PARTLY

As of 13 August 2026, AI can only partly check whether your marketing emails comply with PECR.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsA data-protection solicitor is the human alternative; no price is stated here.

If this goes wrong: you send direct marketing without the required basis or opt-out handling and face complaints, enforcement or damage to your customer relationships.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the current ICO guidance on PECR and save the sections covering direct marketing, electronic mail, consent, existing customers and opt-outs.
    2. Export the proposed recipient list without unnecessary personal data and label each group by recipient type, source, customer status and intended message.
    3. Gather the consent wording, collection channel, timestamps, privacy notice version, customer-purchase records, unsubscribe logs and suppression-list process for each group.
    4. Paste the campaign facts and documents into a chatbot with the prompt above, removing names, email addresses and other unnecessary personal data.
    5. Compare every model finding with the current ICO guidance and mark each point as supported, unsupported or requiring specialist interpretation.
    6. Send the evidence table and unresolved questions to your data-protection solicitor or suitably qualified privacy professional before approving the campaign.

    Prompt

    You are helping me prepare a UK PECR compliance review for a marketing email campaign. This is not professional advice and you must not give a definitive legal sign-off.
    
    Use only the facts and documents I provide. Do not invent consent, business relationships, recipient categories, dates, policies or technical settings. If a fact is missing, mark it as missing. Separate confirmed facts, reasonable inferences and unresolved legal questions.
    
    Review these details:
    - Business and sender identity: [paste]
    - Purpose and content of the email: [paste]
    - Recipient categories, including whether they are individuals, sole traders, partnerships or limited companies: [paste]
    - How each recipient was sourced: [paste]
    - Consent wording, timestamp, channel and records: [paste]
    - Any existing customer relationship and what was bought: [paste]
    - Whether recipients were given an opt-out when details were collected: [paste]
    - Previous emails, unsubscribe method and suppression-list process: [paste]
    - Privacy notice and relevant internal policies: [paste]
    - Email platform settings and proposed send process: [paste]
    - Any complaints, objections or previous regulator contact: [paste]
    
    Produce:
    1. A table with each relevant PECR issue, the fact or document supporting it, what is missing, the likely risk, and the specific action needed.
    2. Separate sections for consent, the existing-customer exception, recipient type, sender identification, unsubscribe and suppression handling, data-source records, and privacy information.
    3. A list of statements that must be checked against current ICO guidance before sending.
    4. A final outcome of only one of: "appears low risk on the facts supplied", "cannot conclude because evidence is missing", or "specialist review needed before sending". Explain the outcome without claiming legal certainty.
    5. A short list of the exact records and questions I should take to a UK data-protection solicitor or suitably qualified privacy professional.
    Do not recommend sending the campaign until the missing evidence and specialist questions have been resolved.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, regulated advice and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta1
Total6 / 10

FAQ

Can ChatGPT check if my emails comply with PECR?
Partly. It can organise your consent records, recipient categories, message purpose and unsubscribe process, then flag gaps against the facts you provide. It cannot give legal sign-off, and this is not professional advice.
Can AI tell me if I have consent to email someone?
It can compare your wording and records with the relevant requirements and identify missing evidence. It cannot prove that the record is genuine or resolve an ambiguous consent history, so a serious or disputed case needs a data-protection solicitor.
Can I use the soft opt-in for my marketing emails?
AI can explain the conditions you need to test against your customer and email records. It should not decide that the exception applies where the purchase, notice, product or opt-out facts are unclear, and you should obtain specialist advice before sending.
Who is responsible if AI says my marketing email is PECR compliant?
Your business remains responsible for the campaign, not the chatbot. This is not professional advice, and a serious case should be checked by a data-protection solicitor or suitably qualified privacy professional.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.