← Back to Regulatory Updates

Regulatory Update • March 2026

PECR And Direct Marketing Compliance Under Increased Scrutiny

Published: March 2026 Topic: PECR / Direct Marketing Source: ICO Guidance

Direct marketing remains one of the most common areas of data protection and e-privacy risk. Organisations using email, SMS, and similar electronic marketing channels should continue reviewing consent practices and compliance controls carefully.

The ICO’s guidance continues to emphasise that businesses must understand when consent is required, when the soft opt-in may apply, and how marketing practices interact with PECR and UK GDPR requirements.

Reading time 2 minutes

What changed

Direct marketing remains one of the most active areas of regulatory scrutiny under PECR and UK GDPR. The ICO continues to emphasise that organisations using email, SMS and similar electronic marketing channels must understand when consent is required and when alternative lawful routes such as the soft opt-in may apply.

This is not a new legal regime, but it is an area where organisations continue to get compliance wrong. Marketing teams should treat this as an ongoing review point rather than assuming that existing practices are already compliant. For a broader explanation of how direct marketing rules interact with UK GDPR, see our guide Direct Marketing and GDPR.

What does PECR cover in this context?

PECR sets rules for certain types of electronic marketing, including email and SMS. In practice, this means organisations must understand whether they need consent, whether the soft opt-in is available, and how those rules interact with UK GDPR transparency and accountability obligations. If you want a clearer explanation of how these rules work in practice, see our guide What is PECR? A practical guide to the Privacy and Electronic Communications Regulations. For a fuller explanation of what organisations must tell people about how their personal data is used, see Transparency Under UK GDPR: What Organisations Must Tell People.

Why this matters

Direct marketing activity is often built into day-to-day business operations, which means risk can build quietly. If consent language, unsubscribe mechanisms, or contact collection practices are weak, organisations can create repeated compliance issues across multiple campaigns.

This is especially relevant for teams running email campaigns, lead generation activity, customer re-engagement journeys, or promotional SMS communications. Organisations should also monitor future developments through the Regulatory Updates page.

What organisations should do

Organisations should review their direct marketing controls before campaigns are sent rather than relying on old assumptions about consent or customer status.

  • Review when consent is being relied upon and whether it meets the required standard.
  • Check carefully whether the soft opt-in actually applies to each marketing scenario.
  • Confirm that unsubscribe mechanisms are clear, easy to use, and consistently applied.
  • Make sure internal marketing processes align PECR requirements with UK GDPR transparency and record-keeping obligations, including being clear about whether third parties involved are acting as controllers or processors. For more on that distinction, see Data Controllers and Data Processors Under UK GDPR: Understanding the Difference.

Practical takeaway

Organisations should treat direct marketing compliance as an operational control issue, not just a legal one. Reviewing consent routes, opt-out processes, and campaign workflows now is far easier than correcting repeated mistakes later.

Grounded in

ICO guidance on direct marketing using electronic mail, including consent requirements, soft opt-in conditions, and PECR compliance expectations for organisations sending promotional communications.

Sources

Future Implementation Support Waitlist