PECR and SMS, Live Chat, and Push Notifications: The Rules Beyond Email
PECR's marketing rules cover more than email, texts, automated calls, and increasingly push notifications and chat widgets all carry their own version of the same consent requirement.
Most PECR content focuses on email, understandably, since it’s the most common marketing channel and the one with the most established case law and guidance. But PECR’s rules on unsolicited electronic communications aren’t email-specific, they cover several channels, each with its own wrinkle. Here’s what applies beyond the inbox.
SMS and text marketing
PECR treats marketing text messages essentially the same as marketing email: prior consent is required, with the same soft opt-in exception available under the same four conditions covered in our soft opt-in guide. In practice, SMS marketing has drawn disproportionate ICO enforcement attention, texts are easy for recipients to complain about, and mass unsolicited SMS campaigns (loan offers, PPI claims, insurance) have historically been a top enforcement category, covered in our PECR enforcement guide. Every marketing text needs sender identification and an easy opt-out (commonly a “reply STOP” mechanism), maintained and actually honored.
Automated and live marketing calls
PECR splits phone marketing into two categories with different rules:
- Automated/recorded marketing calls require prior consent, essentially the same opt-in standard as email and SMS, with no live-call exception.
- Live marketing calls (a real person calling) are allowed without prior consent by default, but the recipient must not have registered with, or previously objected via, the Telephone Preference Service (TPS), and the caller must not have received a direct objection from that specific individual. This is a meaningfully different, opt-out-based model from the rest of PECR’s channels, and it’s easy to conflate the two call types’ rules incorrectly.
Push notifications
Push notifications sent from a mobile app or a browser (via web push APIs) aren’t explicitly named in the original 2003 text of PECR, but they function the same way a cookie does for consent purposes: they require the app or browser to have obtained the user’s permission to send them in the first place (usually through the OS or browser-level notification permission prompt), and marketing content sent through that channel is generally treated consistently with PECR’s broader intent around unsolicited electronic marketing. Practically, most platforms already gate push notification delivery behind an explicit opt-in permission prompt, which does much of this work automatically, but the marketing content sent afterward should still follow the same consent-basis logic as email or SMS rather than being treated as automatically fair game once notification permission is granted.
Live chat widgets
Live chat itself isn’t a marketing channel in the PECR sense; a user actively initiating a chat conversation isn’t “unsolicited” communication. Where PECR becomes relevant is in what the chat widget does in the background: many chat tools set cookies or collect identifiers to track visitors across sessions, log conversations, or feed data into marketing automation. That data collection is subject to the same cookie consent rule covered in our PECR and cookies guide, and any follow-up marketing messages sent after a chat interaction (an email or SMS “since you chatted with us…”) need their own valid consent basis, a chat conversation about a support question isn’t itself marketing consent, the same principle covered for contact forms in our email marketing scenarios guide.
Enzuzo
Chat widgets and push-notification SDKs are exactly the kind of embedded third-party tool that quietly sets its own cookies or identifiers outside your main analytics stack, easy to miss in a cookie inventory. Enzuzo's cookie scanning is built to catch these embedded tools, not just the tags you added deliberately.
The common thread across every channel
Whatever the medium, email, SMS, automated calls, push, or the data layer behind chat, the same underlying question applies: did the recipient give a valid, specific basis to be contacted this way, and can you actually demonstrate it if asked. Channel-specific mechanics differ, but the standard underneath doesn’t.
This guide is educational and not legal advice. Consult a privacy attorney for how PECR applies to your specific marketing channels and tools.