SendBeam

UK email marketing rules in 2026: PECR, UK GDPR consent, and what changing provider actually requires

PECR's soft opt-in, the UK GDPR consent evidence you must keep, the ICO's re-permission fines, and a checklist for moving a list to a new platform.

SendBeam team

8 min read

This post explains the rules as we understand them, with links to the legislation and the regulator’s guidance. It is not legal advice. If a decision turns on it, ask a solicitor.

Two pieces of UK law govern a marketing email: the Privacy and Electronic Communications Regulations, which say whether you may send it, and the UK GDPR, which governs the personal data you hold to send it. People tend to know the second exists and forget the first, which is unfortunate, because most of the enforcement action for email has been under the first.

This post covers what each law requires of a small site, what the regulator has actually fined people for, what changing your email provider does and does not oblige you to do, and a checklist you can work through in an afternoon.

The Privacy and Electronic Communications (EC Directive) Regulations 2003 apply to marketing by electronic mail, which covers email, SMS and similar messaging. Regulation 22 is the operative rule. In summary:

  • You must not send unsolicited marketing by electronic mail to an individual subscriber unless they have previously notified you that they consent to receiving it (reg. 22(2)).
  • There is one exception, usually called the soft opt-in (reg. 22(3)). You may email someone without prior consent if you obtained their details in the course of a sale or negotiations for a sale of a product or service, the marketing is for your own similar products or services, and they were given a simple means of refusing, free of charge, at the time their details were collected and in every message since.

“Individual subscriber” means individuals, sole traders and, in most of the UK, partnerships. Corporate subscribers (limited companies, LLPs, public bodies) are outside reg. 22, though the UK GDPR still applies to the named person you are emailing, and regulation 23 applies to everyone: you must not disguise or conceal who the message is from, and you must provide a valid address at which the recipient can ask you to stop.

For a small site the practical reading is simple. A newsletter signup form is consent. A contact form is not consent to marketing, because writing to ask a question is not “negotiations for a sale” of anything. A customer who bought something from you may fall under the soft opt-in for similar things, provided you offered an opt-out at the checkout and offer one in every email. And a list you bought, scraped or were given is none of these.

The ICO’s Guide to PECR covers each of these points in plain language, and its direct-marketing guidance goes into the edge cases.

PECR says you need consent; the UK GDPR says what consent is. Article 4(11) defines it as a freely given, specific, informed and unambiguous indication of the person’s wishes by a statement or a clear affirmative action. Article 7 adds three obligations that bite in practice:

  • You must be able to demonstrate that the person consented (Art. 7(1)).
  • If consent is bundled into something else, the request must be clearly distinguishable and in plain language (Art. 7(2)).
  • Withdrawing consent must be as easy as giving it (Art. 7(3)).

Recital 32 rules out pre-ticked boxes and silence. A checkbox that is ticked by default is not consent. A visitor who fills in a form to download something and is quietly added to the newsletter has not consented to the newsletter.

The ICO’s consent guidance sets out what a record of consent should contain, and it is worth quoting the shape of it because it is exactly what you will be asked for if anyone ever complains:

  • Who consented: the name or other identifier.
  • When they consented: a timestamp, or a dated copy of a paper form.
  • How they consented: the form or page and the method (a ticked box, a double opt-in confirmation).
  • What they were told at the time: the wording of the consent statement and the privacy information shown, as it was then.
  • Whether they have withdrawn consent, and when.

Double opt-in is not required by UK law. It is, however, the easiest way to produce a record that satisfies all five points, because the confirmation click is dated, tied to an address the person controls, and unambiguous. It also keeps other people’s addresses off your list, which is the main cause of spam complaints, so the deliverability case and the compliance case point the same way.

In March 2017 the ICO fined two companies for sending emails that asked people about their marketing preferences.

Flybe was fined £70,000 for sending about 3.3 million emails in August 2016 to people who had opted out of marketing, with the subject line asking them to update their details and preferences and the chance to win a prize. The ICO’s finding was that an email asking whether someone wants marketing is itself a marketing email, and those people had already said no.

Honda Motor Europe was fined £13,000 for sending 289,790 emails asking whether customers wanted to hear from the company, on the basis that Honda could not show it had consent to send marketing to those people in the first place. Honda argued the emails were customer service, not marketing; the ICO disagreed.

The ICO’s monetary penalty notices for Flybe and Honda Motor Europe set out the reasoning. The lesson for a small site is not about the size of the fines; it is the principle. You cannot fix a list with no consent by emailing it to ask for consent. If you do not have evidence that someone agreed to hear from you, the lawful options are to obtain consent through some channel that is not a marketing email, or not to email them.

The maximum penalty under PECR was £500,000 at the time. The Data (Use and Access) Act 2025 provides for PECR penalties to rise to the UK GDPR maximum (up to £17.5 million or 4% of worldwide turnover) and extends the soft opt-in to charities; those provisions come into force by commencement regulations, so check the ICO’s site for the current position.

What changing provider does and does not require

This is the question we are asked most often when someone is considering moving to SendBeam, so it deserves a straight answer.

Consent is given to you, not to your software. Under the UK GDPR you are the controller; the email platform is a processor acting on your instructions. Moving from one processor to another does not change what your subscribers agreed to, so you do not need to ask them to consent again. Sending a “please confirm you still want to hear from us” email to a list that already has consent is unnecessary, and sending it to a list that does not have consent is the Honda problem.

What a change of provider does require:

  • A contract with the new processor covering the points in Article 28(3): acting only on your instructions, confidentiality, security, sub-processors, assistance with rights requests, deletion or return at the end, and audit. Platforms usually publish this as a data processing agreement; SendBeam’s is at /legal/dpa.
  • The evidence comes with the data. Export the consent record, not just the addresses: source, timestamp, IP where held, and the double opt-in status. If the old platform never kept it, you cannot invent it; those contacts should be left out rather than emailed, and you should decide what to do about them separately.
  • The suppression list moves first. Unsubscribes, bounces and complaints must be loaded into the new platform before a single address is imported, so that nobody who opted out on the old system is emailed by the new one. Then keep the old platform’s unsubscribes syncing for a period after cutover, because emails already delivered still carry the old unsubscribe links.
  • Update your privacy notice if it names the provider, describes where data is stored, or lists international transfers, and the new arrangement differs.
  • Check the lawful basis for anything that is not a newsletter. Transactional email (receipts, sign-in links) is not marketing and does not need consent, but it should not carry marketing content either, or it becomes marketing.

What it does not require: fresh consent, a re-permission campaign, or a gap in sending. If someone tells you otherwise, ask them which regulation they are relying on.

A practical checklist

Work through this once, and again whenever a form or a list changes.

  1. Every list has a source. For each list you can say where the addresses came from: which form, which purchase flow, or which import, and the consent basis for each.
  2. Forms are unambiguous. No pre-ticked boxes. The newsletter checkbox is separate from the terms checkbox. The wording says what people will receive and how often.
  3. Contact forms do not subscribe. A message from a visitor creates a conversation, not a marketing contact.
  4. Double opt-in is on for any list that collects addresses from a public page.
  5. You can produce the record. For any contact, you can show who, when, how and what they were told.
  6. Every email says who it is from and how to stop. A real sender name and address, a working unsubscribe link, and one-click unsubscribe headers for Gmail and Yahoo.
  7. Unsubscribes are processed at once, and suppressed addresses stay suppressed through imports.
  8. Soft opt-in customers were offered an opt-out at the point of sale and are only emailed about similar products.
  9. Nobody is emailed to ask for consent.
  10. When you change provider, the DPA is in place, the suppression list goes first, the consent evidence travels with each contact, and your privacy notice is updated.

Most of this is how a well-run small site behaves anyway. The value of writing it down is that when a complaint arrives, and eventually one will, you answer it in ten minutes with a record rather than in a week with an apology.

Again: this is a summary, not legal advice. The legislation is linked above and the ICO’s guidance is free; when the stakes are real, read both and take advice.

Written by

SendBeam teamThe people building SendBeam

Written by the people building SendBeam. We run five of our own sites on it.

In the docs

The SendBeam blog, by email

Notes on running email for small sites.

New posts when we have something worth saying — what we learn running five sites' email, pricing checks, deliverability changes and UK rules. No drip sequence, no "tips".

Double opt-in: we send one confirmation email and nothing else until you click it. Unsubscribe in one click, any time. Privacy.