Comparison

PECR vs GDPR: Where the Two Rules Overlap and Where They Differ

PECR and GDPR cover a lot of the same ground but aren't the same law, and they don't always agree on the details. Here's a side-by-side comparison of where each one actually governs what.

Published September 3, 2026·Last updated September 3, 2026

PECR and GDPR overlap enough that businesses often treat them as one law with two names. They’re not, they’re separate statutes with separate scopes, separate enforcement histories, and, in a few specific spots, genuinely different rules. Understanding where they split matters because compliance with one doesn’t automatically mean compliance with the other.

The comparison

PECR GDPR
What it covers Cookies/tracking, electronic marketing (email, SMS, calls), traffic data All processing of personal data, any method
Origin UK implementation of the EU ePrivacy Directive (2003, updated) UK GDPR, retained from EU GDPR post-Brexit
Triggers on The act of storing device data or sending a marketing communication Any processing of personal data, broader by design
Default consent model Opt-in for non-essential cookies and most marketing; opt-out framing for some existing-customer scenarios Consent is one of six lawful bases, not always required
Applies even without personal data? Yes, in a narrow sense, PECR’s cookie rule can apply to storing/accessing device information regardless of whether it’s “personal data” under GDPR No, GDPR only applies where personal data is processed
Enforcer ICO ICO
Fine structure Historically lower maximums than GDPR for most violations, though reform proposals have sought to align them Up to £17.5M or 4% of global revenue (UK GDPR equivalent)

The distinction that surprises people most: PECR doesn’t always need “personal data”

GDPR only applies when personal data, information relating to an identifiable person, is being processed. PECR’s cookie rule is worded more broadly: it applies to storing or accessing information on a user’s device, full stop, regardless of whether that information is personal data on its own. In practice this rarely creates daylight, since cookie identifiers are usually treated as personal data anyway (see our personal data guide), but it means PECR’s cookie consent requirement doesn’t hinge on winning an argument about whether something is “really” personal data. If PECR requires consent for a cookie, that requirement doesn’t go away just because you conclude GDPR might not apply.

Where they genuinely work together, not just overlap

  • Cookies: PECR requires consent before setting a non-essential cookie; GDPR sets the standard that consent must meet (freely given, specific, unambiguous). Neither law alone gets you to a compliant banner, you need PECR’s trigger and GDPR’s standard together. See our PECR cookie consent guide.
  • Email marketing: PECR requires opt-in consent to send marketing emails (with the soft opt-in exception); GDPR governs the lawful basis for processing the email address itself and any behavioral data used to personalize the message.
Our recommendation

Usercentrics

Since a compliant setup needs PECR's trigger conditions and GDPR's consent standard satisfied at the same time, tools built around only one half of the picture tend to leave a gap. Usercentrics is built to handle both layers as one configuration rather than two separate settings.

Try Usercentrics

Where they diverge in ways that actually matter

  • B2B marketing exceptions: PECR has historically drawn a sharper line for corporate subscriber emails (company addresses like info@company.com, as opposed to named individuals) than GDPR does, since GDPR still protects a named individual’s work email as personal data regardless of PECR’s corporate-subscriber nuance.
  • Enforcement focus: the ICO’s PECR enforcement has historically concentrated heavily on nuisance calls and texts, a category GDPR doesn’t directly address at all, while GDPR enforcement skews toward broader data-handling and security failures.

Bottom line

Treat PECR as the narrower, more mechanical rulebook governing specific actions, storing something on a device, sending a marketing message, and GDPR as the broader framework governing personal data generally. Satisfying one doesn’t automatically satisfy the other, and for cookies and marketing specifically, you need to check both.

This comparison is educational and not legal advice. Consult a privacy attorney for how PECR and GDPR jointly apply to your specific business activities.