17 August 2026 · Last reviewed 17 August 2026
How to Build a PECR-Compliant Email Marketing Programme
Most email marketing compliance failures don't start with a single bad decision. They build up over time: a sign-up form that doesn't quite meet the consent standard, consent records that weren't kept properly, a platform migration that lost the evidence chain, an opt-out list that wasn't propagated across systems.
Building a PECR-compliant email programme from the ground up — or auditing an existing one — requires working through each component systematically. This guide covers the key building blocks.
Step 1: Establish your legal basis for each segment
Before any email goes out, you need two things confirmed for every contact:
PECR basis: For individual subscribers (consumers, sole traders), you need either:
- Explicit prior consent to receive marketing from you; or
- A valid soft opt-in under Regulation 22(3) — covering contacts acquired through a purchase or genuine sales negotiation, who are being marketed similar products, and who had an opt-out opportunity at collection
For corporate subscribers (limited companies, LLPs), the PECR consent requirement doesn't apply to the company — though you still need a GDPR basis for processing the individual's work email.
GDPR basis: Under the UK GDPR, you need a lawful basis under Article 6 for processing the personal data. For consumer lists where you have PECR consent, consent (Article 6(1)(a)) typically applies. For B2B email and postal marketing, legitimate interest (Article 6(1)(f)) is more common.
Segment your list by contact type and legal basis before you build anything else. The rules work differently and the documentation requirements differ. Our PECR vs GDPR overview explains the two-layer structure.
Step 2: Design consent collection correctly
If consent is your basis, the collection mechanism must meet the standard:
What the consent must be:
- Freely given — no required tick, no bundled consent, not conditional on service
- Specific — the contact knows what they are agreeing to receive, from whom
- Informed — the consent text identifies your organisation, the channel (email), and the types of marketing
- Unambiguous — an unticked checkbox or clear written action, not silence or a pre-ticked box
What you must record at collection:
- The exact wording shown to the contact (version the form)
- The date and time consent was given
- The mechanism used (web form, paper, phone — and if phone, record the call or the note)
- The URL or location of the form where consent was given
Many businesses record that consent was given without recording what the contact was told. This fails Article 7(1) of the UK GDPR, which requires you to be able to demonstrate that consent was given — not just that a subscription occurred. See the consent records retention guide for what to keep and for how long.
Version your consent wording. When you change the consent text on a signup form, archive the previous version with a date range. Subscribers who joined under the old wording are covered by that wording — not by your current text.
Step 3: Document soft opt-in contacts separately
If any contacts on your list are there by virtue of the soft opt-in rather than explicit consent, maintain a separate record:
- How the contact's details were obtained (purchase, inquiry)
- What was sold or discussed — to support the "similar products" condition
- Whether an opt-out opportunity was given at collection (and how)
- When the contact relationship began
This documentation is distinct from your consent records. If challenged, you need to show all four Regulation 22(3) conditions are met for these contacts. Our ICO soft opt-in guidance covers what each condition requires.
Step 4: If relying on legitimate interest for any segment, complete the LIA
For B2B email or any processing activity where you are relying on legitimate interest as your GDPR basis:
- Complete a Legitimate Interests Assessment covering the purpose, necessity, and balancing tests
- Document the analysis in writing before the processing begins
- Record who completed it and when, and set a review date
- Ensure the opt-out mechanism in your emails covers the Article 21 right to object
The DUAA 2025 strengthened the legal position here by inserting direct marketing as an example of a legitimate interest under Article 6(1)(f). But the balancing test still applies in full. See our guide to what the DUAA 2025 actually changed.
Step 5: Build suppression and opt-out infrastructure
Every marketing email must include a working opt-out mechanism. Beyond that basic requirement:
Opt-out processing: When someone unsubscribes, suppress them immediately — not at the next batch. They must not receive another marketing email from you after the opt-out is received.
Cross-system suppression: Your suppression list must apply across all systems that hold the contact's data for marketing purposes. If your ESP, CRM, and data warehouse are separate, opt-outs must propagate to all three.
Right to object: Under Article 21(2) of the UK GDPR, individuals have an absolute right to object to direct marketing. Where legitimate interest is your GDPR basis, this right is particularly prominent and must be honoured without delay or qualification.
Re-contact prevention: Contacts who have opted out or objected must not be re-added if you receive their data from another source (a purchased list, a referral programme, a separate product sign-up). Maintain a permanent suppression list and cross-reference before adding any new contacts.
Step 6: Establish ongoing compliance processes
A PECR-compliant programme isn't a one-time build — it requires ongoing operational processes:
Consent refresh. Depending on the nature of your list and how actively contacts engage, consider whether consent for older, unengaged contacts remains current. The ICO does not specify a maximum consent age, but aged, inactive consent from inactive contacts is a weaker legal position than fresh, actively-demonstrated consent.
Annual records review. Review your consent records for completeness. Identify contacts whose consent evidence is unclear or missing. Decide whether to re-verify consent, to rely on a different basis, or to suppress.
Privacy notice updates. When your processing changes materially, update your privacy notice. When PECR rules change (as they did with the DUAA 2025), check whether your notice still accurately describes your marketing practices and legal bases.
Platform migrations. When you move between ESPs or CRMs, export the full consent metadata — not just email addresses and subscription status. Consent records that don't survive a migration are lost evidence.
Step 7: Prepare for an ICO inquiry
The ICO does not investigate every complaint about marketing emails. But it does investigate complaints that show systemic failures or high volumes of unsolicited contact. If an investigation opens, the things you will need to produce quickly are:
- Consent records for any named contact an investigator asks about
- Your privacy notice as it stood at the time the contact joined your list
- Records of opt-out requests received and when they were actioned
- If relying on soft opt-in: documentation of how each contact's details were obtained
- If relying on legitimate interest: the completed LIA
The ICO's enforcement cases consistently show that organisations that cannot produce these records quickly are in a weaker position than those that can — regardless of whether the underlying marketing was in fact lawful. Evidence that exists but cannot be found or presented is not much better than evidence that was never created.
The PECR compliance checklist covers all 15 evidence categories that matter in an ICO inquiry.
This article is for informational purposes only and does not constitute legal advice. For guidance specific to your organisation, consult a qualified legal professional or data protection officer.