PECR and UK GDPR for business email: the two rules every sender must answer

A marketing email to a UK business can fall under PECR and UK GDPR at the same time, and answering one question never answers the other. This guide separates the two rules so you can record the consent, soft opt-in or legitimate-interest evidence each one needs before you send.

Pink and brown notebooks beside an open lined notebook and pink pencil.

Run two legal tests against the same activity

PECR asks about the communication channel, whether material is direct marketing, whether it is solicited and what kind of subscriber receives it. UK GDPR asks whether personal data is processed lawfully, fairly and transparently, for defined purposes, with rights respected. The ICO’s electronic-mail guidance and direct-marketing guidance show why both regimes may apply.

An address such as sales@example.com may involve little or no identifiable-person data, yet PECR can still govern the electronic message. An address naming an employee is likely personal data, so UK GDPR duties can apply even where PECR permits corporate outreach without consent.

This page gives a review framework, not advice that a particular send is lawful. Subscriber status, content, collection history, country and sector matter. Where facts are disputed or consequences are material, stop and obtain qualified legal advice.

Classify the purpose, not the subject-line style

Direct marketing broadly concerns promoting aims and ideals, not only a discounted product. Personalisation, one-to-one sending or a request for a meeting does not automatically remove promotional purpose. Routine administration can be non-marketing, but adding sales content can create a mixed message.

Write the primary and secondary purposes before selecting recipients. Keep essential service notices free from optional promotion where possible. This separation supports honest classification and lets people refuse marketing without losing operational information.

If teams disagree, preserve the proposed copy and audience and escalate before launch. Relabelling a campaign “relationship management” does not alter what it does.

Distinguish corporate and individual subscribers

The ICO explains that corporate subscribers include bodies with separate legal status, while individual subscribers include people, sole traders and some partnerships ICO PECR guidance. A role address can belong to an individual subscriber; a named employee can work for a corporate subscriber. The email format does not settle the category.

For unsolicited electronic marketing to individual subscribers, consent or a valid soft opt-in is generally needed. Corporate subscribers are not subject to that same PECR consent condition, but the sender must not conceal its identity and must provide a valid opt-out contact.

Keep evidence of legal form and review ambiguous trading names. Apply a cautious hold where the distinction cannot be established, rather than assuming every business address is corporate.

A message is solicited when the recipient specifically asked for that communication. A request for one quotation is not necessarily a request for an ongoing newsletter. Record the request, scope and date, and send only what was asked for.

Where consent is needed, retain the precise wording, named organisation, channels, purposes, affirmative action and withdrawal history. Consent bundled into terms or inferred from silence is weak evidence. A third party cannot simply sell your organisation consent that never named or clearly covered you.

Consent can be withdrawn. Make withdrawal as easy as giving it and propagate the change before scheduled sends. UK GDPR documentation duties remain relevant where the consent record is personal data.

Test every soft-opt-in condition

The products-and-services soft opt-in is conditional. The ICO’s electronic-mail material describes direct collection during a sale or genuine sale negotiation, marketing of your own similar products or services, and a clear refusal opportunity both at collection and in each later message. Missing one condition defeats the route.

A purchased list is not directly collected by you. A person who merely downloads unrelated content may not be in a sale negotiation. A new partner’s offer may not be your own similar service. Document each element rather than storing a single “soft opt-in” flag.

The soft opt-in answers a PECR issue. You still need a UK GDPR lawful basis for personal data and must respect fairness, transparency and the direct-marketing objection.

Choose a lawful basis without using it as PECR permission

The ICO’s data-protection guidance discusses lawful bases in direct marketing. Legitimate interests may be available in suitable circumstances, but requires a purpose, necessity and balancing assessment. Consent may be used where its standard is met. Neither label overrides a PECR requirement for consent.

Document reasonable expectations, likely impact, data source, relevance, frequency, safeguards and less intrusive alternatives. Where processing is unexpected, sensitive or high impact, the balance may not favour the organisation.

Keep privacy information accurate and accessible. Tell people who controls the data, purposes, sources where required, recipients, retention, rights and complaint routes. Do not hide outreach sourcing behind vague wording such as “trusted partners”.

Where sender identity and the opt-out route also matter, see responsible UK B2B outreach guidance and how to keep consent and suppression records distinct.

Give direct-marketing objections their full effect

Where UK GDPR applies, an individual’s objection to processing for direct marketing is absolute. Stop that use, including related profiling. Do not demand special legal wording or continue while debating your legitimate interests. A request may arrive through sales, support or an ordinary reply, so train every receiving team to recognise it.

An objection does not necessarily require deletion of every record. A minimal suppression record can be needed to prevent renewed marketing. Separate that purpose from sales use, restrict access and do not contact the person later to ask whether they have changed their mind.

Corporate opt-outs should also be honoured operationally. It is safer and clearer than trying to exploit a distinction after a recipient has plainly refused.

Record the decision in an auditable order

  1. Fix the message purpose. Save the exact copy and intended audience.
  2. Identify countries and channel. Do not assume UK rules are the only relevant rules.
  3. Classify subscriber type. Keep legal-form evidence.
  4. Decide whether it is solicited. Preserve the recipient request and scope.
  5. Apply the PECR route. Record consent, all soft-opt-in conditions or corporate rationale.
  6. Map personal data. List fields, sources, sharing and systems.
  7. Document UK GDPR compliance. Record basis, fairness, transparency, minimisation, retention and rights.
  8. Test refusal handling. Prove opt-out and suppression across queued and future sends.

Recognise where one answer is wrongly doing two jobs

Common failures include calling every company-domain address corporate, treating public data as consent, using legitimate interests as permission under PECR, relying on a past purchase without a collection-stage refusal, or deleting an objection so thoroughly that a later import contacts the person again.

Another failure is mixing service and promotional content, then denying a marketing refusal because the recipient still needs service notices. Separate streams and purposes. Authentication and provider compliance do not correct any of these legal defects.

Preserve the underlying evidence when investigating. Avoid circulating whole CRM exports or private messages to broad technical channels. Use case identifiers and the minimum fields needed.

Set hold, escalation and resumption rules

Stop an individual send when subscriber type, consent evidence, soft-opt-in conditions, lawful basis or source cannot be supported. Stop the campaign when identity or opt-out is broken, suppression is delayed, privacy information is inaccurate, or recipient country creates unresolved rules.

Escalate children or vulnerable people, special-category data, political messages, monitoring, large-scale profiling, bought datasets, joint campaigns, international targeting and disputed rights to a qualified adviser or data-protection lead. This framework cannot decide those facts from a domain name.

Resume only after evidence is corrected, affected records are excluded, a controlled opt-out test passes and an accountable owner signs off the precise message, audience and route. Reassess when any of those changes.

Build an evidence pack that another reviewer can challenge

For a proposed business-email activity, keep one compact pack containing the exact message, audience definition, countries, subscriber-classification method, collection sources, consent or soft-opt-in evidence where relied upon, personal-data fields, lawful-basis assessment, privacy information and suppression test. Link each judgement to a dated fact. This makes disagreement useful: a reviewer can challenge the partnership type, collection wording or message purpose rather than arguing over a vague “B2B compliant” label.

Test the boundary cases represented in the audience. Include a sole trader using a business domain, a named employee at a limited company, a role address, a former customer, an address supplied by a broker and a person who previously objected. The desired result is not that all can be sent to. It is that the rules exclude or hold each record when its evidence is insufficient. Record which field drove the decision and prevent manual users from overriding it without approval.

After any approved send, reconcile the selected audience with delivery events and rights messages. Confirm that refusals entered the suppression system, that service-only contacts did not receive promotion, and that privacy information matched the actual source. A sample inbox receipt verifies routing only. It does not validate subscriber status, consent, fairness or transparency. Reopen the legal review if the real audience or content differs from the pack.

Keep the pack with the campaign approval rather than in a marketer’s private folder. Set a review date tied to the next audience import or copy change. This preserves accountability while avoiding a claim that one assessment permanently settles future messages.

Give the pack a short plain-English summary a non-specialist can follow, alongside any legal detail. If the accountable owner cannot state in one sentence what is being sent, to whom and on what basis, that is itself a signal to hold the send. A reviewer should be able to test the decision without needing to decode the compliance wording first. Keep the summary current whenever the audience or message changes.

Sources and further reading