The GDPR email marketing rules in plain English
You can absolutely email your customers, and you should. The fear of getting the rules wrong stops a lot of good firms doing it at all, so here are the actual rules, laid out so you can check your own list against them.
The short answer
The email marketing rules are in PECR, not GDPR. To email individuals, sole traders or ordinary partnerships with marketing, you need their consent, or you must pass every part of the soft opt-in: you collected the address yourself during a sale or genuine negotiations for one, you only market your own similar products or services, and you offered an opt-out when you took the details and in every message since. Limited companies can be emailed without consent, but you must still say who you are and give a working opt-out, and a named employee's details remain personal data under UK GDPR. The steps below sort your list into shape.
The rules live in PECR, not GDPR
There's a nervousness around this that I see a lot. You've heard of GDPR, you've heard the fines are eye-watering, and you're not sure whether emailing your own customers is allowed, so you play it safe and don't. Or you go the other way, buy a list from somewhere, and email everyone you've ever had an address for, which is the version that actually lands people in trouble.
The bit almost nobody mentions is that GDPR isn't the law with the email marketing rules in it. Those live in PECR, the Privacy and Electronic Communications Regulations 2003. PECR decides whether you may send the message at all; UK GDPR governs the personal data underneath, the names and addresses on your list. You need both: a lawful route under PECR to press send, and a lawful basis under UK GDPR for holding and using the data. The ICO enforces both, and it updated its electronic mail marketing guidance on 28 April 2026, so this page follows the current version.
Two scope points before the steps. 'Electronic mail' in PECR covers more than email: texts, voicemails, in-app messages and private messages on social media all count, so a promotional text plays by the same rules as a newsletter. And 'marketing' means anything promotional. A plain order confirmation or appointment reminder is a service message and isn't covered, but add an offer to the bottom of one and it becomes marketing.
One caveat: I'm an engineer, not a solicitor, so treat this as good practice laid out plainly, not legal advice.
1. Sort your list into individuals and companies
PECR splits recipients into two kinds of subscriber, and everything follows from which one you're emailing. Individual subscribers are people at their own addresses, plus sole traders and ordinary (non-LLP) partnerships. They get the full protection: consent or the soft opt-in, nothing less. Corporate subscribers are bodies with their own legal personality, chiefly limited companies, LLPs and Scottish partnerships, and PECR's consent rule for electronic mail doesn't apply to them. You can email a contact at a limited company about your services without consent, provided you identify yourself and give a way to opt out.
Two catches. A named employee's work address is still that person's personal data, so UK GDPR applies to it: you need a lawful basis, you must tell people what you're doing with their details, and they have an absolute right to object. If a contact at a company says stop, you stop. And you often can't tell what an address is. [email protected] could be a limited company or a sole trader, and the ICO's advice when you're unsure is to treat the address as an individual subscriber and follow the stricter rules; a Companies House search settles most of them.
So the first job is a sorting exercise. Tag every address on your list as one of three things: individual (including sole traders and ordinary partnerships), verified limited company, or unknown. Unknowns get treated as individuals.
2. Check each individual address against the two lawful routes
Every address in the individual pile needs one of two things. Route one is consent: they actively agreed to marketing emails from you, by ticking a box or saying so. PECR borrows its standard of consent from UK GDPR, so it must be freely given, specific, informed and unambiguous. Pre-ticked boxes don't count, silence doesn't count, and 'by submitting your order you agree to receive our marketing emails' doesn't count either, because consent bundled into the sale isn't freely given. You also need a record of who consented, when and how; consent you can't evidence is consent you don't have.
Route two is the soft opt-in, and it's what makes emailing past customers lawful. It only works when all of the following are true. You collected their details yourself, directly from them, not through a third party or even a sister company. You collected them while selling to them or negotiating a sale, which includes a quote request, a purchase enquiry or a free-trial sign-up, but not someone merely browsing your site. You're only marketing your own similar products and services, the sort they'd reasonably expect given what they bought or asked about, and never anyone else's. You gave them a clear chance to opt out at the moment you collected the details. And you've given them that chance in every message since.
Fail any one of those and the soft opt-in fails; 'they're an existing customer' is not, on its own, a lawful route. Two useful exceptions: if someone specifically asks you to send a particular thing (your price list, say), that message is solicited and needs neither route, and genuine service messages aren't marketing at all, as long as you keep promotions out of them. Charities get a separate soft opt-in for messages that further their charitable purposes, added on 5 February 2026 with its own conditions, and they can't use the products-and-services one for fundraising asks.
3. Bin anything you bought, borrowed or scraped
Bought lists are where firms actually get into trouble. The soft opt-in can never apply to one, because you didn't collect the details yourself; the ICO puts it flatly: there is no such thing as a third-party marketing list that is soft opt-in compliant, whatever the broker's paperwork claims. That leaves consent, and for consent on a bought list to be valid the people on it must have agreed to marketing from your organisation by name (not 'trusted partners' or 'selected third parties'), covering email specifically, and the seller must show you records of who consented, when and how. In practice almost no list for sale clears that bar.
Addresses found on websites or social media profiles are no better. Publicly available doesn't mean consented, and if the address identifies a person, collecting it is itself processing personal data under UK GDPR. Refer-a-friend schemes have the same flaw: if you push customers to forward your marketing, you're the instigator of those messages and you'd need the friend's consent, which you can't demonstrate. If parts of your list arrived by any of these routes, take them out before the next send.
4. Fix your sign-up points so new addresses qualify
Now stop the problem regrowing. Walk through every place you collect an email address (checkout, enquiry form, the counter, the phone) and make each one do one of two things properly. Where you want consent, use an unticked box with plain wording, kept separate from your terms and conditions. Where you'll rely on the soft opt-in with buyers, offer the opt-out at the point you take the details, prominently. Hiding it in the privacy policy fails, and so does mentioning it afterwards in the order confirmation; the ICO says an opt-out offered only after collection means any further marketing breaches PECR. Wording along these lines does the job (the first is a consent ask, the second a soft opt-in opt-out):
Then record what happened. The ICO suggests a simple set of flags or preference fields in your system showing which route applies to each person; for consent, the record needs the who, the when and the how. A column in the CRM or customer spreadsheet is enough, and it's exactly what you'd produce if anyone ever complained. Staff taking details by phone should offer the same choice out loud and note the answer.
☐ I'd like to receive marketing emails from you about your products and services.
☐ We'd like to email you about our own similar products and offers.
Tick here if you'd rather we didn't.
5. Say who you are and give a way out in every send
Two rules apply to every marketing email, whoever the recipient is, individual or company. You must not disguise or hide who the message is from, and you must include a valid contact address the recipient can use to opt out. In practice: the email names your business, and it carries an unsubscribe that actually works. The ICO's own good-practice example is one footer line:
Keep the way out genuinely simple. A clear link or a straight reply is fine; making people ring up and quote a membership number is not, and neither is requiring them to create or log into an account to change preferences. If your newsletter tool adds the unsubscribe automatically, send yourself a test and click it.
If you no longer want to receive these emails from us, please click here to unsubscribe.
6. Handle unsubscribes with a suppression list, not the delete key
When someone unsubscribes, the instinct is to delete them. Don't. Delete the address and it will creep back the next time you rebuild your list from an old export or a re-imported spreadsheet, and then you're marketing to someone who told you to stop. The ICO's model is a suppression list, a 'do not contact' list you deliberately keep the address on, so every future send and every import can be screened against it.
So the routine is: act on the unsubscribe promptly, move the address to suppression rather than removing it, and check new imports against that list before anything goes out. Keep the suppressed status inside whatever tool you send from as well as in your own records, and never delete contacts from the tool and re-import them around it. You may send one automatic bounce-back confirming the unsubscribe and explaining how to opt back in, but after that the next marketing email they get from you should be because they actively consented again. And the right to object under UK GDPR is absolute; it covers named contacts at limited companies too, and there are no grounds to refuse.
Where this gets hard
The genuinely awkward part is the historic list. The soft opt-in requires that you offered an opt-out at the moment you collected each address, and most small firms never did, so years of past customers can fail the test even though they're exactly the people who'd welcome your emails. What to do with them is a risk judgement: write them off, or run a careful re-permission exercise, remembering that PECR's definition of marketing is broad and I'd treat a 'can we email you?' message as marketing in its own right, so it needs a lawful route too.
Provenance is the other wall. After a few CRM migrations, staff exports and that merged spreadsheet from a trade show, nobody can say where half the addresses came from, and every question the law asks is about origin: did you collect it, during what, and what was the person told. Sometimes order history and old copies of your web forms let you reconstruct it. Sometimes they don't, and the honest answer is to treat those addresses as failing.
And the edge cases stack up: the sole trader behind a corporate-looking domain, the partnership that incorporated halfway through your relationship with them, the promotion that crept into a service message. Each one is decidable on its own; across a few thousand rows they're what defeats the DIY attempt, and where it's genuinely ambiguous, that's a question for a solicitor rather than a guide.
What you end up with
- Your list sorted into individuals, companies and unknowns, with unknowns treated as individuals
- Consent recorded properly, so you can show who agreed to what and when
- The soft opt-in met in full, so emailing past customers is actually lawful
- Unsubscribes held on a suppression list, never accidentally re-imported
Facts on this page last checked 14 July 2026, against ico.org.uk.
Related fixes
If your list has years of history and no paper trail, untangling which addresses you can lawfully email is exactly the sort of job I help with.