News & Insights

Do I Need Consent to Send Marketing to my Contacts?

April 2021

  • Data Privacy & Cyber Security
  • Reputation Management

One of the common misconceptions about direct marketing is that you always need express consent before sending marketing to customers, clients or other contacts. That is not necessarily the case.

Whether consent is required depends on who you are contacting, how you are contacting them and the type of marketing you are sending. You also need to consider both the Privacy and Electronic Communications Regulations 2003 (PECR) and UK data protection law.

This article provides an overview of the key rules businesses should consider when sending direct marketing.

What is direct marketing?

Direct marketing generally means communicating advertising or marketing material to particular individuals or organisations.

It can include marketing by:

  • email;
  • text message;
  • telephone;
  • post; and
  • other electronic messages, including certain direct messages via social media.

Not every communication with a customer is direct marketing. For example, genuine customer service messages or communications about an existing contract will not generally constitute direct marketing, provided they do not include promotional material.

Which laws apply?

There are two main sets of rules to consider:

  1. The Privacy and Electronic Communications Regulations 2003 (PECR); and
  2. UK data protection law,

    including the UK GDPR and Data Protection Act 2018.

 

PECR sets specific rules for certain types of electronic and telephone marketing. Where you are processing personal data as part of your marketing activities, you must also comply with data protection law.

The rules differ depending on whether you are marketing to an individual or a corporate subscriber. Sole traders and some partnerships are treated as individuals for these purposes, while companies and LLPs are generally treated as corporate subscribers.

Email and text marketing

The general rule is that you cannot send unsolicited marketing emails or text messages to individuals unless:

  • they have given valid consent; or
  • you can rely on the soft opt-in.

Consent must be freely given, specific, informed and unambiguous, and must involve a clear positive action. Pre-ticked boxes, silence or inactivity will not constitute valid consent.

The soft opt-in

The soft opt-in is a limited exception which allows businesses to send electronic marketing to existing or prospective customers without obtaining consent, provided certain conditions are met.

For the soft opt-in to apply:

  • you must have obtained the individual’s contact details directly from them;
  • you must have obtained those details while selling or negotiating to sell a product or service;
  • the marketing must relate to your own similar products or services;
  • the individual must have been given a clear opportunity to opt out when their details were collected; and
  • every subsequent marketing message must provide an opportunity to opt out.

The soft opt-in does not apply to bought-in marketing lists or contact details obtained from a third party.

There is also a separate soft opt-in for certain charitable purposes, introduced by the Data (Use and Access) Act 2025, subject to specific conditions.

Marketing to companies

PECR generally allows unsolicited marketing emails and texts to be sent to corporate subscribers without consent.

However, this does not mean that businesses can disregard data protection law. If personal data relating to individual employees or other contacts is being processed, you will still need to comply with the UK GDPR and Data Protection Act 2018.

You must also identify yourself and provide a valid means for recipients to opt out of future marketing.

Telephone marketing

The rules are different for telephone marketing.

Live marketing calls

Generally, you can make live marketing calls provided that you:

  • screen numbers against the Telephone Preference Service (TPS) and, where relevant, the Corporate Telephone Preference Service (CTPS);
  • do not call anyone who has previously told you not to contact them;
  • identify yourself;
  • allow your number to be displayed; and
  • provide appropriate contact details.

You should therefore maintain your own “do not call” list as well as screening against the TPS and CTPS.

Automated calls

The rules for automated marketing calls are stricter.

You must have specific consent before making an automated marketing call. General consent to receive marketing, or consent to receive live telephone calls, is not sufficient.

What does data protection law require?

PECR is only part of the picture.

Where your marketing involves processing personal data, you must also identify a lawful basis under UK data protection law. The two lawful bases most likely to be relevant to direct marketing are:

  • consent; and
  • legitimate interests.

The appropriate lawful basis will depend on the circumstances.

Consent

Where consent is required under PECR, you will generally also need consent as your lawful basis under data protection law.

Consent must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous; and
  • given through a clear affirmative action.

Individuals must also be able to withdraw their consent easily.

Legitimate interests

Where PECR does not require consent, legitimate interests may be an appropriate lawful basis for processing personal data for direct marketing.

However, this should not be treated as an automatic exemption from consent. You must consider whether:

  1. you have a legitimate interest;
  2. the processing is necessary to achieve that interest; and
  3. your interests are not overridden by the individual’s interests, rights or freedoms.

This is commonly referred to as the three-part test.

Direct marketing can constitute a legitimate interest, but organisations must still consider the particular circumstances and the reasonable expectations of the people being contacted.

What else should businesses consider?

Even where you do not need consent to send a particular marketing communication, there are other data protection obligations to consider.

For example, businesses should ensure that:

  • individuals are told how their personal data will be used, usually through an appropriate privacy notice;
  • personal data is accurate and kept up to date;
  • individuals can exercise their data protection rights;
  • marketing preferences are recorded accurately;
  • consent, where relied upon, can be evidenced; and
  • individuals’ objections to direct marketing are respected.

Importantly, individuals have an absolute right to object to the use of their personal data for direct marketing. If someone objects, you must stop using their personal data for direct marketing purposes.

At a glance

This table is a general guide only. The rules can vary depending on the circumstances, the recipient, the type of marketing and the data being processed.

Key takeaway

You do not always need consent to send marketing.

However, businesses should consider PECR and data protection law together before contacting customers, clients or other contacts. In particular, you should establish:

  • who you are contacting;
  • what type of communication you are sending;
  • whether the recipient is an individual or corporate subscriber;
  • whether PECR requires consent;
  • whether a soft opt-in applies;
  • what lawful basis you are relying on under data protection law; and
  • how you will record and respect marketing preferences and objections.

Let’s talk.

If you need advice on direct marketing, PECR or your data protection obligations, please contact our Data Protection and Privacy Team.

Rachelle Sellek

Rachelle Sellek

Senior Partner and Compliance Officer

+44 (0)7867 987 927 [email protected]