Skip to main content
Back to blog

UK PECR and ePrivacy, Decoded — the Opt-in Layer Beside UK GDPR

The UK's Privacy and Electronic Communications Regulations sit beside UK GDPR and ask a separate question about marketing SMS, email, calls, and push — was the message itself something you could send before consent. This explainer covers where PECR fits in the omnichannel consent matrix beside TCPA, CAN-SPAM, and CASL, and the tenant-owned consent baseline a UK program configures.

Orbit Editorial Team

Quick answer: The Privacy and Electronic Communications Regulations 2003 (PECR) are the UK layer most outbound programs underweight. UK GDPR asks whether your processing has a lawful basis; PECR separately asks whether the message itself — a marketing text, email, push, or automated call — was one you were allowed to send before you had consent. For direct marketing to UK recipients, PECR is largely an opt-in regime, with one narrow soft opt-in for marketing to your own existing customers and no soft opt-in at all for automated calling. If you send marketing traffic into the UK and your consent evidence is wired only for "GDPR," PECR is the gap a UK-GDPR-style review misses. The full obligation-to-surface map lives in the UK PECR and ePrivacy docs; this post is the buyer-side explainer for placing it in the omnichannel consent matrix.

This is an industry-news explainer in the same register as the CAN-SPAM vs CASL opt-out-vs-opt-in post and the India DPDP phase-II consent receipts post — external regulation plus the tenant-owned posture for meeting it. Nothing here is an Orbit product change, and none of it is legal advice: the platform carries the consent-evidence and send-gating surfaces; counsel determines where your program's soft opt-in reliance and TPS posture sit.

Why UK PECR matters for UK-destination traffic

PECR is one of the UK's e-privacy statutes, and for marketing traffic it is a harder gate than the privacy regime most teams already have wired. UK GDPR frames lawful-basis and data-subject-rights questions; PECR's marketing rules (regs 19–24, covering calls, texts, and calls to corporate-registered numbers) turn on a narrower predicate: whether a given communication is direct marketing — material directed at a particular individual that promotes a product, service, or aim. If it is, PECR's opt-in posture applies to that message regardless of what your lawful-basis review under UK GDPR concluded.

The consequences are real, not rhetorical. The ICO enforces PECR with monetary penalties, and the enforcement pattern since 2020 spiked specifically on unsolicited direct marketing — text messages sent without consent, marketing calls to numbers registered on the Telephone Preference Service (TPS) or its corporate sibling (CTPS) — two classes that PECR places squarely on the sender, never the platform. The full statutory scope and the per-channel posture table are the subject of the UK PECR and ePrivacy docs; buyer-side, the takeaway is that PECR is the regime your UK-destination review must name first.

The soft opt-in, narrowly. PECR permits marketing email (and in ICO guidance, SMS) to an existing customer without fresh consent when three conditions all hold: you collected the contact details during a sale or negotiation, the marketing promotes your own similar products, and the collection gave an opt-out at collection time and in every message. That is a defence you substantiate with the transaction record and the collection-time wording — not a default you assume. Automated calling (recorded voice, AI agents) has no soft opt-in path at all: consent is required on every automated marketing call. The docs page grades this per channel so your reviewers do not have to grade it from the statute.

How PECR sits beside UK GDPR

PECR and UK GDPR are often joined in a program's review queue and must not be conflated in it. UK GDPR governs the processing — the whole lifecycle of personal data and the lawful bases (consent, legitimate interests, contract, legal obligation) that processing rests on. PECR governs the message itself — whether a particular communication to a particular person was one you could send. The two run on separate predicates, and PECR's is strictly harder for direct marketing: the same contact record can carry a lawful basis under GDPR (legitimate interest for service communications, e.g.) and still carry no PECR basis for marketing sent to it.

The sibling GDPR posture guide walks the lawful-basis, erasure, and data-residency surface; the UK PECR and ePrivacy page walks the message-set posture. Orbit's compliance consent-default-policy docs put the two side by side on purpose: "GDPR, UK PECR, Brazil LGPD" appear together as opt-in regimes on the unknown-marketing-policy posture, because the policy mechanism serves both (a contact with no recorded consent gets no marketing) without you having to know which statute asked the question. A UK program needs both reviews — never one conflated review.

Where PECR fits in the omnichannel consent matrix

The buyer's matrix question — "which channels, which jurisdictions, which consent tiers" — is the one the omnichannel compliance matrix concept answers at hub level, and PECR is the UK row of it. Mapping PECR beside the North-American regimes on the same matrix is what stops the false equivalency that blindsides UK-destination programs:

RegimeDefault for marketingThe consent oathOrbit sibling post
US TCPA (voice, SMS)"Prior express consent" (written for telemarketing); federal quiet-hoursOne-to-one (vacated), scope of the language shownTCPA one-to-one, vacated
US CAN-SPAM (email)Opt-out regime; required carry-through unsubscribeConsent-only not required; honour opt-outsCAN-SPAM vs CASL decoding
Canada CASLBroadly opt-in; two-year implied-post-sale windowExpress consent, or the prescribed implied pathsCASL counterpart — same decode
UK PECR / ePrivacyLargely opt-in; narrow soft opt-in for own customers; no soft opt-in for automated callingConsent-first, documented; TPS/CTPS for live callsThis post + the docs
India DPDPConsent-first for marketing; receipt-grade recordsNotice-linked consent; receipt per grantDPDP phase-II consent receipts

Two asymmetries deserve the matrix treatment. First, CAN-SPAM's opt-out posture does not transfer: a UK program that carries the US email playbook ("send, stop on unsubscribe") into PECR jurisdictions mis-routes the posture — PECR is closer to CASL in its consent-first spirit, with the soft opt-in carve-out narrower than CASL's implied-consent paths. Second, the channel rules diverge inside PECR itself: email gets the soft opt-in exception, SMS gets it in ICO guidance, and automated calling gets none — so the per-channel matrix column, not the country row, is what your counsel reviews, and the omnichannel matrix concept structures the review exactly that way.

Setting a UK-PECR-compliant consent baseline in Devotel Orbit

Orbit supplies the posture knobs; your counsel supplies the legal stance. The UK PECR docs page's worked configuration sequence is the implementation; the buyer-side baseline reads as four settings the matrix's UK column resolves to.

  1. Unknown marketing policy stays at `refuse`. A contact whose consent state is unknown receives no marketing — the posture an opt-in regime assumes. Loosening to allow_with_logging is a documented, owner-gated decision the consent-default-policy docs reserve, and for opt-in jurisdictions like PECR there is no lawful widening that justifies it. The consent-proof-first messaging post covers the same posture-first instinct on a different regime.
  2. Consent default policy set to `deny_on_missing`. A data subject with no consent-ledger row does not fan out to CDP destinations or subscription checks — the GDPR-Art-7 posture PECR sits beside. An opt-out, a suppression entry, or an erasure beats both posture knobs in every jurisdiction, so revocation remains honoured regardless of how the knobs are set.
  3. TPS/CTPS scrub on UK voice lists. Live marketing calls must not hit a number registered on the TPS or CTPS under PECR reg 21; the DNC scrub docs describe the per-org check with country=GB scoping so UK registers (and only those) feed the verdict, plus the intl_feeds_synced signal that tells you whether "clear" was backed by a synced feed or only your own suppression. Route revocation to scope all so a UK opt-out propagates across SMS, voice, and email consistently.
  4. Sender identity per the GB row. The live country-requirements row for GB carries the sender-ID registration status; when it marks registration recommended or required, file it through the sender-ID flow before your first send. Voice into the UK carries the same axis: a branded or CLI-owned caller identity is the residual a TPS-scrubbed call still owes.

The result is a UK posture your reviewers can audit: only consent-backed contacts receive marketing, UK live calls avoid registered numbers, the sender identity is filed where the UK row says it should be, and each decision lands in the audit trail. That is the "posture you configure" — Orbit does not enforce a UK gate; it enforces the posture you set.

Where to go next

The full PECR map — per-channel posture table, the soft-opt-in conditions with their evidence list, TPS/CTPS scrub mechanics, sender-ID flow, recording-concern jurisdiction pair, and an end-to-end worked configuration — is the UK PECR and ePrivacy docs page. For the omnichannel matrix in which PECR's UK row sits, the omnichannel compliance matrix concept organizes the channel-vs-jurisdiction-vs-consent-tier decision; for the deeper consent-record design the whole posture resolves to, the consent-management reference documents the ledger the posture resolves from. Sibling explainers run beside these: CAN-SPAM vs CASL opt-out vs opt-in, India DPDP phase-II consent receipts, and the compliance-posture quarterly review operational practice for keeping regimes re-evaluated as statutes or send volumes shift.

Published 22 September 2026.

UK PECR and ePrivacy, Decoded — the Opt-in Layer Beside UK GDPR — Orbit by Devotel