PECR & Soft Opt-In Compliant

Email Marketing Agency UK

A UK list is mailable if PECR says it is, and the penalty ceiling is now £17.5 million. We test each contact against the soft opt-in rule first, then build the flows and authenticated sending a UK inbox accepts.

skilleddesk.com/inbox-analytics
Email-Attributed Revenue
£14,860
+22% MoM
Flow and campaign revenue, last 8 weeks
Web designFull-stack web developmentSocial media marketingGoogle PPC campaignDropshipping websiteEmail marketing & automationConversion tracking setupGraphic designWeb designFull-stack web developmentSocial media marketingGoogle PPC campaignDropshipping websiteEmail marketing & automationConversion tracking setupGraphic design
The Problem

The Gaps That Turn Into An ICO Complaint

Consent To Email Isn't The Same Consent As The Cookie Banner

PECR treats sending a marketing email as a separate question from tracking a website visit, and the ICO's own guidance keeps the two on separate footings. A cookie banner accepting analytics doesn't clear a business to email that person, and an address collected without the soft opt-in conditions met doesn't clear a business to send either. Treating one consent as covering the other is the gap a cookie-banner review cannot find.

Nobody Checked Which UK Contacts Are Corporate Subscribers

PECR draws a real line between a named sole trader and a general company inbox. One still needs consent. The other doesn't. A B2B list assembled for a launch can carry both, and a consumer-style campaign then either leans on a soft opt-in argument it cannot legally make, or skips contacts it never needed permission to reach at all.

A 0.30% Complaint Rate Is The Line Gmail Draws

UK senders get no exemption from Gmail's bulk-sender rules: past 5,000 messages a day, SPF and DKIM both have to be in place, DMARC published, and the spam-complaint rate kept under 0.30%, or the campaign lands in spam however good the subject line is. Complaint rate is the number that decides delivery, and it is the one usually left unwatched until opens have already fallen.

Numbers That Hold Up In Any Currency

130+
Brands Served
14+
Countries Reached
2019
Founded In Wyoming, USA
1:1
Direct Founder Access

PECR Decides Before A Single Email Goes Out

Email marketing for a UK list means we check the soft opt-in test before a campaign goes live, not after a complaint arrives. SkilledDesk is a Wyoming firm, and we build flows and campaigns for UK senders through Klaviyo, Mailchimp, or HubSpot, whichever platform the business actually holds its contacts in. Consent comes first. A welcome flow fires the moment someone genuinely opts in. Campaigns go to the contacts a particular offer fits, filtered on what a subscriber bought or clicked, so the same send never lands on the whole file. Sender identity stays visible on every send, and the unsubscribe link works the day it's clicked, both requirements PECR names outright rather than leaving to convention. Since the Data (Use and Access) Act 2025, getting either of those wrong carries a fine ceiling of up to £17.5 million or 4% of global turnover, against the £500,000 cap that used to apply.

Before writing this page we searched "email marketing agency uk" and read the nine results sitting on the first page. Every one of them sells on growth and ROI, and not a single title or summary mentions PECR, the ICO, or the soft opt-in. A UK buyer trying to settle the one question that decides whether a send is lawful at all gets no answer from the agencies currently ranking for it.

Location Isn't The Risk. Record-Keeping Is.

Being outside the UK changes nothing under PECR. What decides whether an email programme holds up under an ICO complaint is the same wherever the agency sits: a documented soft opt-in test run against each contact before the first send, a suppression list that actually blocks a former subscriber, and SPF/DKIM/DMARC records the business itself owns rather than a shared sending domain buried inside an agency's own account. We hand over the platform login and the authentication keys from the first flow, not after the contract ends, because a regulator asking who controls that list needs one name on file, and it should be the business's, not ours. Reporting runs in pounds, on a schedule built around your working day.

One Build, Reported However The Client Bills

Our reporting follows whichever currency the client invoices in, pounds included. One subscription SaaS account on the portfolio is the email-driven entry: $26K added to its recurring revenue, open to inspection.
See Our Full Portfolio
FAQ

What UK Businesses Ask Before The First Send

For most contacts, yes. PECR requires prior consent before a marketing email goes out, with one narrow exception: the soft opt-in, which only applies to an existing customer who bought or negotiated to buy a similar product, was given a simple opt-out when their details were first collected, and gets that same opt-out in every message after. Anyone outside those three conditions, including a bought-in list, needs real consent first. We run that test against your contact data before the first campaign goes live, not after.
The ICO can now fine up to £17.5 million or 4% of global turnover under the Data (Use and Access) Act 2025, up from the previous £500,000 ceiling. Recent enforcement shows the range in practice: one firm was fined £120,000 over roughly four million unlawful marketing texts, another £105,000 for sending nearly 68 million emails on consent it had bought in rather than collected directly — both of those under the old £500,000 cap, before the ceiling rose. Getting the soft opt-in test wrong at scale is what turns into a fine. Getting it right is mostly a documentation habit.
Retainers for a single list on one platform open at £650 a month with us, covering flow builds, ongoing campaigns, and keeping the list clean. UK agencies commonly cite figures from around £800 up to several thousand a month depending on list size and flow count. We send an itemised quote against your actual numbers before we invoice a single month.
We don't ask for either one before we start. Whatever your store or CRM already connects to is where we build — Klaviyo tends to fit Shopify brands best, Mailchimp or HubSpot suits most service businesses — and the soft opt-in flag on your signup form gets built into that platform's data model from the first field, not bolted on as a tag afterward. Every list stays registered under your own account, never a shared login.
The consent audit comes first, usually inside the first week: checking which contacts pass the soft opt-in test and which need a fresh opt-in before anything gets sent to them. A welcome flow and the first segmented campaign follow inside two to three weeks total. A heavier build, several flows, deeper segmentation, a full campaign calendar, stretches to four to six weeks, mostly because mapping the segmentation logic takes longer than writing the emails themselves.
Nothing moves. SPF, DKIM, and DMARC get set up on your own sending domain from the first campaign, never routed through a shared agency domain, so the sender reputation you build stays attached to your business regardless of who manages the account afterward. Cancel the retainer and the flows already live keep sending exactly as they were left.
Sometimes. PECR's corporate subscriber exemption means a general inbox at a company, LLP, or Scottish partnership can be emailed without consent. A named sole trader or an ordinary partner usually can't, and a named individual's inbox at a company can fall back into needing consent depending on context. We sort a B2B list into these categories before a single campaign runs against it, so a consumer-style send never goes out on the wrong legal basis.

Send Us Your Current List And Its Consent History

Tell us how the list was built and which platform it's on, and you'll get a scoped compliance-and-flow plan back within two working days.

Get Free Consultation