Privacy and Electronic Communications (EC Directive) Regulations 2003
Tier 1 In forcePECR is UK secondary legislation (a statutory instrument, not an Act) implementing the EU ePrivacy Directive 2002/58/EC. It governs electronic direct marketing, cookies and similar tracking technologies, communications network security, and traffic/location data. It operates as lex specialis alongside the UK GDPR: where PECR sets a specific rule for marketing or cookies, that rule prevails over the general UK GDPR position on the same activity. The most misunderstood point is enforcement: PECR breaches are overwhelmingly dealt with by civil monetary penalty, and since the Data (Use and Access) Act 2025 the ceiling has risen dramatically to match the UK GDPR.
Identity
- Citation
- SI 2003/2426
- Jurisdiction
- United Kingdom
- Type
- secondary
- Structure
- Regulations 1-40 across parts covering marketing, cookies, traffic/location data and security.
- Royal assent
- 18 September 2003
- Main commencement
- 11 December 2003
Made under the European Communities Act 1972. Amended repeatedly (notably 2011 for cookie consent, 2018 claims-management cold-calling ban, 2019 pension cold-calling restriction, and 2026 by the DUAA 2025 for penalties and cookie exceptions).
Amended by: Amended by the DUAA 2025 to (a) raise the penalty ceiling to UK GDPR levels (in force 5 February 2026), (b) introduce low-risk cookie/analytics consent exceptions, and (c) extend the cookie rules to those who "instigate" storage of or access to information, not only those who place cookies.
Reads together with
- UK GDPR
The UK GDPR consent standard is imported into PECR: where PECR requires consent (marketing, cookies), it must meet the UK GDPR definition of consent. PECR prevails on the specific activity.
- Data Protection Act 2018
Supplies the ICO's enforcement machinery and the constitution of the regulator that enforces PECR.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | None found — checked | Applies UK-wide with no regional carve-out. |
| 2 | Commencement | Asymmetry found | The DUAA 2025 amendments commence in phases. The increased penalty ceiling and enhanced ICO powers came into force on 5 February 2026 (SI 2026/82). Some cookie-consent exceptions depend on further secondary legislation and updated ICO guidance; practitioners should verify each is live. |
| 3 | Sunset / mandatory review | None found — checked | No sunset or mandatory review clause in PECR itself. |
| 4 | Criminal liability | Asymmetry found | PECR is primarily enforced by civil monetary penalty, not criminal prosecution. The headline enforcement risk (unsolicited marketing, cookie breaches) is a civil monetary penalty, NOT a criminal offence. Care is needed: the vast majority of ICO PECR action is CMPs, not prosecutions. |
| 5 | Civil liability | Asymmetry found | Regulation 30 provides a right for a person who suffers damage by contravention of PECR to bring proceedings for compensation, independent of ICO action. |
| 6 | Regulatory enforcement toolkit | Asymmetry found | Historically the PECR CMP ceiling was £500,000 — far below the UK GDPR ceiling. The DUAA 2025 aligned it: from 5 February 2026 the maximum is the higher of £17.5m or 4% of total worldwide annual turnover, a roughly 35-fold increase. The requirement to prove substantial damage or distress before a monetary penalty was also removed, lowering the enforcement bar. |
| 7 | Personal / director liability | Asymmetry found | PECR CMPs can be issued against company officers in certain circumstances (mirroring the ICO's power to fine directors personally for serious marketing breaches). |
| 8 | Public vs private sector split | None found — checked | One regime applies to public and private senders/operators alike. |
| 9 | Legal-person coverage | Asymmetry found | Unusually, some PECR marketing protections extend to corporate subscribers, not just individuals — e.g. rules on unsolicited communications can protect legal persons. This differs from the UK GDPR, which protects natural persons only. |
| 10 | Exemptions — with conditions | Asymmetry found | PECR's exemptions are activity-conditioned exceptions rather than a schedule of general carve-outs: the strictly-necessary and DUAA-added low-risk analytics exceptions to cookie consent, the reg 22(3) soft opt-in with its cumulative conditions, and the national security (reg 28) and legal-purposes (reg 29) exemptions. Each is condition-bound; none is a blanket permission. The operative scope of some DUAA cookie exceptions was still settling at the research date (see liveIssues). |
Exemptions
Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.
reg. 6 (as amended by DUAA 2025) — Low-risk cookies / storage-and-access exceptions
Trigger
Consent is not required where storage of or access to information on terminal equipment is strictly necessary, or falls within the DUAA-introduced exceptions (e.g. cookies used only for statistical/analytics purposes to measure or improve a service, subject to specified conditions including transparency and an opt-out). Not automatic — the conditions must be met and the ICO's refreshed storage-and-access guidance applies.
Disapplies
- reg. 6 consent requirement for the specified low-risk categories
Advertising and cross-site profiling cookies remain outside the exception and still require consent.
reg. 22(3) soft opt-in — Soft opt-in for electronic marketing
Trigger
A sender may email/text market to an individual without prior consent only where all conditions are met: the contact details were obtained in the course of a sale or negotiations for a sale of a product or service to that person; the marketing is for the sender's own similar products or services; and the recipient was given a simple means to opt out at collection and in every message.
The soft opt-in is a narrow, condition-bound exception, not a general permission to email customers.
Interactions and conflicts
The cross-instrument texture that profiling an Act in isolation misses — including where the real answer to a question about this Act is found in a different one.
| Instrument | Relationship | Note |
|---|---|---|
| UK GDPR | Lex specialis | For electronic marketing and cookies, PECR's specific rules prevail over the general UK GDPR lawful-basis analysis for that activity; UK GDPR still governs the underlying personal-data processing. |
Live issues
Sources
- Secondary Modernising UK E-Privacy: DUAA's Reform of PECR University of East Anglia Law School
- Secondary Marketing compliance under DUAA and PECR DPO Centre
- Primary Data (Use and Access) Act 2025 (Commencement No.1) Regulations 2025 (SI 2025/904) legislation.gov.uk
Never independently verified — seeded from the prototype.