Email is a powerful marketing tool, but send the wrong message to the wrong person and it becomes unlawful spam, with the risk of complaints and ICO fines. The line between legitimate marketing and unsolicited spam is drawn by PECR (the Privacy and Electronic Communications Regulations 2003) and the UK GDPR. Here is how to stay on the right side of it in England and Wales.
The basic rule: consent for marketing emails
Under PECR, sending marketing emails (or texts) to individuals generally requires their prior consent. Consent must be a clear, specific, opt-in choice, not a pre-ticked box, and not buried in long terms. Send marketing without consent (and without an exception) and you risk it being treated as unlawful spam.
The "soft opt-in" exception
There is one important exception that lets you market to existing customers without separate consent. You can email or text a customer about your own similar products or services, without fresh consent, if all of these are true:
- you got their details in the course of a sale (or negotiations for a sale);
- you are marketing your own similar products; and
- you gave them an easy way to opt out when you collected the details, and in every message since.
The soft opt-in can apply where contact details were obtained in the course of a sale or genuine negotiations for a sale, even if no purchase was ultimately completed, provided the other conditions are met. However, it does not cover marketing to people who merely made a general enquiry unconnected with a sale, or promoting third-party products.
Every message needs an easy opt-out
Whatever basis you rely on, every marketing email must:
- identify who is sending it; and
- offer a simple, free way to unsubscribe.
You must act on opt-outs promptly and keep a suppression list so you don't contact them again.
The UK GDPR also applies
The email addresses themselves are personal data, so the UK GDPR applies too. You need a lawful basis, must be transparent (your privacy notice should explain your marketing), and must respect the absolute right to object to direct marketing.
Business-to-business email
Marketing to corporate subscribers (companies, LLPs) is treated more flexibly under PECR than marketing to individuals. Note: sole traders and most non-corporate partnerships are generally treated as individual subscribers for PECR purposes, so the stricter consent rules apply to them, but emailing a named individual at a business still involves their personal data under the UK GDPR, so transparency and the right to object still apply, and good practice is to offer an opt-out.
Practical checklist
- Build your list on genuine opt-in consent (or a valid soft opt-in).
- Keep records of consent.
- Put an easy unsubscribe in every email and maintain a suppression list.
- Don't buy or use bought-in lists without checking the consent behind them, that is a common route to unlawful spam.
- Have a clear privacy notice covering your marketing.
Key takeaways
- Marketing emails to individuals generally need consent (PECR), without it (or an exception) it is unlawful spam.
- The soft opt-in lets you email existing customers about your own similar products, with an easy opt-out.
- Every message needs sender identification and an easy unsubscribe, honoured promptly.
- The UK GDPR also applies, be transparent and respect the right to object.
Sources
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), including the soft opt-in
- UK GDPR and Data Protection Act 2018 (lawful basis, transparency, right to object)
- ICO direct marketing guidance
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.