PECR Marketing Rules After the DUAA: What Changed for UK Email and SMS Senders

Last updated: 29 August 2026

Laptop displaying PECR Marketing Rules After the DUAA with email, messaging, security and marketing icons.

Contents


Introduction

The Privacy and Electronic Communications Regulations (PECR) govern how UK organisations send marketing emails, texts and calls. They have done so since 2003.

The Data (Use and Access) Act 2025 (DUAA) did not replace them. It changed several specific parts, and the changes matter more than their length suggests. One closes a gap that senders had been able to argue their way through. Another gives charities a route they never had. And the maximum penalty can now exceed thirty-five times the previous £500,000 cap.

This article covers the direct marketing changes. The DUAA also rewrote the cookie rules, which are covered separately in UK Cookie Consent Rules in 2026.

The Act received Royal Assent on 19 June 2025, with its provisions introduced in stages. The main PECR changes discussed below are now in force.

The changes arrived in tranches:

  • 20 August 2025: the first provisions, brought into force by SI 2025/904, including the change to PECR breach reporting.
  • 5 February 2026: the main body of PECR reform, brought into force by SI 2026/82. This tranche completed the changes to the definitions, and included the charity soft opt-in, the new cookie exceptions and the new enforcement regime.
  • 28 April 2026: the ICO published updated guidance on direct marketing using electronic mail.

Dates matter here. The higher penalties apply to conduct from 5 February 2026 onwards. Earlier conduct sits under the previous regime.

Chapter 1: A marketing message does not have to arrive before it can cause a problem

One of the quieter changes is also one of the easiest to understand.

Previously, the wording of PECR referred to communications being "exchanged or conveyed". That created an argument that a communication had to reach its intended recipient before the relevant rules could have been breached.

The DUAA closes that gap.

The definitions of a "call" and "communication" now make clear that the rules can apply to calls that are made and communications that are transmitted, whether or not they ever reach the intended person.

That matters for direct marketing.

Imagine an organisation launches a large unsolicited marketing campaign. Hundreds, maybe thousands of messages are generated, but some are caught by spam filters, rejected by mail servers or otherwise fail to reach the businesses or people they were intended for.

Failure to deliver those messages does not necessarily put the sender outside PECR.

The focus is no longer simply on whether somebody actually received the communication. Sending or generating the communication itself can be enough for an infringement to occur.

For businesses carrying out email, SMS or telephone marketing, that makes the compliance process behind a campaign even more important.

The DUAA also clarifies that, where a call or communication is sent or generated but not received, the "recipient" means the intended recipient. It also inserts the existing Data Protection Act 2018 definition of direct marketing directly into PECR for ease of reference: the communication of advertising or marketing material directed to particular individuals.

A bad mailing list does not become a compliant one simply because half the emails got rejected or bounced.

Chapter 2: What this means for B2B senders

The rules on electronic mail marketing turn on who you are writing to, not on whether the message is commercial.

Regulation 22 of PECR, which requires consent for unsolicited electronic mail marketing, applies to individual subscribers. It does not apply to corporate subscribers, meaning bodies with separate legal status: limited companies, limited liability partnerships, Scottish partnerships and some government bodies. That is the basis on which most legitimate B2B email operates.

Two things are commonly misunderstood about that.

Sole traders and ordinary partnerships are individual subscribers, not corporate ones. Note the jurisdictional quirk: a Scottish partnership has separate legal personality and counts as corporate, while an ordinary partnership in England, Wales or Northern Ireland does not. If your prospect list mixes limited companies with sole traders and ordinary partnerships, it is not a uniformly B2B list and cannot be treated as one.

The corporate subscriber position deals with PECR only. If you are writing to a named individual at a company, you are processing that person's personal data, so the UK GDPR still applies. You need a lawful basis and, if you did not collect their details directly, you will generally need to provide the privacy information required by Article 14 unless an exception applies. They also retain the right to object to direct marketing.

Regulation 23 also applies regardless of who the recipient is. You must not disguise or conceal your identity and must provide a valid contact address for recipients to opt out or unsubscribe.

This distinction applies to electronic mail. It does not carry across to live marketing calls, which are also regulated by PECR and generally require screening against the Telephone Preference Service (TPS) and Corporate Telephone Preference Service (CTPS), regardless of subscriber type.

None of that changed in 2026. What changed is that the consequences of getting it wrong are now materially larger, and the argument that an undelivered message falls outside the rules no longer works.

Chapter 3: Breach reporting: a note for communications providers

One change affects providers of public electronic communications services rather than ordinary businesses. The deadline for reporting relevant personal data breaches to the ICO moved from 24 hours to without undue delay and, where feasible, within 72 hours of becoming aware of the breach. This took effect on 20 August 2025. A provider taking longer than 72 hours must give the ICO its reasons for the delay.

If you are not a telecoms or internet service provider, this is not your obligation. It should not be confused with the separate UK GDPR breach-reporting duties, which can apply much more widely.

Chapter 4: Charities now have their own form of the marketing "soft opt-in"

The DUAA also extends an important direct-marketing rule to charities.

Businesses have long been familiar with the soft opt-in. Broadly speaking, it can allow an organisation to market its own similar products or services by electronic mail where it obtained the person's contact details during a sale, or negotiations for a sale, and the other conditions of the exception are met.

Historically, that model did not fit charities particularly well.

Someone might donate money, volunteer, sign a petition or otherwise show an interest in a charity's work without technically buying a product or service.

The DUAA addresses that.

Subject to the conditions set out in PECR, a charity can now send electronic mail marketing without consent where the sole purpose of that direct marketing is to further one or more of its charitable purposes, and where it obtained the recipient's details when that person expressed an interest in, or offered or provided support for, those purposes.

There are still safeguards.

The person must be given an opportunity to opt out when their details are collected and must continue to receive an opportunity to opt out in any further communications.

In practice, this gives charities a route that better reflects the relationship they actually have with their supporters.

Two limits are easy to miss.

Firstly, the exception is available only to organisations meeting the relevant statutory definition of a charity. It does not apply to non-profit organisations generally.

Secondly, and more significant in practice, the ICO's position is that the charitable purposes soft opt-in commenced on 5 February 2026 and may only be used where the contact details were obtained on or after that date. Contact details obtained before that date cannot be used on this basis unless the charity subsequently obtains the person's details again in circumstances that satisfy the new soft opt-in requirements.

The ICO's guidance also explains that the two soft opt-ins are not interchangeable, although a charity may sometimes satisfy both. Buying something from a charity will usually fall within the products and services soft opt-in. However, some purchases may also clearly amount to support for the charity's charitable purposes, in which case the charitable purposes soft opt-in may also be available if its separate conditions are met. Where the requirements for both soft opt-ins have been satisfied, the ICO says a charity may combine both types of marketing in a single message.

Chapter 5: Sector codes of conduct

Trade associations and other representative bodies can now develop codes of conduct dealing specifically with PECR compliance and submit them to the ICO for approval, mirroring an arrangement that already exists under UK data protection law. An organisation may use its adherence to an approved code as a way of demonstrating compliance.

Chapter 6: PECR penalties can now reach £17.5 million or 4% of worldwide turnover

The DUAA replaced the PECR enforcement regime, bringing it into line with the framework used for data protection law.

The previous maximum penalty was £500,000. The DUAA replaced that single ceiling with a two-tier penalty regime. The principal PECR direct marketing provisions fall within the higher of those two bands.

Direct marketing has also been an active area of PECR enforcement. Across 2023/24 and 2024/25, the ICO issued 35 PECR monetary penalty notices totalling £3.48 million. In 2024/25 it also issued nine PECR enforcement notices and said it had focused on organisations undertaking predatory marketing communications.

The new penalty regime applies to conduct from 5 February 2026 onwards. Historic breaches remain subject to the previous regime.

How the PECR maximum fine tiers work

The DUAA brought PECR enforcement into the framework used under the Data Protection Act 2018. This provides two statutory maximum penalty levels, depending on which provision has been infringed.

Higher maximum: £17.5 million or, for an undertaking, 4% of its total annual worldwide turnover in the preceding financial year, whichever is higher. Schedule 13 places a number of PECR provisions in this band, including the direct marketing provisions in Regulations 19 to 24.

Standard maximum: £8.7 million or, for an undertaking, 2% of its total annual worldwide turnover in the preceding financial year, whichever is higher. PECR infringements falling within this penalty-notice framework that are not assigned to the higher band are subject to this standard maximum.

These are statutory maximums, not automatic penalties. The amount of any fine will be determined by the ICO. When determining the fine amount, the ICO will consider the circumstances of the infringement. Relevant factors include its seriousness and, where applicable, the undertaking's turnover, alongside any aggravating or mitigating factors.

What to do now

Start with lists, not templates.

For every contact or prospect you hold, you should be able to say where the address came from, when you obtained it, and on what basis you are entitled to write to them. If you cannot answer those three questions for a given record, the record is a liability rather than an asset.

Check whether your list is genuinely corporate. If a B2B list contains sole traders or ordinary partnerships, you cannot simply treat the whole list as corporate subscribers.

Check that every message identifies you properly and offers a working opt-out, and that opt-outs are actioned rather than logged.

Stop treating deliverability as a proxy for compliance. A campaign that bounces is still a campaign that was sent.

Sources

  1. Data (Use and Access) Act 2025, sections 110, 111, 114, 115 and 116, and Schedule 13 The primary legislation, including the enforcement provisions and fine tiers. Data (Use and Access) Act 2025 - enacted Act Schedule 13 - PECR enforcement powers
  2. Explanatory Notes to the Data (Use and Access) Act 2025, sections 109 - 116 Supports the explanation of the intended-recipient clarification, relocation of the direct-marketing definition, sale/negotiations for sale, charity soft opt-in and sole-purpose requirement. DUAA Explanatory Notes - relevant PECR sections
  3. Data (Use and Access) Act 2025 (Commencement No. 1) Regulations 2025 (SI 2025/904) Supports the 20 August 2025 commencement point, including section 111 and the partial commencement of section 110. SI 2025/904 - regulation 2
  4. Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) Supports the 5 February 2026 commencement of the main PECR reforms. SI 2026/82 - regulation 2 SI 2026/82 - full instrument
  5. ICO, Privacy and electronic communications - DUAA summary Useful regulator summary of the changes to calls, communications, recipients, direct marketing, breach reporting, charities, enforcement and codes of conduct. ICO - Privacy and electronic communications: DUAA changes
  6. ICO, Guidance on direct marketing using electronic mail - updated 28 April 2026 Supports Regulation 22, the products-and-services soft opt-in, sale/negotiations for sale, the charity soft opt-in, the sole-purpose requirement, the post-5-February contact-details restriction and the interaction between the two soft opt-ins. ICO - Direct marketing using electronic mail For the detailed rules discussed in the article, this is a particularly useful subpage: ICO - How do we comply with the PECR electronic mail marketing rules?
  7. ICO, Business-to-business marketing Supports the distinction between corporate and individual subscribers, sole traders, ordinary partnerships, Scottish partnerships, UK GDPR obligations and TPS/CTPS screening. ICO - Business-to-business marketing
  8. ICO, Annual Report and Financial Statements 2023/24 The 2023/24 PECR enforcement figures used in the two-year total above. ICO Annual Report 2023/24
  9. ICO, Annual Report and Financial Statements 2024/25 Supports the 2024/25 figures, the comparison with 2023/24, the nine enforcement notices and the ICO's reference to predatory marketing communications. ICO Annual Report 2024/25
  10. ICO, The maximum amount of a fine under UK GDPR and DPA 2018 Supports the £17.5 million/4% higher maximum and £8.7 million/2% standard maximum used in the fine-tier explanation above. ICO - Maximum amount of a fine
  11. ICO, Calculation of the appropriate amount of the fine Supports the explanation above that the statutory maximum is not automatic and that the ICO considers seriousness, turnover and aggravating or mitigating circumstances when determining a penalty. ICO - Calculation of the appropriate amount of the fine
  12. Department for Science, Innovation and Technology, Data (Use and Access) Act factsheet: PEC Regulations, 27 June 2025 Useful government summary supporting the failed-message rule, breach reporting, charity changes and codes of conduct. GOV.UK - Data (Use and Access) Act factsheet: PEC Regulations

This article provides general information about changes to the Privacy and Electronic Communications Regulations following the Data (Use and Access) Act 2025. It is not legal advice. Organisations should consider their own circumstances and refer to current ICO guidance where appropriate.