Apr
05
In our last blog post, we looked at An Introduction to Email Marketing.
There we met the fictitious company ‘All things Stationery’ who want to send email marketing to their customers with the aim to sell stationery and office products.
We established that their database was made up of a mix of sole traders, partnerships and limited companies and so they would be undertaking both Business to Business (B2B) and Business to Consumer (B2C) marketing. Now we need to identify what the data protection rules are for these.

What did we learn?
There are 3 data protection laws that we need to comply with when it comes to sending marketing communications. These are:
GDPR and the Data Protection Act 2018 govern how you use personal data and PECR 2003 governs direct marketing by electronic means.
When it comes to electronic direct marketing we must always look at what PECR tells us to do first which will then dictate how we comply with GDPR.
First of all, we need to look at some of the definitions and terminology used in PECR as this helps us to understand what the different rules are for undertaking B2B and B2C marketing.
In PECR there is a term called ‘subscriber’ which is defined as:
Basically, this means that the subscriber is the customer who has a contract with the service provider, in this case, All Things Stationery.
That’s not where it ends, subscriber is then split further into ‘corporate subscriber’ and ‘individual subscriber’.
‘Corporate subscriber’ is a corporate body with separate legal status. This includes limited companies, limited liability partnerships, Scottish partnerships, and some government bodies.
‘Individual subscribers’ are individual customers and this includes sole traders and other organisations that don’t come under Corporate subscriber, so all other types of partnerships.
If we look at this from our scenario, the businesses on our marketing database are a mix of what are known as corporate subscribers and individual subscribers. This is because the customers are a mix of sole traders, partnerships and limited companies.
The important bit now is to explore the rules for individual subscribers and corporate subscribers so that we can apply these rules to our scenario.
Individual Subscribers

Do we need to get an individual subscriber’s consent to process their personal data for direct marketing purposes?
YES!
You do need to obtain the consent of the ‘individual subscriber’ to process their personal data for direct marketing by e-mail.
That said, it’s never black and white with data protection there are always grey areas and as such, there is an exception to this rule!
The ‘soft opt-in’ rule.
If you want to use the soft opt-in rule you absolutely must meet all of its 5 requirements:
The soft opt-in rule only applies to marketing sent by email and texts, it does not apply to any other methods used for sending electronic direct marketing.
Luckily for All Things Stationery they comply fully with ALL 5 requirements and so under PECR they DO NOT need to obtain the consent of the individual subscribers.
Corporate Subscribers
What about the ‘corporate subscribers’ then, what are the PECR rules for these?
Again, the question we need to ask is do we need consent to send email marketing to corporate subscribers?
NO!
Under PECR you do not need consent from corporate subscribers to send them email marketing.
The Information Commissioners Office* is very clear about this in their draft Direct Marketing Code of Practice.
“The PECR rules on marketing by electronic mail (e.g. email and text messages) do not apply to corporate subscribers. This means you can send B2B direct marketing emails or texts to any corporate body. However, you must still say who you are and give a valid address for the recipients to unsubscribe from your emails.”
Remember a corporate subscriber is where the organisation, as opposed to the individual, has subscribed to the email or SMS service. This is why marketing to corporate subscribers is commonly referred to as B2B marketing.
So, what does all this mean for All Things Stationary?
All Things Stationery is complying with PECR because:
That’s fantastic news for All Things Stationery, but what happens when you don’t meet these 5 requirements?
We’ll be looking at that in more detail next time. In the meantime, follow the ICO’s Golden Rule:
If you are unsure whether the contact details belong to an individual subscriber or a corporate subscriber this puts you at risk of breaching PECR. To mitigate that risk you should treat the details as belonging to an individual subscriber and ensure that you comply with rules on electronic mail.
Next we’re taking a deeper dive into GDPR:
As mentioned in our previous blog post, we are applying UK data protection laws only as All Things Stationery only sells its products to businesses in the UK. If you market to the EU or internationally you also have to comply with the domestic data protection and e-privacy laws applicable in the countries you specifically target. They do have different rules, so do be careful if you undertake marketing to customers or businesses in other countries.
Need a recap of the terminology used in GDPR & PECR, head to our blog here: Understanding the terminology used in GDPR & PECR
*Information Commissioners Office (ICO) is the UK Regulator that oversees and enforces how businesses comply with data protection laws. ALL businesses must be registered with the ICO, to find out more visit: https://ico.org.uk/for-organisations/data-protection-fee/register/