The RoadmapScaleImproving Customer Retention

Legalities around Data and Marketing Communications

Understanding UK Data Protection, Consent, and Marketing Laws to Retain Customers Legally and Ethically

6 minute read
Scale — Improving Customer Retention
✓ Verified against GOV.UK
Raj Patel
Written by Raj Patel
Operations & Scale Editor · GuideToBusiness
Back to Scale

If you’re scaling a UK small business and want to keep customers coming back, you can’t ignore the legalities around data and marketing communications. One misstep could land you in hot water with regulators—or lose customer trust for good. This guide breaks down the real UK rules, from GDPR to PECR, and shows you exactly how to collect, store, and use customer data for marketing without falling foul of the law. Whether you’re emailing, texting, or running loyalty schemes, you’ll learn what’s allowed, what’s risky, and how to put compliance at the heart of your customer retention strategy.

Why Data and Marketing Laws Matter for UK Small Businesses

For UK small businesses, building loyal customer relationships is often about smart, targeted communications. But every text, email, or call to a customer is governed by strict UK laws. The General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) set out what’s allowed—and hefty fines await those who get it wrong. In 2023 alone, the ICO issued millions of pounds in penalties for unlawful marketing, and even small firms are not exempt.

Beyond fines, there’s the reputational hit. Customers are savvy: a single breach or unsolicited campaign can undermine years of trust and damage your brand. Worse, negative publicity can go viral, especially if customers take to social media. That’s why compliance isn’t just a box-ticking exercise—it’s a real business risk and opportunity.

Understanding the legal landscape helps you design marketing strategies that are both effective and ethical. It also gives you the confidence to innovate, knowing you’re not putting your business—or your customers—at risk. Let’s unpack exactly what you need to consider.

ICO Enforcement

The Information Commissioner's Office (ICO) fined UK companies over £5 million for unlawful direct marketing in 2023. Many were small businesses unaware of their obligations.

The Legal Framework: GDPR, PECR, and the Data Protection Act 2018

When dealing with customer data and marketing, three key UK laws come into play. The GDPR (as retained in UK law post-Brexit) sets the gold standard for data protection and consent. The Data Protection Act 2018 tailors GDPR for the UK context. Meanwhile, PECR is the unsung hero—or villain—of marketing communications, with specific rules for emails, texts, calls, and cookies.

GDPR covers any personal data—think names, emails, addresses, purchase history, even IP addresses—that can identify an individual. It demands transparency, lawfulness, and accountability in how you collect, store, and use data. For marketing, this means you must have a lawful basis (often, but not always, consent).

PECR comes into play whenever you send electronic marketing: emails, texts, automated calls, and cookies. It’s stricter than GDPR in some ways, especially for unsolicited messages. Even if you have customer data, you can’t just start emailing—PECR adds extra hoops.

ICO is Your Regulator

The Information Commissioner's Office (ICO) enforces data and marketing law in the UK. Their website (ico.org.uk) is the best official source for current guidance and case studies.

LawWhat it CoversWho EnforcesKey Points
GDPR (UK)All personal data processingICOLawful basis, transparency, rights
Data Protection Act 2018UK-specific data rulesICOTailors GDPR for UK context
PECRElectronic marketing & cookiesICORules for emails, texts, calls, cookies

What Counts as 'Consent' for Marketing Under UK Law?

Consent is the cornerstone of lawful marketing under both GDPR and PECR. But not all consent is created equal. UK law requires that consent for marketing must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, silence, or inactivity don’t count. You must give people a real choice, and make it just as easy to withdraw consent as to give it.

For most direct marketing—especially by email, text, or automated call—you need explicit, opt-in consent. There’s one main exception: the 'soft opt-in.' This lets you market similar products or services to existing customers, but only if you collected their details during a sale (or negotiation for a sale), gave them a chance to opt out at the time, and offer an opt-out in every future message.

Recording consent is just as important as obtaining it. You need to keep clear records of who consented, when, how, and to what. If someone challenges you or complains to the ICO, you’ll need this evidence.

Transparent Consent Forms

Use plain English in consent requests. Tell customers exactly what they’re signing up for, how you’ll use their data, and how to opt out.

  • Consent must be given by a clear, affirmative action (ticking a box, clicking 'I agree', etc.).
  • No pre-ticked boxes or default opt-ins.
  • Separate consent for different marketing channels (email, SMS, post) is best practice.
  • Always provide an easy opt-out in every marketing message.

Collecting, Storing, and Processing Customer Data Lawfully

Collecting customer data for marketing isn’t just about a sign-up form. Under GDPR, you must only collect data that is necessary, adequate, and relevant for your stated purpose. You can’t ask for a customer’s date of birth if you don’t need it. Your privacy notice must clearly set out how you’ll use their data, who you’ll share it with, and how long you’ll keep it.

Once you have the data, storage matters. The law expects you to keep data secure, accurate, and up to date. This means using secure servers, limiting access to only those who need it, and having processes for regular data reviews and deletion. If you use cloud services, check where data is stored—transfers outside the UK (especially to the US or elsewhere) need extra safeguards under UK GDPR rules.

Processing includes anything you do with the data—sending emails, profiling for loyalty schemes, or analysing buying habits. Every use must have a lawful basis, and you must be able to justify it if challenged. If you want to use data for new purposes (say, a new marketing campaign), you may need fresh consent.

Data TypeLawful Basis NeededRetention Guidance
Name/Contact DetailsConsent or contract (soft opt-in)Until customer opts out or 2 years after last engagement
Purchase HistoryLegitimate interests (with opt-out option)5-7 years for accounting, shorter for marketing analysis
Behavioural Data (e.g. website tracking)Consent (via cookies)As short as possible; review annually
Don’t Over-Collect

Asking for unnecessary data can breach GDPR. Only collect what you truly need for your stated purpose.

Rules for Email, SMS, and Telephone Marketing to Customers

The rules get stricter when it comes to the channel you use. For email and SMS marketing to individuals (B2C), PECR requires prior consent—unless you’re using the soft opt-in for existing customers, and even then, you must offer a clear opt-out every time. For business contacts (B2B), rules are a bit more relaxed, but you still need to offer an opt-out and comply with data protection principles.

For live sales calls, you don’t always need prior consent, but you must not call anyone who has registered with the Telephone Preference Service (TPS) or who has told you not to call. Automated calls, however, always require explicit opt-in consent. If you use telemarketing agencies, you’re still responsible for compliance—they act as your data processor, but you are the data controller.

Every marketing message—email, text, or call—must identify your business and provide an easy, free way to opt out. For emails, this usually means an unsubscribe link. For texts, a STOP reply. For calls, a verbal option. Never hide your identity or spoof numbers; it’s illegal and a red flag for the ICO.

  • Email/SMS to individuals: consent required unless soft opt-in applies.
  • B2B marketing: opt-out must be provided, and data protection still applies.
  • Live sales calls: do not call numbers on the TPS or anyone who has opted out.
  • Automated calls: always require explicit consent.
TPS Non-Compliance

Calling numbers listed on the Telephone Preference Service is a breach of PECR, even if you have their details from elsewhere. Fines up to £500,000 are possible.

Unsubscribes Matter

In 2022, the ICO reported that 61% of UK consumers unsubscribed from at least one marketing list due to unclear opt-out processes.

Using Cookies, Tracking, and Profiling: What’s Legal?

If your business uses website analytics, tracking pixels, or runs personalised ads, PECR and GDPR both apply. Any non-essential cookies (including those for analytics, advertising, or social media) require prior, informed consent. That means a clear cookie banner—no default opt-ins, no confusing settings. You can’t set these cookies until the user agrees.

Profiling—using data to predict behaviour or segment customers—requires transparency and, in some cases, consent. If your profiling has a significant impact on individuals (like credit checks or eligibility for offers), you must inform them and offer a way to object. Using third-party marketing tools (like Facebook Pixel, Google Analytics, or email automation software) doesn’t absolve you of responsibility: you need Data Processing Agreements and must check their compliance.

The ICO has cracked down on non-compliant cookie banners and unlawful profiling. If you use these tools as part of your retention or remarketing strategy, review your processes regularly and update your privacy notice to reflect all tracking and profiling activities.

  • Always obtain consent for non-essential cookies before setting them.
  • Explain clearly what each cookie does and who sets it.
  • Give users a real choice (accept, reject, or customise cookies).
  • Review third-party marketing tools’ data practices for GDPR compliance.

Customer Rights: Access, Deletion, and Objections to Marketing

UK customers have powerful rights under GDPR and the Data Protection Act 2018. They can ask you what data you hold (Subject Access Request), demand corrections, request deletion (the 'right to be forgotten'), or object to any direct marketing. You must act promptly, usually within one month, and never charge for these requests in most cases.

If a customer objects to marketing, you must stop immediately—regardless of how or when they gave consent. Keeping records of opt-outs is just as important as keeping records of opt-ins. If you use multiple systems or platforms, ensure opt-outs sync across all of them.

Responding to data requests isn’t optional. If you ignore or delay, customers can complain to the ICO, leading to investigations and possible penalties. Document your processes for handling requests and train your staff to spot and escalate them quickly.

RightWhat It MeansYour Obligation
AccessCustomer can request all data you holdRespond within 1 month, provide copy of data
RectificationRequest correction of inaccurate dataCorrect promptly and notify customer
ErasureRequest deletion of personal dataDelete unless you have a legal reason to keep it
ObjectOpt-out of direct marketingCease all marketing immediately

Data Sharing, Outsourcing, and International Transfers

Outsourcing—whether to a marketing agency, CRM provider, or cloud platform—doesn’t remove your legal responsibilities. Under UK GDPR, you are the 'data controller,' and anyone processing data on your behalf is a 'data processor.' You must have a written Data Processing Agreement (DPA) that sets out security, confidentiality, and the processor’s obligations.

If your provider is outside the UK (for example, using US-based marketing software), you must ensure appropriate safeguards are in place. This may mean using Standard Contractual Clauses or checking for an 'adequacy decision' from the UK government. The rules are strict and change often—always check latest ICO guidance.

Never share or sell customer data to third parties for their own marketing unless you have explicit, informed consent. Even sharing data within your own group of companies for marketing purposes can require new consent, depending on how data was originally collected.

  • Always have a Data Processing Agreement with any third party handling customer data.
  • Check where your data is physically stored—UK, EEA, or elsewhere.
  • If using cloud services, ensure encryption and robust access controls.
  • Never share data for third-party marketing without explicit consent.

Common Pitfalls and How to Avoid Them

Many UK small businesses fall foul of the law through simple mistakes. One common error is assuming the rules don’t apply to small firms or B2B marketing—both are myths. Another is failing to keep clear records of consent or not syncing opt-outs across all platforms. Using bought-in marketing lists is especially risky: if the list isn’t fully compliant, you’re liable for any breaches.

Outdated privacy notices, poorly configured cookie banners, and sloppy data hygiene (e.g. keeping old customer data for too long) are all red flags for the ICO. Staff training is another weak point; everyone who handles customer data or marketing must know the basics of compliance.

Finally, don’t underestimate the impact of a single complaint. The ICO can investigate on the basis of one unhappy customer, and penalties are often publicised. Prevention—through regular audits, updated policies, and a culture of compliance—is always cheaper than cure.

Bought-In Lists

Never use purchased email or marketing lists unless you are certain every contact has given GDPR-compliant consent for your specific marketing. Most don’t.

Practical Steps: Making Your Marketing Compliant

Getting compliance right isn’t about ticking boxes—it’s about embedding legal and ethical practices into every stage of your customer marketing. Regularly review your processes, update your privacy notices, and make compliance a team responsibility. Here’s a practical step-by-step to get you on track.

Ensuring Data Compliance for UK Small Businesses

1
Map Your Data Flows
Document how customer data enters your business, where it’s stored, who has access, and how it’s used for marketing. Identify all systems and third parties involved.
2
Review Consent Mechanisms
Check your sign-up forms, cookie banners, and opt-in processes. Update language to be clear, unambiguous, and channel-specific. Remove pre-ticked boxes or forced opt-ins.
3
Update Your Privacy Notice
Ensure your privacy policy is up to date, covers all uses of data (including profiling and third-party sharing), and is easily accessible. Link to it in every marketing communication.
4
Test Your Opt-Out Processes
Try unsubscribing or opting out from all your marketing channels. Make sure it’s quick, easy, and works across all platforms. Fix any gaps immediately.
5
Train Your Team
Educate everyone involved in marketing or data handling about the basics of GDPR, PECR, and customer rights. Make compliance part of onboarding and ongoing training.
6
Audit Third-Party Providers
Review contracts and Data Processing Agreements with any agencies, CRM systems, or cloud providers. Check their security and compliance posture.
7
Plan for Data Requests
Set up a clear process to handle Subject Access Requests, corrections, deletions, and opt-outs. Assign responsibility and set up response templates.

Useful Resources and Where to Get Help

The ICO (Information Commissioner’s Office) is the UK’s official regulator for data and marketing law. Their website (ico.org.uk) has practical guides, checklists, model privacy notices, and case studies tailored for small businesses. ACAS offers guidance on data and employment issues. The Federation of Small Businesses (FSB) and local Chambers of Commerce can provide further advice and training.

If you’re unsure about a specific campaign or technology, consider a legal health check with a data protection adviser or solicitor. Many insurers now offer cyber and data protection cover, including legal support in case of a breach or ICO investigation. Don’t wait for a problem—proactive advice is almost always cheaper than cleaning up after the fact.

Free ICO Tools

The ICO’s free self-assessment tool for SMEs covers data mapping, marketing, and cookies. It’s a good starting point for any small business.

Key Takeaways
  • UK law is strict on data and marketing. GDPR, PECR, and the Data Protection Act 2018 all apply to small businesses and set high standards for data use and communications.
  • Consent must be clear and specific. Use plain, explicit opt-in language and always offer an easy opt-out in every message.
  • Soft opt-in is limited. You can only rely on it for marketing similar products to existing customers and must offer an opt-out every time.
  • Every marketing channel has its own rules. Email, SMS, calls, and cookies all have different requirements—don’t assume one-size-fits-all.
  • Customer rights are powerful. Respond promptly to data requests, corrections, deletions, and marketing objections—or risk ICO enforcement.
  • Outsourcing doesn’t remove your responsibility. Always have robust Data Processing Agreements and check where your data is stored.
  • Bought-in lists are a major risk. Most do not meet UK consent standards; using them is likely to result in complaints and fines.
  • Regular audits and staff training are essential. Embedding compliance into your processes protects your business and builds customer trust.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.