PECR, the Privacy and Electronic Communications Regulations, are the UK's ePrivacy rules: the law that decides when a website, app or advertiser may store information on a person's device or read information already there, and when a business may send marketing by email, text or phone. The full title is the Privacy and Electronic Communications (EC Directive) Regulations 2003, statutory instrument 2003/2426. They exist because data protection law did not cover the act of reaching into a device or an inbox. PECR regulate the access itself, which is why almost every cookie banner shown to UK users traces back to them.

The regulations began as the UK's transposition of the European Union's ePrivacy Directive. They survived Brexit as domestic law, and amendments since 2025 have begun to pull the UK away from EU practice.

How the device rule works

For advertising, the provision that matters is regulation 6. It prohibits storing information on, or gaining access to information stored in, a user's terminal equipment unless the user receives clear and comprehensive information about the purpose and gives consent. The rule is technology-neutral. According to the Information Commissioner's Office (ICO), it reaches cookies, pixels, web beacons, JavaScript and any other means of storing or reading device information, including technology supplied by third parties embedded in a service. Device fingerprinting falls inside it as well: the ICO announced draft guidance covering fingerprinting in December 2024, and its final guidance of April 29, 2026 treated fingerprinting alongside cookies and pixels.

PECR does not define consent. According to the ICO, the rules borrow the UK GDPR standard: freely given, specific, informed and unambiguous. In practice that means no advertising scripts firing before a choice, no pre-ticked boxes and a reject option as easy to use as accept. It also excludes legitimate interests as a basis for setting a cookie that needs consent. The ICO's 2019 adtech report found market participants relying on legitimate interests to place cookies rather than obtaining the consent PECR requires.

On the sell side, a consent management platform (CMP) holds tags until a decision exists and passes the result downstream. On the buy side, that decision reaches demand-side platforms (DSPs) as a Transparency and Consent Framework (TCF) string inside the bid request, and reaches advertiser tags through mechanisms such as Google's Consent Mode. The Data (Use and Access) Act 2025 (DUAA) widened the net: according to law firm Macfarlanes, the rule now also covers those who instigate storage or access, not only those who technically perform it.

The exceptions

Until 2026 only two exceptions existed: storage needed solely to transmit a communication, and storage strictly necessary for a service the user explicitly requested. ICO guidance says strictly necessary is judged from the user's point of view, not the operator's. DUAA inserted a new Schedule A1 into PECR, in force from February 5, 2026, adding exceptions for statistical purposeswebsite appearance and emergency assistance. Advisers count the additions differently, some describing three new exceptions and others five, depending on whether security and software-update uses are listed separately.

The statistical and appearance exceptions operate as an opt-out. According to Womble Bond Dickinson's reading of the ICO guidance, users must receive a simple, free means of objecting, and each exception applies only where storage serves that sole purpose. Analytics shared with third parties for their own purposes still requires consent. Advertising sits outside every exception.

The marketing rules

The other half of PECR governs direct marketing. Regulation 21 covers live sales calls and the Telephone Preference Service; regulation 22 requires prior consent before sending marketing emails or texts to individuals. The exception at regulation 22(3), known as the soft opt-in, allows a business to market similar products to someone whose details it obtained during a sale, provided an opt-out was offered at collection and in every message. Section 114 of DUAA added regulation 22(3A), a parallel route for charities, in force since February 5, 2026 and limited, according to Osborne Clarke, to contact details collected from that date. The ICO fined Elderly Aids Limited GBP 190,000 over 758,053 unsolicited marketing calls, according to a Handley Gill summary published in September 2026.

Origin and evolution

The EU adopted Directive 2002/58/EC, the ePrivacy Directive, on July 12, 2002. The UK implemented it through PECR, made on September 18, 2003 and in force from December 11, 2003, replacing telecoms privacy regulations dating from 1999. The original cookie rule required only information and a chance to refuse.

Directive 2009/136/EC, adopted on November 25, 2009, turned that opt-out into a consent requirement. The UK amended PECR in May 2011, and the ICO granted a year before enforcing it, a grace period that expired on May 26, 2012. ICO guidance of that period still accepted implied consent. The GDPR, applicable from May 25, 2018, raised the consent bar, and ICO cookie guidance in July 2019 ruled out implied consent and continued browsing as valid signals.

The ICO's penalty ceiling stood at GBP 500,000, and changes from April 6, 2015 made action on marketing breaches easier. From November 15, 2023, the regulator wrote to operators of the UK's most visited websites about advertising cookies set without consent. On January 23, 2025 it extended the review to the top 1,000 websites, having already raised concerns with 134 of the top 200, and published guidance on consent or pay models the same day.

The DUAA received Royal Assent on June 19, 2025. Most of its provisions commenced on February 5, 2026, raising the PECR penalty ceiling to GBP 17.5 million or 4% of global annual turnover, whichever is higher, a 35-fold rise in the fixed cap.

Why it matters for marketers

Regulation 6 decides how much UK inventory can carry an identifier. Every impression without consent is sold without cross-site targeting, retargeting or user-level attribution, so the consent rate works as a revenue variable for publishers and a reach constraint for buyers. According to the ICO, digital advertising contributes an estimated GBP 129 billion of gross value added a year to the UK economy, and the ICO itself concluded that the uniform consent rule limits incentives to invest in less intrusive models.

The penalty change matters too. A GBP 500,000 maximum was immaterial to a large platform; a turnover-based ceiling puts cookie failures in the same bracket as serious UK GDPR breaches.

Limitations and disputes

The central criticism is uniformity. Regulation 6 treats a contextual ad for bicycles on a cycling article and behavioural profiling across dozens of sites identically. Industry and regulator disagree on what should be freed. Publisher respondents told the regulator that agencies pay several times more for personalised than contextual inventory, and some would not bid on consentless supply at all. The ICO held its position that behavioural targeting stays consent-based, and said cross-site attribution would stay off-limits without consent unless delivered through privacy-enhancing technologies (PETs). Privacy advocates, including the Open Rights Group, pushed the other way and raised concerns about harm from loosening the rule.

Compliance figures are self-reported by the regulator and have moved. The ICO said in December 2025 that more than 95% of the top 1,000 websites met its checks at the time of testing. By May 2026 its response to the call for views put the figure at 99%. Neither figure measures consent quality downstream in the bidstream, and cookie enforcement has so far run largely through letters and reprimands rather than fines.

Divergence carries its own cost. A pan-European campaign now faces one exception set in the UK and another in each EU member state, where national laws such as France's Article 82 transpose Article 5(3) of the directive.

Not the same as

  • ePrivacy Directive. The EU parent law, still in force across the bloc through national transpositions. PECR copied it, but the UK has sat outside the European Economic Area since Brexit, so EU amendments no longer flow through.
  • ePrivacy Regulation. An EU proposal of January 10, 2017 meant to replace the directive. The Commission announced its withdrawal on February 11, 2025, and it took effect with publication on October 6, 2025. The shared word "regulation" causes frequent confusion; it never applied in the UK.
  • UK GDPR. Governs processing of personal data. PECR governs access to devices and marketing channels regardless of whether data is personal, and borrows the UK GDPR consent standard. Both can apply to one cookie.
  • Data (Use and Access) Act 2025. The amending statute, not a replacement. PECR remains the operative instrument.

Recent developments

The ICO finalised its guidance on storage and access technologies on April 29, 2026, after two consultations. On May 18, 2026 it published advice to government proposing a first-party framework under which ad delivery, contextual targeting, first-party frequency capping and aggregated measurement could run without consent. Location targeting to region or city level would qualify. Cross-device frequency capping would not, and behavioural advertising stays inside the consent perimeter. Any change would come through secondary legislation under the new regulation 6A power, which requires statutory consultation. As of September 2026, no amending regulations have been published.

The EU is moving on a different track. The Commission's Digital Omnibus of November 19, 2025 proposed shifting the device rule into the GDPR, and the Council removed the automated consent signal on June 18, 2026, prompting 19 groups to ask for it back. Platforms still treat the UK and EU as one consent zone: on September 9, 2026, Google told AdSense publishers reaching the EEA, UK or Switzerland it would add fallback consent messaging where requests arrive without a TC string.

Timeline

  • July 12, 2002: The EU adopts Directive 2002/58/EC, the ePrivacy Directive.
  • September 18, 2003: PECR are made as SI 2003/2426.
  • December 11, 2003: PECR come into force.
  • November 25, 2009: Directive 2009/136/EC introduces the consent requirement for cookies.
  • May 2011: The UK amends PECR to require consent for non-essential cookies.
  • May 26, 2012: The ICO's one-year enforcement grace period ends.
  • April 6, 2015: Amendments making marketing enforcement easier take effect.
  • January 10, 2017: The European Commission proposes an ePrivacy Regulation.
  • May 25, 2018: The GDPR applies, raising the consent standard PECR borrows.
  • June 20, 2019: The ICO publishes its update report into adtech and real-time bidding.
  • July 2019: ICO cookie guidance rules out implied consent.
  • November 15, 2023: The ICO writes to operators of top UK websites about advertising cookies.
  • December 2024: The ICO opens consultation on draft storage and access technologies guidance.
  • January 23, 2025: The ICO extends cookie review to the top 1,000 websites and publishes consent or pay guidance.
  • February 11, 2025: The Commission announces withdrawal of the ePrivacy Regulation.
  • June 19, 2025: The Data (Use and Access) Act 2025 receives Royal Assent.
  • September 7, 2025: The ICO call for views on regulation 6 and online advertising closes.
  • October 6, 2025: Withdrawal of the ePrivacy Regulation proposal is published.
  • December 2025: The ICO reports more than 95% of the top 1,000 websites meeting its checks.
  • February 5, 2026: DUAA's new cookie exceptions, charitable soft opt-in and higher PECR penalties commence.
  • April 29, 2026: The ICO finalises guidance on storage and access technologies.
  • May 18, 2026: The ICO publishes advice to government on low-risk advertising exceptions.
  • June 18, 2026: The EU Council removes the automated consent signal from its Digital Omnibus position.
  • September 9, 2026: Google notifies AdSense publishers of fallback consent messaging covering the UK.

Summary

Who. The UK government, through the Department for Science, Innovation and Technology, sets the rules; the ICO enforces them. Publishers, app owners, CMPs, ad tech vendors, advertisers, marketers and charities carry the obligations.

What. The Privacy and Electronic Communications (EC Directive) Regulations 2003, the UK's ePrivacy law. Regulation 6 requires consent before storing or reading information on a device, subject to exceptions, and regulations 21 and 22 govern marketing calls, emails and texts.

When. In force since December 11, 2003, with cookie consent introduced in 2011, the GDPR consent standard applied from 2018, and DUAA exceptions and a GBP 17.5 million or 4% penalty ceiling from February 5, 2026.

Where. The UK, applying to services reaching UK users, and in the ad stack at the point where a CMP records a choice and passes it to tags and bid requests.

Why. Data protection law did not address access to devices and inboxes as such. PECR fill that gap, and their consent rule now decides how much UK advertising inventory can carry an identifier.