Cyber Rebels

PECR Explained: What UK Businesses Need to Know

PECR Explained UK businesses digital privacy compliance cybersecurity.

PECR governs much more than marketing emails. This practical guide explains electronic marketing, cookies and tracking technologies, how PECR works alongside UK GDPR, and what recent DUAA changes mean for UK organisations.

The Privacy and Electronic Communications Regulations have been part of the UK privacy landscape since 2003, yet they are still regularly treated as an awkward appendix to GDPR.

That is a mistake.

The Privacy and Electronic Communications (EC Directive) Regulations 2003, usually shortened to PECR, govern some of the most routine ways organisations communicate and operate online. They affect electronic direct marketing, marketing calls, cookies and other technologies that store or access information on people’s devices. They also contain privacy and security rules for organisations providing public electronic communications services.

PECR also matters more in 2026 than its age might suggest. The Data (Use and Access) Act 2025 (DUAA) amended important parts of the Regulations, including the rules around storage and access technologies, direct marketing and enforcement. The Information Commissioner’s Office has since published updated detailed guidance on electronic mail marketing and finalised new guidance covering cookies, tracking pixels, local storage, device fingerprinting and similar technologies.

For businesses, the useful question is therefore not simply whether they “comply with GDPR”. It is whether the ways they communicate, market and use technology comply with the specific rules that apply to those activities.

What is PECR?

PECR is a set of UK regulations concerned with privacy in electronic communications.

Although PECR and the UK GDPR often apply to the same activity, they are not interchangeable. PECR contains more specific rules for particular communications and technologies. The UK GDPR and Data Protection Act 2018 deal more broadly with the processing of personal data.

That difference becomes clearer when you look at what PECR actually covers.

Its scope includes marketing by telephone, email, text, fax and other forms of electronic mail; technologies that store information on or access information from devices; and certain privacy and security obligations connected with public electronic communications networks and services. The latter includes areas such as traffic and location data, security breaches, calling-line identification and directories.

Not every part of PECR applies to every business. Many of the communications-service provisions are principally relevant to providers of public electronic communications services. By contrast, the marketing and storage/access rules can affect organisations across almost every sector.

A retailer running email campaigns, a charity sending fundraising messages, a professional-services firm prospecting for clients and a small business using analytics or advertising technologies on its website can all encounter PECR in different ways.

That breadth is one reason the Regulations are easy to misunderstand. PECR is not simply “the cookie law”, and it is not simply a rule requiring consent before somebody can be emailed.

It controls several different decisions, and those decisions do not all have the same answer.

How PECR works alongside UK GDPR

One of the most important distinctions is between permission to use a communications channel and the lawful processing of personal data.

PECR may determine whether a marketing email can be sent or whether information can be stored on a device without consent. Where personal data is also being processed, the UK GDPR then applies alongside it.

That creates two legal questions rather than one.

Suppose a business wants to send a named employee of a limited company a relevant marketing email. PECR may permit the communication without prior consent because the recipient is using a corporate subscriber’s address. If the business is processing the employee’s name, email address, job role or other identifiable information, however, it still needs to comply with the UK GDPR. Legitimate interests may potentially provide the lawful basis for that processing where the relevant test is satisfied.

Change the recipient to an individual subscriber and the position can be different. PECR may require consent for unsolicited electronic mail unless a relevant exception, such as the soft opt-in, applies. A business cannot bypass that PECR requirement simply by deciding that it has a legitimate interest in sending the marketing.

This is why the familiar question, “Can we rely on legitimate interests?”, is incomplete.

Legitimate interests is a data-protection lawful basis. It is not a general exemption from PECR.

Where PECR requires consent, the channel restriction still has to be satisfied. Where PECR permits the activity without consent, the organisation must separately consider whatever UK GDPR obligations apply to the personal information involved.

Keeping those two layers separate removes a lot of unnecessary confusion.

Direct marketing under PECR

Direct marketing is one of PECR’s best-known areas, but its scope is broader than promotional email.

Following changes introduced by the DUAA, PECR now contains the statutory definition of direct marketing used in the Data Protection Act: broadly, advertising or marketing material directed to particular individuals. That includes commercial promotion, but can also include the promotion of aims and ideals by organisations such as charities.

PECR then applies different rules depending on the method of communication.

For electronic mail, which includes email and text messaging and can extend to other stored electronic messages, unsolicited marketing to individual subscribers generally requires consent unless an applicable exception exists. The familiar commercial soft opt-in can permit marketing of an organisation’s own similar products and services where contact details were obtained during a sale or genuine negotiations for a sale, provided the required opt-out opportunity was given when the details were collected and in every subsequent message.

The distinction between individual and corporate subscribers is important for B2B marketing. PECR does not impose the same prior-consent requirement for electronic marketing sent to corporate subscribers, although sender-identification and opt-out requirements still apply. Where a named person’s data is being used, UK GDPR remains relevant.

Sole traders and certain partnerships do not simply become corporate subscribers because they operate commercially. Their treatment under PECR can therefore be different from that of limited companies or LLPs.

PECR also governs marketing calls. Live direct marketing calls are subject to rules around preferences and objections, while automated marketing calls operate under stricter consent requirements. Businesses making telephone campaigns therefore need to consider PECR rather than assuming that a number being publicly available makes it usable for marketing.

The practical point is that direct marketing is not one permission. The answer can change according to the communication method, the type of subscriber, whether the communication was requested, how the contact details were obtained and whether the person has previously objected.

Someone inside a business still has to make those distinctions before the campaign goes out.

PECR is also the law behind much more than cookies

For many website owners, their first encounter with PECR is a cookie banner.

Regulation 6 deals with storing information on, or accessing information already stored on, a subscriber’s or user’s device. That reaches considerably further than traditional browser cookies.

The ICO’s current guidance describes technologies within this area as storage and access technologies. They can include cookies, tracking pixels, local storage, device fingerprinting, scripts, tags and technologies used to decorate or track links.

The basic rule is that organisations cannot simply store or access information on a person’s device unless PECR’s requirements are met.

Historically, much of the public discussion around this reduced the issue to a simple formula: non-essential cookies require consent.

The current position deserves a little more care.

The DUAA amended regulation 6 and expanded the circumstances in which storage or access can take place without consent. There are now five relevant exceptions: where the sole purpose is transmitting a communication; where it is strictly necessary to provide a service requested by the user; certain statistical uses intended to improve a service or website; particular uses connected with appearance or functionality according to user preference; and locating a device for emergency assistance.

Those newer exceptions are not a free pass for analytics or tracking.

For example, the statistical-purpose exception is subject to defined conditions. The sole purpose must be collecting statistical information to improve the service or website, and organisations relying on it must provide clear information and a simple, free means for users to object. If the information is also used for purposes such as profiling or advertising, the exception will not cover that wider use.

The same principle applies more generally: the purpose matters.

A technology may be technically capable of performing several jobs, but PECR considers what the organisation is actually using it to do. Adding advertising, profiling or another non-exempt purpose can change the legal position even if the underlying piece of code is the same.

Where use of these technologies involves personal data, UK GDPR obligations also remain relevant.

That is why a compliant cookie or tracking setup cannot reliably be produced by installing a banner and assuming the banner has solved the underlying problem. Someone needs to know which technologies are running, what each one does, why it is being used, which PECR rule or exception applies and whether personal-data processing takes place behind it.

The visible banner is only the final part of that decision.

Some PECR obligations sit much deeper in communications services

PECR’s marketing and website rules receive most of the attention, but the Regulations also contain a substantial communications-privacy regime.

Providers of public electronic communications services can have obligations relating to service security and breach reporting. PECR also regulates areas including the handling of traffic data and location data, itemised billing, calling-line identification and subscriber directories.

For an ordinary business buying broadband, mobile or cloud services, many of these duties will not be theirs to perform.

For a business actually providing a service within PECR’s relevant communications definitions, they can be significant.

That distinction matters because organisations should establish which part of PECR applies to their role rather than treating the Regulations as a generic privacy checklist.

A marketing team may principally need to understand regulations concerning electronic marketing. A web and digital team may need a detailed understanding of regulation 6. A communications provider can have a substantially broader set of responsibilities.

One regulation can therefore create very different operational requirements across the same organisation.

The Data (Use and Access) Act changed the PECR landscape

PECR predates smartphones, modern social media, widespread behavioural advertising and most of the cloud services businesses now use every day.

That does not make the Regulations obsolete.

Instead, they have been repeatedly amended, with the DUAA providing the most significant recent changes.

As well as reforming the storage and access provisions, the Act brought the definition of direct marketing directly into PECR and created a new charitable soft opt-in. Qualifying charities can, subject to specific conditions, send electronic direct marketing in furtherance of their charitable purposes without obtaining the type of prior consent otherwise required for individual subscribers. The person must have expressed an interest in, or offered or provided support for, the charity’s purposes, and appropriate opt-out opportunities must still be provided.

The enforcement position has changed too.

The ICO now has substantially greater powers under PECR. Following commencement of the DUAA reforms, it can issue fines of up to £17.5 million or 4% of global annual turnover, depending on the circumstances.

That brings the potential regulatory consequences much closer to those associated with the modern UK data-protection regime.

There is an important practical point here as well. Some of the ICO’s older general PECR material is still being reviewed following the DUAA, while detailed guidance in areas such as electronic mail marketing and storage/access technologies has already been updated or finalised in 2026. Organisations checking a long-standing internal policy should therefore make sure the guidance behind it is still current rather than assuming that a process written several years ago remains correct.

For a wider explanation of the legislation that introduced these reforms, see our guide to the Data (Use and Access) Act 2025.

What should a UK business actually do about PECR?

PECR compliance becomes much more manageable when it is treated as part of the way the organisation works rather than as a single consent statement written by somebody in compliance.

Start by knowing where PECR touches the business.

That normally means understanding which teams carry out direct marketing and through which channels, what contact information they use, which websites and digital services store or access information on people’s devices, and whether the organisation provides any services that bring the wider communications provisions into scope.

From there, the relevant decisions can be made properly.

For marketing, that includes distinguishing individual and corporate subscribers where the distinction matters, understanding when consent or a soft opt-in is required, respecting objections and maintaining suppression records so that someone who has opted out is not casually imported into the next campaign.

For websites and apps, it means maintaining an accurate picture of the storage and access technologies actually in use rather than relying on what the cookie banner was configured to say when the website launched. A new analytics tool, advertising service, embedded platform or plugin can change the position without anybody deliberately deciding to change the organisation’s PECR compliance.

That is where the human side of regulation becomes important.

Many PECR failures are unlikely to begin with somebody consciously deciding to ignore the Regulations. They can emerge when a marketing list is reused for a different purpose, somebody assumes that a business email address can always be contacted, a new tracking technology is added without its purpose being reviewed, or an unsubscribe request never reaches the system used for the next campaign.

The decision often feels operational rather than legal.

That does not mean every employee needs to become a PECR specialist. It means the people making relevant decisions need a usable route for recognising when the regulation is involved, understanding what they are authorised to do and escalating the question when the answer is not obvious.

The organisation has a role in making that possible. Clear responsibilities, usable consent and preference records, sensible marketing processes, current technology inventories and reliable suppression controls do more than another instruction telling staff to “follow PECR”.

Regulation has to survive the way the work is actually done.

PECR deserves its own place in your privacy thinking

PECR is sometimes overshadowed by the UK GDPR because GDPR became the language businesses learned to associate with privacy.

But the two are doing different jobs.

The UK GDPR establishes the broader framework for processing personal data. PECR adds specific rules for the privacy of electronic communications: how organisations market through particular channels, how information is stored or accessed on people’s devices and, for relevant service providers, how communications privacy and security are handled.

That means a business can understand its GDPR lawful bases and still get PECR wrong.

It can also spend too much time asking whether consent is required without first identifying which PECR rule actually applies.

The stronger approach is to begin with the activity itself.

What are we trying to do? Which part of PECR governs it? Does that rule require consent, provide an exception or impose another condition? Are we also processing personal data? What needs to happen in the actual workflow so that the decision remains compliant when somebody comes to make it?

Those questions put PECR where it belongs: not as a forgotten regulation sitting beside a privacy policy, but as part of how organisations communicate with people and use electronic technologies responsibly.

Director of Training and Development, Cyber Rebels. Andy Longhurst is the founder of Cyber Rebels and a cybersecurity practitioner and educator focused on how risk actually shows up in real organisations. His work sits at the intersection of digital safety, education, and practical risk management — helping teams understand not just what policies say, but what happens in the moments where decisions are made under pressure. With a background spanning adult education, web development, and technical consultancy, Andy specialises in translating complex security concepts into clear, usable understanding. Rather than focusing solely on tools or compliance frameworks, his approach centres on human behaviour, judgement, and the systems that shape everyday choices. He delivers live, interactive cyber awareness training for organisations of all sizes, from small businesses and education providers to public-sector teams and larger organisations operating in complex risk environments. Outside of delivery, Andy spends his time analysing emerging attack patterns, refining training design, and exploring how organisations can build resilience that holds up in the real world — usually with a strategically sized cup of tea close to hand.

Shopping cart close