Email campaign screen illustrating UK consent and soft opt-in rules for email marketing in 2026

UK email marketing rules in 2026: consent, the soft opt-in, and what changed in February

As of September 2026, you can legally send marketing emails in the UK in two main situations: the person gave you clear opt-in consent, or they're an existing customer covered by the "soft opt-in" — they bought from you (or began a purchase), you told them at the time they could opt out, you only email them about similar products, and every email includes an unsubscribe link. Emailing outside those situations breaches PECR, and the maximum fine rose in February 2026 from £500,000 to £17.5 million.

That's the short answer. The longer answer matters, because the rules changed on 5 February 2026 and most guides floating around Google were written before they did. Here's what a small UK business — an online shop, a therapist, a supplement brand — actually needs to know, based on the current ICO guidance and the Data (Use and Access) Act 2025.

Which laws cover email marketing in the UK?

Two, working together. The Privacy and Electronic Communications Regulations (PECR) set the specific rules for marketing emails and texts: when you can send them, and what they must contain. The UK GDPR sits underneath, governing how you collect, store and use the email addresses themselves. You need to satisfy both — a lawful basis under UK GDPR doesn't excuse a PECR breach, and vice versa. The regulator for both is the ICO.

In February 2026, the Data (Use and Access) Act 2025 brought PECR's penalties into line with UK GDPR. The old cap of £500,000 became £17.5 million or 4% of global turnover, whichever is higher. Small businesses won't see fines that size — but the ICO fines small firms routinely at the five- and six-figure level, and the direction of travel is clear: nuisance marketing is an enforcement priority.

Do you need consent to send marketing emails?

For individuals — consumers, and (this catches people out) sole traders and most partnerships — yes, unless the soft opt-in applies. Consent under PECR means a clear, positive action: a ticked box the person ticked themselves, a signup form, a "yes" they actively gave. Specifically:

  • Pre-ticked boxes don't count. Neither does silence, inactivity, or burying consent in your terms and conditions.
  • Consent must name you. "I agree to receive offers from selected partners" is not consent for your emails.
  • Consent must cover the channel. Consent to email is not consent to text.
  • Keep records. If the ICO asks, you need to show who consented, when, and what they were told.

What is the soft opt-in, and can your shop use it?

The soft opt-in is the exemption most online shops actually rely on. It lets you email people without explicit consent when all four of these conditions are met:

  1. You collected their details directly from them (never from a bought list);
  2. It happened during a sale, or negotiations for a sale — a purchase, but also a quote request or an account created at checkout;
  3. You only email them about your own similar products or services;
  4. You gave them a simple chance to opt out when you collected the details, and you repeat it in every email.

Miss one condition and the exemption collapses. In January 2026 the ICO fined Allay Claims Ltd £120,000 over four million marketing texts — the company argued soft opt-in, but it had failed to offer a simple way to refuse marketing at sign-up, so the exemption didn't apply. The practical lesson for a Shopify store: put a clearly worded, un-ticked marketing checkbox (or an obvious opt-out) at checkout, and make sure your email platform actually records it. That single setting is the legal foundation of your whole email programme.

"Similar products" is judged from the customer's point of view. A coffee shop emailing about new coffees, brewing kit or a subscription is fine. The same shop launching a clothing line to its coffee list is on thin ice.

Can you email businesses without consent?

Mostly, yes — with two caveats. PECR's consent rules protect "individual subscribers", so corporate subscribers — limited companies and LLPs — can be emailed at their company addresses without consent or soft opt-in. But:

  • Sole traders and most partnerships count as individuals. A huge share of UK small businesses are sole traders, so "it's B2B" is not the free pass people assume. If you're prospecting tradespeople, therapists or independent shops, treat them like consumers.
  • UK GDPR still applies to a named person's work email (jane@company.co.uk is personal data). You still need a lawful basis — usually legitimate interests — plus identification, a valid address, and you must honour opt-outs.

Can you use a bought email list?

For emailing individuals: in practice, no. The soft opt-in never applies to third-party data, and consent collected by someone else almost never stretches to you — it had to specifically name your business. The ICO's January 2026 fine of ZMLUK Ltd (£105,000, for nearly 68 million emails) turned on exactly this: people had supposedly consented to hear from a list of 361 "partner" companies, which the ICO ruled was neither informed nor specific. A cheap list is the most expensive thing you can buy for your marketing.

What must every marketing email include?

Three things, whoever you're sending to: your real identity (no disguised or misleading sender names), a valid contact address, and a working unsubscribe that's simple to use — a clear link or a reply that gets processed. Suppress opt-outs promptly and keep them suppressed: emailing someone who unsubscribed is one of the most common complaints the ICO receives, and it usually happens because a shop's platforms aren't synced, not because anyone intended it.

What changed in February 2026?

Three changes from the Data (Use and Access) Act 2025 took effect on 5 February 2026:

  • Fines: PECR's maximum penalty rose from £500,000 to UK GDPR levels — £17.5 million or 4% of global turnover.
  • Charity soft opt-in: charities can now email supporters who expressed interest in their cause, under conditions mirroring the commercial soft opt-in.
  • Cookies: some low-risk cookies — pure statistics and appearance preferences — no longer need prior consent, though you must still tell users and offer a simple opt-out. Full analytics and advertising cookies still require consent.

What did not change: the core consent and soft opt-in rules for businesses are the same as before. If your list was built properly, February 2026 raised the stakes, not the bar.

A compliant email setup for a small online shop

In practice, compliance for a typical Shopify store is about five settings, not a legal project: an un-ticked marketing consent box at checkout (worded so it's a genuine choice), a signup form that says what you'll send, soft opt-in emails restricted to similar products, one synced suppression list across your store and email platform, and identity plus unsubscribe in every footer. Get those right and you can build the flows that actually make money — we covered which ones in the three emails every online shop needs — without collecting a single address you can't lawfully use.

This is the compliance groundwork included in our Conversion & email foundation (£950, fixed) — GA4 and tracking, three core email flows built on properly collected consent, a review system and two landing sections. If you'd rather check what you already have first, the Conversion audit + action plan (£450) reviews your store end to end, and the Marketing audit + 90-day roadmap (£550) covers email alongside your other channels. All async, all fixed-price.

FAQ

Can I email past customers without their consent in the UK?

Usually yes, under the soft opt-in — if you collected their address yourself during the sale, you offered an opt-out at the time and in every email since, and you're emailing about similar products. If you never offered that opt-out at collection, the exemption doesn't apply and you'd need consent.

Do abandoned-cart emails need consent?

An abandoned checkout generally counts as "negotiations for a sale", so the soft opt-in can cover it — provided the customer entered their email themselves, saw an opt-out, and the email is about completing that purchase or similar products. A promotional series to someone who only browsed, without giving details, is different: that needs consent.

Is cold-emailing other businesses legal in the UK?

Emailing limited companies at company addresses doesn't require PECR consent, though UK GDPR still applies to named individuals and you must identify yourself and honour opt-outs. Sole traders and most partnerships count as individuals — cold-emailing them without consent breaches PECR.

What's the penalty for breaking UK email marketing rules?

Since 5 February 2026, up to £17.5 million or 4% of global turnover. Real fines are scaled to the breach — in January 2026 the ICO fined two firms £120,000 and £105,000 for unlawful texts and emails — but even a small fine comes with public naming and a damaged sender reputation.

Does the soft opt-in cover newsletters?

Only if the newsletter genuinely markets your own similar products or services to people whose details you collected during a sale. If it ranges wider, or goes to people who merely downloaded a freebie or entered a competition, rely on proper opt-in consent instead.


Mind the Shop is a UK web and growth studio founded by Andrea, building Shopify stores and lead-gen websites for UK small businesses and running the marketing behind them — with a specialism in compliant marketing for regulated and wellness brands. Every service has a fixed, published price at mindtheshop.co.uk. Questions about your own list? Get in touch.

This article explains marketing rules in general terms and isn't legal advice. Facts checked 4 September 2026 against ICO guidance and the Data (Use and Access) Act 2025 commentary.

Back to blog