Privacy and Electronic Communications Regulations
The Privacy and Electronic Communications Regulations (PECR) are UK rules that give people specific privacy rights in relation to electronic communications, sitting alongside the Data Protection Act and the UK GDPR. They cover areas such as marketing calls, emails, and texts, and rules on the confidentiality of communications. In practice, they aim to protect individuals from unwanted or unsolicited marketing and to safeguard electronic communications data.
PECR is UK secondary legislation, originating as the Privacy and Electronic Communications (EC Directive) Regulations 2003, that operates alongside the Data Protection Act and the UK GDPR to regulate privacy in the electronic communications context. Its provisions address, among other things, direct marketing by electronic means (including telephone, email, and text), rules relating to automated recorded marketing messages, and confidentiality obligations under which organisations are generally required not to store, monitor, scan, or otherwise intercept electronic communications data absent an applicable lawful ground. PECR sets sector-specific requirements that supplement, rather than replace, general data protection law; where personal data is processed, UK GDPR obligations may also apply, and the interaction between the two regimes should be assessed case by case. Because the applicable provisions and their interpretation can evolve, and this summary reflects only the evidence provided, readers should verify the current regulation text and applicable ICO guidance for the precise scope, article-level requirements, and any exemptions.
Why it matters
PECR matters because it governs an area of everyday commercial activity, electronic direct marketing and the confidentiality of communications, that touches almost every organisation reaching individuals by phone, email, or text. It gives people specific privacy rights that sit alongside the Data Protection Act and the UK GDPR, and it addresses conduct such as unsolicited marketing calls, emails, and texts, along with rules on automated recorded marketing messages. For organisations, this means marketing practices that appear lawful under general data protection principles may still fall foul of PECR's sector-specific requirements, so compliance in this area generally requires assessing both regimes together.
The practical significance is heightened by the interaction between PECR and the UK GDPR. Where personal data is processed for electronic marketing, both frameworks can apply at once, and the appropriate lawful ground under the UK GDPR does not automatically satisfy PECR's own consent and marketing rules. Because PECR also imposes confidentiality obligations, under which organisations are generally required not to store, monitor, scan, or otherwise intercept electronic communications data absent an applicable lawful ground, its reach extends beyond marketing into how communications data is handled more broadly.
Readers should treat this summary as a starting point rather than a definitive statement of current obligations. The applicable provisions and their interpretation can evolve, and the interaction between PECR and the UK GDPR should be assessed case by case. Organisations should verify the current regulation text and applicable ICO guidance before relying on any particular position.
Who it's relevant to
Inside PECR
Common questions
Answers to the questions practitioners most commonly ask about PECR.