The Soft Opt-In Explained: When UK Businesses Can Email Without Explicit Consent

  • The soft opt-in lets you email existing customers about similar products or services without collecting fresh consent, if you meet every PECR condition.
  • You must collect details during a sale, market only similar products, and offer an opt-out at collection and every message.
  • A separate charitable route now exists for eligible charities, covering supporter details collected on or after 5 February 2026.
  • Getting this wrong is costly, because PECR penalties are now much higher than they used to be.

Reaching out to past customers is one of the fastest ways to generate repeat sales, but UK inbox privacy rules mean you can’t just email anyone on your contact list. Fortunately, the Privacy and Electronic Communications Regulations (PECR) include a useful rule known as the “soft opt-in,” which lets you market similar products or services to existing buyers without collecting fresh consent.

Understanding how to apply this rule correctly ensures you stay on the right side of the regulator while making the most of your existing customer relationships. This blog breaks down how the soft opt-in works in practice, the specific conditions you must meet, the newer rules for charities, and the common compliance mistakes to avoid.

What is the soft opt-in?

Think of it as a narrow permission, not a shortcut around the rules. It applies only when you already have a customer relationship and keep your marketing close to what that person came to you for.

A few features define this permission:

  • Existing relationship: The person is already your customer, not a cold contact.
  • Direct collection: You gathered their details yourself during a sale or a genuine pre-sale discussion.
  • Similar products or services: You only market your own products or services that are similar to what they bought or asked about.
  • Opt-out at collection: You offered a clear way to say no when you took their details.
  • Opt-out in every message: Every marketing message includes an easy way to unsubscribe.

The Information Commissioner’s Office (ICO) regulates PECR and can fine organisations that break it. For many small businesses, this matters because email is a high-value channel. In our Q1 2026 Small Business Now report, 41% of small business owners expected email marketing to be their most valuable channel this year. Keeping that channel lawful protects real revenue.

This exception is one slice of a wider idea, permission-based email marketing, which is about earning the right to land in someone’s inbox. Treat it as a limited permission you keep meeting, never as a loophole.

Types of lawful permission for UK marketing emails

This exception isn’t your only lawful route to the inbox. Knowing the main options helps you match the right basis to each contact, so start by learning the three below.

Express consent: A clear, active opt-in that meets the UK General Data Protection Regulation (UK GDPR) standard. The person takes a positive step to agree, so pre-ticked boxes, silence, and inactivity never count.

Rely on it when you have no existing sale to point to, or when you want to market beyond your own similar products. It gives you a clear record that the person actively asked to hear from you.

Here are some example opt-ins:

  • A visitor ticks an unticked box to join your newsletter on your website.
  • A customer texts a keyword to sign up for your Short Message Service (SMS) offers.

The products and services soft opt-in

Products and services soft opt-in: The classic route in Regulation 22(3) of PECR. Use it when you collected someone’s details during a sale and want to promote your own similar products or services.

You must have offered an opt-out at collection and include one in every message. It fits everyday follow-ups where the marketing clearly relates to the original purchase.

Here are some example situations:

  • A café takes email addresses at checkout, then emails those customers about a new lunch menu.
  • A high street salon collects details at a booking, then promotes a similar new treatment.

The charitable purposes soft opt-in

If you run a charity, a separate route may apply to your newer supporter details. Charitable soft opt-in: a provision in Regulation 22(3A) that began on 5 February 2026. Eligible charities may send marketing where the sole purpose is furthering their charitable purposes.

It applies only to details collected on or after that date, so it can’t cover an older supporter list. Only organisations that meet the statutory definition of a charity qualify, so community interest companies and unregistered groups don’t. Charity regulation also varies across the UK, with separate regulators in England and Wales, Scotland, and Northern Ireland, so check your regulator’s guidance alongside PECR.

Here are some example uses:

  • A London charity emails people who signed up to support its cause about a new campaign.
  • An Edinburgh charity texts supporters who offered to help about a volunteering drive.

How to use the soft opt-in correctly

Ready to put this into practice? Follow these four steps and it becomes a routine habit rather than a compliance headache. Now for the good stuff: most of the work is about how you collect details and how you send.

Step 1: Check how you collected the details

Start by checking how you collected each person’s details. They must have come directly from the person during a sale or a genuine pre-sale discussion, or the exception doesn’t apply.

This rules out bought, rented, or brokered lists, and details another organisation passed to you. As the ICO puts it, there’s no such thing as a third-party marketing list that complies. A Cardiff café that captured emails at the till has done it the right way. It helps to focus on collecting the right contact details at the point of sale.

Step 2: Market only your own similar products or services

The next limit is relevance between the original purchase and the later message. You can only promote your own products or services that are similar to what the person bought or asked about.

Marketing unrelated items, or sending offers for another company, breaks the exemption. A salon promoting a new treatment to a haircut customer is on safe ground; an unrelated insurance offer is not.

Step 3: Offer a clear opt-out when you collect the details

When someone shares their details, that’s the moment to show the opt-out choice clearly. Give a simple way to refuse marketing right then, not buried in a privacy policy they never read.

A tick box on a booking or checkout form does the job. Good UK list-building tools make it easy to add that opt-out to sign-up forms.

Step 4: Include an opt-out in every message you send

Check every message for a free, easy way to unsubscribe. An opt-out offered only later, such as in an order confirmation, doesn’t meet the collection-time condition.

Automated messages are easy to overlook. When you set up email automation flows like welcome or confirmation series, keep the opt-out language on every send, including a B&B’s booking email that also carries marketing.

How do you check your lists are soft opt-in ready?

Not sure your current list would pass a check? Work through these three quick reviews before your next send, and you’ll know exactly who you can reach.

Audit where each contact came from

Record the source, date, and method for every contact you hold. This shows who you can lawfully reach and who you can’t.

It stings to trim a list, but a smaller compliant list beats a big risky one. Contacts you can’t evidence as direct sign-ups shouldn’t be marketed to until you fix the basis.

Confirm the ‘similar products or services’ test

Relevance is the next thing to test once you know where a contact came from. Map what each person bought or enquired about against what you plan to send.

This route is more likely to apply when your message closely relates to the original purchase or enquiry. If a group only ever bought one product line, keep your marketing to that line and anything genuinely similar.

Review your opt-out and record-keeping

If a complaint ever arrives, your records and unsubscribe trail will do the heavy lifting. Keep dated copies of your sign-up forms and check that every template carries a working unsubscribe.

The right email marketing platform can store those opt-out records and form versions in one place, which makes each review faster.

Key PECR and UK GDPR rules for UK businesses

Treat the rules below as your baseline, whichever permission route you use. They apply across email, text, and social messages, so read them before your next campaign.

PECR, Regulation 22 and the ICO

Under PECR, this exception lives in Regulation 22 of PECR, and the ICO enforces it. The same regulation sets the default rule that you need consent before marketing to individuals.

‘Electronic mail’ is defined broadly, so it covers email, SMS, and social media direct messages. The same conditions follow your message across each of those channels.

Where you rely on consent instead, it must meet the UK GDPR standard. The ICO’s electronic mail marketing guidance sets out how to get this right.

Valid consent has to be freely given, specific, informed, and unambiguous, shown by a clear affirmative action. In practice, pre-ticked boxes, silence, and consent bundled into your terms all fail.

Penalties and enforcement

Getting this wrong now carries real financial risk. One ICO enforcement action against HelloFresh ended in a £140,000 fine for a large-scale spam email and text campaign. It breached Regulation 22 of PECR. The lesson is plain: Unclear consent and a hard-to-find opt-out can turn routine marketing into a costly breach.

The ceiling has risen too. Since 5 February 2026, the Data (Use and Access) Act 2025 has raised the maximum PECR penalty to £17.5 million or 4% of annual turnover, whichever is higher. For a small business, the turnover-based figure is often the one that bites, because it scales with your revenue.

Soft opt-in best practices

A few habits keep you compliant and build trust.

  • Keep proof of every contact: Record who signed up, when, and how.
  • Offer the opt-out early: Put it where you collect details, not buried in a privacy policy.
  • Stay on topic: Only market products or services similar to what the person bought.
  • Match every channel: The rules cover email, text, and social messages alike.
  • Refresh stale contacts: If someone hasn’t heard from you in a long while, the relationship may be too old to rely on.
  • Keep charity fundraising separate: Charities shouldn’t use the products and services route for fundraising appeals.
  • Make unsubscribing painless: One click should be enough, and never ask people to log in to opt out.
  • Learn the wider rules: Good habits sit on solid general practice, so read up on how to keep your email marketing legal.

Do these consistently and the exception becomes second nature rather than a worry.

Common soft opt-in mistakes

These slip-ups are common, and most come from good intentions rather than bad ones.

  • The mistake: You treat a bought or rented list like your own customers.
  • How to fix it: Only send marketing to people who gave you their details directly.
  • The mistake: You hide the opt-out inside a long privacy policy.
  • How to fix it: Show a clear opt-out the moment you collect someone’s details.
  • The mistake: You market unrelated products or promote another company’s offers.
  • How to fix it: Stick to your own products or services that are similar to what the person bought.
  • The mistake: You assume the charitable route covers your old supporter list.
  • How to fix it: Remember it only applies to details collected on or after 5 February 2026.
  • The mistake: You add an opt-out at sign-up but forget it in later messages.
  • How to fix it: Put a working unsubscribe in every message you send.

Put permission-first email marketing into practice

Complying with PECR’s soft opt-in rules doesn’t have to mean adding hours of manual admin to your week. Once you know where your contacts came from, the right tools can handle the heavy lifting of compliance in the background so you can email existing customers with total confidence.

Constant Contact makes permission-based list management simple and automatic:

  • Automated opt-out management: Every email includes a working, one-click unsubscribe link. When a recipient opts out, Constant Contact updates your list instantly—ensuring you stay well within the five-business-day PECR requirement without lifting a finger.
  • Compliant sign-up forms: Build custom forms for your website or till with explicit opt-out checkboxes, making it easy to capture valid soft opt-in details directly at the point of sale.
  • Segmented contact lists: Group subscribers by purchase history or sign-up date so you can easily target past buyers with “similar products” and keep your marketing strictly relevant.
  • Built-in sender details: Pre-formatted email footers automatically pull in your verified business name and physical contact details, ensuring every message meets ICO identification standards.

Ready to run compliant, permission-first campaigns? Start a free 30-day trial of Constant Contact to set up your lists, automate your opt-outs, and send with peace of mind.

FAQs

No, it’s a separate PECR exception with its own conditions. It isn’t the UK GDPR consent basis, and the two aren’t interchangeable.

Can I use the soft opt-in for bought lists?

Under PECR, bought, rented, or third-party lists never qualify. You must collect the details directly from the person during a sale or pre-sale discussion.

Does the soft opt-in apply to charities?

The charitable route began on 5 February 2026 for organisations that meet the statutory definition of a charity. It only covers contacts whose details were collected on or after that date.

How long can I keep emailing a customer under the soft opt-in?

PECR sets no fixed time limit, but the relationship should stay reasonably recent. Very old contacts weaken your basis, so gather fresh consent if you’re unsure.

Share with your network
Avatar photo

Whitney Filloon is a writer, content strategist, and former Vox Media journalist who has worked with enterprise brands like Skype and Microsoft and helped dozens of small businesses figure out their "secret sauce".

Related Articles