Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Laws and Regulations

Privacy and Electronic Communications Regulations

Also known as: PECR, The Privacy and Electronic Communications (EC Directive) Regulations 2003
Simply put

PECR are UK regulations that set rules on electronic marketing, the use of cookies and similar technologies, and the privacy of electronic communications. They sit alongside data protection law and cover things like marketing by phone, email, or text, as well as placing cookies on a user's device. In the UK, PECR are regulated and enforced by the Information Commissioner's Office (ICO).

Formal definition

The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) are the UK's implementation of the EU ePrivacy Directive, governing matters including the placing of and access to information stored on a user's terminal equipment (such as cookies and similar technologies), unsolicited electronic direct marketing (by phone, fax, email, text, or other electronic message), and aspects of the security and confidentiality of electronic communications services. PECR operate alongside, and are distinct from, the general data protection regime (the UK GDPR and Data Protection Act 2018): PECR's cookie provisions generally regulate the act of storing or accessing information on a device, while any subsequent processing of personal data engages data protection law. Where PECR requires consent, the applicable standard is generally read against the data protection definition of consent. The regulations apply within the UK and are enforced by the ICO; equivalent requirements in EU Member States derive from national implementations of the ePrivacy Directive rather than from PECR itself. The precise scope, exemptions, and enforcement positions are set by the regulations, later amendments, and evolving ICO guidance, which are out of scope for this definition.

Why it matters

PECR are central to how cookie consent and electronic marketing are regulated in the UK. Because they govern the act of storing or accessing information on a user's device, PECR are the primary source of the UK's cookie consent requirements, sitting alongside the UK GDPR rather than being replaced by it. Organisations that operate websites or run marketing programmes reaching UK users generally need to consider PECR whenever they deploy cookies or similar technologies, or send electronic marketing by phone, email, or text.

A common source of compliance confusion is the relationship between PECR and data protection law. PECR's cookie provisions generally regulate the placing of and access to information on a device, while any subsequent processing of the personal data collected engages the UK GDPR and the Data Protection Act 2018. Where PECR requires consent, that consent is generally read against the data protection definition, meaning it typically needs to be freely given, specific, informed, and unambiguous. Treating a single consent mechanism as satisfying only one of these regimes can leave gaps in compliance.

PECR are enforced in the UK by the Information Commissioner's Office (ICO). It is important not to assume that PECR apply outside the UK: while PECR implement the EU ePrivacy Directive, equivalent obligations in EU Member States derive from their own national implementations of that directive rather than from PECR itself. The precise scope, exemptions, and enforcement positions depend on the regulations, later amendments, and evolving ICO guidance, so organisations should treat PECR as one part of a broader, jurisdiction-specific compliance picture rather than a universal standard.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance in organisations reaching UK users need to understand how PECR interacts with the UK GDPR and Data Protection Act 2018, particularly the distinction between placing or accessing information on a device and the subsequent processing of personal data. They should be careful not to treat consent under one regime as automatically satisfying the other.
Marketing and compliance teams
Teams running electronic marketing by phone, fax, email, or text should be aware that PECR restricts unsolicited marketing and applies different rules to different channels. Understanding these channel-specific requirements is generally necessary before launching campaigns aimed at UK recipients.
Web developers and CMP implementers
Those deploying cookies and similar technologies on UK-facing sites need to account for PECR's rules on storing and accessing information on a user's device. Consent management tools can support compliance, but they do not replace legal judgment about whether a given implementation meets the applicable requirements.
Legal counsel advising on UK operations
Counsel should treat PECR as UK-specific and enforced by the ICO, and should not assume it applies to EU Member States, where equivalent obligations derive from national implementations of the ePrivacy Directive. Because scope, exemptions, and enforcement positions evolve through amendments and ICO guidance, advice should be grounded in the current regulations and guidance rather than general assumptions.

Inside PECR

Full title and status
PECR stands for the Privacy and Electronic Communications Regulations, the UK implementation of the EU ePrivacy Directive. It sits alongside the UK GDPR rather than replacing it, and continues to apply in the UK following its departure from the EU.
Cookie and similar technology rules
PECR governs the storing of information on, and gaining of access to information stored on, a user's terminal equipment. This covers not only cookies but similar technologies such as pixels, local storage, SDKs, and device fingerprinting, which fall within the same rules even though they are not literally cookies.
Consent requirement and its exemption
PECR generally requires prior consent before non-essential cookies or similar technologies are placed or accessed. Cookies that are strictly necessary to provide a service explicitly requested by the user are typically exempt, whereas analytics, advertising, and functional cookies typically require consent.
Relationship to the UK GDPR consent standard
Where consent is required under PECR, the standard of consent is generally understood to align with the UK GDPR: it should be freely given, specific, informed, and unambiguous, requiring a clear affirmative action. PECR governs the placing of and access to information on the device, while the UK GDPR governs any subsequent processing of personal data.
Wider electronic marketing provisions
Beyond cookies, PECR also addresses other areas of electronic communications, such as rules relating to electronic marketing by means such as email and telephone. These provisions are distinct from the cookie rules but form part of the same regulatory instrument.
Supervisory authority
PECR is overseen by the UK's data protection authority, which issues guidance on how the rules are interpreted and enforced. Enforcement positions and guidance may evolve over time.

Common questions

Answers to the questions practitioners most commonly ask about PECR.

Does PECR replace or override the GDPR for cookies?
No. PECR (the Privacy and Electronic Communications Regulations) sits alongside the UK GDPR rather than replacing it. In the UK, PECR governs the rules on storing or accessing information on a user's device (such as cookies and similar technologies), while the UK GDPR governs any subsequent processing of personal data. Where PECR requires consent, it generally borrows the UK GDPR standard of consent, but the two operate together and complying with one does not automatically satisfy the other. Each has its own scope and its own supervisory considerations.
Do all cookies require consent under PECR?
Not all. PECR generally requires prior consent before storing or accessing information on a user's device, but it provides an exemption for cookies that are strictly necessary to provide a service explicitly requested by the user, and for those used solely to carry out or facilitate a communication. Cookies typically used for analytics, advertising, and many functional purposes generally fall outside this exemption and require consent. The exemption is narrow, and whether a given cookie qualifies depends on its specific purpose rather than how it is labelled.
What standard of consent does PECR expect for non-exempt cookies?
PECR relies on the consent standard drawn from the UK GDPR, which generally means consent must be freely given, specific, informed, and unambiguous, requiring a clear affirmative action. In practice this means approaches such as pre-ticked boxes or inferring consent from continued browsing are widely regarded as insufficient. You typically need to give users clear information about the cookies in use and a genuine choice before non-exempt cookies are set. Note that this reflects UK practice and may differ from requirements in other jurisdictions.
How does PECR apply to technologies that are not literally cookies?
PECR's rules on storing and accessing information on a user's device are technology-neutral, so they can extend beyond cookies to similar technologies such as tracking pixels, local storage, software development kits (SDKs), and device fingerprinting where these involve storing or accessing information on the user's device. The same general consent requirement and strictly necessary exemption apply. Whether a particular technology is caught depends on how it operates in a given implementation, which is a fact-specific assessment.
Who does PECR apply to, and where does it fit geographically?
PECR is a UK framework and applies to organisations operating in the relevant context within the UK. It should not be treated as universal: the EU regime rests on the ePrivacy Directive as implemented in national law, and US state laws such as the CCPA and CPRA in California take a different approach that often relies on opt-out rather than opt-in. Organisations operating across regions generally need to consider each applicable framework separately rather than assuming PECR compliance covers other jurisdictions.
How can a consent management platform support PECR compliance?
A consent management platform (CMP) can help operationalise PECR requirements by presenting cookie information, capturing user choices before non-exempt cookies are set, and maintaining records of consent. However, a CMP supports compliance rather than guaranteeing it. Its effectiveness depends on correct configuration, accurate categorisation of cookies, and ensuring non-exempt technologies do not fire before consent. Tools do not replace the legal judgment needed to assess whether a particular setup meets PECR's standards, and enforcement positions and regulatory guidance can evolve over time.

Common misconceptions

PECR is just part of the UK GDPR, so complying with one covers the other.
PECR and the UK GDPR are separate instruments addressing different things. PECR governs the placing of and access to information on a user's device, while the UK GDPR governs the processing of any personal data that follows. Meeting the requirements of one does not automatically satisfy the other.
PECR applies to the same territory and in the same way as the EU ePrivacy Directive across all of Europe.
PECR is the UK's implementation and continues to apply in the UK after its departure from the EU. Cookie consent obligations vary between the UK, the EU, and other regimes, so PECR's rules should not be treated as universal or identical to national implementations elsewhere.
PECR only concerns HTTP cookies.
The rules on storing and accessing information on a user's device extend to similar technologies, including pixels, local storage, SDKs, and fingerprinting, even though these are not literally cookies.

Best practices

Treat PECR and the UK GDPR as complementary but distinct: address the placing of and access to information on the device under PECR, and separately document a lawful basis for any resulting processing of personal data under the UK GDPR.
Classify all cookies and similar technologies (including pixels, local storage, SDKs, and fingerprinting) and identify which are strictly necessary and potentially exempt versus which typically require prior consent, such as analytics and advertising technologies.
Where consent is required, obtain it through a clear affirmative action before non-essential technologies are set, avoiding reliance on pre-ticked boxes or implied consent from continued browsing.
Provide clear and specific information to users about the technologies in use so that any consent given can be considered informed.
Consult current guidance from the UK's data protection authority when interpreting PECR, since enforcement positions and guidance may evolve, and do not assume that rules from the EU or US regimes apply unchanged in the UK.
Keep records supporting your approach to consent and use tools such as consent management platforms to assist, while recognising that such tools support compliance but do not replace legal judgment.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps