Definition
PECR (Privacy and Electronic Communications Regulations) is the UK legislation that implements the ePrivacy Directive and governs how businesses can use electronic communications for marketing purposes. It covers email marketing, SMS marketing, cookies, and similar technologies.
PECR works alongside UK GDPR to create the legal framework for email marketing in the United Kingdom. While GDPR covers general data protection principles, PECR specifically addresses electronic communication rules including consent for marketing emails.
Key PECR Requirements for Email Marketing
| Requirement | Detail | Penalty for Non-Compliance |
|---|---|---|
| Consent for marketing emails | Marketing emails to individuals require prior consent (soft opt-in applies for existing customers) | Unlimited fine from ICO |
| Clear identification | Marketing emails must clearly identify who is sending them | Unlimited fine from ICO |
| Valid unsubscribe | Every marketing email must include a working unsubscribe mechanism | Unlimited fine from ICO |
| Opt-out honouring | Unsubscribe requests must be processed without delay | Unlimited fine from ICO |
| Cookie consent | Cookies require informed consent (subject to analytics exemption) | Unlimited fine from ICO |
PECR Soft Opt-In
PECR includes a soft opt-in provision similar to the UK GDPR. It allows organisations to send marketing emails to existing customers who have purchased or negotiated to purchase a similar product or service, provided they were given the opportunity to opt out at the point of data collection and in every subsequent message.
PECR vs ePrivacy Directive vs GDPR
| Regulation | Scope | Key Email Marketing Impact |
|---|---|---|
| UK PECR | Electronic communications in the UK | Consent for marketing emails, cookies |
| EU ePrivacy Directive | Electronic communications in the EU | Similar to PECR, transposed into national laws |
| UK GDPR | General data protection in the UK | Lawful basis, data rights, processing records |
| EU GDPR | General data protection in the EU | Same as UK GDPR, with minor differences post-Brexit |
How to Comply with PECR
- Obtain valid consent: Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes do not constitute valid consent under PECR.
- Maintain consent records: Document when, how, and what consent was given. Store this evidence in case of regulatory investigation.
- Provide clear unsubscribe: Every marketing email must include a working unsubscribe link that is clearly visible and functional.
- Process opt-outs immediately: Unsubscribe requests should be processed within 28 days at most. Best practice is within 48 hours.
- Audit third-party data: If you use third-party data sources, verify that the data was collected in compliance with PECR.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
AIDA Model for Email
The AIDA model (Attention, Interest, Desire, Action) is a classic copywriting framework used to structure email campaigns that guide subscribers from awareness to conversion.
AMP for Email
AMP for Email is a Google-developed framework that allows email messages to include interactive elements like forms, carousels, accordions, and live content. It turns static emails into dynamic, interactive experiences directly inside the inbox.
Announcement Email
An announcement email is a dedicated campaign that communicates a specific update, milestone, or change to subscribers, from product launches and feature releases to company news and events.
AOL Mail for Email Marketers
AOL Mail is a legacy email provider with specific deliverability requirements and rendering quirks, now operating as part of the Yahoo+AOL network under shared infrastructure.
Frequently Asked Questions
Yes, if you send marketing emails to subscribers in the UK. PECR applies to any organisation sending electronic marketing communications to UK recipients, regardless of where the sender is based.
UK GDPR governs the general processing of personal data. PECR specifically regulates electronic communications. For email marketing, UK GDPR determines the lawful basis for processing personal data (usually consent or legitimate interests). PECR determines the specific rules for sending marketing emails including consent requirements and unsubscribe mechanisms.
PECR requires prior consent for marketing emails sent to individual subscribers (B2C). For corporate subscribers (B2B), consent is not required, but you must still identify yourself and provide a valid unsubscribe. The soft opt-in provision allows limited marketing without prior consent to existing customers for similar products.
The UK Information Commissioners Office (ICO) can impose fines of up to £17.5 million or 4% of annual global turnover for PECR violations. Beyond fines, non-compliance damages sender reputation and can result in blacklisting.
Maintain records of consent including the timestamp, method of collection, the specific wording presented to the subscriber, and any subsequent consent changes. Store unsubscribe requests and their processing dates. Document your soft opt-in justifications for existing customer marketing.