Ask most small business owners about GDPR and email marketing, and you’ll get a slightly nervous shrug. It’s one of those topics that sounds like it needs a lawyer, so a lot of businesses either avoid email marketing altogether or do it anyway and hope for the best. Neither is a great strategy — email is one of the highest-return marketing channels available, but getting the compliance basics wrong can mean real fines and, just as damaging, a reputation for spamming the people you were trying to build trust with.

The good news: for most small businesses, the rules are more straightforward than they sound once you strip away the legal jargon. Here’s what actually matters.

It’s Not Just GDPR — There’s a Second Law Involved

This is the bit that trips people up first. UK email marketing sits under two overlapping laws, not one:

  • UK GDPR sets the general standard for how personal data (including email addresses) must be handled, and defines what counts as valid consent.
  • PECR (the Privacy and Electronic Communications Regulations) is the specific rulebook for electronic marketing — email, text, and similar messages — and it’s PECR, not GDPR alone, that governs most of the practical rules around sending marketing emails.

In practice, this means a business can be fully GDPR-compliant in how it stores and processes an email address, and still fall foul of PECR by sending marketing to someone who never agreed to receive it. Both matter, and ICO guidance treats them as one joined-up system rather than two separate boxes to tick.

Consent Is the Default — And It Has to Be a Real Opt-In

Under PECR, the default position is that you need consent before sending marketing emails to an individual. Not implied consent, not “they didn’t complain last time” — a clear, affirmative action. That means:

  • No pre-ticked checkboxes
  • No bundling email marketing consent in with terms and conditions (“by signing up you agree to our T&Cs and marketing emails”)
  • The person has to actively opt in, specifically to marketing, not just to using your service

If someone hands you a business card at a networking event, that’s not consent to add them to a newsletter — however tempting it is to treat it that way.

The “Soft Opt-In” — The Exception Most Small Businesses Actually Rely On

There’s one genuinely useful exception, commonly called the soft opt-in, and it’s the reason most small businesses can email existing customers without a separate sign-up form. It applies when all of the following are true:

  1. You collected the person’s contact details during a sale, or while negotiating one
  2. You only email them about your own similar products or services (not something unrelated)
  3. You gave them a clear chance to opt out at the point you collected their details
  4. Every email you send afterwards includes an easy, obvious way to unsubscribe

Get all four right, and you can email existing customers about relevant offers without chasing separate marketing consent. Miss even one — for example, forgetting the opt-out option at the point of collection — and the exception doesn’t apply, which means you’re back to needing explicit consent.

One important limit: the soft opt-in never applies to bought or rented lists. If you’ve bought an email list from a third party, there is no version of the soft opt-in that makes emailing it compliant — you need genuine, specific consent from each person on that list, which a purchased list almost never has.

B2B Is Slightly Different — But Not a Free Pass

Marketing to a generic company inbox (info@company.com) is treated differently to marketing a named individual (sarah@company.com). PECR’s consent rules are built around individual people, not corporate entities as such — but the moment you’re emailing a named person at a business, UK GDPR still applies to how you handle their personal data, even if the message itself is B2B. In short: B2B email marketing has more flexibility than consumer marketing, but “it’s B2B so the rules don’t apply” isn’t accurate.

What Every Marketing Email Needs, Regardless of How You Got Consent

Whether someone opted in directly or you’re relying on the soft opt-in, current ICO guidance is consistent on two points that come up in nearly every enforcement case:

  • Consent records must be clear and retrievable. If you can’t show when and how someone agreed to receive marketing, you can’t demonstrate compliance if it’s ever questioned.
  • Unsubscribing must be as easy as subscribing was. A hidden or multi-step unsubscribe process is itself a compliance problem, not just bad practice.

Why This Matters More As Your List Grows

A five-person mailing list run informally from a personal inbox rarely attracts attention. But as email becomes a genuine part of how a business grows — which, as we’ve covered in our comparison of email marketing and social media, is exactly where the strongest long-term marketing return tends to sit — the compliance basics matter more, not less. A larger list means more people who could complain, more data being processed, and more scrutiny if something goes wrong.

Getting the Foundations Right From the Start

The easiest time to get email marketing compliance right is before you’ve built a large list the wrong way, not after. That means a proper sign-up process with genuine opt-in, a clear privacy notice explaining what people are signing up for, and an email platform that handles unsubscribes and consent records properly rather than a spreadsheet and a BCC field.

Bildabiz builds and manages email marketing for small businesses across the UK, including making sure sign-up forms, consent records, and campaigns are set up compliantly from day one. Find out more about our email marketing services or get in touch to talk through your current list and process.

This article is a general guide and not a substitute for legal advice — if you’re unsure about a specific situation, the ICO’s own guidance on electronic mail marketing is the authoritative source, or it’s worth speaking to a data protection specialist for anything beyond general practice.