PECR (Privacy and Electronic Communications Regulations)
What is PECR (Privacy and Electronic Communications Regulations)?
PECR (Privacy and Electronic Communications Regulations) is the UK law that governs electronic direct marketing — including SMS — and requires prior consent or a valid soft opt-in before promotional messages are sent.
PECR is the UK regulation that sits alongside UK GDPR and controls how businesses can use electronic channels — SMS, email, phone calls, and cookies — for direct marketing. For messaging, the core rule is simple: you need prior consent from the recipient, or you must qualify for the “soft opt-in” exception, which applies only to existing customers who gave their details during a sale and were offered a clear chance to refuse marketing. Every promotional message must also carry a free, working opt-out, and suppression requests must be honoured immediately.
Enforcement belongs to the ICO, and the stakes rose sharply in February 2026, when the Data (Use and Access) Act 2025 lifted the maximum PECR fine from £500,000 to £17.5 million or 4% of global annual turnover. Example: a retailer running a bulk SMS campaign to UK numbers must hold a consent record — timestamp, source, exact wording — for every contact on the list, or exclude that contact from the send.
See BSG's Text Message Marketing Compliance: Understanding SMS Regulations for the United States, the UK, and Europe for a closer look at how this plays out in practice.
Related terms
Related BSG products