PECR compliance for a newsletter
Privacy and Electronic Communications Regulations 2003. This page applies it to one kind of product (newsletter), so you get the obligations that are actually yours instead of a summary of the whole statute.
Does it apply to you?
Cookies, similar technologies and electronic marketing to UK users.
What a newsletter typically processes
- email addresses collected through a signup form
- open and click tracking
- list data held by an email service provider
Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.
Documents you need
The intersection of what PECR requires and what a newsletter actually does:
- Cookie policy and consent banner
Rights you must honour
PECR gives people in the United Kingdom the right to:
- Withdraw consent at any time
Cookies and trackers
Nothing non-essential may load before the visitor agrees. Analytics and marketing scripts must be blocked until then — a banner that only informs is not enough.
See what your site is actually missing
Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.
No signup · result in seconds
Primary sources
- PECR — Privacy and Electronic Communications Regulations 2003 · official text · Information Commissioner's Office (ICO)
- Reg. 6 — Consent before storing or accessing information on a device
- Reg. 22 — Consent for electronic mail marketing
PECR for other kinds of product
Other frameworks for a newsletter
This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.