PECR Amendment: Personal Liability for Directors

PECR amendment personal liability directors

As noted in DPAS’s January Update, PECR (the Privacy and Electronic Communications (EC Directive) Regulations 2003) is likely to have a replacement in the new year. This new law, the E-Privacy Regulation (ePR) is in draft status and so for now, PECR still applies.

PECR was amended recently and on 17th December 2018, a small but significant insertion in Schedule 1 came in to force, that creates personal liability for senior members of an organisation that breach PECR’s rules.

Where an organisation has been served a monetary notice under PECR for breach of marketing requirements, the ICO may now also serve a monetary notice on an officer of the body corporate, where the contravention (a) took place with the consent or connivance of the officer, or (b) was attributable to any neglect on the part of the officer.

Here an officer should be taken to mean a director, manager, secretary or other similar officer of the body, or person purporting to act in such a capacity. In essence then, the decision makers, the partners, the controlling members.

This is significant because directors can no longer use the corporate veil to protect themselves against liability or simply wind up a company and set up a similar one a short time later, to avoid payment of the fine.

Whilst “connivance” might be an old-fashioned word, negligence is not so narrow, and directors therefore are likely to want to pay tight attention to their marketing practices, so as to ensure they stay on the right side of the law.

Sign up for our newsletter for the latest in Data Protection. We’ll bring you updates on this potential PECR replacement as they happen.

related posts

Bethany Meredith

Navigating SAR Chaos: Why PDF Conversion and Deduplication Are Your Secret Weapons

When a Subject Access Request lands in your inbox, the one-month clock starts ticking immediately, and the real bottleneck usually isn’t finding the data, it’s wading through duplicate files and endless email threads. Discover why deduplication and PDF conversion aren’t just nice-to-haves but non-negotiable steps in your SAR pipeline: cutting review volume by up to 60%, closing redaction loopholes, and delivering a secure, universally accessible disclosure , all while keeping your compliance team sane and your deadline intact.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – August 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »

Get a Free Consultation