Adding someone to a marketing or mailing list without their permission is not just poor practice, it is illegal under UK law. The rules exist to protect people’s privacy, prevent unwanted marketing, and ensure that organisations handle personal data responsibly.
The Legal Basis
The main laws governing this issue are:
Together, these laws set out strict rules on how businesses and organisations can collect and use personal data for marketing purposes, including email communications.
Consent Is Required
Under UK GDPR and PECR, organisations must have clear, informed consent before sending direct marketing emails to individuals. This means a person must take a positive action to join a mailing list, for example, ticking an unchecked box or filling out a subscription form.
Automatically adding people, pre-ticked boxes, or assuming consent from previous interactions are all prohibited. Consent must also be easy to withdraw at any time, usually through an unsubscribe link.
These rules protect people’s right to privacy and reduce spam. Unsolicited emails can be intrusive, damage trust, and, in some cases, expose individuals to scams or phishing attempts. From a business perspective, sending emails without permission can harm reputation and lead to formal complaints.
Enforcement and Penalties
The Information Commissioner’s Office (ICO) is the UK’s independent regulator for data protection and privacy. The ICO has the power to investigate complaints, issue enforcement notices, and impose significant fines on organisations that breach these rules.
Recent enforcement actions have seen companies fined thousands of pounds for sending marketing emails or texts without consent. Even small businesses are not exempt from the law.
Best Practices
To stay compliant and maintain trust:
-
Always obtain explicit consent before adding anyone to a mailing list.
-
Keep records of how and when consent was given.
-
Provide a clear and simple way to opt out of future communications.
-
Respect opt-outs immediately, continuing to send emails after someone unsubscribes is also unlawful.
In the UK, subscribing people to mailing lists without their permission breaches data protection and privacy law. The requirement for consent is not a formality, it’s a legal obligation designed to safeguard individuals and ensure responsible marketing. Ignoring it can lead to regulatory action, financial penalties, and lasting reputational damage.

