What Is PECR?
TL;DR
PECR, the Privacy and Electronic Communications Regulations 2003, are the UK rules covering marketing by email, text message and telephone, along with cookies and similar tracking. They sit alongside UK GDPR rather than replacing it, so a send can have a valid lawful basis and still breach PECR.
What does PECR say about marketing email?
The rule turns on the type of subscriber. To an individual subscriber you need consent, or you need to meet every condition of the soft opt-in: the address was obtained during a sale or negotiations for a sale of your own product or service, you are marketing similar products or services, the person was given a clear chance to refuse when you collected the address, and you offer a refusal in every message you send. Sole traders and partnerships that are not LLPs count as individual subscribers.
Corporate subscribers, meaning limited companies, LLPs and similar incorporated bodies, sit outside the electronic mail marketing rule, so unsolicited marketing to them needs neither consent nor the soft opt-in. Two things do not go away: the sender still has to identify itself and offer an opt-out, and UK GDPR still governs the personal data of the named individual behind a work address. Bought, rented or broker-supplied lists need consent regardless.
How do PECR and UK GDPR fit together?
They answer different questions. PECR governs the channel, deciding whether a message may be sent at all. UK GDPR governs the data, deciding what lawful basis supports holding and using it. Both have to be satisfied, and satisfying one says nothing about the other.
This is where legitimate interests gets misread. A flawless legitimate interests assessment supports the processing but does not remove a PECR consent requirement, so marketing email to an individual subscriber without consent breaches PECR whatever the assessment concluded. The ICO position is that legitimate interests can carry direct marketing only where PECR does not demand consent in the first place.
What are the penalties under PECR?
The ceiling used to be 500,000 pounds, which made PECR the cheaper regulation to breach. The Data (Use and Access) Act 2025 removed that gap and raised the maximum to UK GDPR level: 17.5 million pounds or 4 percent of total annual worldwide turnover, whichever is higher. The new ceiling applies to conduct on or after 5 February 2026, and earlier conduct stays under the old cap.
That change matters more for direct marketing and cookie practice than any wording change, because the ICO has enforced PECR steadily while the low ceiling limited what enforcement cost. Which regime reaches a specific list is a legal question for a UK adviser; what a definition can give you is the shape of the rule and the fact that the price of ignoring it moved.
Frequently asked questions
The electronic mail marketing rule does not apply to corporate subscribers, so a message to a limited company or LLP does not need consent under PECR. You still have to identify yourself, offer an opt-out in every message, and satisfy UK GDPR for the personal data of the individual you are writing to.