Skip to main content
LiveUK

PECR

Privacy and Electronic Communications Regulations 2003

The UK’s ePrivacy rules — cookies, consent and electronic marketing — alongside UK GDPR.

Overview

What is PECR?

PECR — the Privacy and Electronic Communications Regulations 2003 — is the UK’s ePrivacy law. It sits alongside UK GDPR and governs the specific areas GDPR doesn’t address head-on: cookies and similar technologies, electronic marketing by email, SMS and telephone, and the security of public communication services.

It is narrower than GDPR — there is no RoPA, DPIA or data-subject-request machinery here — but it is where the obligations people actually think of as “cookie consent” and “marketing opt-in” really live. PECR is enforced by the ICO, and the penalties are now substantial: the original £500,000 maximum has been brought broadly into line with UK GDPR — up to £17.5 million or 4% of turnover — under the Data (Use and Access) Act 2025.

In substance it breaks into a handful of duties: prior consent for non-essential cookies (Reg 6); rules for unsolicited electronic marketing and the existing-customer “soft opt-in” (Reg 22); identifiable senders with a working opt-out (Reg 23); consent rules for live and automated marketing calls (Reg 21/19); and basic security of the communication service (Reg 5).

Almost every UK organisation with a website and a mailing list is subject to both PECR and UK GDPR at once. The good news is that the technical controls — a working cookie banner, recorded marketing consent — are largely shared, so the work overlaps heavily even though the two regimes are legally distinct.

Applicability

Who must comply?

  • Any organisation that stores or accesses information on users’ devices — cookies, pixels, local storage or device fingerprinting — beyond what is strictly necessary to deliver the service.
  • Any organisation sending electronic marketing: email, SMS, or live and automated marketing calls.
  • Providers of public electronic communication services, which carry additional service-security and confidentiality duties.
  • In practice, essentially every UK business with a website and any form of direct marketing — consumer-facing, and for many duties business-to-business too.

Obligations

What you must maintain

Prior consent for non-essential cookies

Clear information and a genuine, freely-given choice before non-essential cookies load, with reject as easy as accept. The DUA Act 2025 widened the exceptions — alongside strictly-necessary cookies, low-risk uses such as first-party analytics no longer need consent — but advertising and any third-party sharing still do (Reg 6).

A substantive cookie policy

A policy that names the cookies and similar technologies you use, their purpose, who sets them, and how long they persist.

Valid marketing consent — or a proper soft opt-in

Explicit opt-in for email/SMS marketing, or the soft opt-in applied correctly — for existing customers, and since February 2026 for charities pursuing their charitable purposes: similar products or purposes only, with an opt-out at the point of collection and in every message (Reg 22).

Identifiable senders

Every marketing message must make clear who it is from and provide a working, cost-free way to opt out (Reg 23).

Screened and consented calls

Live marketing calls screened against the Telephone Preference Service / Corporate TPS (TPS/CTPS) registers; automated or recorded calls require specific prior consent (Reg 19/21).

Records to prove it

Evidence of who consented, when, how, and to what — the documentation an ICO investigation will ask to see.

A secure service

Appropriate technical security for the communication service — HTTPS, modern TLS and no mixed content (Reg 5).

Coverage

How Audulate covers PECR

Automated scan

Automated website scans

Most of PECR is observable on your live site, so most of it is checked automatically — 29 rules in total across cookies, marketing and service security, largely shared with your GDPR scan plus PECR-native rules.

  • Cookies (Reg 6): a consent banner that is genuinely present, reject as easy as accept, granular categories, no pre-ticked boxes or cookie walls — and detection of scripts or storage firing before consent, including CNAME-cloaked trackers and pre-consent local storage.
  • Electronic marketing (Reg 22): an explicit opt-in on marketing sign-ups, and the soft-opt-in precondition — an opt-out offered at the point of collection where there is no explicit tick.
  • Sender identification (Reg 23): the page hosting your marketing sign-up discloses who you are and how to opt out.
  • Service security (Reg 5): HTTPS, modern TLS, security headers and no mixed content.
AI-assessed

AI-assessed checks

Cookie and consent quality is a judgement call, not a checkbox — so AI reads the actual banner and policy and forms a view, then verifies it.

  • Cookie-banner quality and dark-pattern detection — including implied-consent wording such as “by continuing you agree”.
  • Cookie-policy substance — whether it genuinely names cookies, purposes, providers and lifetimes.
  • Marketing-consent quality — clear, specific, channel-appropriate wording rather than bundled or vague consent.
Attested

Organisational controls (attested)

Live-call screening and consent record-keeping happen off your website, so Audulate provides four attestation controls with evidence surfaces — and is candid that these are attested, not scanned.

  • TPS / CTPS screening of marketing call lists (Reg 21).
  • Specific consent for automated or recorded calls (Reg 19).
  • Marketing consent records — who consented, when, how, and to what.
  • Soft opt-in audit — confirming the existing-customer exemption is being applied correctly.

PECR findings roll into the same compliance score and reports as your other frameworks, so cookies and marketing sit next to the rest of your posture.

Get started

Up and running in 3 steps

1

Run a free scan

Add your website URL — your first scan is free and runs in minutes.

2

Review your findings

See every gap with severity, plain-English explanation and fix guidance.

3

Fix & evidence

Resolve issues, track them over time, and export audit-ready reports.

FAQ

PECR questions

Is PECR the same as GDPR?

No — PECR is narrower and UK-specific. It covers cookies and electronic marketing, where UK GDPR covers personal data broadly. Most UK organisations must comply with both at once; helpfully, the cookie and consent controls overlap, so the technical work is largely shared.

What are the penalties under PECR?

Historically PECR fines were capped at £500,000. The Data (Use and Access) Act 2025 brought the ceiling broadly into line with UK GDPR — up to £17.5 million or 4% of turnover — so cookie and marketing compliance is now genuinely high-stakes.

Does Audulate screen my marketing call lists?

No. TPS/CTPS screening and automated-call consent happen off your website, so Audulate provides attestation controls and evidence surfaces for them rather than scanning — we’re upfront about that. The cookie, email/SMS-marketing and service-security checks, by contrast, are automated.

What counts as a non-essential cookie?

Broadly, anything not strictly necessary to deliver the service the user asked for. This historically included analytics — but the DUA Act 2025 added new exceptions, in force from February 2026, so first-party cookies used purely for aggregate analytics (and certain appearance settings) no longer need consent in the UK. Advertising and anything shared with third parties still does. Audulate detects non-essential cookies — and equivalent local-storage and fingerprinting techniques — firing before consent.

Does PECR apply to business-to-business marketing?

Partly. The cookie rules apply to everyone. For marketing, the rules are strongest for individual subscribers (consumers and sole traders/partnerships); corporate bodies have a lighter regime, but you must still identify yourself and honour opt-outs. Audulate’s sender-identification and opt-out checks apply either way.

Do I still need UK GDPR if I comply with PECR?

Yes — they are complementary. PECR governs the cookie and marketing mechanics; UK GDPR governs the underlying personal data, individual rights and accountability. Audulate covers both as separate live frameworks.

This page is informational and not legal advice. Coverage describes Audulate’s current capabilities; your compliance obligations depend on your specific circumstances.

Get started today

Your compliance changes
every time you ship.

Audulate keeps up. Free to start.

2 free scans / monthNo credit card5-minute setup