Privacy and Electronic Communications Regulations

United KingdomTelecommunications2003
ByDecipherU Editorial

UK PECR governs cybersecurity and privacy in electronic communications, covering cookies, direct marketing, and communications security. It is the UK equivalent of the EU ePrivacy Directive. PECR requires consent for non-essential cookies, opt-in for marketing emails, and security measures for public electronic communications networks.

Quick Reference

EnactedDecember 11, 2003
Last Amended2018 (amendments for GDPR alignment)
Enforcement BodyInformation Commissioner's Office (ICO)
PenaltiesUp to 500,000 GBP for direct marketing violations; GDPR-level penalties where PECR and UK GDPR overlap
Applicable ToOrganizations using electronic communications for marketing, operating websites, or providing public electronic communications services in the UK

Key Requirements

Regulation 6 (Confidentiality of communications)

Storing or gaining access to information stored in a user's terminal equipment (cookies) requires consent, except for strictly necessary purposes

Regulation 22 (Use of electronic mail for direct marketing)

Unsolicited electronic mail for direct marketing to individual subscribers is prohibited unless they have given prior consent

Regulation 5 (Security of public electronic communications services)

Providers of public electronic communications services must take appropriate technical and organizational measures to safeguard the security of those services

How Does UK PECR Affect Cybersecurity Careers?

Cybersecurity professionals implementing cookie consent mechanisms and email security controls work with PECR requirements. Security engineers at UK telecommunications providers must meet Regulation 5 security obligations. GRC analysts must understand how PECR interacts with UK GDPR for enforcement purposes.

Cybersecurity Roles That Work With UK PECR

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of UK PECR at the official source: https://www.legislation.gov.uk/uksi/2003/2426/contents/made

Frequently Asked Questions

UK PECR governs cybersecurity and privacy in electronic communications, covering cookies, direct marketing, and communications security. It is the UK equivalent of the EU ePrivacy Directive. PECR requires consent for non-essential cookies, opt-in for marketing emails, and security measures for public electronic communications networks.

Cybersecurity professionals implementing cookie consent mechanisms and email security controls work with PECR requirements. Security engineers at UK telecommunications providers must meet Regulation 5 security obligations. GRC analysts must understand how PECR interacts with UK GDPR for enforcement purposes.

Up to 500,000 GBP for direct marketing violations; GDPR-level penalties where PECR and UK GDPR overlap

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?