1. Purpose
This policy outlines our commitment to comply with UK laws governing unsolicited communications and marketing, including the Privacy and Electronic Communications Regulations 2003 (PECR), the UK General Data Protection Regulation (UK GDPR), and the Data Protection Act 2018 (DPA 2018). It sets out how we collect, use, and manage personal data for marketing purposes while protecting individuals’ rights.
Scope
This policy applies to all unsolicited communications and marketing activities conducted by or on behalf of [Your Business Name], including:
- Emails
- Text messages (SMS)
- Phone calls
- Direct mail
It covers communications directed at individuals and corporate subscribers within the UK.
3. Legal Framework
Our marketing activities comply with:
- Privacy and Electronic Communications Regulations 2003 (PECR): Governing consent requirements for electronic marketing.
- UK GDPR: Setting standards for the lawful processing of personal data.
- Data Protection Act 2018: Providing additional protections and enforcement mechanisms.
4. Policy Principles
4.1 Consent for Marketing Communications
We will obtain explicit consent from individuals before sending unsolicited marketing emails, texts, or other electronic communications unless an exemption applies (e.g., soft opt-in). Consent must be:
- Freely given, specific, informed, and unambiguous.
- Obtained via a clear opt-in mechanism.
4.2 Soft Opt-In Exemption
We may send marketing communications to existing customers without explicit consent if:
- We obtained their contact details during the sale or negotiation of a product or service.
- The communication relates to similar products or services.
- The recipient was provided with an option to object (opt out) at the point of data collection and in every subsequent communication.
4.3 Corporate Subscribers
We may send marketing communications to corporate email addresses (e.g., info@company.com) without prior consent. However, recipients must still be provided with an opt-out option.
4.4 Opt-Out Mechanism
All marketing communications will include:
- A clear and accessible mechanism for recipients to opt out of future communications.
- Instructions on how to update their preferences or withdraw consent.
Opt-out requests will be processed promptly and no later than one month after receipt.
5. Data Protection and Privacy
We will handle all personal data in accordance with the principles of UK GDPR:
- Transparency: We will clearly inform individuals how their data will be used at the point of collection.
- Data Minimisation: We will only collect and process data necessary for marketing purposes.
- Purpose Limitation: Personal data collected for marketing will not be used for other purposes without additional consent.
- Data Security: We will implement technical and organisational measures to protect personal data from unauthorised access, alteration, or disclosure.
6. Monitoring and Record-Keeping
We will maintain records of:
- Consent obtained from individuals.
- Opt-out requests and preferences.
- Compliance with legal requirements for all marketing campaigns.
7. Complaints Handling
Complaints about unsolicited communications or marketing can be directed to:
- Email: [Your Business Email]
- Phone: [Your Business Phone Number]
We will respond to complaints within 30 days. If the issue is not resolved, individuals can escalate complaints to the Information Commissioner’s Office (ICO):
Website: www.ico.org.uk
Phone: 0303 123 1113


