
PECR regulations: marketing sign-ups and opt-out
At a glance
UK-11MediumPECR regs. 22 and 23; DUAA 2025, Sch. 13
Peeky looks at the marketing sign-up forms on your public pages: whether the wording asks clearly, names who will write, and tells people how to stop.
Last checked against the source:
The rule
Regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 applies to unsolicited communications sent by electronic mail to individual subscribers. Paragraph (2) says that, except in the circumstances in paragraph (3) or (3A), a person “shall neither transmit, nor instigate the transmission of, unsolicited communications for the purposes of direct marketing by means of electronic mail unless the recipient of the electronic mail has previously notified the sender that he consents for the time being to such communications being sent by, or at the instigation of, the sender.”
The ICO reads this as covering texts as well as email. Its guidance says: “You must not send marketing emails or texts to individuals without specific consent.”
There are two exceptions. The first is the soft opt-in in paragraph (3). It applies where the sender obtained the recipient’s contact details “in the course of the sale or negotiations for the sale of a product or service”, the marketing is for the sender’s “similar products and services only”, and the recipient was given “a simple means of refusing” the use of the details, free of charge except for the cost of transmission, when the details were first collected and in each later message. Paragraph (3A) adds a narrower exception for charities.
The ICO’s guide adds that the soft opt-in “does not apply to prospective customers or new contacts (eg from bought-in lists)”.
Regulation 23 applies to every direct marketing email, whether or not the recipient consented. A person must not send, or instigate, one “where the identity of the person on whose behalf the communication has been sent has been disguised or concealed”, or “where a valid address to which the recipient of the communication may send a request that such communications cease has not been provided”. Paragraphs (c) and (d) tie the rule to regulation 7 of the Electronic Commerce (EC Directive) Regulations 2002.
What counts as consent is set by the ICO’s guidance, which uses the UK GDPR standard: freely given, specific, informed and unambiguous, shown by a clear affirmative action. The guidance says you “must not use pre-ticked opt-in boxes, silence or inactivity as evidence of consent”, and that consent collected through a third party must name your organisation specifically.
The Act also changed enforcement. Schedule 13 to the 2025 Act, which commenced on 5 February 2026 under SI 2026/82, applies the Data Protection Act 2018 penalty machinery to PECR, including the “higher maximum amount” for the regulations it lists. Section 157 of the 2018 Act defines that amount as £17,500,000 or 4% of worldwide annual turnover, whichever is higher. Regulation 22 itself was also amended on 5 February 2026, with new paragraphs (3A) and (5). The fines described below were announced before that date.
What PeekWell checks and how
UK-11 asks what a visitor can see on a public page: where the site invites people to join a marketing list, does the wording ask clearly, and is there a visible way to stop?
The scan finds newsletter and marketing sign-up forms on the pages it visits and records the consent wording around each one. A language model reads that wording and flags copy that looks bundled, vague or silent about marketing by text. Plain text matching looks for unsubscribe or opt-out references in any marketing content the scan can reach without signing in, such as a public web copy of a newsletter.
Because the model reads wording, this check is marked ai-assisted. The page elements and the quoted sentences are evidence. The reading of the wording is a lead for a person to look at, and the report says which is which.
The scan has limits, and the report says so. It does not sign up, submit a form or read any email your business sends, so it cannot see whether an email carries an unsubscribe link, whether a stop request was acted on, or where an address came from. Those are the facts the ICO’s cases turn on, and they sit in your mail system and your records. The scan sees the public pages it visited and nothing behind a sign-in. It does not read your contracts. A Passed means the expected wording was observed on the pages scanned. It does not say the sending complies.
The US sibling, US-14, uses the same passive method for the American email rules. This article states the UK rule and its cases.
Why it matters for a company
The ICO’s published cases show what it looks at, and much of it starts with a sign-up. In HelloFresh, the ICO’s enforcement page describes an opt-in statement that did not refer to marketing by text and was bundled with an age confirmation statement that the ICO said was likely to unfairly incentivise customers to agree. It also records that customers were not told their data would be used for marketing for up to 24 months after cancelling. Each of those points is visible in the wording of a form. The penalty was £140,000 for about 79 million emails and 1 million texts over seven months.
ZMLUK turned on a sign-up on a third party’s website. The ICO’s January 2026 release says people were shown 361 partner companies and could not choose among them, so the consent was not specific or informed. The same release records Allay Claims, where the company failed to offer a simple way to refuse when details were collected and could not rely on the soft opt-in. The fines were £105,000 and £120,000.
Consent wording is evidence the ICO can read from outside, and the volumes in these cases are large because one list produces many messages. The rule also reaches whoever instigates the sending, so an agency or a bought list does not move the responsibility elsewhere.
Smaller companies and larger companies
The rules have no size threshold. A one-person shop that emails its customers and a national brand are asked the same questions.
In a small company the list often grows by accident. A web form plugin adds every customer who checks out, a box is pre-ticked by default, or a spreadsheet of old contacts is imported into a mailing tool. The soft opt-in is relied on without anyone checking that the sale, the similar products and the refusal option were all in place. Two of the cases here involve smaller companies. They show that the ICO pursues companies of that size when the volumes are high. In Allay’s case it records more than 46,000 reports through the 7726 service.
In a larger company there are many forms and many senders. One brand’s checkout, a competition page, an app and a partner’s landing page each collect addresses with different wording. Consent has to be recorded per purpose and per channel, and the HelloFresh decision shows that a mismatch between what the form said (email) and what was sent (texts) is something the ICO notices. Retention is a second issue: marketing to former customers months later needs the form to have said so.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Grocery Delivery E-Services UK Ltd (HelloFresh)
The ICO's enforcement page records a seven-month campaign of about 79 million emails and 1 million texts. It says the opt-in statement did not mention marketing by text and was bundled with an age confirmation, that the opt-in was bundled with an age confirmation statement which the ICO said was likely to unfairly incentivise customers to agree, and that customers were not told their data would be used for marketing for up to 24 months after they cancelled.
Read the ICO (United Kingdom) publication about Grocery Delivery E-Services UK Ltd (HelloFresh)
Smaller companies
ZMLUK Limited
The ICO found that the Bristol company sent 67,772,285 marketing emails between January and July 2023 using data from a third-party website. People signing up there saw a list of 361 partner companies with no way to choose which could contact them, so the ICO treated the consent as not specific or informed. The penalty notice is dated 11 December 2025 and the ICO announced it in January 2026.
Read the ICO (United Kingdom) publication about ZMLUK LimitedAllay Claims Ltd
The ICO found that the Newcastle-upon-Tyne company sent 4,046,947 marketing texts between February 2023 and February 2024 promoting PPI tax refund services. The messages lacked valid consent, no simple way to refuse was offered when details were collected, and the soft opt-in did not apply.
Read the ICO (United Kingdom) publication about Allay Claims Ltd
How to fix it
These steps follow the ICO’s guidance on pre-ticked boxes, bought-in lists, identity and opt-out. What your lawyer needs to confirm is whether the soft opt-in applies to a given list.
- List every place a person can join. Check the footer, checkout, account sign-up, competition pages, pop-ups and the contact form. Write down the exact sentence beside each one.
- Make consent an empty box or a button. Remove any pre-ticked marketing box. Keep marketing consent separate from terms, age confirmations and other statements.
- Say what people are joining. Name your business, say whether you will send email, texts or both, and give each channel its own wording or its own box.
- Avoid pushing people towards yes. Keep marketing consent separate from other statements, and do not tie it to anything that pushes people to agree.
- Say how long marketing continues after someone leaves. If you keep marketing to former customers, the form should say so at the start.
- Put the stop option in every message and on the page. The footer link, the reply route and the address people can write to must all work, and your privacy notice should say how to stop messages.
- Check where your list came from. Only use a bought-in list if the consent named your business. Keep a record of when, where and with what wording each person said yes.
- Re-scan. Run a scan again once the forms are updated. Findings about vague or bundled consent wording and missing unsubscribe references should clear.
<label>
<input type="checkbox" name="marketing_email" value="yes">
Send me news and offers from Example Ltd by email.
</label>
<p>You can unsubscribe at any time using the link in every email.</p>
The sample is an empty box with a named sender and a stop route. Whether a particular list can rely on it is a question for your legal adviser, and Peeky reports only what it sees.
Questions
Do you need consent to send marketing emails in the UK?
Yes, for emails and texts to individuals, unless the soft opt-in applies. Regulation 22(2) says a person must not send unsolicited direct marketing by electronic mail unless the recipient has previously notified the sender that they consent.
The ICO's guidance puts it directly: you must not send marketing emails or texts to individuals without specific consent.
What is the soft opt-in?
It lets a business email its own customers about similar products or services without fresh consent. Three things must be true under regulation 22(3): the address was collected during a sale or negotiations for a sale, the marketing is for similar products and services only, and the person was offered a simple, free way to refuse when the address was collected and in every later message. The ICO says it does not cover new contacts from bought-in lists.
What do the PECR regulations say about unsubscribe links?
Regulation 23 bans marketing email that conceals the sender's identity or has no valid address for stopping messages. The ICO says you should make it easy to reply or click a clear unsubscribe link. Under the soft opt-in, the refusal option must be repeated in every message.
Are pre-ticked boxes allowed for email marketing sign-ups?
No. The ICO says you must not use pre-ticked opt-in boxes, silence or inactivity as evidence of consent. Consent needs a clear affirmative action, such as a person ticking an empty box.
How big can PECR fines be now?
Since 5 February 2026 the ceiling follows the Data Protection Act 2018. Schedule 13 to the Data (Use and Access) Act 2025 applies those penalty provisions to PECR, and section 157 sets the higher maximum at £17,500,000 or 4% of worldwide turnover, whichever is higher. The fines listed on this page were announced before that date.
Filed with
The rule
Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426), regs. 22 and 23
Read the rule (Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426), regs. 22 and 23)A case
Grocery Delivery E-Services UK Ltd (HelloFresh)
Read the decision (Grocery Delivery E-Services UK Ltd (HelloFresh))Sources
- Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22 (as amended, in force)
- Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 23
- Data (Use and Access) Act 2025, Schedule 13: PECR enforcement powers (commenced 5 February 2026 by SI 2026/82)
- Data Protection Act 2018, section 157: maximum amount of penalty
- ICO, Electronic mail marketing (guide to PECR)
- ICO, How do we comply with the PECR electronic mail marketing rules?
- ICO, PECR guide: what's new (guidance under review after the Data (Use and Access) Act)
- ICO, enforcement action: Grocery Delivery E-Services UK Ltd t/a HelloFresh, 12 January 2024
- ICO, Fines of £225,000 for nuisance marketing messages, 20 January 2026 (Allay Claims Ltd and ZMLUK Limited)
- ICO, enforcement action: Allay Claims Ltd, penalty notice of 15 January 2026
- ICO, enforcement action: ZMLUK Limited, penalty of 11 December 2025
Last checked against the source:
For information only. Not legal advice.


