Phone Marketing Regulations
Privacy and Electronic Communications (EC Directive) Regulations (PECR)
The Privacy and Electronic Communications (EC Directive) Regulations, known as PECR, complement the UK GDPR by governing electronic communication methods such as email, text messages, and cookies. They are part of UK law and implement the 2003 PECR regulations, which are based on the EU’s ePrivacy Directive ( ICO, Wikipedia).
Scope of Application
PECR applies whether or not you know the identity of the person you are contacting. It covers marketing through phone, text, email, and fax; the use of cookies or similar technologies; and the creation of public directories ( DPO INDIA, ICO).
Key Definitions
Electronic communications under PECR include any message sent between specific parties via phone lines or the internet, such as phone calls, text messages, video messages, faxes, emails, or internet-based messaging. This excludes general content like websites or broadcasts ( ICO).
Consent under PECR must be clear, specific, and freely given to your organization for each marketing method used, such as email, phone, text, or fax ( ICO, Data Protection Network).
How to Obtain Valid Consent
The best way to secure consent is through an unticked opt-in box where the individual actively selects to agree. You must also provide a clear and easy method for recipients to withdraw their consent ( ICO, Data Protection Network).
Compliance Requirements under PECR
Unsolicited marketing via phone, text, email, or fax is restricted. Regulation 21 prohibits telemarketing calls to individuals who have not consented or who are registered with the Telephone Preference Service (TPS) or Corporate Telephone Preference Service (CTPS) ( ICO, Wikipedia).
All marketing communications must transparently identify the sender and provide a contact address or freephone number on request ( ICO, Sprintlaw UK).
Telemarketing Rules
Telemarketing calls are allowed only to individuals who have opted in or who are not listed on TPS/CTPS and have not previously objected. Automated marketing calls have stricter rules and require explicit consent. They must also identify who is calling and include contact information ( ICO, Sprintlaw UK).
The TPS is a legally enforced opt-out register that prevents marketing calls to the numbers listed unless there is explicit permission ( Wikipedia). Note that TPS restrictions do not apply to market research calls or SMS messages, although it remains best practice to include opt-out options in SMS communications ( , ICO).
Email and SMS Marketing Rules
You must not send marketing emails or texts to individuals without their specific consent, except under the “soft opt-in” rule which applies to existing customers and only if you offered them easy opt-out options both when you first collected their data and in every message sent ( ).
Penalties and Enforcement
The ICO is the regulator responsible for PECR and UK GDPR compliance. PECR breaches can result in fines up to £17.5 million or 4 percent of global turnover under the updated Data (Use and Access) Act 2025. These revisions align PECR with UK GDPR fines and introduce reforms around cookie consent, breach reporting timelines, and the definition of direct marketing ( Mayer Brown).
Conformity Marking – CE and UKCA
Following Brexit, the UK introduced UKCA (UK Conformity Assessed) marking, effective from January 1 2021 ( Wikipedia, GOV.UK). However, CE marking remains acceptable for most goods in Great Britain, often indefinitely under the Product Safety and Metrology (Amendment) Regulations 2024 ( , Compliance Gate).