Guide

PECR and Email Marketing: When You Can and Cannot Send

A scenario-by-scenario guide to when PECR actually lets you send a marketing email, cold prospects, existing customers, purchased lists, referrals, and where the line sits for each.

Published September 4, 2026·Last updated September 4, 2026

Most PECR email marketing questions aren’t abstract, they’re “can I email this specific list.” Rather than repeating the general opt-in rule, here’s a scenario-by-scenario breakdown of the situations that come up most, and whether PECR actually lets you send.

Scenario: a cold prospect who never interacted with you

Generally no, not without prior opt-in consent. PECR requires affirmative consent before sending unsolicited marketing email to an individual subscriber, someone who’s never engaged with your business, bought from you, or explicitly signed up doesn’t have a basis for you to email them marketing content, regardless of how relevant you think the offer is.

Scenario: an existing customer who bought something from you

Often yes, under the “soft opt-in” exception, if you collected their email during a sale (or sale negotiation), you’re marketing similar products or services, and you gave them a clear opportunity to opt out both at collection and in every subsequent email. This exception has specific conditions that are easy to get wrong, we cover it in full in our dedicated soft opt-in guide. Marketing a genuinely unrelated product or service to that same customer falls outside the exception and needs separate consent.

Scenario: someone who filled out a “contact us” or quote-request form

No, not automatically. Submitting a contact form is consent to be contacted about that specific inquiry, it is not marketing consent. Adding that person to your newsletter list because they asked a question needs a separate, clearly presented opt-in at the point of collection.

Scenario: a purchased or rented email list

Almost never compliant. PECR’s consent requirement is specific to the sender, consent given to a list broker or a different company doesn’t transfer to you. A purchased list essentially never carries valid consent for you to send marketing under PECR, this is one of the more consistently enforcement-flagged practices.

Scenario: a referral, someone gave you a friend’s email address

No. The person who received the referral (the friend) never consented to anything, the referring customer’s permission to share the contact isn’t the same as the recipient’s consent to receive marketing. “Refer a friend” schemes need to be structured so the friend is invited to opt in themselves, not automatically added to a marketing list.

Scenario: B2B outreach to a named individual at a company

More flexible, but not unlimited. PECR treats “corporate subscribers”, generic addresses like info@company.com, differently from named individuals, jane.smith@company.com still belongs to an identifiable person and generally needs the same opt-in treatment PECR requires for individuals, though in practice enforcement against relevant, well-targeted B2B outreach has been lighter than consumer spam. GDPR’s separate lawful-basis question for this scenario is covered in our B2B data guide.

Our recommendation

Enzuzo

Because the compliant answer changes based on exactly how and where an email address was collected, the practical fix is tagging every contact with its collection source and consent basis at the point of capture. Enzuzo's consent dashboard is built to keep that source-and-basis record intact as your list grows.

Try Enzuzo

The requirement that applies no matter which scenario got you there

Regardless of which basis applies, every marketing email needs a working unsubscribe mechanism, and you need to honor unsubscribe requests going forward without exception. A soft-opt-in or existing consent doesn’t survive an unsubscribe request.

What to do if you’re not sure how a specific contact ended up on your list

Treat unknown-provenance contacts as requiring fresh opt-in before marketing to them, rather than assuming a historical justification exists that you can no longer verify. For the general mechanics of what a compliant opt-in checkbox and disclosure need to look like, see our broader GDPR and PECR email marketing guide.

This guide is educational and not legal advice. Consult a privacy attorney for how PECR applies to your specific email lists and their collection history.