← all posts

PECR email marketing: what a UK small business can legally send

Most UK guidance on email marketing law still tells you the maximum fine is £500,000. That figure is out of date. Since February 2026 the ICO can issue penalties of up to £17.5 million, or 4% of global turnover, under the same regulations that govern your newsletter. The PECR email marketing rules are not new — but the consequences of ignoring them are considerably larger than the advice you'll find on most agency blogs.

Before anything else: this is a plain-English summary, not legal advice. We're a marketing company, not a law firm. Every claim below is linked to the ICO's own guidance so you can check it, and anything with real money riding on it deserves a conversation with the ICO or an adviser.

who the PECR email marketing rules actually apply to

Two regimes operate at once. PECR — the Privacy and Electronic Communications Regulations — governs the act of sending marketing by electronic mail. UK GDPR governs the personal data you hold in order to send it. You need to satisfy both; getting one right doesn't excuse the other.

PECR then splits your list in a way most people find counter-intuitive. What matters is whether each recipient is an individual subscriber or a corporate subscriber.

That distinction is worth reading twice, because "it's a business address" is not the test. A sole trader is an individual subscriber under PECR. The one-person landscaping firm and the incorporated landscaping firm next door are treated differently, and nothing in the email address itself tells you which is which.

Two duties apply either way, solicited or not: you must not disguise or hide your identity, and you must give a valid contact address so people can opt out. And even where PECR's consent rule doesn't bite, data protection law still applies to any personal data you're processing — a named individual at a company is still a person.

what counts as consent

PECR borrows its definition from the UK GDPR, and the bar is higher than a tick-box culture assumes. Consent must be a freely given, specific, informed and unambiguous indication of the person's wishes, by a statement or clear affirmative action.

In practice that rules out the three things small businesses most often do: pre-ticked boxes, consent buried in terms and conditions, and treating "they gave me their card at an event" as a subscription. A business card is a contact detail, not an opt-in.

Where p.a. fits: we write and produce the emails; you own the list and the consent record. That split is deliberate — nobody outside your business can manufacture consent you don't have. We're the vendor here, so weight our opinion accordingly.
See what the packages cost →

the soft opt-in, and the five conditions it depends on

The soft opt-in is the exception most small businesses actually rely on, usually without knowing its limits. It lets you email your own similar products and services without consent — but the ICO is clear that all of the following must be true:

  1. You obtained the recipient's contact details.
  2. You did so while selling or negotiating to sell a product or service.
  3. You are marketing only your own similar products and services.
  4. You gave them an opportunity to refuse or opt out when you collected the details.
  5. You give them that opportunity in every subsequent message.

Condition one carries a trap worth spelling out: the ICO says you must obtain the details directly from the person, and the soft opt-in doesn't apply if someone else obtained them for you. A lead-generation supplier, a partner's list, an event organiser's attendee export — none of those are yours to soft opt-in.

Condition two is where lists quietly fail, and the ICO's own examples are the clearest guide. Nobody has to actually buy anything — "negotiations for the sale" is enough — but the person must actively express an interest in buying. Requesting a quote, asking for more detail about what you offer, or signing up to a free trial all count. Browsing your website does not. Nor does a query that isn't about buying: the ICO's own example is someone emailing to ask whether you'll open a branch in their town, which fails the test even though they made contact.

the three lists that cause the most trouble

Bought-in lists. You can only use one if the people on it gave valid consent to hear from you. The ICO's test is specific: the consent must have named your organisation — not "trusted partners" — covered the marketing method you intend to use, been freely given, specific, informed and unambiguous, and been recorded so you can show who consented, when and how. If it doesn't name you, or doesn't cover email, it isn't valid and you must not send. In practice that disqualifies most lists sold to small businesses.

Publicly available addresses. This is where UK law diverges sharply from Canada's. The ICO states plainly that just because someone's details are publicly available — on social media, a website or anywhere else — it doesn't mean they've consented. There is no UK equivalent of the Canadian conspicuous-publication exemption we described in our guide to CASL for Canadian businesses. Scraping a directory of sole traders and emailing them is not made lawful by the addresses having been published.

Marketing someone else sends for you. PECR catches whoever instigates the sending, which the ICO describes as encouraging, inciting, incentivising or asking someone else to send your marketing. Hand your campaign to an agency or an affiliate and you remain responsible alongside them. Using a bulk-email platform doesn't transfer the duty either — that's just technical delivery. Yours is the name on the message and the liability.

what changed in 2026

The Data (Use and Access) Act's remaining provisions came into force on 5 February 2026, and two changes matter for anyone sending marketing email.

The ICO's statement confirms the Act gives it new powers, including the ability to compel witnesses and to issue fines of up to £17.5 million or 4% of global turnover under PECR. That replaces the old £500,000 ceiling still quoted across most of the internet.

The second change is narrower but genuinely useful: a charitable-purposes soft opt-in now sits alongside the products-and-services one, so charities can build supporter lists on comparable terms. If you run one, that's a real change in what you're allowed to send.

A penalty at that ceiling isn't what a small business should be picturing — powers of that size exist for operations sending at industrial volume. But the direction of travel is unambiguous, and "nobody enforces this" was always a weaker plan than it sounded.

the honest takeaway

PECR email marketing compliance comes down to sorting your list before your next send. For each contact: are they an individual or corporate subscriber, do I have consent or a genuine soft opt-in, did I collect the details myself during a sale, and can I show it? Everything else follows.

The pattern worth noticing is that the compliant path and the effective one are the same path. Consent that was freely given, from people you actually sold to, marketed with something similar to what they already wanted — that describes a list that opens your email, which is the argument our guide to email that doesn't get deleted makes on commercial grounds alone. The rules mostly forbid what wasn't working anyway.

And if the honest answer is that your list can't survive this audit, that's worth knowing now rather than after you've built a year of marketing on it. Starting a clean list is a slow month. Rebuilding after you've had to abandon one is a slow year — a version of the time problem we wrote about for UK owners with no time to spare.

we'll write the emails; you keep the list clean

A fixed monthly fee, a full batch of on-brand content produced for you including the newsletters, and a dated calendar telling you what goes out when.
Three-month minimum, stated up front, and you own everything we make.

Book a free call