Compliance2026-01-2012 min read

GDPR Compliant Digital Marketing: A Practical Guide for UK Businesses

GDPR compliance does not have to kill your marketing effectiveness. This guide covers consent management, email marketing rules, cookie policies, and advertising data use under UK GDPR.

Emma Williams

Content Strategist

UK GDPR: What Marketers Actually Need to Know

Since the UK left the EU, the UK has its own version of GDPR (the UK GDPR), which is almost identical to the EU version but administered by the Information Commissioner's Office (ICO). The Privacy and Electronic Communications Regulations (PECR) sit alongside UK GDPR and specifically govern electronic marketing communications, cookies, and similar technologies.

Many UK marketers either over-comply (refusing to do any marketing for fear of fines) or under-comply (ignoring the rules entirely and hoping for the best). Neither approach is sensible. This guide explains what you actually need to do to run effective digital marketing campaigns while staying on the right side of the law.

The Six Lawful Bases for Processing Personal Data

UK GDPR requires a lawful basis for processing personal data. For marketing purposes, the three relevant bases are:

Consent

The individual has given clear, affirmative consent to you processing their data for a specific marketing purpose. Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes do not count. Consent for one purpose (e.g., a newsletter) does not cover a different purpose (e.g., sharing data with partners).

When you need consent: email marketing to individuals who have not purchased from you, SMS marketing, sharing data with third parties, and placing non-essential cookies.

Legitimate Interest

You have a genuine business reason to process someone's data, and this does not override their rights and interests. Legitimate interest requires a balancing test documented in a Legitimate Interest Assessment (LIA). You must weigh your business interest against the individual's expectations and the impact on their privacy.

When legitimate interest often applies: B2B marketing emails to business contacts at their work email addresses, postal marketing, remarketing to existing website visitors, and analysing customer data to improve your services.

Performance of a Contract

You need to process data to fulfil a contract with the individual or to take pre-contractual steps at their request. This applies to transactional emails (order confirmations, service updates) rather than marketing communications.

Email Marketing: The Rules

Email marketing is governed by PECR as well as UK GDPR. The rules differ for B2C and B2B:

B2C Email Marketing

  • You need consent to send marketing emails to individual consumers, with one exception: the "soft opt-in".
  • Soft opt-in: If someone has purchased from you (or actively enquired about your products/services), you can email them about similar products or services without explicit consent, provided you gave them a clear opportunity to opt out when you first collected their details and in every subsequent email.
  • Every email must include a clear and working unsubscribe mechanism, your business identity, and your contact details.
  • Process opt-outs promptly. The ICO expects unsubscribe requests to be actioned within 28 days, but best practice is to process them immediately.

B2B Email Marketing

  • Emails to corporate subscribers (company email addresses like [email protected]) do not require prior consent under PECR, though you must still offer an opt-out in every email.
  • Emails to individual employees at their personal or named work email ([email protected]) technically require consent under the strictest interpretation, but the ICO has indicated that legitimate interest is generally acceptable for B2B marketing to named individuals at work addresses.
  • You must still comply with UK GDPR even when PECR consent is not required. This means having a lawful basis (usually legitimate interest), being transparent about how you use data, and honouring opt-outs.

Cookie Compliance

PECR requires that you obtain consent before placing non-essential cookies on a user's device. "Non-essential" covers analytics cookies (including Google Analytics), advertising cookies, social media tracking pixels, and remarketing tags.

A compliant cookie consent mechanism must:

  • Not use pre-ticked boxes. Consent must be actively given by the user.
  • Allow granular choices. Users should be able to accept analytics cookies but reject advertising cookies, for example.
  • Make it as easy to reject as to accept. The ICO has criticised designs where "accept all" is a prominent button but rejecting cookies requires navigating multiple menus.
  • Not block access to the site. Cookie walls that prevent access unless the user accepts all cookies are not considered freely given consent.
  • Record and store consent. You need to be able to demonstrate that each user gave valid consent.

Consent management platforms (CMPs) like Cookiebot, OneTrust, and TrustArc automate much of this process. They scan your site for cookies, generate the consent banner, and manage the technical blocking and unblocking of scripts based on user choices.

Advertising and Data Use

Remarketing and Retargeting

Running remarketing campaigns (showing ads to people who have visited your website) requires valid cookie consent for the tracking pixel that builds the audience. If a user declines advertising cookies, their visit should not be captured for remarketing purposes. Ensure your CMP correctly blocks remarketing pixels when consent is not given.

Customer Match and Lookalike Audiences

Uploading customer email lists to Google Ads or Meta for customer match targeting requires a lawful basis under UK GDPR. If you collected the emails with appropriate consent or under legitimate interest that covers advertising, you can use them for custom audiences. However, you should inform customers in your privacy notice that their data may be used for targeted advertising.

Lead Generation Forms

When collecting leads through forms (on your website or on-platform lead forms on Facebook/LinkedIn), you must:

  • Tell people what you will do with their data at the point of collection
  • Link to your privacy policy
  • Not bundle marketing consent with the form submission (e.g., "by submitting this form you agree to receive marketing emails" is not valid consent)
  • Use a separate, unticked checkbox for marketing consent if you want to add them to your email list

Data Subject Rights

UK GDPR gives individuals several rights that affect marketing activities:

  • Right of access: People can request a copy of all personal data you hold about them. You have one month to respond.
  • Right to erasure: People can ask you to delete their personal data. If they are not a current customer and there is no legal obligation to retain the data, you must comply.
  • Right to object: People can object to processing based on legitimate interest. If they object to direct marketing specifically, you must stop immediately with no exceptions.
  • Right to withdraw consent: If your lawful basis is consent, people can withdraw it at any time, and you must make it easy to do so.

Practical Compliance Checklist

  • Audit your data collection points (forms, cookies, CRM imports) and document your lawful basis for each
  • Update your privacy policy to clearly explain how you use personal data for marketing
  • Implement a compliant cookie consent mechanism that blocks non-essential cookies by default
  • Review your email marketing lists and ensure you have valid consent or legitimate interest for each contact
  • Add unsubscribe links to every marketing email and process opt-outs promptly
  • Train your team on data subject rights and create a process for handling requests
  • Document everything: your lawful basis assessments, consent records, and data processing activities
  • Review your third-party data processors (email platforms, CRM, analytics tools) and ensure you have data processing agreements in place

Compliance as a Competitive Advantage

Businesses that handle data responsibly build trust with their audience. A clear, honest privacy policy and a respectful approach to consent actually improve marketing metrics. People who actively opt in to your emails are more engaged subscribers. Transparent data practices differentiate you from competitors who take a cavalier approach.

The ICO has increased its enforcement activity against UK businesses, with fines and reprimands becoming more frequent. But beyond the risk of fines, GDPR compliance is simply good business practice. Treat your prospects' data with the same respect you would want for your own, and you will build a marketing operation that is both effective and sustainable.

GDPRData PrivacyComplianceEmail MarketingCookie Consent

Ready to Improve Your Marketing Results?

Get a free consultation and discover how Click2Leads can reduce your cost per lead by up to 32%.