Guide

What Is PECR and How Does It Work Alongside GDPR?

PECR is the UK law that governs cookies, marketing emails, and electronic communications, sitting alongside GDPR rather than being replaced by it. Here's what PECR actually is.

Published September 3, 2026·Last updated September 3, 2026

PECR, the Privacy and Electronic Communications Regulations 2003, is a UK law that gets far less attention than GDPR but drives some of the most commonly enforced compliance requirements on an ordinary business website: cookie consent and marketing communications rules. It’s the UK’s implementation of the EU’s ePrivacy Directive, and despite GDPR’s much higher profile, PECR hasn’t been replaced or absorbed by it, the two laws operate side by side, each doing a different job.

Where PECR came from

PECR predates GDPR, it came into force in 2003, implementing the EU’s original ePrivacy Directive. When GDPR took effect in 2018 (and was retained in UK law post-Brexit as “UK GDPR”), PECR wasn’t repealed. Instead, PECR was updated to work alongside GDPR’s stricter consent standard, so today PECR sets what requires consent for cookies and electronic marketing, while GDPR sets what counts as valid consent once PECR says you need it.

What PECR actually regulates

  • Cookies and similar tracking technologies (Regulation 6), requiring consent before storing or accessing information on a user’s device, with a narrow exemption for strictly necessary cookies. See our dedicated guide on PECR and cookies.
  • Unsolicited marketing communications (Regulations 19-24), covering email, SMS, automated calls, and live calls, with different rules for each channel. See our piece on channels beyond email.
  • Traffic and location data held by network and service providers, more relevant to telecoms companies than typical websites.
  • Directory listings and calling line identification, niche provisions mostly relevant to phone and directory services.

For most businesses running a website, the two provisions that actually matter day to day are the cookie rule and the marketing communications rules.

The relationship with GDPR, in one sentence

PECR decides whether you need consent in the first place; GDPR decides whether the consent you got is valid. If PECR requires consent for a cookie and the “consent” you obtained was a pre-checked box, you’ve failed GDPR’s consent standard even though PECR was the law that triggered the requirement. Getting either half wrong breaks the whole chain.

Our recommendation

CookieYes

Because PECR sets the trigger and GDPR sets the standard, a compliant setup needs both handled correctly at once, not just a banner that exists. CookieYes is built around satisfying both layers together rather than treating them as separate problems.

Try CookieYes

Who enforces PECR

The UK’s Information Commissioner’s Office (ICO), the same regulator that enforces UK GDPR, also enforces PECR. In practice, PECR has historically generated some of the ICO’s highest-volume enforcement action, particularly around nuisance calls and texts; see our guide to PECR enforcement patterns for what the ICO actually prioritizes.

Does PECR apply if you’re not in the UK?

PECR is UK law, but its reach isn’t limited to UK-incorporated businesses in the same way that might seem intuitive, we cover the actual scope test in our dedicated guide on PECR’s territorial reach.

This guide is educational and not legal advice. Consult a privacy attorney for how PECR applies to your specific business.