If you collect an email address, build an audience, or run a retargeting campaign, you are processing personal data — and in the UK that means the UK GDPR and the Data Protection Act 2018 apply to you. The rules are less mysterious than their reputation suggests. This guide explains, in plain terms, what marketers can and cannot do with customer data, and how to stay on the right side of the line.

This is general information, not legal advice. For decisions about your own business, check the official guidance or take professional advice.

The one rule everything hangs on: a lawful basis

You cannot use someone's personal data for marketing unless you have a lawful basis for doing so. The UK GDPR lists six, but for marketing two matter most:

  • Consent — the person has actively agreed.
  • Legitimate interests — you have a genuine business reason that does not override the person's rights and expectations.

Choosing the right one is not a free-for-all. You pick the basis that genuinely fits the activity, document it, and tell people about it in your privacy notice. You should not switch bases later just because the first one became inconvenient.

Consent under the UK GDPR is a high bar. To be valid it must be:

  1. Freely given — not a condition of buying something unrelated.
  2. Specific — separate consent for separate purposes (email vs SMS, your offers vs partners').
  3. Informed — they know who you are and what they are agreeing to.
  4. Unambiguous — a clear, affirmative action.

That rules out some common shortcuts. Pre-ticked boxes do not count. Bundling marketing consent into your terms and conditions does not count. "By using this site you agree to receive offers" does not count. You also have to make it as easy to withdraw consent as it was to give it, and keep a record of who consented, when, and to what.

UK GDPR for Marketers: What You Can and Can't Do With Customer Data
Photo: KasparasJ / Wikimedia Commons (CC BY-SA 4.0)

A simple test: if you cannot show when and how someone said yes, you probably do not have valid consent.

Legitimate interests: useful, but not a loophole

Legitimate interests is more flexible, but it is not a way to dodge consent. To rely on it you should carry out a short legitimate interests assessment with three parts: identify the interest (e.g. promoting your products), show the processing is necessary for it, and balance it against the individual's rights and reasonable expectations.

It tends to fit things like business-to-business marketing, fraud prevention, or analytics — situations a reasonable person would expect. It rarely justifies emailing or texting individuals out of the blue, because a separate set of rules steps in there.

Where PECR changes the game for email and SMS

The UK GDPR is not the only law in play. The Privacy and Electronic Communications Regulations (PECR) sit on top of it and govern electronic marketing — emails, texts, automated calls and cookies. For marketing emails and texts to individuals, PECR generally requires consent, even where the UK GDPR might have allowed legitimate interests. We cover the cookie side of PECR in our plain-English guide to cookie consent.

There is one important exception, the soft opt-in. You may email or text existing customers about your own similar products without fresh consent if:

  • you got their contact details during a sale, or negotiations for one;
  • you offered an easy opt-out at that point; and
  • every message since has included an easy opt-out.

That exception does not extend to prospects who never bought anything, to unrelated products, or, in most cases, to organisations buying lists. For more on the broader regime, see our overview of UK advertising and marketing compliance.

The data rights you must honour

Customers have rights you are legally required to support. The ones marketers meet most often are:

RightWhat it means in practice
Be informedA clear, accessible privacy notice
AccessProvide a copy of their data on request
RectificationCorrect inaccurate data
ErasureDelete data when there is no good reason to keep it
Object to marketingAn absolute right — you must stop
Withdraw consentAs easy as giving it was

The right to object to direct marketing is absolute: when someone opts out, you must stop, full stop. Most requests must be handled free of charge and within one month. Practically, that means your CRM and email tools need a reliable suppression list, and an unsubscribe must actually unsubscribe.

Practical safeguards that keep you compliant

You do not need a legal department to get the basics right. A few habits cover most of the ground:

  • Map your data. Know what you collect, where it lives, and why. You cannot protect or justify what you have not catalogued.
  • Write a clear privacy notice and link to it wherever you collect data.
  • Use separate, unticked opt-ins for each marketing channel.
  • Honour unsubscribes immediately and centrally, across every tool.
  • Set retention periods and delete dormant contacts you no longer have a reason to hold.
  • Minimise. Collect only the data a campaign genuinely needs.
  • Vet your suppliers. If a third-party platform processes data for you, you need a contract and basic due diligence.

Getting this balance right — respecting the rules while still running effective campaigns — is increasingly a competitive issue, not just a legal one. London consultancy CM Beyer, for instance, sets out a marketer's view of what you can and cannot do with customer data, framing compliance as part of building durable customer trust. That framing is worth borrowing: the businesses that treat data respect as a feature, not a chore, tend to keep their audiences longer.

The bottom line

UK GDPR for marketers comes down to a short discipline: have a lawful basis, prefer genuine opt-in consent for email and SMS, tell people what you are doing, and make it effortless for them to stop. Do that consistently and you will rarely trip over the regulator — and you will run cleaner, more trusted, and ultimately more effective marketing. If you also handle measurement, our guide to marketing attribution pairs well with a privacy-first approach.

Frequently asked questions

Do I always need consent to market to someone?

No. Consent is one lawful basis, but you can sometimes rely on legitimate interests instead — for example, some business-to-business postal or phone marketing. However, marketing emails and texts to individuals are governed by PECR, which usually requires consent.

What is the 'soft opt-in' for email marketing?

It lets you email existing customers about your own similar products or services without fresh consent, provided you obtained their address during a sale (or negotiation of a sale) and gave them a clear chance to opt out, both then and in every message.

How long can I keep marketing data?

Only as long as you have a genuine reason to. There is no fixed period in law; you should set a retention schedule, review inactive contacts and delete data you no longer need.

What happens if I get it wrong?

The Information Commissioner's Office can investigate complaints, issue enforcement notices and impose fines. The bigger day-to-day risk for most marketers is losing customer trust and having campaigns flagged as spam.

Sources

  1. Information Commissioner's Office (ICO)
  2. GOV.UK: Data protection