The Privacy and Electronic Communications Regulations 2003 (PECR) and the UK General Data Protection Regulation (UK GDPR) are the main laws that govern unsolicited communications in the UK, including emails and advertisements. These laws lay out precise guidelines for how companies can manage personal data and convey marketing messages.
Important Laws and Regulations:
- The 2003 Regulations on Privacy and Electronic Communications (PECR):
Particularly, electronic communications including phone calls, texts, and emails are covered by PECR. Important clauses consist of:
Regulation 22: Consent for Direct Marketing
Before sending unwanted marketing emails or texts, businesses must have the recipient’s prior authorisation.
Exclusions:
Soft opt-in: Sending marketing emails about comparable goods or services is possible if the recipient is an existing client and the company acquired their contact information during a sale or negotiation for a good or service. However, both during data collection and in each follow-up message, recipients must be provided with an easy method to opt out.
Sender’s Identity (Regulation 23):
Marketing emails ought to have accurate contact information and a clear sender identification.
Unwanted SMS and Calls:
Unless there are certain exclusions (such as calls conducted for lawful non-marketing purposes), unsolicited calls and messages require prior consent.
Business Subscribers:
Emails sent to people are subject to stricter regulations than those sent to businesses. Without permission, businesses are able to send unwanted marketing emails to generic corporate addresses (such as info@company.com). Other PECR regulations must still be followed by the material, though.
- The UK General Data Protection Regulation, or UK GDPR, regulates the collection, storage, and use of personal data, including email addresses. Adherence to the UK GDPR is crucial when sending marketing emails.
Among the fundamental ideas are:
Lawfulness, Equity, and Openness (Article 5):
Companies must process personal data legally and disclose their intentions in a clear and concise manner.
Article 6: Legal Foundation for Processing
The most popular legal justification for sending marketing emails is consent. Alternatively, in some situations, companies might rely on legitimate interests (e.g., soft opt-in).
Article 21 Right to Object:
Businesses are required to quickly comply with consumers’ right to refuse to direct marketing at any time.
Article 5: Data Minimisation and Purpose Limitation
Marketing-related data must only be utilised for the intended purpose and be kept to a minimum.
Information Protection (Article 32):
Companies need to make sure that personal information is processed and stored safely.
- DPA 2018 (Data Protection Act of 2018):
The DPA 2018 offers the legal foundation for data protection in the UK and is a supplement to the GDPR. It adds clauses for managing complaints and violations while enforcing GDPR standards.
Complaints and Enforcement: In the UK, the regulatory agency in charge of implementing the PECR and UK GDPR is the Information Commissioner’s Office (ICO). Companies who violate these rules risk fines of up to £500,000 under PECR and up to £17.5 million, or 4% of their yearly worldwide turnover, under UK GDPR.
Key Rules Summary:
Before sending unsolicited commercial emails, businesses must obtain express authorisation, unless the soft opt-in exemption applies.
Marketing emails must clearly identify the sender and include an opt-out option.
Businesses are required to abide by data protection regulations under the UK GDPR, ensuring that personal data is gathered and handled lawfully.
Complaints about unsolicited communications should be directed to the ICO.
info@staylegal.co.uk


