UK Privacy Law United Kingdom

UK PECR Compliance: Cookie Consent and Marketing Rules

What PECR requires for cookies, email and SMS marketing, and the soft opt-in; how it interacts with UK GDPR; and the ICO's fining pattern.

Regulation

Privacy and Electronic Communications Regulations 2003 (PECR)

Max Penalty

GBP 500,000 under PECR; up to GBP 17.5M where UK GDPR also applies

Enforcing Authority

Information Commissioner's Office (ICO)

Official Source

www.legislation.gov.uk

Executive Summary

  • PECR (SI 2003/2426) implements the EU ePrivacy Directive in UK law and survived Brexit; it governs cookies, electronic marketing, and communications privacy.
  • Regulation 6 requires consent before storing or accessing information on a user's device, with exemptions only for communication transmission and strictly necessary services.
  • Regulation 22 requires prior consent for marketing emails and SMS to individuals, subject to the soft opt-in for existing customers being offered similar products.
  • Consent takes its definition from the UK GDPR: freely given, specific, informed, unambiguous. Pre-ticked boxes and cookie walls fail.
  • The ICO fines under PECR routinely, mostly for spam texts, calls, and emails, with penalties up to GBP 500,000 per case, and has warned the UK's top websites over non-compliant cookie banners since 2023.

PECR is the UK’s ePrivacy law: older than the GDPR, narrower, and enforced far more often than most compliance teams assume. It survived Brexit intact as the Privacy and Electronic Communications Regulations 2003 and is the legal basis for both cookie consent and electronic marketing rules in the UK. The ICO’s public fining record is dominated not by GDPR cases but by PECR ones: spam texts, nuisance calls, and unlawful marketing emails.

RegulationPECR (SI 2003/2426), as amended
Max penaltyGBP 500,000 (PECR); GBP 17.5M where UK GDPR is also breached
Enforcing authorityICO
Official textlegislation.gov.uk SI 2003/2426

Cookies: Regulation 6

Storing information on, or reading information from, a user’s device requires clear information and consent. The only exemptions are transmission of a communication and services the user explicitly requested (login sessions, shopping baskets, security). Everything else, analytics included, waits for consent, and consent means the UK GDPR standard: no pre-ticked boxes, no implied consent from scrolling, and a reject option as prominent as accept. The rule is technology-neutral: pixels, localStorage, SDKs, and fingerprinting all count.

Since 2023 the ICO has run a visible cookie-banner enforcement program, writing to the operators of the UK’s most-visited sites and securing changes from the large majority; it has said it will consider formal action against holdouts. The Data (Use and Access) Act 2025 added narrow new consent exemptions (including for certain first-party statistical purposes) and raised future PECR fine ceilings toward UK GDPR levels, so the direction of travel is more enforcement, not less.

Marketing: Regulation 22 and friends

Unsolicited marketing email and SMS to individual subscribers need prior consent, with one carve-out: the soft opt-in for your own existing customers and similar products, refusable at collection and in every message. Live calls are permitted unless the number is on the TPS or the person objected; automated calls need consent. Every message must identify the sender and provide a working opt-out. The classic enforcement fact patterns are bought lists, “legitimate interest” email campaigns to non-customers, and ignoring unsubscribes; these draw five- and six-figure fines month after month.

Getting compliant

Audit what fires on your site before consent, fix the banner (equal-prominence reject, granular categories, no pre-consent tags), and align marketing workflows: consent records per channel, soft opt-in scoping, suppression lists honored everywhere. PECR sits alongside the UK GDPR and mirrors the EU’s ePrivacy regime, so a single consent architecture can serve both markets. Test what your pages actually set before and after consent with a free scan.

Frequently Asked Questions

What does PECR cover that UK GDPR does not?

Device-level rules and channel-level marketing rules. PECR protects the terminal equipment (cookies, SDKs, fingerprinting need consent regardless of whether personal data is involved) and sets per-channel marketing rules for email, SMS, calls, and faxes. UK GDPR then governs whatever personal data the activity processes.

Do I need consent for analytics cookies in the UK?

Yes. The ICO is explicit that analytics cookies are not strictly necessary and need consent before they are set. Only cookies essential to a service the user requested, such as session or basket cookies, are exempt.

What is the soft opt-in?

Regulation 22(3): you may email or text marketing to someone whose details you obtained during a sale or negotiation of a sale, for your own similar products, if they were given a chance to refuse at collection and in every message. It never applies to bought lists or third-party marketing.

Can the ICO really fine for bad cookie banners?

Yes. Beyond the long record of six-figure spam fines, the ICO wrote to the UK's most-visited websites from 2023 demanding reject-all be as easy as accept-all, and reported most brought their banners into line. PECR breaches carry fines up to GBP 500,000, and the underlying data use can also breach UK GDPR at up to GBP 17.5 million.

Does PECR apply to B2B marketing?

Partly. The consent and soft opt-in rules in Regulation 22 protect individual subscribers; corporate subscribers (info@company addresses, employees at corporate numbers) are outside them, though UK GDPR still applies to any personal data such as a named work email, and the right to object to marketing always stands.

Regulatory Crosswalk

UK GDPRePrivacy DirectiveEU GDPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.