If you’re planning to engage customers, clients, or donors through email marketing in the UK this year, it’s essential to understand the legal landscape. As of 2025, new legislation, tighter enforcement, and updated marketing norms are reshaping how UK businesses and international companies targeting UK audiences need to approach email outreach.
This blog breaks down what’s changed, what hasn’t, and what you absolutely must do to stay compliant.
Email Marketing Laws: The Big Three
Three key laws govern email marketing in the UK:
- PECR (Privacy and Electronic Communications Regulations) : the backbone of email-specific marketing rules
- UK GDPR : governs how personal data is collected, stored, and used
- DUAA 2025 (Data Use and Access Act) : a brand-new law that strengthens enforcement and introduces some modernizations
Together, these form a legal framework that protects recipients from unwanted email marketing while offering businesses clear (if strict) guidelines to follow.
Can You Email Individuals Without Consent? Usually, No.
To send marketing emails to private individuals (consumers), you almost always need active, informed consent . That means:
- No pre-ticked boxes
- No vague “by signing up, you agree…” statements
- Consent must be freely given, specific, and recorded
Each email must:
- Clearly state who it’s from
- Be obviously a marketing message
- Include a visible unsubscribe link
Purchased email lists almost never meet these requirements. Avoid them.
🔗 ICO: Electronic mail marketing
Soft Opt-In: The One Exception
There is one major exception to the consent rule, known as the “soft opt-in.” It allows you to send marketing emails without prior consent, but only if all of the following apply:
- The recipient gave you their email during a sale or negotiation
- You clearly gave them the chance to opt out at the time
- You include an opt-out in every future email
- You’re only promoting similar products or services
If you meet all four, you’re in the clear.
And there’s a new twist in 2025.
Charities Can Now Use Soft Opt-In Too
Under the Data Use and Access Act (DUAA) , charities can now take advantage of the soft opt-in rule. That means if someone gave you their email while supporting your cause, through a donation, event registration, or volunteer inquiry, you can legally follow up with relevant supporter communications.
Of course, you still need to offer opt-outs at every step. And if someone unsubscribes, that’s final.
What About B2B Email Marketing?
Sending marketing emails to corporate business addresses (like info@company.com) is allowed under PECR without prior consent, as long as:
- The content is relevant to the recipient’s business
- The company can reasonably expect it
- You include clear unsubscribe options
However, this does not apply to sole traders or partnerships. These individuals are treated the same as private consumers and require full consent or soft opt-in compliance.
🔗 DPNetwork – Email marketing rules
New in 2025: Higher Fines and New Enforcement Rules
One of the most significant changes this year is the alignment of fines. The DUAA allows UK regulators to issue fines under PECR that match those under UK GDPR:
- Up to £17.5 million , or
- 4% of annual global turnover —whichever is higher
That’s a big leap from previous years and signals a new level of enforcement seriousness. If your email campaigns don’t comply, you could face major financial and reputational damage.
🔗 Arnold & Porter – DUAA analysis
What Every Marketing Email Must Include
To comply with PECR and UK GDPR, your marketing emails must contain:
- Your business name
- A valid contact address
- A clear explanation that it’s a promotional message
- A working unsubscribe link (and immediate action when it’s used)
Even for B2B campaigns, skipping these basics can land you in hot water.
Behind the Scenes: Consent Logs and Privacy Notices
It’s not enough to get consent- you need to prove it.
That means keeping detailed records of:
- When and how consent was given
- What the person was told at the time
- IP addresses and form IDs (if applicable)
- When they unsubscribed (if ever)
Using double opt-in is highly recommended- it reduces your legal exposure and increases list quality.
Also, your website should feature a clear privacy notice that explains how you collect, store, and use personal data (especially if you use third-party platforms like Mailchimp or HubSpot).
Your Email Marketing Checklist
Here’s a simple list to help keep you compliant:
✔️ Do you have clear, documented consent from individuals?
✔️ Are you using the soft opt-in only when appropriate?
✔️ Does every message include an unsubscribe link?
✔️ Do you keep logs of all opt-ins and opt-outs?
✔️ Are you avoiding purchased lists or scraped emails?
✔️ Do you treat sole traders like individuals?
✔️ Have you updated your privacy policy for 2025?
✔️ Do you remove unsubscribed users immediately?
If you can’t answer yes to all of the above, fix it now.
Final Thoughts
Email marketing in the UK isn’t impossible. It just demands attention to detail. When done right, it’s still one of the most effective and affordable ways to reach your audience.
But in 2025, the cost of cutting corners became higher than ever. The best approach is to be transparent, respectful, and well-documented. That’s how you build both compliance and trust.
Want help reviewing your current process or privacy policy? Reach out! We’re happy to support.