keep as proof of marketing consent?
If you rely on consent for electronic marketing, your records should always show who consented, when they consented, how they consented and what they were told at the time. This should be provided in your privacy policy.
For online consent, this may include the wording displayed to the individual, the date and time consent was recorded, the method used to provide consent and the marketing channels selected. You should also retain records of subsequent changes, including withdrawals of consent and objections to direct marketing.
Where the soft opt-in is relied upon, the organisation should be able to demonstrate why its conditions were satisfied, including how the contact details were collected and whether an opportunity to opt out was provided at that point.
What is the PECR soft opt-in?
Despite its name, the soft opt-in is not consent.
It is an exception that allows an organisation to send certain electronic marketing to an individual subscriber without obtaining prior consent.
For the products and services soft opt-in to apply, all of the relevant conditions must be satisfied.
You must have obtained the person’s contact details directly from them during the sale, or negotiations for the sale, of a product or service.
The marketing must relate to your own products or similar services. Doe example, if you sell shirts, you can market individuals with jackets or trousers. You wouldn’t be allowed to market them for hats or shoes as these are unrelated.
The person must have been given a clear opportunity to opt out when their details were collected.
And they must be given an opportunity to opt out every time you subsequently send marketing.
An important point about the soft opt-in
Being an existing customer does not automatically mean that you can use the soft opt-in.
For example, if an organisation obtained a customer’s email address to deliver a service but did not provide an appropriate opt-out when collecting it, the conditions may not have been met. As an organisation you will need to satisfy yourself that you provided this if challenged.
Similarly, the soft opt-in cannot simply be transferred between organisations. In this instance, it is wise to put a provision within your privacy policy to explain in the event of this happening.
Does the PECR soft opt-in apply to charities?
Yes. PECR now contains a separate charitable purposes soft opt-in. It can allow a charity to send electronic mail marketing without consent where the statutory conditions are met.
Broadly, the charity must have obtained the person’s contact details directly in connection with the person expressing an interest in, or offering support for, the charity’s purposes. The marketing must be solely for the purpose of furthering the charity’s charitable purposes, and the person must be given an appropriate opportunity to opt out when their details are collected and in subsequent communications.
The ICO updated its electronic mail marketing guidance in 2026 to reflect this change.
Need help applying PECR to your marketing?
We review email marketing, consent, soft opt-in arrangements, transactional messages, cookies, tracking technologies and customer journeys. Learn more about our PECR Compliance Services.
Does PECR apply to B2B email marketing?
Yes, but the rules are different. PECR distinguishes between individual subscribers and corporate subscribers.
PECR and the UK GDPR: what is the difference?
PECR and the UK GDPR are separate pieces of legislation, but they frequently operate together.
PECR regulates particular communications and technologies. The UK GDPR regulates the processing of personal data associated with them.
For example, PECR may determine whether you are permitted to send someone an unsolicited marketing email. The UK GDPR may then govern your collection, storage and use of that person’s name, email address, marketing preferences and other personal information.
PECR can also apply in circumstances where personal data is not being processed. An organisation should therefore avoid assuming that UK GDPR compliance by itself means its marketing or cookie arrangements are PECR compliant.
Do transactional emails fall under PECR?
A genuinely administrative or service communication is not automatically direct marketing merely because it is sent by email. An order confirmation, security notification or genuine service update may therefore be different from a message promoting a product or service.
The difficulty arises when the two are mixed. An email described as a renewal reminder, account notification or service update may still contain direct marketing if it includes promotional material or encourages the recipient to buy additional products or services.
The content and purpose of the communication matter. Simply describing a message as “transactional” or “service” does not determine whether it contains direct marketing. Read our separate guidance on transactional versus marketing emails under PECR.
What are the PECR rules for cookies and tracking technologies?
As a general rule, organisations must provide clear information about the technology and obtain prior consent before storing or accessing information on a user’s device, unless a PECR exception applies. This will also appear as a pop up consent box on most websites.
Do all cookies require consent?
No. Following changes made by the Data (Use and Access) Act 2025, PECR contains five exceptions to the normal consent requirement. These cover storage or access used for the transmission of a communication, strictly necessary services, certain statistical purposes, certain appearance or functionality purposes, and certain emergency-assistance purposes.
The conditions are not identical for every exception. In particular, the statistical and appearance exceptions include requirements around clear information and a simple means of objecting. If the use of a technology goes beyond the relevant exception, consent is still required.
Does PECR cover tracking pixels and advertising technology?
Yes. PECR has always been concerned with the act of storing information on, or accessing information from, terminal equipment. It is therefore not limited to files technically described as cookies. Tracking pixels, scripts, tags, web storage and fingerprinting techniques can all fall within the rules.
Using a consent management platform does not by itself establish compliance. Organisations need to understand what technology actually loads, when it loads, what purpose it serves and whether consent or a statutory exception applies. The ICO’s final guidance on storage and access technologies was updated in April 2026.
What is PECR? Rules for marketing calls
The rules differ depending on whether a call is live or automated, the type of marketing involved, the recipient’s status and whether a telephone number appears on an applicable preference register. (Organisations should always display their number).
Organisations carrying out telephone marketing should therefore assess their calling lists and processes separately rather than assuming that the email marketing rules apply in the same way.
What are the fines for breaching PECR?
The Data (Use and Access) Act 2025 significantly strengthened the Information Commissioner’s enforcement powers under PECR.
For infringements of specified PECR provisions, including key rules on storage and access technologies and electronic marketing, the higher statutory maximum can reach £17.5 million or, for an undertaking, 4% of total worldwide annual turnover, whichever is higher. Did you know, the ICO make more fines under PECR than GDPR.
The actual level of any penalty will depend on the circumstances of the infringement.
What is a PECR compliance audit?
A PECR compliance audit reviews how an organisation’s marketing and tracking arrangements work in practice, rather than looking only at its privacy wording.
The review can cover marketing databases, the source of contact details, consent records, soft opt-in arrangements, suppression lists, unsubscribe processes, CRM and email-platform settings, transactional messages, cookies, analytics tools, advertising pixels and consent-management technology.
The aim is to identify where the documented position and the actual customer journey do not match.
A practical PECR compliance checklist
- Identify whether the recipient is an individual subscriber or a corporate subscriber.
- Decide whether the communication is genuinely administrative or contains direct marketing.
- If relying on consent, keep evidence of who consented, when, how and to what.
- If relying on the soft opt-in, check that every condition is satisfied.
- Make sure opt-outs and objections are reflected across all relevant marketing systems.
- Know what cookies, pixels, scripts, tags and other technologies your website or app actually uses.
- Identify which storage and access technologies require consent and which fall within a PECR exception.
- Check that your privacy, cookie and marketing information reflects what happens in practice.
Where several systems are involved, such as a CRM, email marketing platform, analytics tools, advertising technology and a consent management platform, the review should follow the information and marketing journey across all of them.
When should you seek professional advice on PECR?
PECR becomes more difficult where an organisation uses several marketing channels, different customer databases, automated journeys, bought or historic contact data, cookies, advertising technologies or multiple consent routes.
Advice can also be useful where you are unsure whether a message is transactional or promotional, whether the soft opt-in was properly established, whether B2B contacts are being handled correctly, or whether your cookie and tracking configuration reflects the choices shown to users.
The important point is to review the actual marketing journey. Good wording will not correct a system that sends marketing to people who have opted out, sets tracking technologies before the required consent is obtained, or records a marketing permission that cannot be evidenced.
Need help with PECR compliance?
Westbrook Data Protection Services provides solicitor-led advice on PECR, direct marketing, consent, the soft opt-in, cookies and tracking technologies. We can review an individual issue or the wider marketing journey, including consent wording, suppression processes, customer communications and the technologies operating on your website.
Learn more about our PECR Compliance Services →
Written by Clara Westbrook, solicitor and founder.
Speak to our team
Explore More Data Protection & Privacy Services
Our team has a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]





