ICO

Information Commissioner's Office — UK GDPR and PECR

Personal data and electronic marketing — consent for tracking, the rules for marketing messages, and how customer lists may be used.

Who this binds

Anyone running a pixel, building a custom audience, sending marketing email or DMs, or holding customer contact details.

7 rules · last verified 2 October 2026 · see changes


The rules

What the statistical-purposes exception does not cover

It covers aggregate usage statistics to improve your own service only. It does not cover advertising, tracking individuals, or conversion monitoring — so a conversions pixel always needs consent.

Verified 22 Sept 2026 · Read the source

The PECR position on business-to-business email

Corporate subscribers may be sent unsolicited marketing email without consent. Sole traders and most partnerships count as individual subscribers and need consent or the soft opt-in.

Verified 22 Sept 2026 · Read the source

Who controls the data in a platform audience tool

The ICO's position is that in many cases the advertiser and the platform are joint controllers, because both decide what the information is used for. The platform's terms do not insulate the advertiser.

Verified 22 Sept 2026 · Read the source

Maximum ICO fine under PECR

Up to £17.5 million or 4% of global turnover, following the Data (Use and Access) Act, in force 5 February 2026. The previous ceiling was £500,000.

Verified 22 Sept 2026 · Read the source

Whether social media DMs count as electronic mail under PECR

Yes. Marketing by direct message on social media is caught by the electronic mail marketing rules in PECR regulation 22, exactly as email and SMS are.

Verified 2 Oct 2026 · Read the source

The three conditions of the soft opt-in

(a) the details were obtained in the course of a sale or negotiations for a sale to that person; (b) you market only similar products or services; (c) a simple, free opt-out is offered at collection and in every message.

Verified 2 Oct 2026 · Read the source


What people get wrong

Not hypotheticals — these are the three failure modes that recur, and what follows from them.

Using the soft opt-in for people who never entered a sale process — lead-magnet downloaders, competition entrants, webinar registrants, bought lists.

A regulation 22 breach. The soft opt-in requires negotiations for a sale, and a free download is not one. The ceiling for this is now £17.5m or 4% of turnover.

Firing the Meta, TikTok or LinkedIn pixel on page load before consent, or offering "Accept all" with no equally prominent "Reject all".

A PECR regulation 6 breach. Non-exempt technologies must not be pre-enabled, and rejecting must be as easy as accepting. The analytics exception does not rescue a conversions pixel.

Uploading a customer list to an ad platform with no mention of it in the privacy notice and no recorded lawful basis.

A fairness and transparency breach, compounded by likely joint controllership with the platform — which means the platform's terms do not transfer the risk.


The other four

ASA / CAPCMAOfcom / OSASector rules
Next step

Knowing the rule is not the same as having a process

Module 22 turns these into the things you actually need: the disclosure wording, the consent flow, the review policy, the sign-off step. Take the free assessment and see where it lands on your path.

Take the free assessment

Nothing here is legal advice. Every rule links to the regulator’s own words so you can read them yourself.