27 July 2026 · Last reviewed 27 July 2026
ICO Soft Opt-In Guidance: What the Rules Actually Say
The soft opt-in is the only way to send marketing emails to individual subscribers without their explicit prior consent. It is a specific exemption in PECR Regulation 22(3) — and the ICO's guidance makes clear that it is an exemption with four precise conditions, not a general permission to market to existing customers.
This article works through what the ICO's guidance says about each condition, where businesses commonly misapply the exemption, and what the DUAA 2025 added.
Where the soft opt-in comes from
PECR Regulation 22 is the rule that requires prior consent for marketing emails to individual subscribers. Regulation 22(3) is the exemption — commonly called the soft opt-in — that allows marketing without that prior consent where four specific conditions are met.
The legal text appears in the Privacy and Electronic Communications Regulations 2003. The ICO's interpretation of the conditions appears in its guidance on direct marketing using electronic mail.
For a broader explanation of how the soft opt-in fits into the PECR consent framework, see PECR vs GDPR for UK email marketing and our full guide to the soft opt-in explained.
The four conditions
Condition 1: You obtained the contact details in the course of a sale or negotiations for a sale
The email address must have come from a commercial transaction — either a completed purchase or a genuine pre-sale engagement (an inquiry, a quote request, or a negotiation for a purchase that was underway).
The ICO's guidance is clear that this does not include:
- Contact details collected at events or from marketing campaigns where no purchase was taking place
- Free sign-ups to newsletters or mailing lists where no product or service purchase was involved
- Inquiries about non-commercial matters (general support questions, accessibility queries)
The sale or negotiation must be real. Organisations that stretch this condition — treating any interaction as "negotiations" — are applying the exemption more broadly than the ICO considers justified.
Condition 2: You are marketing similar products or services
The marketing must be for products or services "similar" to those involved in the original transaction or negotiation. The ICO has consistently said this requires genuine similarity, not a loose connection.
The similarity test is a qualitative one. Practical examples of how it tends to work:
Likely to pass: A software company sells a project management tool to a business customer and emails them about an add-on reporting module for the same tool.
Likely to fail: A software company sells a project management tool and emails the customer about unrelated cybersecurity consultancy services the company also offers.
The ICO does not provide a bright-line test, and there is inevitably grey area — but the question to ask is whether the customer would reasonably see the marketed product as part of the same product or service family as what they bought.
Condition 3: You gave the person the opportunity to opt out at the time you collected their details
At the point you obtained the email address — the point of sale, or during negotiations — you must have given the person a clear, prominent opportunity to refuse marketing. This must be:
- Clear — the opt-out must be easy to find and easy to understand. Burying it in small text at the bottom of a form does not meet this standard.
- Specific — the person must know they are declining marketing from your organisation by electronic mail.
This is an opt-out, not an opt-in. The condition does not require the person to actively decline — only that they had a genuine, visible opportunity to do so.
Condition 4: You give the person the opportunity to opt out in every subsequent marketing message
Every marketing message you send under the soft opt-in must include an opportunity to opt out, and any opt-out request must be honoured promptly and permanently.
This is a continuing obligation, not a one-time check. If you stop providing opt-out mechanisms in ongoing messages, you lose the soft opt-in basis for those contacts.
All four conditions must be met
The ICO is explicit that all four conditions must be satisfied — failing any single condition means the soft opt-in does not apply. This is a common source of error: organisations that meet three of the four conditions but assume the exemption still holds.
In practice, the two conditions that most often fail are:
- Condition 2 (similar products) — marketing too broadly across unrelated product lines
- Condition 3 (opportunity to opt out at collection) — incomplete or buried opt-out mechanisms at the point of sale
If any condition fails, you fall back to the default requirement: explicit prior consent before marketing.
What the DUAA 2025 added
The Data (Use and Access) Act 2025 added a new soft opt-in for charitable organisations at PECR Regulation 22(3A). This allows charities to send marketing emails to existing supporters without prior consent, subject to similar conditions (the supporter provided details in the course of a previous donation or supporter activity, the marketing relates to similar charitable activities, and opt-out opportunities are provided).
This applies only to registered charities. It does not affect the conditions for the commercial soft opt-in under Regulation 22(3).
Our guide to the DUAA 2025 PECR changes covers all the changes made to PECR by the Act.
Soft opt-in and B2B email
The soft opt-in applies specifically to individual subscribers — consumers, sole traders, and some small partnerships. For corporate subscribers (limited companies, LLPs), PECR's consent requirement does not apply to the company in the first place, so the soft opt-in is not needed.
This is a common source of confusion in B2B marketing. If you are emailing a limited company's general or departmental address, you do not need PECR consent or soft opt-in for the PECR element — though you still need a GDPR lawful basis (usually legitimate interest) for processing the named individual's data. Our B2B email marketing opt-out rules guide explains how this works.
Checking your soft opt-in position
If you are relying on the soft opt-in for any part of your email list, the key questions to document are:
- How was this contact's email address collected? Was it in connection with a sale or genuine sales negotiation?
- What did we sell or discuss? Is what we are now marketing genuinely similar?
- Did we provide a clear, prominent opt-out opportunity at the point of collection?
- Does every marketing message we send include an opt-out? Are opt-outs processed promptly?
If you cannot answer all four questions affirmatively, the soft opt-in basis is not secure for those contacts. The PECR Compliance Checker runs through these questions as part of a broader consent status assessment.
This article is for informational purposes only and does not constitute legal advice. For guidance specific to your situation, consult a qualified legal professional or data protection officer.