Two laws, working together
Email marketing in the UK is governed by two overlapping rulebooks. PECR — the Privacy and Electronic Communications Regulations — sets the specific rules for electronic marketing: when you may email someone, and the opt-out you must give. UK GDPR sits underneath it, governing how you handle the personal data itself — your lawful basis, transparency, and people's rights. You need to satisfy both. The regulator for both is the Information Commissioner's Office (ICO).
The default: you need consent
Under PECR, you generally need consent before sending marketing emails to an individual. And "consent" means the UK GDPR standard, which is strict: it must be freely given, specific, informed and unambiguous, given by a clear affirmative action. In practice that means:
- A genuine opt-in — an unticked box the person actively ticks, never a pre-ticked one.
- Separate from other terms, so agreeing to your T&Cs isn't bundled with agreeing to marketing.
- Clear about who you are and what they're signing up to receive.
- Recorded — you should be able to show when and how each person consented.
The exception: the soft opt-in
There's one important carve-out that most legitimate businesses rely on. The soft opt-in lets you email existing customers without fresh consent, provided all three of these are true:
- You obtained their contact details in the course of a sale (or negotiations for a sale) of your product or service.
- You're marketing your own similar products or services — not someone else's, and not something unrelated.
- You gave a simple opt-out when you collected the details, and you include one in every message since.
The soft opt-in is about existing customers. It doesn't cover people who merely enquired without buying, and it doesn't let you email a bought or scraped list.
B2B is different — but not exempt
PECR's email consent rule applies to individual subscribers, and that includes sole traders and ordinary (non-LLP) partnerships — treat them like individuals. Emails to corporate bodies — limited companies, LLPs, public bodies — aren't caught by the same consent requirement, so genuine B2B outreach to a corporate address has more latitude. But you must still identify yourself, offer an opt-out, and, wherever you're processing a named person's data (say, jane.smith@company.com), comply with UK GDPR. "It's B2B" is not a free pass.
Every email: identify yourself and offer an opt-out
Regardless of consent or soft opt-in, every marketing email must not disguise or conceal who sent it, and must give a valid, working way to opt out — in every single message. Honour opt-outs promptly. A hidden or broken unsubscribe drives spam complaints, which damage your deliverability far more than the unsubscribe itself would. Make it easy: it's both the law and good practice. The spam checker flags a missing unsubscribe as part of its content review.
UK GDPR: handling the data itself
Beyond the send, UK GDPR governs the list. In short:
- Lawful basis: you need one — usually consent, or in some B2B cases legitimate interests (with a balancing assessment).
- Transparency: a clear privacy notice explaining what you collect and why.
- Data minimisation: collect only what you need. You don't need a date of birth to send a newsletter.
- Retention: don't keep data forever — clean out people who never engage.
- Rights: people can ask to access their data, object to marketing, or have it erased.
Good list hygiene is compliance as well as deliverability. Because the Mailfois list cleaner runs entirely in your browser, your subscriber data never leaves your device — which is exactly the kind of data-minimising, privacy-first handling UK GDPR encourages.
The penalties just went up
This matters more than it used to. The Data (Use and Access) Act 2025 (Royal Assent 19 June 2025) lifted the maximum PECR penalty from the old £500,000 cap to UK GDPR levels — up to £17.5 million or 4% of global annual turnover, whichever is higher. The ICO also gained stronger investigatory powers. The higher ceiling applies to conduct occurring after 5 February 2026; earlier breaches remain under the old cap. The ICO has signalled it will focus on high-impact conduct — mass unsolicited email, ignored opt-outs, and manipulative consent flows.
A practical compliance checklist
- Collect email addresses with a clear, unbundled opt-in — or rely properly on the soft opt-in for existing customers.
- Keep a record of when and how each person consented.
- Put a working, visible unsubscribe in every email and action opt-outs quickly.
- Identify your business clearly in every send.
- Hold a privacy notice and a defined retention period.
- Keep your list clean and only hold data you actually use.
Frequently asked questions
Do I need consent to send marketing emails in the UK?
Usually yes — unless the soft opt-in applies. Consent must be a clear, unbundled opt-in meeting the UK GDPR standard.
What is the soft opt-in?
It lets you email existing customers without fresh consent if you got their details during a sale, market your own similar products, and offer an opt-out at collection and in every message.
Does PECR apply to B2B?
The email consent rule applies to individuals, including sole traders and non-LLP partnerships. Corporate bodies have more latitude, but UK GDPR and opt-out duties still apply.
What are the penalties?
Since the DUAA 2025, up to £17.5m or 4% of global turnover for conduct after 5 February 2026 — up from the old £500,000 cap.
Compliance and craft go together. Work through the pre-send checklist, or run the whole email through the Mailfois pre-send checker.