What changed
Direct marketing remains one of the most active areas of regulatory scrutiny under PECR and UK GDPR. The ICO continues to emphasise that organisations using email, SMS and similar electronic marketing channels must understand when consent is required and when alternative lawful routes such as the soft opt-in may apply.
This is not a new legal regime, but it is an area where organisations continue to get compliance wrong. Marketing teams should treat this as an ongoing review point rather than assuming that existing practices are already compliant. For a broader explanation of how direct marketing rules interact with UK GDPR, see our guide Direct Marketing and GDPR.
What does PECR cover in this context?
PECR sets rules for certain types of electronic marketing, including email and SMS. In practice, this means organisations must understand whether they need consent, whether the soft opt-in is available, and how those rules interact with UK GDPR transparency and accountability obligations. If you want a clearer explanation of how these rules work in practice, see our guide What is PECR? A practical guide to the Privacy and Electronic Communications Regulations. For a fuller explanation of what organisations must tell people about how their personal data is used, see Transparency Under UK GDPR: What Organisations Must Tell People.
Why this matters
Direct marketing activity is often built into day-to-day business operations, which means risk can build quietly. If consent language, unsubscribe mechanisms, or contact collection practices are weak, organisations can create repeated compliance issues across multiple campaigns.
This is especially relevant for teams running email campaigns, lead generation activity, customer re-engagement journeys, or promotional SMS communications. Organisations should also monitor future developments through the Regulatory Updates page.
What organisations should do
Organisations should review their direct marketing controls before campaigns are sent rather than relying on old assumptions about consent or customer status.
- Review when consent is being relied upon and whether it meets the required standard.
- Check carefully whether the soft opt-in actually applies to each marketing scenario.
- Confirm that unsubscribe mechanisms are clear, easy to use, and consistently applied.
- Make sure internal marketing processes align PECR requirements with UK GDPR transparency and record-keeping obligations, including being clear about whether third parties involved are acting as controllers or processors. For more on that distinction, see Data Controllers and Data Processors Under UK GDPR: Understanding the Difference.
Practical takeaway
Organisations should treat direct marketing compliance as an operational control issue, not just a legal one. Reviewing consent routes, opt-out processes, and campaign workflows now is far easier than correcting repeated mistakes later.
Grounded in
ICO guidance on direct marketing using electronic mail, including consent requirements, soft opt-in conditions, and PECR compliance expectations for organisations sending promotional communications.
Sources
- Information Commissioner’s Office: guidance on direct marketing using electronic mail .
- ICO direct marketing guidance on planning campaigns and complying with PECR and UK GDPR.