Our WorkAll ServicesAI VisibilitySEO AutomationProduct ManagementClaude AI ServicesZatrovo BookingStart a Project
revenue · 9 min read · 4 September 2026

Email Consent Rules: GDPR and PECR for UK SMBs

A practical UK guide to email marketing consent under GDPR and PECR: valid consent, the soft opt-in, bought lists, and what ICO fines actually punish.

Jacob Horgan, Founder, Irvale Studio
Jacob Horgan
Founder, Irvale Studio
A UK small business owner reviewing an email sign-up consent checkbox on a laptop screen.

Email marketing consent rules in the UK trip up more small businesses than any other part of data law, because the rules feel simple until a complaint lands. This is a plain guide to what the Privacy and Electronic Communications Regulations (PECR) and UK GDPR actually require before you press send, written for owners who market their own products and want to stay on the right side of the Information Commissioner's Office (ICO).

In the UK you may only send marketing emails to individuals if you have their consent or you meet the soft opt-in exemption. Consent means an active, informed agreement. The soft opt-in lets you email existing customers about your own similar products, provided you gave them an opt-out when you collected their details and in every message since.

The rule sits in PECR, and it applies to what the law calls electronic mail: email, text messages, picture and video messages, voicemail, in-app messages and direct messages on social platforms. For a typical small business, two lawful routes exist. The first is consent. The second is the soft opt-in, a narrow exemption for people who already bought from you. If neither applies, the send is unlawful, however good your intentions. That is the whole test in one line, and most of the detail below is about proving which route you are relying on.

Do GDPR and PECR both apply to marketing emails?

Yes, both apply at once. PECR decides whether you are allowed to send a marketing email at all. UK GDPR sets the standard for the consent behind it and governs how you collect, store and evidence the underlying personal data. A lawful campaign needs a PECR basis and GDPR-grade records showing how you obtained it.

People often treat these as competing rules to choose between. They are not. PECR is the specific regulation for marketing by electronic mail, and where PECR requires consent, it borrows the UK GDPR definition of consent. So you cannot satisfy PECR with a weaker standard of agreement than GDPR demands. The practical effect is that your sign-up form, your records and your suppression list all have to meet the GDPR bar, while the decision to send is governed by PECR. Keeping the two straight is easier once your email and CRM setup records the basis for every contact in one place rather than across scattered spreadsheets.

Valid consent is a clear, specific, informed and freely given agreement, shown by a positive action such as ticking an unticked box. It must name who is sending the marketing and cover only what the person actually agreed to. Pre-ticked boxes, bundled permissions and silence do not count.

The ICO's guidance on the PECR electronic mail rules is blunt about what fails. Consent has to be an active choice, so a pre-ticked box, an assumed opt-in, or a single tick that quietly covers dozens of unrelated companies is not valid (ICO). It also has to be specific and informed, which means the person should know who will contact them and roughly what for. The clearest test is whether you can produce, for any given contact, what they saw, what they ticked, when, and that you were named. If you cannot, assume the consent will not hold up.

What is the soft opt-in and when can you use it?

The soft opt-in lets you email existing customers about your own similar products without separate consent, but only when five conditions are all met. Miss one and the send is unlawful. It covers people who bought from you or were in negotiations to buy, never contacts you did not collect yourself.

According to the guidance summarised by law firm Geldards, all five of these must be true (Geldards):

  1. You collected the contact details directly from the person.
  2. You collected them during a sale, or negotiations for a sale, of your products or services.
  3. You are marketing your own similar products or services.
  4. You gave a clear, simple, free opt-out at the point you collected the details.
  5. You give a clear, simple, free opt-out in every message you send.

The word doing the heavy lifting is "similar." A garden centre that sold someone compost can email about plants and tools. Stretching that to an unrelated financial product breaks condition three. The soft opt-in is generous for genuine customer relationships and useless for cold prospecting, which is exactly the line the rule is meant to draw.

Can you email a bought or rented list?

In practice, no. The soft opt-in cannot apply to bought or rented lists, because it requires that you collected the details directly from the person during a sale. To email a third-party list you need valid consent that specifically names you as the sender, and most brokered lists cannot prove that.

This is the single most common way a small business ends up in breach. A supplier promises a "fully GDPR-compliant, opted-in" list, but consent is not transferable in the loose way that phrase implies. The person has to have agreed to hear from you, by name, not from an unnamed pool of partners. The ICO has acted on exactly this: one firm fined in January 2026 had sourced data through a website listing hundreds of partner companies, and recipients had no way to choose who could contact them, so the consent was not informed or specific (ICO). If you did not collect the address yourself, treat it as a red flag.

You risk a PECR penalty, and the maximum rose sharply in 2026. The old cap was £500,000. The Data (Use and Access) Act 2025 lifted it to £17.5 million or 4% of global turnover, whichever is higher. Real fines are usually smaller, but complaints, investigations and lost trust cost more than most owners expect.
£225,000Total fines the ICO issued to two firms in January 2026
Source: ICO
67,772,285Unlawful marketing emails sent by one of the fined firms
Source: ICO
£17.5mNew maximum PECR fine after the DUAA 2025
Source: DUAA 2025

The ICO reports that in January 2026 it fined two firms a combined £225,000: £120,000 for a company that sent 4,046,947 marketing texts, and £105,000 for one that sent 67,772,285 emails without a lawful basis (ICO). Those figures predate the higher cap. As reported by TDP, the Data (Use and Access) Act 2025 raised the PECR ceiling from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher (TDP). For most small businesses the ceiling is academic. The realistic damage is the volume of complaints that triggers an investigation in the first place, and the time and reputation lost answering it.

Consent is the broad route: an active agreement that lets you market anything you named. The soft opt-in is the narrow route: it needs no separate agreement but only covers your own similar products sold to people who dealt with you directly. Choose consent for prospects and the soft opt-in for existing customers.
QuestionConsentSoft opt-in
Who can you email?Anyone who actively agreedOnly people who bought or were negotiating
What can you promote?Whatever they consented toYour own similar products or services
Works for bought lists?Only if consent names youNo
Opt-out required in each message?YesYes
Best forNewsletters, prospects, eventsRepeat and cross-sell to customers

Most small businesses run both at once: consent for a newsletter sign-up, the soft opt-in for follow-ups to buyers. The mistake is blurring them, then failing to prove either. The same care that keeps a marketing list clean also pays off across customer service and the way you chase late payments, because all of it rests on accurate, permission-aware contact records.

Capture the evidence at the moment of collection, not later. For every contact, store what they saw, the exact wording, an unticked box or clear action, the date, the source, and confirmation that you were named. Keep opt-outs in a suppression list you never delete, and honour them fast.

A defensible record is boring by design. It logs the source of each address, the consent wording shown, the timestamp, and the basis you are relying on, whether that is consent or the soft opt-in. It keeps a permanent suppression list so an unsubscribed person is never re-added by a later import. And it lets you answer the regulator's first question in seconds. The reason bought lists fail so often is that none of this exists for them. If you are drowning in inbound and cannot keep records straight, tightening how you sort and route email is a sensible first step before you scale any sending.

How do you keep a marketing list clean over time?

Treat your list as a living asset, not a one-off harvest. Record the date and source of every opt-in, remove hard bounces and complaints promptly, honour unsubscribes immediately, and re-permission or drop contacts who have gone silent for a long period. A smaller, provable list outperforms a large stale one.

Consent does not carry a legal expiry date, but it decays. An address collected five years ago, never emailed since, is a liability rather than an asset: the person may not remember you, and a complaint from them is more likely. Sensible hygiene means pruning long-dormant contacts, watching your complaint and spam rates, and re-permissioning anyone whose basis you cannot clearly evidence. This protects deliverability as much as compliance, because mailbox providers punish senders who generate complaints. The businesses that win with email are not the ones with the biggest lists. They are the ones who can prove every name on it agreed to be there.

Next stepMap your consent flowSee how a compliant email and CRM setup handles opt-in, records and suppression by default.

The rules reward the same behaviour good marketing already needs: collect permission honestly, name yourself, keep the evidence, and make leaving easy. Do that, and PECR and GDPR stop being a threat and become the baseline that keeps your list worth having.

Common Questions

Email Consent Rules — FAQ

Do I need consent to email my existing customers?

Not always. If someone bought from you, or was in negotiations to buy, and you gave them a clear, free way to opt out when you collected their email, you can email them about your own similar products or services under the soft opt-in. Every message must also carry an easy opt-out. If you never offered that opt-out at the point of collection, or you want to market unrelated products, you need consent instead. The soft opt-in only covers people who dealt with you directly, so it never stretches to contacts you did not collect yourself.

Is a pre-ticked consent box legal in the UK?

No. Under UK GDPR, consent must be a clear, affirmative action, so a pre-ticked box or a bundled tick that covers several unrelated uses does not count. The person has to actively choose to receive your marketing, and you must name who is sending it. The ICO has fined firms where consent was buried in a long list of partner companies with no way to pick who could make contact, because that is not informed or specific. If you cannot show exactly what someone agreed to and when, treat the consent as invalid.

Can I email a list I bought or rented?

Almost never safely. The soft opt-in cannot apply to bought or rented lists, because the rule requires that you collected the details directly from the person during a sale or negotiation. To email a third-party list you need valid consent that specifically names you as a sender, and most brokered lists cannot prove that. In January 2026 the ICO fined a firm £105,000 for sending more than 67 million emails using third-party sourced data where recipients could not give informed, specific consent. Bought data is where most PECR breaches begin.

What are the fines for getting email consent wrong?

They rose sharply in 2026. The old maximum PECR penalty was £500,000. The Data (Use and Access) Act 2025 lifted the cap to £17.5 million or 4% of global annual turnover, whichever is higher, bringing it in line with UK GDPR. Real fines are still smaller in practice: in January 2026 the ICO issued penalties of £120,000 and £105,000 to two firms for unlawful texts and emails. The bigger risk for a small business is often the complaint, the investigation and the reputational damage, not the theoretical ceiling.

What is the difference between GDPR and PECR for email?

PECR sets the specific rule that you need consent or the soft opt-in before sending marketing by electronic mail. UK GDPR sets the standard for what valid consent looks like and how you must handle the personal data behind the list. In practice they work together: PECR decides whether you are allowed to send the message, and GDPR governs how you collected, stored and evidenced the permission. You have to satisfy both, so a lawful send needs a PECR basis and GDPR-grade records of how that basis was obtained.

How long does email marketing consent last?

There is no fixed expiry in the regulations, but consent is not permanent. It weakens as it ages, and it ends the moment someone opts out. Good practice is to record the date and source of every opt-in, honour unsubscribes quickly, and review contacts who have not engaged for a long stretch. If you cannot show when and how a person agreed, or they have ignored you for a year or more, the safer position is to re-permission them or stop emailing. A clean, provable list is worth more than a large stale one.

Next stepGet this run for youWe run Claude AI, websites, booking and SEO for UK small businesses. From £495 a month.
Start a Project