UK — PECR 2003 (cookies and electronic marketing)
The UK's ePrivacy rules (UKSI 2003/2426), substantially restructured by the Data (Use and Access) Act 2025: the cookie consent rule and its exceptions now live in Schedule A1, and PECR fines were raised to UK GDPR levels.
Applicability to EdTech
- Cookie rule (regulation 6 → Schedule A1): storing or accessing information on terminal equipment needs consent, with the DUAA's expanded exceptions — strictly necessary purposes, and now also statistical/service-improvement collection, appearance/functionality preferences, emergency assistance and security updates, each with their own conditions. A school platform's analytics may fit the new statistical exception if its conditions (information duty, objection right) are met — check Schedule A1's exact terms before relying on it.
- E-mail marketing (regulation 22): opt-in for unsolicited marketing e-mail to individual subscribers, soft opt-in for existing customers of similar products with per-message refusal; sender identity must not be concealed (regulation 23).
Contents
| Document | Covers |
|---|---|
| COOKIES-AND-MARKETING.md | regulations 6, 22, 23 |
| STORAGE-CONSENT.md | Schedule A1 in full (consent + the post-DUAA exception catalogue) |
Enforcement
ICO — since the DUAA 2025, PECR breaches carry UK-GDPR-level fines (up to £17.5m / 4% turnover).
Related
- UK GDPR — consent standard incorporated by reference
- EU ePrivacy Directive — the origin instrument
- PT Lei 41/2004, PL PKE — EU siblings
Sources
Meta
Regulation text is reproduced verbatim from the consolidated text on legislation.gov.uk via the shared CLML converter by tools/legislation-gov-uk/build_pecr.py; verify re-checks every source text node. Official ids kept as anchors.