Organisations should map each channel to the PECR rule that applies, then verify they have a lawful basis before sending any message or collecting tracking data. That means screening against preference services for calls and faxes, obtaining valid consent for most email and text marketing, and aligning cookie use with privacy requirements. Compliance is not just a legal check, it is a process control.
Mapping PECR to each marketing channel
PECR compliance starts by treating each channel as a different control problem. Email, SMS, automated calling, live calls and cookies do not share the same permission logic, so the organisation needs a channel-by-channel register that records the lawful route to contact, the audience source, and the suppression checks required before send or tracking.
The practical test is whether the campaign can be justified at the point of execution, not just in policy. For email and text marketing, that means verifying consent or a valid soft opt-in where it truly applies. For calls and faxes, it means screening against the relevant preference service and internal do-not-contact records before any outbound activity.
Cookie use is a separate compliance track because it concerns tracking and device access, not simply message delivery. The organisation should classify cookies by purpose, decide whether they are strictly necessary or require consent, and ensure the consent journey is aligned with privacy notices and user choice. This is a process control, not a one-time legal review.
- Keep a live channel matrix that shows rule, lawful basis, owner, and evidence source for each campaign type.
- Block execution when suppression lists, consent records, or cookie settings are incomplete.
- Retain evidence that the permission state was current at the time the campaign ran.
Good compliance practice is to make the marketing platform enforce those rules automatically, with legal and privacy teams owning the policy and operations teams owning the controls. That reduces the risk of fragmented decisions across agencies, regions, or product teams.
Where PECR programmes usually fail in practice
Most failures are operational, not conceptual. Organisations often have one policy for “marketing” and assume it fits every channel, or they rely on a consent record that is too old, too broad, or collected for a different purpose. Another common failure is failing to sync internal preference data with external suppression requirements before a campaign is launched.
Channel mixing creates the sharpest risk. A contact may be valid for one route, such as service email, but not for promotional SMS or automated calls. Likewise, a cookie banner that appears compliant can still be deficient if consent is bundled, unclear, or does not let users refuse non-essential tracking without losing access to the service inappropriately.
For practitioners, the important distinction is between permission to communicate and permission to track. Those are related but not interchangeable, and the evidence required to prove each one is different. Campaign operations need records that show who approved the audience, what suppression logic ran, and what the user had actually agreed to.
- Review consent language for channel specificity, purpose specificity, and recency.
- Check whether agency-run campaigns inherit the same suppression logic as internal campaigns.
- Test the full journey, from preference capture to message send or cookie activation, and not just the front-end form.
That is why PECR compliance should be managed as a controlled workflow with clear checkpoints, not as a checklist applied after the campaign has already been scheduled.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 — Oversight | PECR campaigns need governance and policy oversight across channels and consent states. |
| PR.AA-04 — Identity Management, Authentication, and Access Control | Campaign tools should only send when the current permission state authorises the action. | |
| GV.RM-01 — Risk Management Strategy | PECR compliance is a repeatable operational risk that needs defined rules and escalation. | |
| Recommendation — Assign clear ownership for campaign compliance and review control performance regularly. Require systems to check current authorisation before any outbound message or tracking action. Embed PECR checks into the marketing risk process and escalate exceptions before launch. | ||
| CIS Controls v8 | 6 — Access Control Management | Suppression lists, consent state, and cookie gating enforce who may be contacted or tracked. |
| 13 — Data Protection | Cookies and marketing records involve regulated personal data and collection controls. | |
| Recommendation — Enforce least-privilege campaign execution and block sends when permission data is missing. Minimise tracking collection and protect consent evidence throughout the campaign lifecycle. | ||
Practitioner Guidance
What to prioritise: Build one authoritative consent and suppression record per contact, then force every outbound system to read from it before send. If the marketing stack cannot do that consistently, the compliance gap is architectural, not editorial.
What to verify: Confirm that the campaign has channel-specific evidence, including the source of consent, the timestamp of collection, the scope of permission, and the current suppression state. For cookies, verify that non-essential tracking is gated by a valid consent decision and that refusal is as easy as acceptance.
Common mistake: Treating “we have consent somewhere” as sufficient. In PECR programmes, the issue is usually whether the right permission exists for the exact channel, audience, and purpose at the exact time of execution.
Practitioner takeaway: The strongest control is not a longer notice, it is a marketing workflow that prevents an unpermitted send or track from happening in the first place.
Related resources from NHI Mgmt Group
- How can organisations keep marketing operations running during phone outages without weakening account security?
- What breaks when organisations rely on SMS or email MFA for sensitive access?
- What should organisations do with consent when agents can act across multiple tool calls?
- How should organisations reduce the success of SMS phishing campaigns?