S.I. 2003 No. 2426 · Last verified

PECR

PECR's cookie rule and penalty regime were rewritten on 5 February 2026; this record carries the wording now in force, not the superseded text. Regulation 6 was substituted, Schedule A1 inserted and Schedule 1 replaced on that date. Reproduced here with section numbers and links.

Citation
S.I. 2003 No. 2426
Jurisdiction
GB
Regulator
Information Commissioner's Office (ICO)
Last verified

What it is

Regulation 6 was substituted, Schedule A1 inserted and Schedule 1 replaced on that date. Reproduced here with section numbers and links.

The Privacy and Electronic Communications (EC Directive) Regulations 2003 ↗

Key dates

  • Made: — S.I. 2003/2426 introduction
  • Laid before Parliament: — S.I. 2003/2426 introduction
  • Coming into force: — S.I. 2003/2426 introduction
  • Regulation 6 substituted: — Textual amendment note: “Reg. 6 substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 112(2), 142(1); S.I. 2026/82, reg. 2(w)”
  • Schedule A1 inserted: — Textual amendment note: “Sch. A1 inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 12; S.I. 2026/82, reg. 2(z13)”
  • Schedule 1 (enforcement powers) substituted: — Textual amendment note: “Sch. 1 substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 13; S.I. 2026/82, reg. 2(z14) (with regs. 8-11)”

Scope

Regulation 4 — Relationship between these Regulations and the data protection legislation (revised text)

(1) Nothing in these Regulations shall relieve a person of his obligations under the data protection legislation in relation to the processing of personal data.

(2) In this regulation— “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act); “personal data” and “processing” have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4) and (14) of that Act).

(3) Regulation 2(2) and (3) (meaning of certain expressions) do not apply for the purposes of this regulation.

legislation.gov.uk — PECR reg. 4 (revised text, as amended) ↗

Penalties

Data Protection Act 2018, section 157(5), as applied by Schedule 1 paragraph 18 (revised text)

The “higher maximum amount” is— (a) in the case of an undertaking, £17,500,000 or 4% of the undertaking’s total annual worldwide turnover in the preceding financial year, whichever is higher, or (b) in any other case, £17,500,000.

Data Protection Act 2018, section 157(6), as applied by Schedule 1 paragraph 18 (revised text)

The “standard maximum amount” is— (a) in the case of an undertaking, £8,700,000 or 2% of the undertaking’s total annual worldwide turnover in the preceding financial year, whichever is higher, or (b) in any other case, £8,700,000.

How the DPA 2018 ceilings attach to PECR (the modification)

Schedule 1, paragraph 18 (revised text)

18. Section 157 has effect as if— (a) subsection (1) were omitted; (b) in subsection (2)— (i) for “Part 3 of this Act” there were substituted “the PEC Regulations”; (ii) in paragraph (a), for the words from “section 35” to “or 78” there were substituted “regulation 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23, 24 or 32B(4) or (5)”; (c) subsections (3) and (4A) were omitted…

Why the pre-2026 ceiling can still apply (transitional saving)

S.I. 2026/82, regulation 11

11.—(1) Where any act or omission constituting a breach of the PEC Regulations occurred before 5th February 2026, any enforcement action taken in respect of that act or omission must be taken under those Regulations as they had effect immediately before that date.

The cookie rule, as it now reads

Regulation 6(1) (substituted 5 February 2026)

6.—(1) Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.

Consent moved into Schedule A1

Schedule A1, paragraph 2(1) (inserted 5 February 2026)

2.—(1) Regulation 6(1) does not prevent a person storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user if the subscriber or user— (a) is provided with clear and comprehensive information about the purpose of the storage or access, and (b) gives consent to the storage or access.

Unsolicited marketing email

Regulation 22(2)

Except in the circumstances referred to in paragraph (3) or (3A), a person shall neither transmit, nor instigate the transmission of, unsolicited communications for the purposes of direct marketing by means of electronic mail unless the recipient of the electronic mail has previously notified the sender that he consents for the time being to such communications being sent by, or at the instigation of, the sender.

Pending changes

The Data (Use and Access) Act 2025 (c. 18) has already reshaped this instrument: regulation 6 was substituted and Schedule A1 inserted on 5 February 2026 (S.I. 2026/82), and Schedule 1 (the Commissioner's enforcement powers) was substituted on the same date with transitional savings in S.I. 2026/82 regs 8-11. legislation.gov.uk states the revised text is up to date with changes in force on or before 7 September 2026, with outstanding changes from S.I. 2026/386 pending application.

Sources

Last verified:

This page is for information only and is not legal advice. It reproduces the regulation's own wording; always confirm against the primary source linked above and consult qualified counsel for how it applies to your organisation.

Cite this page

Attributing this record helps other researchers verify it independently.

"PECR." Certifidex, FutureTechnologies. Last verified 7 September 2026. https://certifidex.com/regulations/pecr

All regulations →