Email & SMS Marketing Consent: The UK GDPR and PECR Rules Explained

In the UK you almost always need someone's permission before sending them a marketing email or text - unless you can tick every box of the 'soft opt-in' exemption. Marketing to other businesses is lighter-touch, but not a free-for-all. And since 5 February 2026 the ICO can fine breaches up to £17.5 million, so a permission-based list isn't just good manners - it's the law.
What counts as direct marketing (and why it matters)
Direct marketing is any advertising or promotional message aimed at particular people - a newsletter, a 'we miss you' text, a discount code, an event invite. If a message is designed to sell, promote or persuade and it lands in a named person's inbox or on their phone, it counts. Two sets of UK rules then apply at the same time.
The Privacy and Electronic Communications Regulations (PECR) govern the channel - email, SMS and phone calls. The UK GDPR governs the personal data behind the campaign. You have to satisfy both. In practice, PECR usually decides whether you are allowed to hit send at all, while the UK GDPR decides how you collect, store and handle the data.
The default rule: get consent first
For marketing emails and texts to individuals, PECR's starting point is simple - you need consent before you send. And 'consent' has a specific legal meaning. The ICO defines it as a 'freely given, specific, informed and unambiguous' indication of the person's wishes.
In plain terms, that means a clear, positive opt-in. As the ICO puts it, 'people must take a positive action to consent, so you must not use pre-ticked opt-in boxes, silence or inactivity.' Burying consent in your terms and conditions, or assuming someone is happy to hear from you because they once bought something, does not meet the bar.
The soft opt-in: your most useful exemption
There is one important exception most small businesses can use - the 'soft opt-in'. It lets you email or text existing customers without a separate opt-in, but only if you meet every one of these conditions:
✔ You collected the person's contact details directly from them.
✔ You obtained them during the sale, or negotiations for the sale, of a product or service.
✔ You are only marketing your own similar products and services.
✔ You gave a simple way to opt out at the point you collected the details.
✔ You include an easy opt-out in every message you send.
Miss a single condition and the exemption falls away. The soft opt-in never covers bought-in lists, other brands, or unrelated products, and it has historically been available to businesses only. Since 5 February 2026, the Data (Use and Access) Act has introduced a matching 'charitable purposes' soft opt-in, letting charities contact past supporters about their cause under similar conditions.
B2B is different - but not a free-for-all
PECR treats 'corporate subscribers' - limited companies and limited liability partnerships - differently from individuals. You can send marketing emails to a company's generic address without prior consent, as long as you identify yourself and offer an opt-out.
Two catches trip people up. First, sole traders and most ordinary partnerships count as individuals, so the stricter consent rules apply to them. Second, the moment you email a named person - such as sarah@company.co.uk - you are processing personal data, so the UK GDPR still applies: you need a lawful basis (usually legitimate interests), you must tell people how you got their details, and you must stop if they object.
Every message must identify you and offer an easy exit
Whoever you are sending to, two rules never change. You must not 'disguise or hide your identity', and every message must include 'a valid contact address for recipients to opt out or unsubscribe'. Make that unsubscribe obvious and one click, and act on requests quickly - a link that leads to a dead end, or a five-step process, is a compliance risk dressed up as a retention tactic.
The cost of getting it wrong
This is not theoretical. In January 2026 the ICO fined two firms a combined £225,000 for consent failures. Claims company Allay Claims Ltd was penalised £120,000 for sending more than four million unsolicited texts, and ZMLUK Limited £105,000 for over 67 million emails built on vague third-party 'consent' that buried recipients under a list of 361 partner companies. Crucially, on 5 February 2026 the maximum PECR fine jumped from £500,000 to the UK GDPR ceiling of £17.5 million, or 4% of global annual turnover. Most fines are far smaller, but the direction of travel is unmistakable.
Your pre-send compliance checklist
✔ Record your consent: who opted in, when, how, and exactly what they agreed to.
✔ Keep marketing consent separate from your terms and conditions - never pre-ticked or bundled in.
✔ Before using any purchased or third-party list, confirm the consent specifically named your business. If it didn't, don't send.
✔ Put a clear sender name and reply address on every email and text.
✔ Make unsubscribing one click, and process opt-outs within a few days at most.
✔ Check whether each contact is an individual or a corporate subscriber, and apply the right rule.
✔ Review your lists regularly and remove contacts who never engage.
This is general guidance, not legal advice - when a decision is finely balanced, check the ICO's direct marketing guidance or take professional advice.
Quick FAQ
Do I need consent to email my existing customers?
Often not - if you can meet all five soft opt-in conditions: you got their details during a sale of your own product or service, you are marketing similar things, and you offered an opt-out at sign-up and in every message. If any condition fails, you need consent.
Are B2B marketing emails exempt from the rules?
Emails to corporate subscribers (limited companies and LLPs) don't need prior PECR consent, but you must identify yourself and give an opt-out. Sole traders and most partnerships are treated as individuals, and the UK GDPR still applies whenever you email a named person.
Can I buy an email list and market to it?
Only if the consent collected specifically covered marketing from your business by name. Generic or 'partner' consent almost never qualifies, and the ICO has repeatedly fined firms that relied on bought-in data, so due diligence is essential.
How much can the ICO fine me for breaking PECR?
Since 5 February 2026, up to £17.5 million or 4% of global annual turnover, up from the old £500,000 cap. In reality most fines run from a few thousand to low six figures, but the reputational damage often costs more than the penalty.
Permission isn't a hurdle, it's the whole point. A smaller list of people who genuinely want to hear from you will always outperform a bigger one you rented. Treat consent as a promise, honour every unsubscribe instantly, and your marketing gets more effective - not less. — Daniel Nikolla, Founder of Merx Marketing
The bottom line: build your email and SMS lists on genuine, recorded consent, lean on the soft opt-in only when you meet every condition, and make opting out effortless. That's how you stay on the right side of the ICO and keep the people who actually want to hear from you.
How confident are you that every contact on your marketing list has properly opted in?
If you would like to know more about this topic, please contact us on danieln@merxmarketing.co.uk
Related reading
Written by Daniel Nikolla, Founder of Merx Marketing Ltd and Marketing Minute




Comments