"It's already public, so I can use it" is one of the most common (and most dangerous) assumptions in marketing. In the UK, personal data does not lose its protection just because it appears on a public register, a website or social media. If you use it to market to people, the UK GDPR and PECR still apply. Here is how to use publicly available data lawfully in 2026.
Public data is still personal data
If information identifies a living person (a name, email, phone number or social media handle) it is personal data, wherever you found it. Scraping it from a website, a public register or LinkedIn does not change that. So the moment you process it for marketing, you need to comply with the UK GDPR.
You still need a lawful basis
To use public personal data for marketing, you need a lawful basis under the UK GDPR, usually consent or legitimate interests:
- Legitimate interests can sometimes apply to business-to-business marketing, but you must carry out a balancing test and respect people's reasonable expectations. People generally do not expect data they posted for one purpose to be reused to market to them.
- Consent may be required, particularly for electronic marketing to individuals (see PECR below).
You must also be transparent: tell people you are processing their data and why, and provide the information the UK GDPR requires, which is harder when you collected the data indirectly.
PECR still bites for electronic marketing
For marketing emails, texts or calls, PECR adds its own rules on top of the UK GDPR. Marketing emails/texts to individuals generally need consent, and the limited "soft opt-in" only helps where you obtained the details during your own sale. Calling numbers requires screening against the Telephone Preference Service. A number being "public" does not give you the right to market to it.
Special caution with public registers and scraping
- Public registers (such as company or professional registers) are published for specific purposes; using them for unrelated marketing may breach the purpose limitation principle.
- Web scraping of personal data at scale carries significant legal risk and has attracted regulatory attention.
Always honour objections
People have an absolute right to object to direct marketing. Whatever the source of the data, you must stop on request and keep a suppression list.
Practical checklist
- Treat public personal data as fully protected, the source does not remove obligations.
- Identify a lawful basis and document any legitimate-interests balancing test.
- Comply with PECR for electronic marketing (consent / soft opt-in / TPS).
- Be transparent about how you obtained the data.
- Respect objections and keep a suppression list.
Key takeaways
- "Public" data is still personal data, the UK GDPR applies when you market with it.
- You need a lawful basis (consent or a justified legitimate interest) and must be transparent.
- PECR still requires consent (or soft opt-in) for electronic marketing and TPS screening for calls.
- Using public registers for unrelated marketing, or scraping at scale, is high-risk; always honour objections.
Sources
- UK GDPR and Data Protection Act 2018 (lawful basis, transparency, purpose limitation, right to object)
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- ICO guidance on direct marketing and on the use of publicly available data
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.