Definition
PECR (Privacy and Electronic Communications Regulations) is the UK legislation that implements the ePrivacy Directive and governs how businesses can use electronic communications for marketing purposes. It covers email marketing, SMS marketing, cookies, and similar technologies.
PECR works alongside UK GDPR to create the legal framework for email marketing in the United Kingdom. While GDPR covers general data protection principles, PECR specifically addresses electronic communication rules including consent for marketing emails.
Key PECR Requirements for Email Marketing
| Requirement | Detail | Penalty for Non-Compliance |
|---|---|---|
| Consent for marketing emails | Marketing emails to individuals require prior consent (soft opt-in applies for existing customers) | Unlimited fine from ICO |
| Clear identification | Marketing emails must clearly identify who is sending them | Unlimited fine from ICO |
| Valid unsubscribe | Every marketing email must include a working unsubscribe mechanism | Unlimited fine from ICO |
| Opt-out honouring | Unsubscribe requests must be processed without delay | Unlimited fine from ICO |
| Cookie consent | Cookies require informed consent (subject to analytics exemption) | Unlimited fine from ICO |
PECR Soft Opt-In
PECR includes a soft opt-in provision similar to the UK GDPR. It allows organisations to send marketing emails to existing customers who have purchased or negotiated to purchase a similar product or service, provided they were given the opportunity to opt out at the point of data collection and in every subsequent message.
PECR vs ePrivacy Directive vs GDPR
| Regulation | Scope | Key Email Marketing Impact |
|---|---|---|
| UK PECR | Electronic communications in the UK | Consent for marketing emails, cookies |
| EU ePrivacy Directive | Electronic communications in the EU | Similar to PECR, transposed into national laws |
| UK GDPR | General data protection in the UK | Lawful basis, data rights, processing records |
| EU GDPR | General data protection in the EU | Same as UK GDPR, with minor differences post-Brexit |
How to Comply with PECR
- Obtain valid consent: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes do not constitute valid consent under PECR.
- Maintain consent records: Document when, how, and what consent was given. Store this evidence in case of regulatory investigation.
- Provide clear unsubscribe: Every marketing email must include a working unsubscribe link that is clearly visible and functional.
- Process opt-outs immediately: Unsubscribe requests should be processed within 28 days at most. Best practice is within 48 hours.
- Audit third-party data: If you use third-party data sources, verify that the data was collected in compliance with PECR.
Was this useful?
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
AI Email Summary
An AI email summary is a short, machine-generated overview of an email's key points, shown by Gmail, Outlook and Apple Mail before a recipient opens the message. It is reshaping how email marketers think about subject lines, preview text and open rates.
AI Inbox Summary
An AI inbox summary is an AI-generated digest that condenses unread email — often highlighting news, actions and senders — changing how clearly your marketing email reaches and engages subscribers.
AI Inbox
An AI inbox is an email client that uses artificial intelligence to summarise, sort, prioritise and sometimes answer emails before the human recipient reads them. It is transforming email marketing metrics and copywriting.
Frequently Asked Questions
Yes, if you send marketing emails to subscribers in the UK. PECR applies to any organisation sending electronic marketing communications to UK recipients, regardless of where the sender is based.
UK GDPR governs the general processing of personal data. PECR specifically regulates electronic communications. For email marketing, UK GDPR determines the lawful basis for processing personal data (usually consent or legitimate interests). PECR determines the specific rules for sending marketing emails including consent requirements and unsubscribe mechanisms.
PECR requires prior consent for marketing emails sent to individual subscribers (B2C). For corporate subscribers (B2B), consent is not required, but you must still identify yourself and provide a valid unsubscribe. The soft opt-in provision allows limited marketing without prior consent to existing customers for similar products.
The UK Information Commissioners Office (ICO) can impose fines of up to £17.5 million or 4% of annual global turnover for PECR violations. Beyond fines, non-compliance damages sender reputation and can result in blacklisting.
Maintain records of consent including the timestamp, method of collection, the specific wording presented to the subscriber, and any subsequent consent changes. Store unsubscribe requests and their processing dates. Document your soft opt-in justifications for existing customer marketing.