Can You Email Your Customers Without Their Permission?
Someone bought from you 3 years ago. You still email them every Tuesday.
Is that legal?
Most business owners I speak to think the answer is yes, because "they're a customer". Some think the answer is no, because "we never got GDPR consent". Both groups are half right, and the half they have wrong is the half the ICO fines people for.
So let's go through it properly. No jargon, no scaremongering, just the actual rules for emailing your customers in the UK and where businesses trip over them.
The short answer
Yes, you can email your existing customers with marketing without asking for consent first. But only if you meet 4 conditions, and only if you keep meeting them on every single email you send.
The rule that governs this is not the UK GDPR. It is Regulation 22 of the Privacy and Electronic Communications Regulations, or PECR. GDPR sits behind it, but PECR is the one that decides whether a marketing email is allowed to land in someone's inbox at all.
The exception that lets you email customers without asking is called the "soft opt-in". If you get one thing from this article, get the soft opt-in right.
What the soft opt-in actually requires
PECR says you can send marketing emails to an individual without consent when all 4 of these are true:
→ You collected their email address yourself, in the course of a sale or negotiations for a sale.
→ You are marketing your own similar products or services.
→ You gave them a simple way to refuse marketing at the point you collected their details.
→ You give them a simple way to opt out in every message after that.
Miss one and the exception falls away. You are then sending unsolicited marketing to someone who never agreed to it, which is exactly what PECR prohibits.
Let me take each of the 4 in turn, because the detail is where businesses get caught.
1. You collected the details yourself
The ICO is explicit on this. You must collect the contact details directly from the person. A list you bought, rented, or were "given" by a partner can never qualify for the soft opt-in, whatever the supplier tells you about how clean it is.
"Negotiations for a sale" means the person actively showed buying interest. Someone who filled in a quote form on your website counts. Someone who logged in and browsed does not. Someone who entered a prize draw does not.
2. Similar products or services
You can only market things the customer would reasonably expect from you, given what they bought and the context they bought it in.
The ICO's own example: a supermarket customer who buys groceries can expect emails about groceries. They would not expect emails about the supermarket's banking products, because those are not sold in a similar context.
If you have branched into a new line of business, your old customer list does not automatically come with you.
3. A chance to refuse at the point of collection
This is the one that fails most often, and it fails silently.
At the moment you take the email address, on the checkout page, the quote form, the account sign-up, there has to be a clear, simple way for the person to say "no marketing". An unticked box. A visible link. Something they can act on right there.
If your checkout form takes the address and says nothing about marketing, you never gave them the choice. Every marketing email you send to that customer afterwards is unsolicited. It does not matter that they never complained. It does not matter that they open your emails. The soft opt-in never existed for them.
In January 2026 the ICO fined Allay Claims Ltd £120,000 for exactly this. 4 million texts to people who had used the company's services, and the ICO's finding was that the soft opt-in did not apply because customers were never given a way to refuse when their details were collected.
4. Opt out in every message
Every marketing email needs a working unsubscribe. Not a "reply and we'll remove you". Not "log in to your account to change preferences". A link they can click, that works, that takes effect.
And when someone uses it, they stay off the list. Sending to someone who opted out is the easiest PECR complaint there is, because the evidence is sitting in their inbox.
"But we have legitimate interests"
This is the line I hear most, so let's deal with it.
Legitimate interests is a UK GDPR lawful basis. It governs whether you can process the personal data. It does not override PECR. If PECR says you need consent or the soft opt-in to send the email, then legitimate interests under GDPR does not get you round that.
Think of it as 2 locks on the same door. GDPR is one, PECR is the other. Legitimate interests only opens the first.
The Data (Use and Access) Act 2025 added a new list of "recognised legitimate interests" from 5 February 2026. Direct marketing is not one of them, and even if it were, it would not change the PECR position.
Where the rules are different
A few situations catch people out in the other direction, where the rules are looser than they assume.
Business customers. PECR's email rule protects individual subscribers. It does not apply to corporate subscribers, which means limited companies, LLPs, Scottish partnerships and public bodies. You can email [email protected], or a named employee at their work address, without consent. You still have to say who you are, give a valid address to opt out, and honour opt-outs, and UK GDPR still applies to the named person's data. But the consent requirement is not there.
Sole traders and ordinary partnerships are not corporate subscribers. They are individuals in the eyes of PECR. Treat them like consumers.
Charities. Until this year the soft opt-in was for products and services only, so a charity could not use it for fundraising. From 5 February 2026 the Data (Use and Access) Act extended a version of the soft opt-in to charities, covering people who have expressed an interest in or supported the charity's purposes. The same 2 conditions on opting out apply.
Service messages. An email that tells a customer their order has shipped, their renewal is due, or their password has changed is not marketing. The moment you add "and here's 20% off your next order", it is.
What has changed on penalties
For years the maximum PECR fine was £500,000. That ceiling is gone.
From 5 February 2026 the ICO can fine PECR breaches up to £17.5 million or 4% of global annual turnover, whichever is higher. The same ceiling as a UK GDPR breach.
The ICO does not need to use the top end of that for a small business to feel it. In the same January 2026 batch as Allay, ZMLUK Limited was fined £105,000 for 67 million marketing emails sent using bought-in data where the "consent" pointed at a list of 361 partner companies. The ICO found the consent was not valid and the company had done no real due diligence on where the data came from.
"The supplier said it was fine" was not a defence then. It is not a defence now.
Three things to check right now
→ Open your checkout, quote form and sign-up page. Is there a clear way to refuse marketing at the point you collect the email address? If not, your soft opt-in does not exist.
→ Look at your last 5 marketing emails. Does each one have a working unsubscribe link, and does your system actually suppress people who click it?
→ Look at where your list came from. Every address you did not collect yourself needs specific, recorded consent naming your business. If you cannot show it, stop sending to it.
What good looks like
You do not need a legal department to get this right. You need 3 things.
A tick box (unticked) or a plain "no thanks" option wherever you capture email addresses in a sale. A record of what the customer saw and when. An unsubscribe that works and a suppression list that is checked before every send.
Do that and you can email your customers with confidence, without asking anyone for permission they already gave you by buying from you.
Skip it and you are relying on nobody ever forwarding one of your emails to the ICO. In the Allay case, the ICO's 7726 reporting service logged over 46,000 complaints about that one company.
I work with UK businesses as their outsourced DPO, and email marketing is one of the first things I look at, because it is the one most likely to generate a complaint. If you want a second pair of eyes on your sign-up forms and your list, get in touch. Happy to have a no-obligation chat.
References
ICO, Guide to PECR: Electronic mail marketing
https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/electronic-and-telephone-marketing/electronic-mail-marketing/
ICO, How do we comply with the PECR electronic mail marketing rules?
https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-direct-marketing-using-electronic-mail/how-do-we-comply-with-the-pecr-electronic-mail-marketing-rules/
ICO, Business-to-business marketing
https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/business-to-business-marketing/
ICO, Fines of £225,000 for nuisance marketing messages (January 2026)
https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/01/fines-of-225-000-for-nuisance-marketing-messages/
Data Protection Network, UK GDPR and PECR: key DUAA reforms take effect (February 2026)
https://dpnetwork.org.uk/uk-gdpr-and-pecr-key-duaa-reforms-take-effect/
Clifford Chance, Key aspects of the Data (Use and Access) Act take effect (February 2026)
https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2026/02/key-aspects-of-the-data--use-and-access--act-take-effect.html
Blake Morgan, Data (Use and Access) Act 2025: Privacy and Electronic Communications Regulations
https://www.blakemorgan.co.uk/data-use-and-access-act-2025-privacy-and-electronic-communications-regulations/

