...

Over 20 Years of Legal Expertise – Trusted by UK Businesses. Secure Your Peace of Mind Today!

Email Marketing and PECR: Lawful Marketing, Consent, and Avoiding ICO Enforcement

This article explains how to develop an email marketing programme that yields results while adhering to the law.

Introduction

Email marketing remains one of the most effective tools for businesses. It offers direct access to potential and existing customers at a relatively low cost, with measurable results and a high return on investment. However, the legal framework governing email marketing in the United Kingdom is strict, and the penalties for non-compliance are significant.

The primary legislation governing electronic marketing in the UK is the Privacy and Electronic Communications Regulations 2003, known as PECR. These regulations, which sit alongside the UK GDPR, set out specific rules about when and how businesses can send marketing communications by email, text message, telephone, and fax. The Information Commissioner’s Office is empowered to issue fines of up to £500,000 for breaches of PECR, and it exercises that power with increasing frequency.

This article elucidates the legal guidelines that govern email marketing, the prerequisites for valid consent, the applicable exceptions, and strategies for constructing a compliant marketing program that optimises outcomes while adhering to the law.

The Basic Rule: Consent

Regulation 22 of PECR prohibits the sending of unsolicited marketing communications by electronic means unless the recipient has previously notified the sender that they consent. This is an opt-in requirement. Unlike some other jurisdictions, UK law does not permit businesses to send marketing emails to individuals unless those individuals have actively agreed to receive them.

The consent must meet the UK GDPR standard. It must be freely given, specific, informed, and unambiguous, and it must involve a clear affirmative action. Pre-ticked opt-in boxes do not constitute valid consent. Bundling marketing consent with acceptance of terms and conditions is unlikely to be considered freely given. Consent must be specific to the type of marketing being sent, so blanket consent to receive ‘communications’ is insufficient if you intend to send promotional offers, newsletters, and third-party advertising.

You must also keep records of consent. You must show when and how consent was obtained, what information was provided, and what was consented to if challenged by the ICO or an individual. Good record-keeping is not just best practice; it is a legal necessity.

The Soft Opt-In Exception

PECR provides one important exception to the consent requirement, commonly known as the soft opt-in. Under Regulation 22(3), you may send marketing emails to an individual without their prior consent if four conditions are met. First, you obtained the individual’s contact details in the course of a sale or negotiations for a sale of a product or service. Second, the marketing relates to similar products or services. Third, individuals were given a simple means to refuse the use of their contact details both when they were collected and in every subsequent communication. Fourth, the individual has not opted out.

The soft opt-in is a valuable tool for businesses that sell directly to consumers, but it must be applied carefully. The requirement that the marketing relates to similar products or services means you cannot use a customer’s email address to promote an entirely different line of business. The requirement for a simple opt-out at the point of collection means you must include an unsubscribe mechanism from the very first email. And the fact that the exception applies only where details were obtained in the course of a sale or negotiation means it does not apply to contact details collected through a newsletter sign-up, a competition entry, or a free download.

The soft opt-in excludes marketing on behalf of third parties. If you wish to share your customers’ email addresses with another business for their marketing purposes, you need separate, explicit consent.

Business-to-Business Marketing

The rules for marketing to corporate subscribers differ from those for individual subscribers. PECR permits unsolicited marketing emails to be sent to corporate email addresses, such as info@company.com or sales@company.com, without prior consent, provided the sender identifies themselves and provides a valid contact address for opt-out requests. However, an email sent to a named individual at a business, such as john.smith@company.com, is treated as a communication to an individual subscriber and requires consent or the soft opt-in.

This distinction is narrower than most businesses realise. In practice, most business email addresses identify individuals, which means the consent requirements apply to the majority of B2B email marketing. The ICO has stated that businesses should not assume they are exempt from the consent requirement just because they are marketing to other businesses.

Even where the corporate subscriber exception applies, you must still comply with UK GDPR (General Data Protection Regulation) if the email address contains personal data, which it invariably does when it identifies a named individual. This means you need a lawful basis for processing the personal data, and you must comply with all the other requirements of data protection law, including the right to object.

What Must Be Included in Marketing Emails

Every marketing email you send must clearly identify the sender. You must not conceal or disguise the identity of the person making the communication. You must include a valid address to which the recipient can send an opt-out request. In practice, this means including a functional unsubscribe link in every email.

The unsubscribe mechanism must be simple and free. Requiring the recipient to log in to an account, complete a form, or send a written request by post does not meet the standard. A single-click unsubscribe link is best practice and is increasingly expected by the Information Commissioner’s Office (ICO), which is the UK’s independent authority set up to uphold information rights. Once a recipient has opted out, you must honour their request promptly; the ICO expects that opt-outs are processed without delay and recommends a maximum of 28 days, though the best practice is to process them within 48 hours.

You should also ensure that your marketing emails comply with the Electronic Commerce Regulations 2002, which require commercial communications to be clearly identifiable as such. If an email is a marketing communication, it should be obvious to the recipient from the outset. Disguising marketing as personal correspondence or transactional emails is both legally problematic and damaging to customer trust.

Bought Mailing Lists

One of the most frequent areas of non-compliance involves the use of purchased or rented mailing lists. The law is clear: you can only rely on consent given to you or on your behalf. Consent obtained by a third party for their purposes does not transfer to you when you purchase a mailing list. Sending marketing emails is unlawful unless the individuals on the list specifically consented to receive marketing from your business or from businesses in general, in a way that is specific enough to cover your communications.

The ICO has taken enforcement action against businesses that relied on purchased lists, and the fines involved have been substantial. The reputational damage can be equally significant; unsolicited emails generate complaints, damage your sender reputation, and can result in your domain being blacklisted by email providers. From both a legal and a practical perspective, purchased mailing lists are a false economy.

SMS and Telephone Marketing

While this article focuses primarily on email, it is worth noting that PECR applies equally to marketing by text message and by telephone. The rules for text messages mirror those for email: consent is required unless the soft opt-in applies. For telephone marketing, the rules differ. Unless they have registered with the Telephone Preference Service or told you not to call, you can call people. Automated marketing calls, which play a recorded message, always require consent.

Businesses that operate across multiple marketing channels need to ensure their compliance framework addresses each channel separately, as the rules and exceptions differ.

ICO Enforcement

The ICO has consistently identified unsolicited marketing as a priority area for enforcement. It publishes details of the fines it issues, and the figures are instructive. Fines for breaches of PECR regularly run to tens of thousands of pounds, with the most serious cases attracting fines of several hundred thousand pounds. The ICO’s enforcement is complaint-driven; a single complaint can trigger an investigation, and a pattern of complaints will almost certainly result in action.

Beyond the direct financial penalties, ICO enforcement can result in enforcement notices that restrict your marketing activities, negative publicity that damages your brand, and loss of trust among your customer base. The reputational cost of being publicly named by the ICO for unlawful marketing can far exceed the fine itself.

Building a Compliant Email Marketing Programme

Compliance begins with your data collection processes. Every sign-up form, checkout page, and point of contact should include a clear, specific, and unbundled opt-in mechanism for marketing. The language should explain what the individual is signing up for, how often they will hear from you, and what types of content they will receive. Consent should be recorded with timestamps and associated with the specific wording that was presented to the individual.

Maintain your mailing list meticulously. Process opt-outs promptly. Remove hard bounces and inactive addresses regularly. Segment your list so that you can target communications appropriately and demonstrate that your marketing relates to similar products and services where you rely on the soft opt-in.

Review your marketing activities regularly. Changes in your product range, marketing strategy, or use of third-party platforms may affect your compliance position. Train your marketing team to understand the legal requirements and to recognise the boundaries of what is permissible. And keep records of everything: consent, opt-outs, complaints, and the content of the emails you send.

Conclusion

Email marketing is a powerful business tool, but it operates within a strict legal framework. The rules under PECR and UK GDPR are clear: consent is required, the soft opt-in has specific conditions, and every email must include a simple opt-out mechanism. Businesses that invest in building compliant mailing lists and maintaining proper records will not only avoid enforcement action but will achieve better results, because engaged, consenting subscribers are far more valuable than a large list of reluctant or unaware recipients.

Need help with marketing compliance?

Lawdit Solicitors’ The StayLegal package covers email marketing compliance, including consent frameworks, privacy notices, and PECR-compliant opt-in mechanisms. Visit staylegal.co.uk to learn more.

Next in this series: Article 8 – Consumer Rights and Online Sales: Handling Refunds, Returns, and Complaints

More From Stay Legal

Share this with your network