Keep UK Supporter and Customer Emails Out of Spam: PECR Soft Opt In

PECR still applies, and the soft opt-in still works the way most compliance teams remember it, but there are now two versions rather than one. Organisations selling products and services have relied on the original soft opt-in for years, while charities gained a separate charitable purposes soft opt-in once the Data (Use and Access) Act 2025 amended the regulations. Meeting either test under PECR does not remove the separate duty to satisfy UK GDPR, including a documented legitimate interests assessment and a clear opt-out at every stage.


TL;DR:
  • The original soft opt-in allows marketing to existing customers about similar products or services when details were collected during a sale or negotiation, given five specific conditions are met.
  • The charitable purposes soft opt-in, introduced in 2025, applies only to registered charities contacting supporters about related charitable activities and requires strict compliance with supporter engagement rules.
  • Both soft opt-ins still require a documented legitimate interests assessment under UK GDPR, with separate rules for lawful data processing beyond PECR’s email marketing conditions.
  • Using third-party or purchased contact lists, or hiding opt-outs, immediately invalidates soft opt-in compliance and risks enforcement action from ICO.
  • Technical deliverability factors, such as proper sender reputation and authentication, are essential for ensuring emails reach the inbox after relying on soft opt-in legal permissions.

Table of Contents

What the two soft opt-ins are and when each applies

The phrase “soft opt-in” describes a narrow exception in regulation 22 of the Privacy and Electronic Communications Regulations 2003, which otherwise requires consent before sending marketing by electronic mail. Without it, every commercial or charitable email to an individual would need prior opt-in consent, full stop.

The original soft opt-in, available to any organisation, lets you email existing customers about similar products or services without fresh consent, provided you collected their details during a sale or negotiation. The newer charitable purposes soft opt-in, introduced by the Data (Use and Access) Act 2025, is reserved for registered charities and lets them contact people who have previously expressed support, such as donors or volunteers, about similar charitable purposes. A high street retailer cannot use the charity version, and a charity’s trading arm selling merchandise would need to rely on the standard products and services test instead, not the charitable one.

Comparison of two PECR soft opt-ins

Five-condition checklist for the products-and-services soft opt-in

According to ICO guidance on electronic mail marketing rules, five conditions must all be met before you rely on the products and services soft opt-in, and missing even one removes the exception entirely.

  • You obtained the person’s contact details directly from them during the sale or negotiation of a sale, not from a third party or purchased list.
  • You are only marketing your own similar products or services, not an unrelated range or a partner’s offering.
  • You gave the person a simple, clear opportunity to opt out when you first collected their details.
  • You offer the same opt-out in every subsequent marketing message, not just the first.
  • The individual is a sole trader or an unincorporated partnership, or a private individual, since corporate subscribers fall outside these particular protections in most cases.

Pro Tip: Put the opt-out in the same sentence as the consent statement on your form, not buried in a linked privacy notice, so the “simple and free” test is obviously satisfied.

Charitable purposes soft opt-in: DUAA 2025 amendment and its limits

Regulation 22(3A), inserted by the Data (Use and Access) Act 2025, gives registered charities a parallel route to the products and services soft opt-in, built around supporter relationships rather than sales. A charity can rely on it only where several conditions line up together.

  • The contact details were collected directly from the individual in the course of them expressing interest in, or support for, the charity’s purposes, such as signing up at an event or making a donation.
  • The further communications are about similar charitable purposes to those the person has already engaged with, rather than a substantially different cause the charity additionally runs.
  • A clear opt-out was offered at collection and appears in every later message, mirroring the products and services test.

The Fundraising Regulator’s guidance on the charitable purposes soft opt-in is clear that this is not a general licence to email anyone who has ever donated. Charities still need to justify contact frequency and avoid supporter fatigue, and a merger or rebrand that changes the charitable purpose substantially can break the link the soft opt-in depends on.

How PECR soft opt-ins interact with UK GDPR obligations

Satisfying PECR’s tests answers the electronic marketing question, but it does not answer the separate question of whether you have a lawful basis to process the person’s personal data under UK GDPR. In practice, most organisations relying on a soft opt-in use legitimate interests as that basis, and ICO guidance expects a documented Legitimate Interests Assessment to sit behind that choice.

A proportionate LIA should set out the purpose of the processing, why it is necessary, and a genuine balancing test against the individual’s rights and expectations, as Charity Digital’s explainer on legitimate interest describes. Where recipients may include vulnerable people, such as elderly donors or people in financial difficulty, the assessment needs to weigh that risk explicitly and set mitigations like reduced frequency or extra-prominent opt-outs. Keep the LIA, the collection source, and the opt-out timestamp on file, because these are exactly what the ICO will ask to see first if a complaint arrives.

Legitimate interests assessment and records flow

Step-by-step compliance actions for charities and small businesses

Turning the legal tests into daily practice is where most of the risk actually sits, since the law rarely trips people up as much as sloppy list management does.

  1. Write collection forms so the opt-out sits next to the consent or interest statement, using plain wording such as “we will email you about similar causes unless you tell us not to here.”
  2. Tag every contact record with its collection source, date, and the basis relied upon (consent, products and services soft opt-in, or charitable purposes soft opt-in), using a CRM field structure similar to the approach shown in Pipeline’s mailing-list features built for UK small businesses managing enquiries and supporter data.
  3. Keep soft opt-in contacts in a separate list from fully consented contacts, as the ICO’s preparation guidance recommends, so an unsubscribe or complaint is easy to trace and action.
  4. Draft the LIA before you send, not after a complaint lands, and set a clear threshold for when legal advice should be sought, such as campaigns targeting people known to be vulnerable.
  5. Monitor bounce rates, spam complaints, and unsubscribe volume closely in the fortnight after any new soft opt-in send, since a sudden spike usually means the targeting or wording needs revisiting.

Pro Tip: Ramp new soft opt-in sends gradually rather than mailing the whole list on day one, because mailbox providers judge a sudden volume increase from an unfamiliar segment far more harshly than a steady build.

Common pitfalls and red flags that cause non-compliance

Most soft opt-in problems come from a handful of repeated mistakes rather than genuinely ambiguous law.

  • Using a bought-in, rented, or third-party list breaks the soft opt-in immediately, because the contact details were not collected directly by you.
  • Marketing products, services, or causes that are not genuinely similar to what the person originally engaged with falls outside both versions of the test.
  • Hiding the opt-out in small print, or forgetting to repeat it in later messages, undermines the “clear and simple” requirement the ICO looks for.
  • Failing to document the LIA or the collection source leaves you unable to answer an ICO enquiry quickly, which tends to make a minor issue look far worse than it is.

Why compliance and deliverability go together

Getting the legal tests right only solves half the problem, because a technically compliant send that annoys recipients still generates complaints, and complaint rates are one of the clearest signals mailbox providers use when deciding whether your next campaign reaches the inbox or the spam folder. We see this pattern often in reviews of permission-based lists that still struggle with placement, as explored in our piece on why emails go to spam even with permission.

Deliverability support for organisations expanding soft opt-in sending

When you start mailing new segments under either soft opt-in, the legal groundwork matters, but so does the technical foundation underneath it, and the two tend to fail together rather than separately. Deliverability audits that evaluate sender reputation, authentication records, and list quality are important before an expansion goes live, as they help identify configuration issues that could cause a compliant campaign to be treated as spam.

Digistrat

Our services cover the full range a growing sender needs: a free health check to establish a baseline, authentication setup covering SPF, DKIM, and DMARC, ongoing reputation monitoring, and reputation recovery work if a previous send has already caused damage. For teams that want fast, focused input before a specific campaign, our advisory session is a one-off £250 session built around exactly that kind of question. Where dormant contacts are part of the list you’re about to mail under a soft opt-in, our guide to how dormant subscribers damage a sending programme is worth reading first. You can see the full range of our deliverability services or book a free check-up to get a baseline reading before you expand your sending.

FAQ

Does PECR still apply in the UK?

Yes, PECR remains in force and continues to govern electronic marketing including email, text, and automated calls, sitting alongside UK GDPR rather than being replaced by it. The Data (Use and Access) Act 2025 amended specific provisions, including adding the charitable purposes soft opt-in, but left the core consent framework in place.

What is the difference between soft opt-in and hard opt-in?

A hard opt-in means the individual has given explicit, affirmative consent before you send any marketing, while a soft opt-in is a narrow statutory exception that lets you market without that prior consent when strict conditions, such as an existing customer relationship or supporter relationship, are met. Both still require a clear opt-out in every message under PECR’s electronic mail marketing rules.

Can charities use the products and services soft opt-in instead of the charitable purposes one?

A charity’s trading subsidiary selling goods or services can rely on the standard products and services soft opt-in for those sales relationships, but fundraising and supporter communications about charitable purposes fall under the separate charitable purposes soft opt-in introduced by the Data (Use and Access) Act 2025. Using the wrong one for the wrong type of message risks falling outside both exceptions.

Does meeting the PECR soft opt-in conditions mean we don’t need a lawful basis under GDPR?

No, PECR and UK GDPR are separate legal frameworks, and satisfying the soft opt-in conditions only addresses the marketing rules, not your data protection obligations. You still need a lawful basis, most commonly legitimate interests, supported by a documented assessment as described in ICO guidance on what else to consider.

Sources

Primary legislation and regulator guidance to consult next

For the statutory wording itself, the Privacy and Electronic Communications Regulations 2003 on legislation.gov.uk is the primary source for regulation 22 and should be the reference point whenever precise legal wording matters, such as in a policy document or a response to an ICO enquiry. The Data (Use and Access) Act 2025 factsheet on PECR explains the charitable purposes amendment in accessible terms and is a sensible starting point before reading the full statutory text.

The Information Commissioner’s Office publishes the most detailed operational guidance, including the electronic mail marketing rules that set out the five conditions in detail. Charities should also read the Fundraising Regulator’s guidance on the charitable purposes soft opt-in, which addresses sector-specific expectations around contact frequency and supporter fatigue that sit alongside, rather than instead of, the ICO’s own rules.

Not sure if this applies to you?

Book a free check-up and we will walk through your sending situation. No obligation, no pitch.

Book a free check-up

More on deliverability advice

Not sure where your emails are landing?

Send a test email and we will walk through what we find in 15 minutes. No pitch. No obligation.

Book a free check-upFree. 15 minutes. No obligation.