DJ Daily Junction.mobi portal

KaiOS phone? Install the free app »
SearchNewsWorldBusinessTechTVWeatherStarsMore

UK GDPR for Marketers: What You Can and Can't Do With Customer Data

Marketing · April 14, 2026 · Liam Chen · 5 min

[View image]

A plain-English guide to the UK GDPR for marketers: lawful basis, when to use consent versus legitimate interest, the rules for email marketing, and the data rights every customer can exercise.

If you collect an email address, build an audience, or run a retargeting campaign, you are processing personal data — and in the UK that means the UK GDPR and the Data Protection Act 2018 apply to you. The rules are less mysterious than their reputation suggests. This guide explains, in plain terms, what marketers can and cannot do with customer data, and how to stay on the right side of the line.

This is general information, not legal advice. For decisions about your own business, check the official guidance or take professional advice.

The one rule everything hangs on: a lawful basis

You cannot use someone's personal data for marketing unless you have a lawful basis for doing so. The UK GDPR lists six, but for marketing two matter most:

Choosing the right one is not a free-for-all. You pick the basis that genuinely fits the activity, document it, and tell people about it in your privacy notice. You should not switch bases later just because the first one became inconvenient.

Consent: what "good" actually looks like

Consent under the UK GDPR is a high bar. To be valid it must be:

  1. Freely given — not a condition of buying something unrelated.
  2. Specific — separate consent for separate purposes (email vs SMS, your offers vs partners').
  3. Informed — they know who you are and what they are agreeing to.
  4. Unambiguous — a clear, affirmative action.

That rules out some common shortcuts. Pre-ticked boxes do not count. Bundling marketing consent into your terms and conditions does not count. "By using this site you agree to receive offers" does not count. You also have to make it as easy to withdraw consent as it was to give it, and keep a record of who consented, when, and to what.

A simple test: if you cannot show when and how someone said yes, you probably do not have valid consent.

Legitimate interests: useful, but not a loophole

Legitimate interests is more flexible, but it is not a way to dodge consent. To rely on it you should carry out a short legitimate interests assessment with three parts: identify the interest (e.g. promoting your products), show the processing is necessary for it, and balance it against the individual's rights and reasonable expectations.

It tends to fit things like business-to-business marketing, fraud prevention, or analytics — situations a reasonable person would expect. It rarely justifies emailing or texting individuals out of the blue, because a separate set of rules steps in there.

Where PECR changes the game for email and SMS

The UK GDPR is not the only law in play. The Privacy and Electronic Communications Regulations (PECR) sit on top of it and govern electronic marketing — emails, texts, automated calls and cookies. For marketing emails and texts to individuals, PECR generally requires consent, even where the UK GDPR might have allowed legitimate interests. We cover the cookie side of PECR in our plain-English guide to cookie consent.

There is one important exception, the soft opt-in. You may email or text existing customers about your own similar products without fresh consent if:

That exception does not extend to prospects who never bought anything, to unrelated products, or, in most cases, to organisations buying lists. For more on the broader regime, see our overview of UK advertising and marketing compliance.

The data rights you must honour

Customers have rights you are legally required to support. The ones marketers meet most often are:

RightWhat it means in practice
Be informedA clear, accessible privacy notice
AccessProvide a copy of their data on request
RectificationCorrect inaccurate data
ErasureDelete data when there is no good reason to keep it
Object to marketingAn absolute right — you must stop
Withdraw consentAs easy as giving it was

The right to object to direct marketing is absolute: when someone opts out, you must stop, full stop. Most requests must be handled free of charge and within one month. Practically, that means your CRM and email tools need a reliable suppression list, and an unsubscribe must actually unsubscribe.

Practical safeguards that keep you compliant

You do not need a legal department to get the basics right. A few habits cover most of the ground:

Getting this balance right — respecting the rules while still running effective campaigns — is increasingly a competitive issue, not just a legal one. London consultancy CM Beyer, for instance, sets out a marketer's view of what you can and cannot do with customer data, framing compliance as part of building durable customer trust. That framing is worth borrowing: the businesses that treat data respect as a feature, not a chore, tend to keep their audiences longer.

The bottom line

UK GDPR for marketers comes down to a short discipline: have a lawful basis, prefer genuine opt-in consent for email and SMS, tell people what you are doing, and make it effortless for them to stop. Do that consistently and you will rarely trip over the regulator — and you will run cleaner, more trusted, and ultimately more effective marketing. If you also handle measurement, our guide to marketing attribution pairs well with a privacy-first approach.

Key takeaways

Sources

Related

« How to Build a Marketing Stra… · Brand Consistency: Why It Mat… »
Home · Search · Sitemap · About · Full site

© 2026 Ventri Digital Systems. Mobile edition — see dailyjunction.org for full content.