2025 Guide to Social Media Marketing Under UK GDPR and PECR

2025 Guide to Social Media Marketing Under UK GDPR and PECR

Social media is where most UK businesses now meet their customers. But every like, follow, targeted ad and marketing email sits on top of personal data, and that data is governed by some of the strictest rules in the world. This guide explains, in plain English, how to run effective social media campaigns in 2026 while staying on the right side of the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).

A quick note on geography: unlike most areas of law, these rules apply UK-wide (England, Wales, Scotland and Northern Ireland), because they are set by UK-wide statute and regulation.

The two rulebooks you need to know

Marketing data is governed by two overlapping regimes:

  • The UK GDPR and the Data Protection Act 2018, the general law on handling personal data (any information that identifies a living person). This covers how you collect, store, use and share customer data.
  • PECR, a more specific set of rules about electronic marketing (emails, texts, automated calls) and the use of cookies and similar tracking technologies.

Where both apply, you have to satisfy both. The regulator for all of this is the Information Commissioner's Office (ICO), which also publishes a statutory direct marketing code of practice (required by section 122 of the Data Protection Act 2018) that is well worth reading.

You need a "lawful basis" to use personal data

Under Article 6 of the UK GDPR, you can only process personal data if you have one of six lawful bases. For marketing, two matter most:

  • Consent, the person has actively agreed (see below for what counts).
  • Legitimate interests, you can show that marketing is a genuine business interest that is not overridden by the individual's rights. This requires a documented balancing exercise, and it does not work where PECR separately demands consent.

A recent development to be aware of: the Data (Use and Access) Act 2025 has begun amending parts of the UK GDPR framework, including the lawful-basis provisions. The fundamentals below still hold, but check the current ICO guidance before relying on the detail.

PECR and your marketing messages

PECR is the rule that catches most businesses out. For marketing by electronic mail (which includes email and text/SMS) to individuals, the general position is that you need prior consent.

There is one important exception, often called the "soft opt-in": you can email or text existing customers about your own similar products or services, without fresh consent, provided you collected their details during a sale (or sale negotiations), and you gave them a simple way to opt out both then and in every message since.

For social media specifically:

  • Organic posts to your followers are generally fine, people chose to follow you.
  • Paid and targeted advertising (custom audiences, "lookalike" audiences, retargeting pixels) involves processing personal data, and often sharing it with the platform. You need a lawful basis, transparency about what you are doing, and (for the tracking technologies behind it) PECR-compliant cookie consent.

What valid consent looks like

Consent under the UK GDPR is a high bar. To be valid it must be:

  • Freely given, not bundled into terms and conditions or a condition of service.
  • Specific and informed, people know who they are agreeing to hear from and about what.
  • Unambiguous, a clear, affirmative action. Pre-ticked boxes and silence do not count.
  • Easy to withdraw, as simple to stop as it was to start.

Keep records of when and how each person consented.

People can object, make it easy

Article 21 of the UK GDPR gives individuals an absolute right to object to direct marketing. When someone objects (for example, by clicking "unsubscribe"), you must stop using their data for marketing straight away. Build a reliable suppression list so you do not accidentally re-contact them.

A practical compliance checklist

  • Map what personal data you collect through your social channels and ads, and why.
  • Pick and document your lawful basis for each marketing activity.
  • Use clear, unbundled consent wording where consent is required; avoid pre-ticked boxes.
  • Honour the soft opt-in limits if you rely on it for email/SMS.
  • Put a compliant cookie/consent banner on any site running tracking pixels.
  • Provide a clear privacy notice explaining your marketing and ad-targeting.
  • Make opting out one click, and act on objections immediately.
  • Review platform settings for custom and lookalike audiences.

Why it matters

The ICO can investigate complaints and issue substantial penalties. For serious UK GDPR breaches, fines can reach up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher, and PECR breaches can attract significant monetary penalties of their own. Beyond fines, getting this wrong damages customer trust, the opposite of what marketing is for.

Key takeaways

  • Two regimes apply to social media marketing: the UK GDPR/Data Protection Act 2018 and PECR.
  • You always need a lawful basis; for electronic marketing, PECR often requires consent.
  • The soft opt-in lets you market to existing customers about similar products, with an easy opt-out.
  • People have an absolute right to object, stop immediately and keep a suppression list.
  • The ICO enforces the rules and can impose large fines.

Sources

  • UK GDPR (assimilated Regulation (EU) 2016/679), Articles 6 and 21
  • Data Protection Act 2018, including section 122 (ICO direct marketing code of practice)
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • Data (Use and Access) Act 2025
  • Information Commissioner's Office (ICO) guidance and direct marketing code

--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.

Back to the blog