PECR and marketing email signatures

The UK's electronic marketing rules require clear sender identification and a working opt-out on marketing email - and they turn on whether a message is marketing, not on where in it the opt-out sits.

The UK Privacy and Electronic Communications Regulations (PECR), sitting alongside UK GDPR, require that marketing email clearly identify the sender and offer a simple way to opt out, with no exception for small businesses or B2B recipients. A narrow 'soft opt-in' lets a company market similar products to its own existing customers without prior consent, provided every message still offers an opt-out.

Who this applies to

PECR implements the EU ePrivacy Directive (2002/58/EC, Article 13) in UK law and governs electronic marketing communications, including marketing email, alongside cookies and other electronic communications. It applies to unsolicited marketing email sent to any UK recipient, individual or business, sent by any organization, however small or infrequent its sending.

What it actually requires

Consent before sending, unless the soft opt-in applies
Marketing email generally requires the recipient's prior consent. The recognized exception is the 'soft opt-in': a company can email its own existing customers about similar products or services without fresh consent, provided it collected the contact detail in the course of a sale or negotiation, and offered an opt-out at collection and in every message since.
A simple, working opt-out in every message
Every marketing message needs a clear way to refuse further marketing - the ICO's guidance says an opt-out link buried inside a privacy policy is not a simple way to refuse. The recipient must be able to opt out at any time, and the sender must stop promptly once they do.
Clear identification of the sender
The organization sending the marketing message must be clearly identifiable - a recipient should not have to guess who is emailing them or hunt for the sending company behind a personal name or a generic address.
No exception for B2B or for small or infrequent senders
The ICO is explicit that there is no exemption from the opt-out requirement for small businesses, for infrequent senders, or for B2B email sent to a named individual - the same core rules apply regardless of company size or sending volume.

Myths we hear often

The myth

PECR only applies to consumer marketing, not B2B email.

What the source actually says

PECR's marketing rules apply to marketing email generally, including messages sent to named individuals at a business address - the ICO's own guidance does not carve out a blanket B2B exception the way some read GDPR's legitimate-interests provisions.

The myth

An unsubscribe link anywhere in the privacy policy satisfies the opt-out requirement.

What the source actually says

The ICO specifically warns that an opt-out hidden inside a privacy policy is not a simple way for people to refuse marketing - the mechanism needs to be visible and usable in the message itself, not buried in a linked document.

The myth

Once someone is a customer, a company can market anything to them without asking again.

What the source actually says

The soft opt-in exception is narrower than that: it covers similar products or services to the ones the customer already bought, the contact detail has to have been collected during that sale, and every message still needs its own opt-out - it is not a blanket license to market anything to anyone who has ever bought something.

A worked example

A fictional example: Thistlewood Print Supplies
Thistlewood Print Supplies, a fictional B2B stationery wholesaler, emails its existing account customers about a new range of recycled paper stock similar to what they already buy - it relies on the soft opt-in, since it collected each customer's email during an actual sale and gave them an opt-out at the time. Each promotional email carries a clear 'Thistlewood Print Supplies' sender name and a one-click unsubscribe link in the message body itself, not just a reference to the privacy policy; a customer who unsubscribes is removed from that list before the next send.

Questions people ask

Does PECR apply to B2B marketing email in the UK?

Generally yes - the ICO's guidance on the PECR electronic mail marketing rules does not exempt B2B messages sent to a named individual, and the same opt-out and identification requirements apply.

What is the PECR "soft opt-in" exception?

It lets a company market similar products or services to its own existing customers without asking for fresh consent, provided the contact detail was collected in the course of a sale or negotiation and every message offers a simple opt-out - it does not cover contacts bought or gathered from other sources.

Is an unsubscribe link in my email signature enough for PECR?

A working, visible opt-out is required on marketing messages, wherever it sits in the message - the ICO's concern is that it be simple and not buried, not that it live in any one specific place. Whether a given placement counts as simple enough is worth checking against current ICO guidance rather than assumed.

Put your own details on every signature you send

Signatoro puts your name, title and contact details on every signature, free for one person. From the Up to 15 plan, a company adds one compliance footnote to everyone's signature.

Other pages in this series

Sources