Email marketing consent rules in the UK trip up more small businesses than any other part of data law, because the rules feel simple until a complaint lands. This is a plain guide to what the Privacy and Electronic Communications Regulations (PECR) and UK GDPR actually require before you press send, written for owners who market their own products and want to stay on the right side of the Information Commissioner's Office (ICO).
What are the email marketing consent rules in the UK?
The rule sits in PECR, and it applies to what the law calls electronic mail: email, text messages, picture and video messages, voicemail, in-app messages and direct messages on social platforms. For a typical small business, two lawful routes exist. The first is consent. The second is the soft opt-in, a narrow exemption for people who already bought from you. If neither applies, the send is unlawful, however good your intentions. That is the whole test in one line, and most of the detail below is about proving which route you are relying on.
Do GDPR and PECR both apply to marketing emails?
People often treat these as competing rules to choose between. They are not. PECR is the specific regulation for marketing by electronic mail, and where PECR requires consent, it borrows the UK GDPR definition of consent. So you cannot satisfy PECR with a weaker standard of agreement than GDPR demands. The practical effect is that your sign-up form, your records and your suppression list all have to meet the GDPR bar, while the decision to send is governed by PECR. Keeping the two straight is easier once your email and CRM setup records the basis for every contact in one place rather than across scattered spreadsheets.
What counts as valid consent under UK law?
The ICO's guidance on the PECR electronic mail rules is blunt about what fails. Consent has to be an active choice, so a pre-ticked box, an assumed opt-in, or a single tick that quietly covers dozens of unrelated companies is not valid (ICO). It also has to be specific and informed, which means the person should know who will contact them and roughly what for. The clearest test is whether you can produce, for any given contact, what they saw, what they ticked, when, and that you were named. If you cannot, assume the consent will not hold up.
What is the soft opt-in and when can you use it?
According to the guidance summarised by law firm Geldards, all five of these must be true (Geldards):
- You collected the contact details directly from the person.
- You collected them during a sale, or negotiations for a sale, of your products or services.
- You are marketing your own similar products or services.
- You gave a clear, simple, free opt-out at the point you collected the details.
- You give a clear, simple, free opt-out in every message you send.
The word doing the heavy lifting is "similar." A garden centre that sold someone compost can email about plants and tools. Stretching that to an unrelated financial product breaks condition three. The soft opt-in is generous for genuine customer relationships and useless for cold prospecting, which is exactly the line the rule is meant to draw.
Can you email a bought or rented list?
This is the single most common way a small business ends up in breach. A supplier promises a "fully GDPR-compliant, opted-in" list, but consent is not transferable in the loose way that phrase implies. The person has to have agreed to hear from you, by name, not from an unnamed pool of partners. The ICO has acted on exactly this: one firm fined in January 2026 had sourced data through a website listing hundreds of partner companies, and recipients had no way to choose who could contact them, so the consent was not informed or specific (ICO). If you did not collect the address yourself, treat it as a red flag.
What happens if you get email consent wrong?
The ICO reports that in January 2026 it fined two firms a combined £225,000: £120,000 for a company that sent 4,046,947 marketing texts, and £105,000 for one that sent 67,772,285 emails without a lawful basis (ICO). Those figures predate the higher cap. As reported by TDP, the Data (Use and Access) Act 2025 raised the PECR ceiling from £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher (TDP). For most small businesses the ceiling is academic. The realistic damage is the volume of complaints that triggers an investigation in the first place, and the time and reputation lost answering it.
How do consent and soft opt-in compare?
| Question | Consent | Soft opt-in |
|---|---|---|
| Who can you email? | Anyone who actively agreed | Only people who bought or were negotiating |
| What can you promote? | Whatever they consented to | Your own similar products or services |
| Works for bought lists? | Only if consent names you | No |
| Opt-out required in each message? | Yes | Yes |
| Best for | Newsletters, prospects, events | Repeat and cross-sell to customers |
Most small businesses run both at once: consent for a newsletter sign-up, the soft opt-in for follow-ups to buyers. The mistake is blurring them, then failing to prove either. The same care that keeps a marketing list clean also pays off across customer service and the way you chase late payments, because all of it rests on accurate, permission-aware contact records.
How do you build a consent record that survives a complaint?
A defensible record is boring by design. It logs the source of each address, the consent wording shown, the timestamp, and the basis you are relying on, whether that is consent or the soft opt-in. It keeps a permanent suppression list so an unsubscribed person is never re-added by a later import. And it lets you answer the regulator's first question in seconds. The reason bought lists fail so often is that none of this exists for them. If you are drowning in inbound and cannot keep records straight, tightening how you sort and route email is a sensible first step before you scale any sending.
How do you keep a marketing list clean over time?
Consent does not carry a legal expiry date, but it decays. An address collected five years ago, never emailed since, is a liability rather than an asset: the person may not remember you, and a complaint from them is more likely. Sensible hygiene means pruning long-dormant contacts, watching your complaint and spam rates, and re-permissioning anyone whose basis you cannot clearly evidence. This protects deliverability as much as compliance, because mailbox providers punish senders who generate complaints. The businesses that win with email are not the ones with the biggest lists. They are the ones who can prove every name on it agreed to be there.
The rules reward the same behaviour good marketing already needs: collect permission honestly, name yourself, keep the evidence, and make leaving easy. Do that, and PECR and GDPR stop being a threat and become the baseline that keeps your list worth having.
Email Consent Rules — FAQ
Do I need consent to email my existing customers?
Not always. If someone bought from you, or was in negotiations to buy, and you gave them a clear, free way to opt out when you collected their email, you can email them about your own similar products or services under the soft opt-in. Every message must also carry an easy opt-out. If you never offered that opt-out at the point of collection, or you want to market unrelated products, you need consent instead. The soft opt-in only covers people who dealt with you directly, so it never stretches to contacts you did not collect yourself.
Is a pre-ticked consent box legal in the UK?
No. Under UK GDPR, consent must be a clear, affirmative action, so a pre-ticked box or a bundled tick that covers several unrelated uses does not count. The person has to actively choose to receive your marketing, and you must name who is sending it. The ICO has fined firms where consent was buried in a long list of partner companies with no way to pick who could make contact, because that is not informed or specific. If you cannot show exactly what someone agreed to and when, treat the consent as invalid.
Can I email a list I bought or rented?
Almost never safely. The soft opt-in cannot apply to bought or rented lists, because the rule requires that you collected the details directly from the person during a sale or negotiation. To email a third-party list you need valid consent that specifically names you as a sender, and most brokered lists cannot prove that. In January 2026 the ICO fined a firm £105,000 for sending more than 67 million emails using third-party sourced data where recipients could not give informed, specific consent. Bought data is where most PECR breaches begin.
What are the fines for getting email consent wrong?
They rose sharply in 2026. The old maximum PECR penalty was £500,000. The Data (Use and Access) Act 2025 lifted the cap to £17.5 million or 4% of global annual turnover, whichever is higher, bringing it in line with UK GDPR. Real fines are still smaller in practice: in January 2026 the ICO issued penalties of £120,000 and £105,000 to two firms for unlawful texts and emails. The bigger risk for a small business is often the complaint, the investigation and the reputational damage, not the theoretical ceiling.
What is the difference between GDPR and PECR for email?
PECR sets the specific rule that you need consent or the soft opt-in before sending marketing by electronic mail. UK GDPR sets the standard for what valid consent looks like and how you must handle the personal data behind the list. In practice they work together: PECR decides whether you are allowed to send the message, and GDPR governs how you collected, stored and evidenced the permission. You have to satisfy both, so a lawful send needs a PECR basis and GDPR-grade records of how that basis was obtained.
How long does email marketing consent last?
There is no fixed expiry in the regulations, but consent is not permanent. It weakens as it ages, and it ends the moment someone opts out. Good practice is to record the date and source of every opt-in, honour unsubscribes quickly, and review contacts who have not engaged for a long stretch. If you cannot show when and how a person agreed, or they have ignored you for a year or more, the safer position is to re-permission them or stop emailing. A clean, provable list is worth more than a large stale one.



