
PECR and ePrivacy
Cookies, direct marketing and electronic communications privacy
Telecoms privacy, direct marketing and cookie compliance under the Privacy and Electronic Communications Regulations
Anyone who sets a cookie or similar technology on a user’s device, sends marketing by email, SMS or telephone, or handles traffic or location data on a communications network must comply with the Privacy and Electronic Communications Regulations 2003. PECR applies alongside the UK GDPR: it carries its own consent requirements, its own penalties and its own enforcement route, and a lawful basis under the UK GDPR does not satisfy it. Since 5 February 2026, when Schedule 13 to the Data (Use and Access) Act 2025 substituted the PECR enforcement schedule, the maximum fine for breach of the principal PECR duties is £17.5 million or 4% of total annual worldwide turnover, whichever is higher; for other PECR breaches the maximum is £8.7 million or 2%.
When PECR compliance becomes urgent
Each PECR duty applies from the moment the activity starts. A consent mechanism must be in place before a tracking technology is deployed on a website; marketing consent must be recorded before the first campaign is sent; and a provider of an electronic communications service must settle its traffic and location data retention policy before it handles subscriber data. A business launching direct marketing by email, SMS or telephone, deploying cookies, operating an electronic communications service or network, or planning to monetise data derived from electronic communications therefore resolves its PECR position at the design stage.
Why PECR compliance matters now
Under the Data (Use and Access) Act 2025, the maximum penalty for breach of the principal PECR duties increased from £500,000 to £17.5 million or 4% of total annual worldwide turnover, whichever is higher, bringing PECR penalties into line with UK GDPR enforcement. Cookie consent has been the ICO’s most visible PECR priority. It tested the UK’s top 1,000 websites on whether non-essential advertising cookies were stored before the user could accept or reject them, whether rejecting was as easy as accepting, and whether such cookies were placed without consent. On 4 December 2025 it reported that 979 of the 1,000 met its checks, 564 of them only after ICO intervention, with 17 preliminary enforcement notices issued along the way and 21 sites still failing. It has said it will keep testing the top 1,000 periodically.
A business operating in both the UK and the EU now complies with two diverging rulebooks. In the UK, the Data (Use and Access) Act 2025 has reformed PECR: with effect from 5 February 2026 it replaced regulation 6 and moved the cookie rules into a new Schedule A1 with a set of exceptions, extended the soft opt-in to charities, and aligned the penalty with the UK GDPR, while retaining the core structure of PECR. In the EU, the ePrivacy Directive 2002/58/EC, as amended by Directive 2009/136/EC, remains in force and will not now be replaced: the European Commission approved the withdrawal of its proposed ePrivacy Regulation on 16 July 2025 and published the withdrawal in the Official Journal on 6 October 2025 (C/2025/5423). A UK compliance approach built on the reformed PECR does not carry across to EU operations, and a controller marketing into the EU applies the Directive as implemented in each member state.
The regulation 22 requirement is separate from the UK GDPR lawful basis, although the consent it calls for is the same concept: regulation 2(1) provides that consent by a user or subscriber corresponds to the data subject’s consent in the UK GDPR. So an organisation may have a lawful basis under the UK GDPR to use an email address for a particular purpose and still lack the PECR consent needed to market to it. Regulation 22(3), and for charities regulation 22(3A), are the only routes to marketing by electronic mail to an individual subscriber without consent. ICO enforcement is increasingly focused on nuisance calls and unsolicited texts to subscribers, often investigating both PECR violations under regulations 21 and 22 and Telephone Preference Service compliance simultaneously.
Common PECR compliance failures
Regulation 6 was replaced on 5 February 2026. It now prohibits storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user except as Schedule A1 allows. Consent is the general route, under paragraph 2 of Schedule A1, and it requires clear and comprehensive information about the purpose of the storage or access together with the consent of the subscriber or user, which takes its meaning from the UK GDPR: freely given, specific, informed and unambiguous. So a banner that makes rejection difficult, defaults non-essential cookies to accept, or mixes essential and non-essential cookies into a single choice does not obtain it, and a reject button on its own does not establish consent either. The remaining paragraphs of Schedule A1 set out the cases in which no consent is needed, and they have to be worked through cookie by cookie rather than assumed.
PECR marketing consent and UK GDPR consent are separate requirements. An organisation may lawfully send a marketing email under UK GDPR because the recipient is an existing customer and marketing falls within the organisation’s legitimate interest. That same email will breach PECR regulation 22 if the recipient has not given separate PECR consent to marketing by electronic mail. The two consent regimes operate independently. Marketing emails to individuals (not corporate subscribers) require opt-in consent under PECR; UK GDPR may permit a different basis such as legitimate interest. This is a frequent source of enforcement action.
An organisation relying on the soft opt-in under PECR regulation 22(3) must satisfy three conditions together: it obtained the recipient’s contact details in the course of the sale, or negotiations for the sale, of a product or service to that recipient; the marketing is in respect of its own similar products and services only; and the recipient was given a simple means of refusing at the time the details were collected and, where they did not then refuse, at the time of each subsequent communication. The organisation must be able to show that the opt-out was offered at both points. The soft opt-in reaches SMS as well as email, because regulation 22 applies to “electronic mail”, which regulation 2(1) defines to include messages sent using a short message service. It does not reach marketing calls: those are governed by regulation 21 and, where the number is registered with the Telephone Preference Service, may not be made without the subscriber’s consent.
PECR applies to B2B marketing, subject to one exception for electronic mail. Regulation 22(1) applies only to unsolicited marketing by electronic mail to individual subscribers, and electronic mail includes SMS, so a corporate subscriber (a company, a government body or a partnership with separate legal status) may be sent marketing by email or SMS without prior consent. The exception does not extend to fax marketing or to telephone calls, and it does not permit marketing calls to any number registered with the Telephone Preference Service, whether the subscriber is a company or an individual.
Subscriber consent and user consent are distinct. A subscriber is the party with a contract with the electronic communications provider. A user is anyone using the service (for example, an employee using a company phone line). PECR regulation 6 (on cookies) requires the consent of the user, not necessarily the subscriber. If your website is accessed by employees on corporate networks, you cannot rely on the company’s consent to set cookies on those employees’ browsers.
A provider of an electronic communications service must erase or anonymise traffic data as soon as it is no longer required for the communication or for billing, under regulation 7. It may retain the data beyond that point for the payment of charges and for interconnection payments until the time set by regulation 7(5), or, with the consent of the subscriber or user, for the purpose of marketing electronic communications services or providing a value added service to that subscriber or user, under regulation 7(3). Marketing anything else is not a permitted purpose, and any other retention needs its own statutory basis. Where the provider relies on consent, it must still justify the retention period it has set and apply that period in practice.
Legitimate interest is not a lawful basis for electronic marketing under PECR. Regulation 22 requires opt-in consent for marketing to an individual subscriber by electronic mail, subject to the narrow soft opt-in exception in regulation 22(3) and, for charities, in regulation 22(3A). There is no PECR equivalent to the UK GDPR’s legitimate interest basis. If you cannot satisfy regulation 22, you cannot send the marketing. The fact that your organisation has a legitimate interest in marketing to the recipient is irrelevant.
PECR compliance in practice
Compliance with regulation 6 starts with an inventory of what the website actually sets. Every cookie, pixel, tag and similar technology has to be identified, classified by purpose (essential, analytics, marketing, functional) and matched to a basis under PECR and the UK GDPR, and the consent mechanism then has to be built to that inventory rather than to a template. In practice that means a tiered flow: storage or access within paragraph 3, 4 or 7 of Schedule A1 loads without consent; storage or access relying on the statistical paragraph or the website-appearance paragraph loads on information and an unexercised objection; everything else is withheld until consent is given; and the user reaches meaningful content and functionality without accepting all cookies. The organisation must also keep a record of the consent mechanism, of the consents obtained and of any later refresh, because it has to be able to demonstrate compliance.
A direct marketing consent mechanism has to satisfy PECR and the UK GDPR at the same time. That usually means separate consent requests, or one request clearly segmented, for each channel (email, SMS, telephone), each purpose (product updates, discounts, research) and each entity that will rely on the consent, including any third-party partner. The records must distinguish PECR soft opt-in consent, PECR prior consent and the UK GDPR lawful basis, because the three are not interchangeable. An opt-out must take effect immediately, without requiring the user to pass through several systems or to confirm the request more than once. Where the organisation relies on the soft opt-in, it records the transaction, the collection point, the opt-out opportunity, and the relationship between what is being marketed and what the recipient bought.
A telecommunications provider has more to do than the operator of a consumer website. Its retention policy must reconcile operational need (billing, dispute resolution, network management) with the requirement in regulation 7 that traffic data be erased or anonymised once it is no longer needed, and the lawful basis for any retention beyond that point has to be recorded. Where a value-added service uses traffic or location data, the provider needs a subscriber consent mechanism for it, and its subscriber directory entries and itemised billing must comply with regulations 18 and 9 respectively. The data flows are more complex than on a consumer website and the rules are more prescriptive, so PECR compliance for a communications provider is a telecoms regulatory question as much as a data protection one.
When to take specialist PECR advice
Take specialist advice as soon as the ICO opens an investigation or begins enforcement action. PECR investigations move quickly and often end in substantial fines, and early engagement can lead to compliance undertakings agreed with the ICO rather than formal enforcement. A business with reason to believe it is non-compliant does not need to wait for the ICO to make contact.
Take advice on a cookie consent mechanism at the design stage. Cookie compliance is technically complex, uncertain in places and under active ICO enforcement, and a banner that does not obtain valid consent exposes the organisation to investigation and to a fine. Replacing a consent mechanism after deployment costs more than building it correctly.
A business running regular email, SMS or telephone marketing campaigns should audit its marketing compliance. An audit tests whether the consent records exist, whether the soft opt-in conditions were met, whether consent was captured for the purpose actually being marketed, and whether opt-out requests are acted on. Correcting those points costs far less than answering ICO enforcement.
A provider of a telecommunications service or electronic communications network should take advice on traffic and location data handling, subscriber directories and itemised billing. These questions depend on the technical detail of the network as much as on the regulations.
Any business handling traffic or location data needs a documented retention policy and a lawful basis for it, whether it is an internet service provider, a VPN service, a mobile application collecting location data or any other business handling telecommunications metadata.
Frequently asked questions about PECR and ePrivacy
Does PECR apply to my website if I only collect analytics data?
Regulation 6 reaches any storage of, or access to, information in a user’s terminal equipment, whether or not the information identifies the user. Since 5 February 2026 an analytics cookie does not always need consent. Paragraph 5 of Schedule A1 permits storage or access whose sole purpose is to collect statistics about how the service, or the website through which it is provided, is used with a view to improving it, provided the information is not shared with anyone except to help make those improvements, the user is given clear and comprehensive information about the purpose, and the user is given a simple means of objecting free of charge and does not object. Analytics that feed advertising, or that share data more widely, fall outside that paragraph and still need consent. Paragraph 4 covers storage or access strictly necessary to provide the service the user requested, which the paragraph itself says can include authentication, security, fraud detection and fault detection, and paragraph 6 covers adapting how a website appears or functions, again on information and an objection right rather than consent. Obtain specialist advice on which cookies genuinely qualify as exempt.
Can I rely on a third party’s cookie consent platform to manage PECR compliance for my website?
A third-party consent platform (such as OneTrust or Cookiebot) can help automate consent management, but it does not transfer your PECR liability to the vendor. You remain liable for breaches. If the platform fails to obtain valid consent, or allows non-essential cookies to load without consent, the breach is yours. Audit your consent platform regularly, understand how it classifies cookies, and ensure it implements your consent decisions accurately. Some platforms default to weak consent flows; do not assume the default is compliant.
Does PECR require consent to my marketing list if the recipient is an existing customer?
It depends on the channel and whether you can apply the soft opt-in. For marketing by email to an individual, PECR requires opt-in consent unless the soft opt-in applies. The soft opt-in permits marketing by email or SMS without prior consent if you obtained the contact details in the course of the sale, or negotiations for the sale, of a product or service to that recipient, the marketing is in respect of your own similar products and services, and the recipient was given a simple means of refusing when the details were collected and in every subsequent message. SMS counts because regulation 22 applies to “electronic mail”, which includes short message service messages. Telephone marketing is a different regime: the rules are in regulation 21 and the soft opt-in does not apply to it. For email or SMS to a corporate subscriber, prior consent is not required under PECR because regulation 22 reaches only individual subscribers, but the recipient must still be able to opt out easily and you must respect opt-out requests immediately.
What is the difference between PECR consent and UK GDPR consent for marketing?
PECR consent under regulation 22 and UK GDPR consent under Article 6 are separate legal requirements. You may have a valid UK GDPR lawful basis (such as legitimate interest or performance of contract) to use an email address for business purposes, but still lack PECR consent to send marketing. Conversely, if you have obtained valid PECR consent, you still need a separate UK GDPR lawful basis for processing that individual’s personal data for marketing purposes. In practice, most organisations use consent as the lawful basis for both PECR and UK GDPR for marketing. If your marketing is not one-off but ongoing, structure your consent request to satisfy both regimes clearly.
What is the ICO’s current position on cookie compliance?
The ICO expects prior informed consent under PECR regulation 6 before non-essential cookies are placed. Cookie consent must be freely given (no dark patterns or pre-ticked boxes), specific (separate consents for different purposes or categories of cookies), informed (the user understands what data will be collected and how), and unambiguous (clearly affirmative action is required). Reject and accept buttons must be equally prominent. The ICO tested the top 1,000 most visited UK websites and reported on 4 December 2025 that 979 of them met its compliance checks, 21 having still failed and 17 preliminary enforcement notices having been issued in the course of the work. It has said it will keep testing the top 1,000 periodically. If your website handles substantial traffic, assume it will be tested.
Can I use legitimate interest as the lawful basis for PECR marketing?
No. PECR regulation 22 permits marketing without prior consent only in narrow circumstances: if the recipient is a corporate subscriber, because regulation 22 reaches individual subscribers only; if the soft opt-in conditions in regulation 22(3) are satisfied; or, since 5 February 2026, if a charity satisfies the conditions in regulation 22(3A) for marketing whose sole purpose is to further its charitable purposes. If none applies, you must have prior opt-in consent. Legitimate interest is a lawful basis available under UK GDPR for some types of processing, but it is not a basis for electronic marketing under PECR. If you cannot satisfy regulation 22, you cannot send the marketing, no matter how strong your legitimate interest.
Advice on PECR and ePrivacy compliance
Representative experience
Recent and representative matters include:
- Advised a telecoms operator on PECR compliance for the processing of traffic data and location data, including the conditions under regulations 7 and 14 for value-added services and emergency caller location.
- Reviewed cookie consent mechanisms for a media company, assessing compliance with regulation 6 and the ICO’s guidance on analytics cookies, advertising technologies and consent management platforms.
- Advised an e-commerce business on the PECR direct marketing rules, including the regulation 22 consent requirement, the soft opt-in exception, and the interaction with UK GDPR lawful basis requirements.
- Prepared a PECR compliance assessment for a telecoms provider’s subscriber directory services, addressing regulation 18 on directory listings and regulations 10 to 12 on calling line identification.
- Advised on the divergence between the UK and EU ePrivacy regimes and its effect on cross-border marketing campaigns.
Rob Bratby advises on PECR compliance and ePrivacy issues, drawing on his telecoms regulatory background, including a one-year secondment to Oftel, the predecessor of Ofcom. Rob is ranked in Chambers UK (Band 2) for telecommunications and is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection.
Related data protection pages
See also our related practice area pages:
UK GDPR Compliance
Lawful Basis and Legitimate Interests
Data Protection Impact Assessments
Data Governance, Transfers and Accountability
UK/EU Data Protection Divergence
AI and Automated Decision-Making
The EU AI Act: what UK businesses need to know
Sector-Specific Data Protection
Data Breach Response and ICO Notification
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



The Core Communication case study covers consumer-facing privacy notices.
Discuss your matter
Primary sources
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426)
- Data (Use and Access) Act 2025, Schedule 13: New PECR enforcement schedule (£17.5 million / 4% of global annual turnover cap)
- ICO: Direct marketing guidance
- ICO: Guidance on the use of storage and access technologies (cookies and similar)
