Data Protection Atlas

Privacy and Electronic Communications (EC Directive) Regulations 2003

Tier 1 In force

PECR is UK secondary legislation (a statutory instrument, not an Act) implementing the EU ePrivacy Directive 2002/58/EC. It governs electronic direct marketing, cookies and similar tracking technologies, communications network security, and traffic/location data. It operates as lex specialis alongside the UK GDPR: where PECR sets a specific rule for marketing or cookies, that rule prevails over the general UK GDPR position on the same activity. The most misunderstood point is enforcement: PECR breaches are overwhelmingly dealt with by civil monetary penalty, and since the Data (Use and Access) Act 2025 the ceiling has risen dramatically to match the UK GDPR.

Identity

Citation
SI 2003/2426
Jurisdiction
United Kingdom
Type
secondary
Structure
Regulations 1-40 across parts covering marketing, cookies, traffic/location data and security.
Royal assent
18 September 2003
Main commencement
11 December 2003

Made under the European Communities Act 1972. Amended repeatedly (notably 2011 for cookie consent, 2018 claims-management cold-calling ban, 2019 pension cold-calling restriction, and 2026 by the DUAA 2025 for penalties and cookie exceptions).

Amended by: Amended by the DUAA 2025 to (a) raise the penalty ceiling to UK GDPR levels (in force 5 February 2026), (b) introduce low-risk cookie/analytics consent exceptions, and (c) extend the cookie rules to those who "instigate" storage of or access to information, not only those who place cookies.

← United Kingdom overview

Reads together with

  • UK GDPR

    The UK GDPR consent standard is imported into PECR: where PECR requires consent (marketing, cookies), it must meet the UK GDPR definition of consent. PECR prevails on the specific activity.

  • Data Protection Act 2018

    Supplies the ICO's enforcement machinery and the constitution of the regulator that enforces PECR.

Asymmetry checklist

All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.

# Point Finding Notes
1 Territorial extent None found — checked Applies UK-wide with no regional carve-out.
2 Commencement Asymmetry found The DUAA 2025 amendments commence in phases. The increased penalty ceiling and enhanced ICO powers came into force on 5 February 2026 (SI 2026/82). Some cookie-consent exceptions depend on further secondary legislation and updated ICO guidance; practitioners should verify each is live.
3 Sunset / mandatory review None found — checked No sunset or mandatory review clause in PECR itself.
4 Criminal liability Asymmetry found PECR is primarily enforced by civil monetary penalty, not criminal prosecution. The headline enforcement risk (unsolicited marketing, cookie breaches) is a civil monetary penalty, NOT a criminal offence. Care is needed: the vast majority of ICO PECR action is CMPs, not prosecutions.
5 Civil liability Asymmetry found Regulation 30 provides a right for a person who suffers damage by contravention of PECR to bring proceedings for compensation, independent of ICO action.
6 Regulatory enforcement toolkit Asymmetry found Historically the PECR CMP ceiling was £500,000 — far below the UK GDPR ceiling. The DUAA 2025 aligned it: from 5 February 2026 the maximum is the higher of £17.5m or 4% of total worldwide annual turnover, a roughly 35-fold increase. The requirement to prove substantial damage or distress before a monetary penalty was also removed, lowering the enforcement bar.
7 Personal / director liability Asymmetry found PECR CMPs can be issued against company officers in certain circumstances (mirroring the ICO's power to fine directors personally for serious marketing breaches).
8 Public vs private sector split None found — checked One regime applies to public and private senders/operators alike.
9 Legal-person coverage Asymmetry found Unusually, some PECR marketing protections extend to corporate subscribers, not just individuals — e.g. rules on unsolicited communications can protect legal persons. This differs from the UK GDPR, which protects natural persons only.
10 Exemptions — with conditions Asymmetry found PECR's exemptions are activity-conditioned exceptions rather than a schedule of general carve-outs: the strictly-necessary and DUAA-added low-risk analytics exceptions to cookie consent, the reg 22(3) soft opt-in with its cumulative conditions, and the national security (reg 28) and legal-purposes (reg 29) exemptions. Each is condition-bound; none is a blanket permission. The operative scope of some DUAA cookie exceptions was still settling at the research date (see liveIssues).

Exemptions

Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.

reg. 6 (as amended by DUAA 2025) — Low-risk cookies / storage-and-access exceptions

Trigger

Consent is not required where storage of or access to information on terminal equipment is strictly necessary, or falls within the DUAA-introduced exceptions (e.g. cookies used only for statistical/analytics purposes to measure or improve a service, subject to specified conditions including transparency and an opt-out). Not automatic — the conditions must be met and the ICO's refreshed storage-and-access guidance applies.

Disapplies

  • reg. 6 consent requirement for the specified low-risk categories

Advertising and cross-site profiling cookies remain outside the exception and still require consent.

reg. 22(3) soft opt-in — Soft opt-in for electronic marketing

Trigger

A sender may email/text market to an individual without prior consent only where all conditions are met: the contact details were obtained in the course of a sale or negotiations for a sale of a product or service to that person; the marketing is for the sender's own similar products or services; and the recipient was given a simple means to opt out at collection and in every message.

The soft opt-in is a narrow, condition-bound exception, not a general permission to email customers.

Interactions and conflicts

The cross-instrument texture that profiling an Act in isolation misses — including where the real answer to a question about this Act is found in a different one.

Instrument Relationship Note
UK GDPR Lex specialis For electronic marketing and cookies, PECR's specific rules prevail over the general UK GDPR lawful-basis analysis for that activity; UK GDPR still governs the underlying personal-data processing.

Live issues

Sources

Never independently verified — seeded from the prototype.