GDPR & PECR compliant marketing automation: a UK guide
How to run marketing automation that grows revenue and respects UK data-privacy law. A practical walk-through of lawful basis, consent, the PECR soft opt-in, preferences, suppression and data residency.
Not legal advice. This guide is a practical overview for marketing and technology teams, not legal advice. Rules depend on your specific circumstances — consult a qualified data-protection adviser and the ICO’s guidance before making decisions.
Key takeaways
- UK marketing automation usually has to satisfy two laws at once: UK GDPR and PECR.
- For email/SMS/push to individuals, PECR generally requires consent — with a narrow “soft opt-in” for existing customers.
- Build consent, preferences and suppression into your platform from day one — retrofitting is costly.
- Good compliance and good performance go together: cleaner lists deliver better and convert better.
Marketing automation makes it easy to message a lot of people, quickly. That is precisely why UK regulators care about how you do it. Get compliance right and you build trust, protect deliverability and avoid enforcement. Get it wrong and you risk complaints, reputational damage and action from the Information Commissioner’s Office (ICO). The good news: the practices that keep you compliant also tend to make your programme perform better.
GDPR vs PECR: the two laws that apply
Most UK marketing automation has to respect both regimes:
- UK GDPR is the general data-protection law. It governs how you collect, store and use personal data: you need a lawful basis, you must be transparent, you must honour data-subject rights (access, erasure and so on) and keep data secure.
- PECR — the Privacy and Electronic Communications Regulations — sits alongside UK GDPR and deals specifically with electronic marketing and cookies. It sets the rules for when you may send marketing by email, SMS and automated calls, and what consent that needs.
In short: UK GDPR asks “are you allowed to use this data at all?”, while PECR asks “are you allowed to send this specific electronic message?”. You usually need to answer both.
Choosing a lawful basis
Under UK GDPR you need a lawful basis to process personal data for marketing. The two most relevant are consent and legitimate interests. Consent must be specific, informed and freely given. Legitimate interests can sometimes support certain processing, but where PECR requires consent for the electronic message itself (as it often does for email and SMS to individuals), legitimate interests cannot be used as a workaround for that. The two frameworks work together, and PECR frequently sets the higher bar.
The PECR “soft opt-in”
The soft opt-in is the most misunderstood rule in UK marketing. It lets you email or text existing customers about your own similar products or services without prior consent — but only if all of the following are true:
- You obtained their contact details in the course of a sale (or negotiations for a sale) of a product or service;
- You gave them a simple way to opt out at the point you collected the details; and
- You give them an easy opt-out in every message you send.
It does not cover prospects who merely downloaded a guide, entrants to a competition, or marketing for unrelated products. When in doubt, get consent.
Consent done right
Valid consent is unbundled, granular, opt-in and recorded. In practice that means:
- No pre-ticked boxes. The user takes a clear, affirmative action.
- Separate the asks. Don’t bundle marketing consent with terms and conditions.
- Be specific. Say what they’ll get and from whom; let them choose channels where practical.
- Keep records. Store what they consented to, when, and how — your automation platform should capture this.
- Make withdrawal as easy as giving it.
Data-subject rights your platform must support
Under UK GDPR, individuals have rights over their data — and your marketing automation stack has to be able to honour them, quickly and completely, across every connected system. Build the processes before you need them.
Preference centres and suppression
Two pieces of plumbing make ongoing compliance manageable. A preference centre lets people choose channels, topics and frequency instead of only unsubscribing — which both respects the law and reduces list churn. Suppression ensures that once someone opts out or is deleted, they stay out across every campaign and integration. Weak suppression is one of the most common causes of complaints, so it must work reliably across your whole stack, not just one tool.
Think of consent as a lifecycle your platform manages end to end:
Capture
Clear, unbundled, opt-in — no pre-ticked boxes.
Record
Store what, when and how consent was given.
Honour
Respect channel, topic and frequency preferences.
Suppress
Opt-outs and deletions stick across the whole stack.
Prove
Be able to demonstrate compliance if asked.
Performance bonus: honouring preferences and suppressing the disengaged improves inbox placement and open rates. Compliant lists are healthier lists.
Data residency and international transfers
UK personal data can be processed outside the UK, but any such transfer needs a valid mechanism and safeguards under UK GDPR (for example an adequacy decision or the appropriate contractual safeguards). Because getting this right adds complexity, many UK organisations prefer platforms offering UK or EU data residency and clear sub-processor transparency. That’s why residency is a core selection criterion in our guide to the best marketing automation tools for UK businesses.
Why it matters: the ICO
In the UK, the Information Commissioner’s Office (ICO) regulates both UK GDPR and PECR. It can investigate complaints, issue enforcement notices and impose monetary penalties — and electronic marketing (unsolicited email, SMS and calls under PECR) is a recurring focus of its action. Beyond any fine, the bigger day-to-day cost of poor practice is usually reputational: complaints, spam reports and the deliverability damage that follows.
The reassuring part is that the same habits that keep you on the right side of the ICO — clean consent, honoured preferences, watertight suppression — are exactly the habits that make marketing automation perform. Compliance and results are not in tension.
A practical compliance checklist
- Documented lawful basis for each marketing use of personal data.
- PECR position clear for every channel (consent, or a genuine soft opt-in).
- Consent captured with no pre-ticked boxes, and recorded (what/when/how).
- A working preference centre covering channels, topics and frequency.
- Reliable, stack-wide suppression and one-click unsubscribe in every message.
- Clear privacy information at the point of data capture.
- A process for data-subject requests (access, erasure, objection).
- Known data residency and a current sub-processor list from your platform.
If you can’t tick every box today, you’re not alone — most teams inherit gaps. The point is to close them deliberately, ideally as you design or re-platform your automation rather than after a complaint.
Frequently asked questions
What is the difference between UK GDPR and PECR?
UK GDPR governs processing of personal data generally; PECR governs electronic marketing specifically (email, SMS, push) and the consent it needs. UK marketing automation usually has to satisfy both.
Do I always need consent to send marketing emails in the UK?
Usually yes for marketing to individuals, but the limited PECR “soft opt-in” can apply to existing customers for similar products where an opt-out was offered. B2B corporate email has different rules. Check your specific case and take legal advice.
What is the PECR soft opt-in?
It lets you market your own similar products to existing customers without prior consent, if you got their details during a sale, offered an opt-out then, and offer one in every message. It doesn’t cover prospects or unrelated products.
Does the data have to be stored in the UK or EU?
Not strictly, but transfers outside the UK need a valid mechanism and safeguards under UK GDPR. Many organisations prefer UK/EU residency to simplify compliance, which makes residency and sub-processor transparency key platform criteria.
Marketing automation that’s compliant by design
We build UK marketing automation with consent, preferences, suppression and data residency handled from the start — so growth and privacy pull in the same direction.
Talk to a UK specialist ↗