Back to Frameworks

UK Privacy and Electronic Communications Regulations 2003 (PECR)

United Kingdom
vPrivacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426); revised text valid 5 February 2026, including the Data (Use and Access) Act 2025 amendments
6 domains
35 controls

The United Kingdom's Privacy and Electronic Communications Regulations 2003 (PECR) as revised by the Data (Use and Access) Act 2025: the duties on telecoms providers (security, 72-hour breach notice, traffic and location data, caller ID, directories), on anyone storing or reading information on users' devices (cookies with the new analytics and functionality exemptions), and on anyone marketing by call, fax, email or text (consent, TPS and CTPS screening, soft opt-ins including the charity route), each with commencement status and penalty level; enforcement at UK GDPR levels from 5 February 2026.

Verified

UK Privacy and Electronic Communications Regulations 2003 (PECR) is a compliance framework from United Kingdom with 6 domains and 35 controls. The largest domains are Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (11 controls), Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls), Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Access request procedures and code monitoring bodies (regulations 29A and 32B) – UK Privacy and Electronic Communications Regulations 2003 (PECR)

2 controls
Controls in the Access request procedures and code monitoring bodies (regulations 29A and 32B) – UK Privacy and Electronic Communications Regulations 2003 (PECR) domain of UK Privacy and Electronic Communications Regulations 2003 (PECR) — 2 controls
CodeTitle
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.29ARegulation 29A: Procedures for requests for access to users' personal data
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.32B(4)Regulation 32B(4) and (5): Accredited code monitoring bodies acting on infringements

Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR)

6 controls
Controls in the Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR) domain of UK Privacy and Electronic Communications Regulations 2003 (PECR) — 6 controls
CodeTitle
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.10Regulation 10: Free means to withhold calling line identity on outgoing calls
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.11Regulation 11: Called-subscriber controls over calling and connected line identity
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.12Regulation 12: Public information on line identification options
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.13Regulation 13: Cooperation between communications providers on line identification
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.17Regulation 17: Stopping third-party automatic call forwarding free of charge
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.18Regulation 18: Subscriber directories: information, choice, reverse search consent and corrections

Security of services and personal data breaches (regulations 5 and 5A) – UK Privacy and Electronic Communications Regulations 2003 (PECR)

5 controls
Controls in the Security of services and personal data breaches (regulations 5 and 5A) – UK Privacy and Electronic Communications Regulations 2003 (PECR) domain of UK Privacy and Electronic Communications Regulations 2003 (PECR) — 5 controls
CodeTitle
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5Regulation 5(1), (1A), (2) and (4): Security of public electronic communications services
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5(3)Regulation 5(3) and (5): Informing subscribers of a significant residual security risk
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5A(2)Regulation 5A(2), (3A) and (4): Notifying the Commissioner of a personal data breach within 72 hours
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5A(3)Regulation 5A(3), (5), (6) and (7): Notifying affected subscribers and users of a personal data breach
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5A(8)Regulation 5A(8): Inventory of personal data breaches

Terminal equipment: cookies and similar technologies (regulation 6 and Schedule A1) – UK Privacy and Electronic Communications Regulations 2003 (PECR)

5 controls
Controls in the Terminal equipment: cookies and similar technologies (regulation 6 and Schedule A1) – UK Privacy and Electronic Communications Regulations 2003 (PECR) domain of UK Privacy and Electronic Communications Regulations 2003 (PECR) — 5 controls
CodeTitle
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.6Regulation 6 and Schedule A1 paragraph 2: Storing or accessing information in terminal equipment only with information and consent
uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.3-4Schedule A1 paragraphs 3 and 4: Exemptions for transmission and strictly necessary storage or access
uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.5Schedule A1 paragraph 5: Statistical analytics exemption with information and a right to object
uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.6Schedule A1 paragraph 6: Website appearance and functionality exemption with information and a right to object
uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.7Schedule A1 paragraph 7: Emergency assistance location exemption

Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR)

6 controls
Controls in the Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR) domain of UK Privacy and Electronic Communications Regulations 2003 (PECR) — 6 controls
CodeTitle
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.14Regulation 14: Location data processed only anonymously or with informed, withdrawable consent
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.16Regulation 16: Calling line identity and location for 999 and 112 emergency calls
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.16ARegulation 16A: Emergency alert processing on direction, with erasure afterwards
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.7Regulation 7: Erasing or anonymising traffic data and consent for marketing and value added services
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.8Regulation 8: Information before traffic data processing and limits on purpose and personnel
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.9Regulation 9(1): Non-itemised bills on request

Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR)

11 controls
Controls in the Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR) domain of UK Privacy and Electronic Communications Regulations 2003 (PECR) — 11 controls
CodeTitle
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.19Regulation 19: Automated marketing calls only with prior consent and caller identity shown
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.20Regulation 20: Marketing faxes: consent for individuals, objections and the Fax Preference Service
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21(1)Regulation 21(1) and (3) to (5): Live marketing calls: objections and TPS and CTPS screening
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21(A1)Regulation 21(A1) and (2): Showing a contactable calling line identity on every marketing call
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21ARegulation 21A: Claims management marketing calls only with prior consent
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21BRegulation 21B: Pension scheme marketing calls: authorised callers with consent or an existing client relationship
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.22(2)Regulation 22(1), (2) and (4): Marketing emails and texts to individuals only with prior consent
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.22(3)Regulation 22(3): Commercial soft opt-in for existing customers
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.22(3A)Regulation 22(3A) and (5): Charity soft opt-in for supporters
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.23Regulation 23: Marketing emails must not conceal the sender and must carry a valid opt-out address
uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.24Regulation 24: Identifying the marketer on automated calls, faxes and live calls

What is UK Privacy and Electronic Communications Regulations 2003 (PECR) and who does it apply to?

UK Privacy and Electronic Communications Regulations 2003 (PECR) is a compliance framework from United Kingdom with 6 domains and 35 controls. The United Kingdom's Privacy and Electronic Communications Regulations 2003 (PECR) as revised by the Data (Use and Access) Act 2025: the duties on telecoms providers (security, 72-hour breach notice, traffic and location data, caller ID, directories), on anyone storing or reading information on users' devices (cookies with the new analytics and functionality exemptions), and on anyone marketing by call, fax, email or text (consent, TPS and CTPS screening, soft opt-ins including the charity route), each with commencement status and penalty level; enforcement at UK GDPR levels from 5 February 2026. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does UK Privacy and Electronic Communications Regulations 2003 (PECR) actually require?

UK Privacy and Electronic Communications Regulations 2003 (PECR) has 35 controls organised across 6 domains. The largest domains are Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (11 controls), Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls), Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of UK Privacy and Electronic Communications Regulations 2003 (PECR) do I already cover?

UK Privacy and Electronic Communications Regulations 2003 (PECR) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement UK Privacy and Electronic Communications Regulations 2003 (PECR)?

Start your UK Privacy and Electronic Communications Regulations 2003 (PECR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Privacy and Electronic Communications Regulations 2003 (PECR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 702 frameworks.

Get Started Free →

Free forever — no credit card required