PECR is the UK’s ePrivacy law: older than the GDPR, narrower, and enforced far more often than most compliance teams assume. It survived Brexit intact as the Privacy and Electronic Communications Regulations 2003 and is the legal basis for both cookie consent and electronic marketing rules in the UK. The ICO’s public fining record is dominated not by GDPR cases but by PECR ones: spam texts, nuisance calls, and unlawful marketing emails.
| Regulation | PECR (SI 2003/2426), as amended |
|---|---|
| Max penalty | GBP 500,000 (PECR); GBP 17.5M where UK GDPR is also breached |
| Enforcing authority | ICO |
| Official text | legislation.gov.uk SI 2003/2426 |
Cookies: Regulation 6
Storing information on, or reading information from, a user’s device requires clear information and consent. The only exemptions are transmission of a communication and services the user explicitly requested (login sessions, shopping baskets, security). Everything else, analytics included, waits for consent, and consent means the UK GDPR standard: no pre-ticked boxes, no implied consent from scrolling, and a reject option as prominent as accept. The rule is technology-neutral: pixels, localStorage, SDKs, and fingerprinting all count.
Since 2023 the ICO has run a visible cookie-banner enforcement program, writing to the operators of the UK’s most-visited sites and securing changes from the large majority; it has said it will consider formal action against holdouts. The Data (Use and Access) Act 2025 added narrow new consent exemptions (including for certain first-party statistical purposes) and raised future PECR fine ceilings toward UK GDPR levels, so the direction of travel is more enforcement, not less.
Marketing: Regulation 22 and friends
Unsolicited marketing email and SMS to individual subscribers need prior consent, with one carve-out: the soft opt-in for your own existing customers and similar products, refusable at collection and in every message. Live calls are permitted unless the number is on the TPS or the person objected; automated calls need consent. Every message must identify the sender and provide a working opt-out. The classic enforcement fact patterns are bought lists, “legitimate interest” email campaigns to non-customers, and ignoring unsubscribes; these draw five- and six-figure fines month after month.
Getting compliant
Audit what fires on your site before consent, fix the banner (equal-prominence reject, granular categories, no pre-consent tags), and align marketing workflows: consent records per channel, soft opt-in scoping, suppression lists honored everywhere. PECR sits alongside the UK GDPR and mirrors the EU’s ePrivacy regime, so a single consent architecture can serve both markets. Test what your pages actually set before and after consent with a free scan.