Email marketing is one of the cheapest, most effective channels a small business has. It is also governed by rules that catch a lot of owners out. UK GDPR and PECR are not there to stop you emailing, they are there to make sure people hear from you because they chose to. Get the basics right and you can market with confidence, knowing you are compliant and building a list that actually wants your mail.
This is a plain-English overview, not legal advice, but it covers the parts that matter most for everyday email marketing.
GDPR and PECR: what each one does
Two sets of rules work together. UK GDPR governs how you handle personal data, including email addresses. PECR, the Privacy and Electronic Communications Regulations, governs electronic marketing specifically, including email and SMS. In practice, PECR sets the rules on when you can send marketing, and GDPR sets the rules on how you store and protect the data behind it.
The headline principle across both is simple: people should know what they signed up for, be able to change their mind easily, and trust that their data is handled responsibly.
When you can email someone
For marketing email to individuals, you usually need one of two lawful routes:
- Consent. The person actively agreed to receive marketing from you, for example by ticking an unticked box. Pre-ticked boxes and buried terms do not count.
- The soft opt-in. You may email existing customers about similar products or services, as long as you collected the address during a sale, gave them a clear chance to opt out at the time, and offer an easy opt out in every message.
Business-to-business email has more flexibility, but treating everyone with the same respect keeps you safe and keeps your reputation healthy. When in doubt, get clear consent.
Keep your list clean and compliant
Remove duplicates, spot risky and role-based addresses, and keep your contacts tidy so your marketing only reaches people who should receive it.
Try the free Email Cleaner →Make consent clear and specific
If you rely on consent, it has to be genuine. That means:
- Use unticked opt-in boxes, never pre-ticked ones.
- Say clearly what people are signing up for and who from.
- Keep marketing consent separate from agreeing to your terms.
- Record when and how each person opted in, so you can show it if asked.
Good consent is not just a legal box to tick. It produces a list of people who genuinely want to hear from you, which is exactly the list that gets opened, clicked and converted.
Every email needs an easy way out
Whichever route you use, every marketing message must include a simple, working unsubscribe. Honour opt-outs promptly and permanently. A clean, one-click unsubscribe is far better for you than an annoyed reader who marks you as spam, which damages your deliverability for everyone on the list. If you want to understand how that plays out, see our guide on how to stop emails going to spam.
Look after the data you hold
GDPR also expects you to handle the underlying data responsibly:
- Only keep addresses you have a lawful reason to hold, and delete ones you no longer need.
- Keep your list secure and limit who can access it.
- Be ready to honour requests from people to see or delete their data.
- Keep records of consent and of the emails you send, so you can demonstrate compliance.
Tidy, well-kept data is easier to comply with and easier to market to. Cleaning your list regularly removes contacts you should no longer hold and keeps everything defensible. The related rules for text message marketing are covered in our SMS marketing and PECR guide.
Frequently asked questions
Do I need consent to email my existing customers?
Not always. The soft opt-in lets you email existing customers about similar products or services if you collected the address during a sale and gave them a chance to opt out, both then and in every message. For everyone else, get clear consent.
Are pre-ticked opt-in boxes allowed under UK GDPR?
No. Consent must be a positive action, so opt-in boxes must be unticked and the person must choose to tick them. Pre-ticked boxes and consent buried in terms and conditions are not valid.
Is B2B email marketing exempt from these rules?
B2B has more flexibility than marketing to individuals, but GDPR still applies to personal data such as named business addresses. The safest approach is to treat all contacts with clear consent and easy opt-outs.
What happens if I get email marketing consent wrong?
Beyond the risk of complaints and regulatory action, poor consent leads to spam complaints and unsubscribes that damage your sender reputation. Doing it properly protects both your compliance and your deliverability.
The takeaway
Compliant email marketing is mostly common sense written down: only email people who chose to hear from you or who fit the soft opt-in, make opting out effortless, and look after the data you hold. Do that and you are both compliant and more effective, because a permission-based list is a list that engages.
Start with clean, well-kept data. Run your contacts through the free Email Cleaner to remove risky and outdated addresses, and keep your marketing focused on the people who genuinely want it. This guide is general information, not legal advice, so check with a professional if you are unsure about your specific situation.