UK Privacy and Electronic Communications Regulations 2003 (PECR)
The United Kingdom's Privacy and Electronic Communications Regulations 2003 (PECR) as revised by the Data (Use and Access) Act 2025: the duties on telecoms providers (security, 72-hour breach notice, traffic and location data, caller ID, directories), on anyone storing or reading information on users' devices (cookies with the new analytics and functionality exemptions), and on anyone marketing by call, fax, email or text (consent, TPS and CTPS screening, soft opt-ins including the charity route), each with commencement status and penalty level; enforcement at UK GDPR levels from 5 February 2026.
UK Privacy and Electronic Communications Regulations 2003 (PECR) is a compliance framework from United Kingdom with 6 domains and 35 controls. The largest domains are Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (11 controls), Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls), Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Access request procedures and code monitoring bodies (regulations 29A and 32B) – UK Privacy and Electronic Communications Regulations 2003 (PECR)
| Code | Title |
|---|---|
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.29A | Regulation 29A: Procedures for requests for access to users' personal data |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.32B(4) | Regulation 32B(4) and (5): Accredited code monitoring bodies acting on infringements |
Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR)
| Code | Title |
|---|---|
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.10 | Regulation 10: Free means to withhold calling line identity on outgoing calls |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.11 | Regulation 11: Called-subscriber controls over calling and connected line identity |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.12 | Regulation 12: Public information on line identification options |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.13 | Regulation 13: Cooperation between communications providers on line identification |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.17 | Regulation 17: Stopping third-party automatic call forwarding free of charge |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.18 | Regulation 18: Subscriber directories: information, choice, reverse search consent and corrections |
Security of services and personal data breaches (regulations 5 and 5A) – UK Privacy and Electronic Communications Regulations 2003 (PECR)
| Code | Title |
|---|---|
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5 | Regulation 5(1), (1A), (2) and (4): Security of public electronic communications services |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5(3) | Regulation 5(3) and (5): Informing subscribers of a significant residual security risk |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5A(2) | Regulation 5A(2), (3A) and (4): Notifying the Commissioner of a personal data breach within 72 hours |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5A(3) | Regulation 5A(3), (5), (6) and (7): Notifying affected subscribers and users of a personal data breach |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.5A(8) | Regulation 5A(8): Inventory of personal data breaches |
Terminal equipment: cookies and similar technologies (regulation 6 and Schedule A1) – UK Privacy and Electronic Communications Regulations 2003 (PECR)
| Code | Title |
|---|---|
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.6 | Regulation 6 and Schedule A1 paragraph 2: Storing or accessing information in terminal equipment only with information and consent |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.3-4 | Schedule A1 paragraphs 3 and 4: Exemptions for transmission and strictly necessary storage or access |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.5 | Schedule A1 paragraph 5: Statistical analytics exemption with information and a right to object |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.6 | Schedule A1 paragraph 6: Website appearance and functionality exemption with information and a right to object |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::SchA1.7 | Schedule A1 paragraph 7: Emergency assistance location exemption |
Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR)
| Code | Title |
|---|---|
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.14 | Regulation 14: Location data processed only anonymously or with informed, withdrawable consent |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.16 | Regulation 16: Calling line identity and location for 999 and 112 emergency calls |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.16A | Regulation 16A: Emergency alert processing on direction, with erasure afterwards |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.7 | Regulation 7: Erasing or anonymising traffic data and consent for marketing and value added services |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.8 | Regulation 8: Information before traffic data processing and limits on purpose and personnel |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.9 | Regulation 9(1): Non-itemised bills on request |
Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR)
| Code | Title |
|---|---|
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.19 | Regulation 19: Automated marketing calls only with prior consent and caller identity shown |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.20 | Regulation 20: Marketing faxes: consent for individuals, objections and the Fax Preference Service |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21(1) | Regulation 21(1) and (3) to (5): Live marketing calls: objections and TPS and CTPS screening |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21(A1) | Regulation 21(A1) and (2): Showing a contactable calling line identity on every marketing call |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21A | Regulation 21A: Claims management marketing calls only with prior consent |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.21B | Regulation 21B: Pension scheme marketing calls: authorised callers with consent or an existing client relationship |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.22(2) | Regulation 22(1), (2) and (4): Marketing emails and texts to individuals only with prior consent |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.22(3) | Regulation 22(3): Commercial soft opt-in for existing customers |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.22(3A) | Regulation 22(3A) and (5): Charity soft opt-in for supporters |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.23 | Regulation 23: Marketing emails must not conceal the sender and must carry a valid opt-out address |
| uk-privacy-and-electronic-communications-regulations-2003-pecr::Reg.24 | Regulation 24: Identifying the marketer on automated calls, faxes and live calls |
What is UK Privacy and Electronic Communications Regulations 2003 (PECR) and who does it apply to?
UK Privacy and Electronic Communications Regulations 2003 (PECR) is a compliance framework from United Kingdom with 6 domains and 35 controls. The United Kingdom's Privacy and Electronic Communications Regulations 2003 (PECR) as revised by the Data (Use and Access) Act 2025: the duties on telecoms providers (security, 72-hour breach notice, traffic and location data, caller ID, directories), on anyone storing or reading information on users' devices (cookies with the new analytics and functionality exemptions), and on anyone marketing by call, fax, email or text (consent, TPS and CTPS screening, soft opt-ins including the charity route), each with commencement status and penalty level; enforcement at UK GDPR levels from 5 February 2026. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does UK Privacy and Electronic Communications Regulations 2003 (PECR) actually require?
UK Privacy and Electronic Communications Regulations 2003 (PECR) has 35 controls organised across 6 domains. The largest domains are Unsolicited direct marketing by calls, fax, email and text (regulations 19 to 24) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (11 controls), Calling line identification, call forwarding and directories (regulations 10 to 13, 17 and 18) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls), Traffic data, billing, location data and emergency services (regulations 7 to 9, 14, 16 and 16A) – UK Privacy and Electronic Communications Regulations 2003 (PECR) (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of UK Privacy and Electronic Communications Regulations 2003 (PECR) do I already cover?
UK Privacy and Electronic Communications Regulations 2003 (PECR) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement UK Privacy and Electronic Communications Regulations 2003 (PECR)?
Start your UK Privacy and Electronic Communications Regulations 2003 (PECR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Privacy and Electronic Communications Regulations 2003 (PECR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 702 frameworks.
Get Started Free →Free forever — no credit card required