PECR Amendment: Personal Liability for Directors

PECR amendment personal liability directors

As noted in DPAS’s January Update, PECR (the Privacy and Electronic Communications (EC Directive) Regulations 2003) is likely to have a replacement in the new year. This new law, the E-Privacy Regulation (ePR) is in draft status and so for now, PECR still applies.

PECR was amended recently and on 17th December 2018, a small but significant insertion in Schedule 1 came in to force, that creates personal liability for senior members of an organisation that breach PECR’s rules.

Where an organisation has been served a monetary notice under PECR for breach of marketing requirements, the ICO may now also serve a monetary notice on an officer of the body corporate, where the contravention (a) took place with the consent or connivance of the officer, or (b) was attributable to any neglect on the part of the officer.

Here an officer should be taken to mean a director, manager, secretary or other similar officer of the body, or person purporting to act in such a capacity. In essence then, the decision makers, the partners, the controlling members.

This is significant because directors can no longer use the corporate veil to protect themselves against liability or simply wind up a company and set up a similar one a short time later, to avoid payment of the fine.

Whilst “connivance” might be an old-fashioned word, negligence is not so narrow, and directors therefore are likely to want to pay tight attention to their marketing practices, so as to ensure they stay on the right side of the law.

Sign up for our newsletter for the latest in Data Protection. We’ll bring you updates on this potential PECR replacement as they happen.

related posts

Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »

Get a Free Consultation