Privacy and Electronic Communications Regulations
PECR are UK regulations that set rules on electronic marketing, the use of cookies and similar technologies, and the privacy of electronic communications. They sit alongside data protection law and cover things like marketing by phone, email, or text, as well as placing cookies on a user's device. In the UK, PECR are regulated and enforced by the Information Commissioner's Office (ICO).
The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) are the UK's implementation of the EU ePrivacy Directive, governing matters including the placing of and access to information stored on a user's terminal equipment (such as cookies and similar technologies), unsolicited electronic direct marketing (by phone, fax, email, text, or other electronic message), and aspects of the security and confidentiality of electronic communications services. PECR operate alongside, and are distinct from, the general data protection regime (the UK GDPR and Data Protection Act 2018): PECR's cookie provisions generally regulate the act of storing or accessing information on a device, while any subsequent processing of personal data engages data protection law. Where PECR requires consent, the applicable standard is generally read against the data protection definition of consent. The regulations apply within the UK and are enforced by the ICO; equivalent requirements in EU Member States derive from national implementations of the ePrivacy Directive rather than from PECR itself. The precise scope, exemptions, and enforcement positions are set by the regulations, later amendments, and evolving ICO guidance, which are out of scope for this definition.
Why it matters
PECR are central to how cookie consent and electronic marketing are regulated in the UK. Because they govern the act of storing or accessing information on a user's device, PECR are the primary source of the UK's cookie consent requirements, sitting alongside the UK GDPR rather than being replaced by it. Organisations that operate websites or run marketing programmes reaching UK users generally need to consider PECR whenever they deploy cookies or similar technologies, or send electronic marketing by phone, email, or text.
A common source of compliance confusion is the relationship between PECR and data protection law. PECR's cookie provisions generally regulate the placing of and access to information on a device, while any subsequent processing of the personal data collected engages the UK GDPR and the Data Protection Act 2018. Where PECR requires consent, that consent is generally read against the data protection definition, meaning it typically needs to be freely given, specific, informed, and unambiguous. Treating a single consent mechanism as satisfying only one of these regimes can leave gaps in compliance.
PECR are enforced in the UK by the Information Commissioner's Office (ICO). It is important not to assume that PECR apply outside the UK: while PECR implement the EU ePrivacy Directive, equivalent obligations in EU Member States derive from their own national implementations of that directive rather than from PECR itself. The precise scope, exemptions, and enforcement positions depend on the regulations, later amendments, and evolving ICO guidance, so organisations should treat PECR as one part of a broader, jurisdiction-specific compliance picture rather than a universal standard.
Who it's relevant to
Inside PECR
Common questions
Answers to the questions practitioners most commonly ask about PECR.
