Skip to main content
Category: Legal Framework & Instruments

Privacy and Electronic Communications Regulations

Also known as: PECR, Privacy and Electronic Communications (EC Directive) Regulations 2003, The Privacy and Electronic Communications Regulations
Simply put

The Privacy and Electronic Communications Regulations (PECR) are UK rules that give people specific privacy rights in relation to electronic communications, sitting alongside the Data Protection Act and the UK GDPR. They cover areas such as marketing calls, emails, and texts, and rules on the confidentiality of communications. In practice, they aim to protect individuals from unwanted or unsolicited marketing and to safeguard electronic communications data.

Formal definition

PECR is UK secondary legislation, originating as the Privacy and Electronic Communications (EC Directive) Regulations 2003, that operates alongside the Data Protection Act and the UK GDPR to regulate privacy in the electronic communications context. Its provisions address, among other things, direct marketing by electronic means (including telephone, email, and text), rules relating to automated recorded marketing messages, and confidentiality obligations under which organisations are generally required not to store, monitor, scan, or otherwise intercept electronic communications data absent an applicable lawful ground. PECR sets sector-specific requirements that supplement, rather than replace, general data protection law; where personal data is processed, UK GDPR obligations may also apply, and the interaction between the two regimes should be assessed case by case. Because the applicable provisions and their interpretation can evolve, and this summary reflects only the evidence provided, readers should verify the current regulation text and applicable ICO guidance for the precise scope, article-level requirements, and any exemptions.

Why it matters

PECR matters because it governs an area of everyday commercial activity, electronic direct marketing and the confidentiality of communications, that touches almost every organisation reaching individuals by phone, email, or text. It gives people specific privacy rights that sit alongside the Data Protection Act and the UK GDPR, and it addresses conduct such as unsolicited marketing calls, emails, and texts, along with rules on automated recorded marketing messages. For organisations, this means marketing practices that appear lawful under general data protection principles may still fall foul of PECR's sector-specific requirements, so compliance in this area generally requires assessing both regimes together.

The practical significance is heightened by the interaction between PECR and the UK GDPR. Where personal data is processed for electronic marketing, both frameworks can apply at once, and the appropriate lawful ground under the UK GDPR does not automatically satisfy PECR's own consent and marketing rules. Because PECR also imposes confidentiality obligations, under which organisations are generally required not to store, monitor, scan, or otherwise intercept electronic communications data absent an applicable lawful ground, its reach extends beyond marketing into how communications data is handled more broadly.

Readers should treat this summary as a starting point rather than a definitive statement of current obligations. The applicable provisions and their interpretation can evolve, and the interaction between PECR and the UK GDPR should be assessed case by case. Organisations should verify the current regulation text and applicable ICO guidance before relying on any particular position.

Who it's relevant to

Marketing and communications teams
Teams running direct marketing by phone, email, or text are directly affected, as PECR governs rules against unsolicited communications and automated recorded marketing messages. They should generally treat PECR's marketing requirements as distinct from, and additional to, any UK GDPR lawful ground, and confirm the applicable rules for each marketing channel against current ICO guidance.
Data protection officers and privacy leads
DPOs and privacy leads need to manage the interaction between PECR and the UK GDPR, since both may apply where personal data is processed for electronic communications. This includes assessing case by case how the sector-specific PECR requirements supplement general data protection obligations.
Compliance and legal teams
Compliance and legal functions rely on PECR when advising on electronic marketing and on the confidentiality of communications data, including the general requirement not to store, monitor, scan, or otherwise intercept such data absent an applicable lawful ground. They should verify the current regulation text and any exemptions before providing definitive advice.
Engineers and product teams handling communications data
Those building systems that transmit, store, or process electronic communications should be aware that PECR's confidentiality obligations may constrain how communications data is handled. Technical design choices around monitoring, scanning, or interception should be reviewed against the applicable lawful grounds and current guidance.

Inside PECR

Scope of application
The Privacy and Electronic Communications Regulations (PECR) are UK rules that sit alongside the UK GDPR and the Data Protection Act 2018. They govern specific electronic communications activities, including direct marketing by electronic means, use of cookies and similar technologies, security of public electronic communications services, and certain aspects of traffic and location data. PECR derive from the EU ePrivacy Directive; readers should verify the current consolidated text as the regime has been subject to amendment and possible future reform.
Electronic direct marketing rules
PECR set conditions for marketing by telephone, fax, email, SMS and similar electronic means. The applicable condition varies by channel and by whether the recipient is an individual subscriber or a corporate subscriber, so the treatment is not uniform. Requirements should be checked against the specific rule for the relevant channel rather than assumed to be identical across all methods.
Cookies and similar technologies
PECR contain rules on storing information, or gaining access to information stored, on a user's terminal equipment (commonly described in relation to cookies and similar tracking technologies). Generally this requires clear information and, in most cases, consent, subject to limited exemptions such as where the activity is strictly necessary for a service requested by the user. The precise application depends on the technology and purpose.
Relationship with the UK GDPR
PECR and the UK GDPR operate together. Where PECR govern a specific activity, they generally take precedence for that activity, while the UK GDPR continues to apply to any underlying processing of personal data. Where PECR require consent, that consent is typically interpreted by reference to the UK GDPR standard for consent. The two instruments are distinct and should not be conflated.
Security and confidentiality provisions
PECR include obligations relevant to the security of public electronic communications services and the confidentiality of communications, and place certain obligations on relevant service providers. The specific obligations depend on the type of provider and service, so the applicable duties should be confirmed against the text.
Supervision and enforcement context
PECR fall within the remit of the UK's supervisory authority for data protection and electronic marketing matters. Enforcement powers and any penalty levels should be verified against the current official text and guidance, as they can change and this entry does not state specific figures.

Common questions

Answers to the questions practitioners most commonly ask about PECR.

Is PECR the same thing as the GDPR, or has it been replaced by it?
No. PECR (the Privacy and Electronic Communications Regulations) and the GDPR are separate instruments that operate alongside one another. PECR sits within the broader data protection framework but sets specific rules for electronic communications, such as marketing calls, emails, texts, cookies and similar technologies. The GDPR (and, in the UK context, the UK GDPR) provides the general data protection regime. Where personal data is processed, both may apply at the same time, and PECR often relies on GDPR concepts, for example the standard of consent. PECR was not replaced by the GDPR; it continues to apply in its own right, subject to any amendments made through national law over time, which readers should verify against the current official text.
Does PECR only apply when personal data is being processed?
Not necessarily. Unlike the GDPR, some PECR obligations can apply even where no identifiable personal data is involved. For example, rules on cookies and similar technologies, and certain marketing rules, can be engaged based on the act of accessing or storing information on a user's device or sending a communication, rather than solely on whether personal data is processed. This means an organisation may have PECR duties in situations that fall outside the core scope of the GDPR. The precise boundary depends on the specific provision and the facts, and should be assessed case by case.
What consent standard applies to cookies and similar technologies under PECR?
PECR generally requires consent before storing or accessing information on a user's device, unless a recognised exemption applies (such as where the storage or access is strictly necessary for a service the user has requested). The consent standard is typically read in line with the GDPR definition of consent, meaning it should generally be freely given, specific, informed and an unambiguous indication of the user's wishes. Certain non-essential technologies used for analytics or advertising typically require consent, while strictly necessary functions may fall within an exemption. Because interpretation and enforcement expectations can evolve through regulator guidance, organisations should assess each use of cookies individually and verify current guidance.
How should an organisation approach consent for electronic marketing under PECR?
PECR sets rules for marketing by electronic means such as email, SMS, automated calls and, in some cases, live calls and faxes, and the applicable rule depends on the channel and the recipient. In many cases consent is required before sending electronic marketing, although a limited route sometimes described as the 'soft opt-in' may be available for certain communications to existing customers in defined circumstances. Different rules can apply to marketing directed at individuals compared with corporate subscribers. Organisations should identify the channel, the type of recipient, whether an exemption or soft opt-in condition is met, and maintain records supporting the basis relied upon. The detailed conditions should be checked against the current regulations and regulator guidance.
What records should an organisation keep to demonstrate PECR compliance?
Organisations should generally maintain evidence supporting the lawful basis for their electronic marketing and cookie practices. In practice this may include records of when and how consent was obtained, the wording presented to the user at the time, the scope of what was agreed, and how users can withdraw consent or opt out. For cookies, this may include records of consent mechanisms and the categories of technologies used. Keeping clear, contemporaneous records helps demonstrate accountability and supports the ability to respond to complaints or regulator enquiries. The specific documentation appropriate to an organisation depends on its activities and risk profile and should be assessed accordingly.
Who is responsible for enforcing PECR and what should organisations be aware of about enforcement?
In the UK, the Information Commissioner's Office is the supervisory authority responsible for overseeing and enforcing PECR, and it may issue guidance on how the regulations should be interpreted and applied. Enforcement approaches and guidance can develop over time, and regulator expectations, for example around cookie consent, may shift as practice and technology evolve. Organisations should therefore treat compliance as an ongoing, context-dependent exercise rather than a fixed state, monitor updated guidance, and verify current requirements, powers and any penalty provisions against the official regulations and the regulator's published materials.

Common misconceptions

PECR is just part of the GDPR, so complying with the UK GDPR automatically means complying with PECR.
PECR is a separate instrument that addresses specific electronic communications activities and can impose requirements that the UK GDPR does not, such as channel-specific direct marketing conditions and cookie rules. Compliance with one does not guarantee compliance with the other; both should be assessed. Where they interact, PECR generally governs the specific activity while the UK GDPR governs any underlying personal data processing.
PECR only protects the personal data of individuals in the same way the UK GDPR does.
PECR rules on direct marketing distinguish between individual subscribers and corporate subscribers, so some obligations can apply to communications directed at organisations, which is a different scope boundary from the UK GDPR's focus on personal data of individuals. Practitioners should check which subscriber type and channel apply rather than assuming an identical scope.
Consent is always required before setting any cookie.
PECR generally requires consent for storing or accessing information on a user's device, but there are limited exemptions, for example where the activity is strictly necessary to provide a service the user has requested. The correct position depends on the specific technology and purpose and should be assessed case by case rather than treated as an absolute rule.

Best practices

Map each electronic communications activity (email, SMS, telephone, cookies) to the specific PECR rule that applies, rather than applying a single blanket standard across all channels.
Distinguish individual subscribers from corporate subscribers in marketing processes, since the applicable conditions can differ, and record the basis relied on for each channel.
Where PECR requires consent, align the mechanism with the UK GDPR consent standard and keep records that demonstrate how consent was obtained.
Review cookie and similar-technology deployments to identify which are strictly necessary and which require consent, and document the assessment supporting any exemption relied upon.
Assess PECR and UK GDPR obligations together for any activity that also involves processing personal data, treating them as distinct but overlapping requirements.
Verify enforcement powers, penalty levels, and any amendments or reform against the current official PECR text and supervisory authority guidance before relying on them, as this area can change.