Skip to content
UK GDPR

UK GDPR for Marketing Teams: What's Allowed

5 min readUpdated 9 September 2026

UK marketing teams operate in one of the most actively enforced areas of data protection law. Direct marketing violations account for the ICO's highest-volume enforcement category. The rules are not complex, but they are specific — and the consequences of getting them wrong are immediate and financial.

This article covers what UK GDPR and PECR permit for B2B and B2C marketing teams.


The Two Frameworks: UK GDPR + PECR

Marketing compliance in the UK involves two overlapping frameworks:

UK GDPR: Governs the processing of personal data for marketing purposes — lawful basis, transparency, retention, and data subject rights. Applies to all personal data processing including B2B marketing lists.

Privacy and Electronic Communications Regulations (PECR): Governs the sending of electronic marketing messages — email, SMS, calls, and faxes. Imposes specific consent requirements for direct marketing to individuals.

Both apply simultaneously. You need a UK GDPR lawful basis for holding the data AND PECR compliance for sending the messages.


B2C Marketing: Consent Required

For marketing to consumers (individuals acting in a personal capacity):

Email and SMS: Consent required under PECR Regulation 22. Pre-ticked boxes, implied consent, and bundled consent do not count.

Valid consent:

  • An active opt-in — unticked box that the person checks
  • Clear information about what they are signing up for: "I agree to receive marketing emails from [Company] about [topic]"
  • Separate from other terms and conditions

Soft opt-in exception: You may market to an existing customer by email about similar products, provided:

  • They gave you their contact details in the course of a sale
  • You offered an opt-out at the time (and they did not opt out)
  • You include an easy unsubscribe in every communication

Social media and paid advertising: UK GDPR governs the processing. PECR consent rules apply to re-targeting using cookies (see cookie compliance article). The platforms' own advertising policies also apply.


B2B Marketing: Legitimate Interest Available

For marketing to business contacts (individuals acting in a professional capacity — a named person at their company):

Email: PECR applies slightly differently for corporate subscribers. You can contact business email addresses (company domain addresses) without consent if you have a legitimate interest and offer an opt-out. But named individuals at their business email are still "subscribers" under PECR — best practice is to treat B2B marketing similarly to B2C.

Direct calls: B2B cold calls are permitted to corporate numbers not registered with the Corporate Telephone Preference Service (CTPS). Check CTPS registration before calling.

Legitimate interest for B2B email marketing:

  • You must have a genuine business reason to contact this person
  • The contact would reasonably expect to hear from you
  • You offer an easy and genuine opt-out in every message
  • You document the legitimate interest assessment

B2B prospecting using purchased or scraped data: This requires careful assessment. The data must have been collected lawfully, the consent or legitimate interest basis must cover your use, and you must be transparent about the source in the first communication (Article 14 requires notification when you obtained data from a third party).


Opt-Out Management

Every marketing communication must include:

  • A clear, easy opt-out mechanism (unsubscribe link in email, keyword unsubscribe for SMS)
  • The opt-out must be processed promptly — within days, not weeks
  • Suppression lists must be maintained — an individual who opts out must not be re-added to the marketing list from future data purchases

Suppression lists: Keep a permanent suppression list of everyone who has opted out. When you acquire new data, screen it against your suppression list before sending. Ignoring your own opt-out list is a PECR violation.


Marketing Database Compliance

Audit your database:

  • For each contact, can you identify the legal basis for holding the contact?
  • For each contact who receives email marketing, can you demonstrate valid consent or legitimate interest?
  • When was the data last used? Are you retaining contacts who have never engaged?

Data hygiene best practices:

  • Remove contacts who have not opened or clicked in 24 months (or per your retention policy)
  • Segment engaged and unengaged contacts — unengaged contacts present disproportionate PECR risk and reduce email deliverability
  • Document the source and basis for each segment of your marketing database

Third-party data: Data purchased from list brokers or data enrichment services (Clearbit, Apollo, Cognism) requires scrutiny:

  • Verify the data was collected lawfully
  • Confirm the consent or basis covers your marketing use
  • You are not insulated by the vendor's representations — if the data is unlawfully collected, you are still liable for using it

What the ICO Checks in Marketing Investigations

When the ICO investigates a marketing complaint:

  1. What is the consent basis for this person receiving the marketing?
  2. Can you produce evidence of the consent (timestamp, source, consent text)?
  3. Did the person opt out? What was the opt-out date? Were subsequent messages sent?
  4. Was a suppression list check conducted before the message was sent?

Without documentary evidence for each question, the enforcement position is difficult to defend.

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →