A salon keeps years of records in one booking system. It holds clients who never came back, people who asked for a price and went quiet, and cards from a wedding fair. Someone suggests a "database reactivation": one friendly message to everyone.
So, can you email old customers in the UK? Some of them. Database reactivation (a win-back or re-engagement campaign) means messaging old customers, past enquirers and lapsed contacts again. By email or text, the law allows it for people who gave you consent, and for past customers and enquirers who fall within the "soft opt-in". The rest, unless they are companies, need another route or none.
Checked against the regulations and the guidance of the Information Commission (the ICO) on 5 October 2026. WebAsk is a web and CRM agency, not a law firm. This is not legal advice.
TL;DR
Email or text individuals only if they consented, or if they bought or asked about buying, were offered a simple way to refuse at the time, and hear only about your similar products and services. Do not email or text any other individual, even to ask. Use post under UK GDPR, a screened call or their next visit instead, and keep every opt-out on a suppression list.
Who the email and text rule protects
PECR is the Privacy and Electronic Communications Regulations 2003. Its regulation 22 covers unsolicited marketing by "electronic mail" to "individual subscribers". Electronic mail "includes messages sent using a short message service" (regulation 2). The rule as in force on 5 October 2026:
"Except in the circumstances referred to in paragraph (3) [or (3A)], a person shall neither transmit, nor instigate the transmission of, unsolicited communications for the purposes of direct marketing by means of electronic mail unless the recipient of the electronic mail has previously notified the sender that he consents for the time being to such communications being sent by, or at the instigation of, the sender."
The words "or (3A)" were added on 5 February 2026 by the Data (Use and Access) Act 2025, for charities.
The ICO says: "You can send unsolicited electronic mail marketing to corporate subscribers without consent or a soft opt-in." Sole traders, partnerships outside Scotland that are not LLPs, and anyone using their personal email address are individual subscribers (ICO, under review). Our PECR guide to B2B outreach covers companies.
The three piles
Pile one: consent you can show
While the consent stands, you may email or text these people, within what they agreed to. The ICO says you must "give your name in the consent request". It adds: "You should ask for consent for each type separately." You "should keep a record of the consent (eg who, when, how)". A pre-ticked box is not consent. Nor is an address given for a receipt: "Consent for an e-receipt doesn’t cover sending direct marketing."
Pile two: the soft opt-in
Regulation 22(3) allows email or text without consent if all three of these conditions are met.
(a) "that person has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient;"
(b) "the direct marketing is in respect of that person’s similar products and services only; and"
(c) "the recipient has been given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) the use of his contact details for the purposes of such direct marketing, at the time that the details were initially collected, and, where he did not initially refuse the use of the details, at the time of each subsequent communication."
The ICO's detailed guidance says "A person doesn’t need to actually buy anything from you." Asking for a quote, or for details of what you offer, counts. But it also sets a limit.
"You must have some form of express communication from the person and it must involve them buying your products or services."
"Similar" turns on whether people "reasonably expect" your marketing. The details must come "directly from the person".
When no refusal was offered
If nobody offered a way to refuse when the details were taken, the soft opt-in was never there. The ICO says: "Including an opt-out in an order confirmation email is not sufficient." In its takeaway example, the opt-out first came in the order confirmation text. The verdict: "Any further marketing text messages would breach PECR."
Pile three: no basis
Every other person. The ICO rules out the soft opt-in for bought lists.
"you must not use the soft opt-ins to send unsolicited electronic mail marketing to people on a bought-in marketing list."
Our reading adds a case no ICO page we read names: a number from a missed call. If they never made an "express communication" about buying, and nobody offered a way to refuse, they belong here. What a text-back to that call may say is in our missed-call text guide.
Sorting the records you actually hold
"Our reading" is our view where no source decides; "unsettled" means the sources leave it open.
| What you hold | Pile | Email or text? | Why |
|---|---|---|---|
| Booked and paid, offered a simple way to refuse when you took the details, and did not refuse | Two | Yes, about your similar services, with a way to refuse every time | Regulation 22(3). Unsettled: no end date (see below) |
| Booked and paid, but the first chance to refuse came later, as in a confirmation | Three | No | ICO: an opt-out in an order confirmation "is not sufficient" |
| Asked for a quote or for details, offered a way to refuse then, and did not refuse | Two | Yes, as above | ICO: "requesting a quote or asking for more details about what you offer" |
| Asked for a quote, with no refusal offered | Three | No | Regulation 22(3)(c) |
| Ticked an unticked box that named you, for that channel, years ago | One, if the consent still stands | Yes, within what they agreed to | Consent "does not last forever" (ICO). Unsettled: no source sets an end date (see below) |
| A pre-ticked box | Not consent | Only if a pile-two row applies | ICO: you "must not use pre-ticked opt-in boxes, silence or inactivity as evidence of consent" |
| A missed call, nothing more | Three (our reading) | No | No "express communication" about buying, and no refusal offered |
A company's info@ inbox, or a named address on its own domain | Corporate | Yes under PECR, naming yourself, with a valid opt-out address | ICO; UK GDPR applies to a named person (see our B2B guide) |
| An event card from a sole trader, or a personal address, or a mobile in their own name | Three, unless they asked about buying and were offered a way to refuse | No | ICO (under review): a delegate's "personal email address" makes them an individual subscriber |
| A person's details found online | Three | No | ICO: "publicly available" does not mean "they’ve consented" |
| Opted out, or objected to direct marketing | Suppression list | No on that channel, and no direct marketing at all after an objection | UK GDPR Article 21(3); ICO |
| A bought list of individuals | Three; consent that named you for that channel would be pile one | No | ICO: no soft opt-in for "a bought-in marketing list" |
| A clinic or dental patient picked out by the treatment they had | The row above that fits, plus a health-data question | As that row | Unsettled: see "Treatment history can be health data" below |
How old is too old?
Neither PECR nor UK GDPR gives consent or the soft opt-in an end date. The ICO's direct marketing guidance (updated 28 April 2026) says: "Consent for direct marketing does not last forever." Its UK GDPR consent guidance (under review, updated 4 August 2026) says consent "is likely to degrade over time". It adds a recommendation, not a deadline:
"If in doubt, we recommend you consider refreshing consent every two years – but you may be able to justify a longer period, or need to refresh more regularly to ensure good levels of trust and engagement."
No ICO page we read gives the soft opt-in a period. The Guide to PECR (under review) speaks of someone who "bought something from you recently".
Our build standard, not a rule: every record is dated, and a person checks before a send that the customer would still expect to hear from you. Refresh consent while it stands. Once it has lapsed, an email asking for it is a consent request, which the ICO counts as direct marketing (next section).
Why you cannot email or text to ask
For a person with no basis, the request is itself the message you may not send. The ICO's guidance lists "contacting people to ask them for consent to direct marketing" among direct marketing purposes. Its example is a hotel.
"A hotel sends an email to its previous guests asking them if they would like to consent to receiving its special offers and discounts. Whilst this email doesn’t contain any of these discounts or offers, the hotel is still sending it for direct marketing purposes."
Nor can the request hide in a message asking people to "check their contact details are correct". If a service message "has elements that are direct marketing", the ICO says it "will count as direct marketing".
What you can do with pile three
Post: outside PECR, inside UK GDPR
The ICO's direct marketing guidance says this about post.
"Direct marketing by post is not covered by PECR. But you must still comply with data protection law, if you are using personal information as part of your campaign."
The ICO's checklist: a lawful basis, telling people about postal marketing, a suppression check, and a way to handle objections. "In general, consent and legitimate interests are the two lawful bases most likely to apply" (ICO). You "should" check the Mailing Preference Service (MPS) too, though it "is not a statutory preference service".
People may object to direct marketing "at any time" (UK GDPR Article 21). The ICO says you must tell them about this right "at the latest" in your first message.
A live call, after a screen
The ICO's Guide to PECR (under review) rules out unsolicited live marketing calls "to anyone who has told you they don’t want your calls". The same goes for a number on the Telephone Preference Service (TPS) or Corporate TPS without specific consent, "even if they are an existing customer". How to screen is in our B2B guide.
Not a recorded or AI-voiced call
An automated call that plays recorded marketing falls under regulation 19. The ICO says consent "must specifically cover automated calls" (under review). Nothing official settles whether a conversational AI voice makes a live call or an automated one (our AI receptionist guide). Until that is settled, treat it as automated.
In person, or not at all
In person, the ICO says "Staff taking down details verbally should specifically offer a choice of opting out." Our reading: if a past client books again, gives their details and is offered a way to refuse, the soft opt-in can start that day.
Or let them go. If you no longer need the details for direct marketing, the ICO says "you must delete or anonymise it". You may keep "a small amount for another purpose, such as a suppression list". Other records follow their own rules. And the ICO says you "should not" trace new contact details for marketing.
Keep the opt-outs
The ICO's preferences guidance says:
"Data protection law and PECR don’t say you have to use a suppression list, but you should use one to help you to comply instead of just deleting their details."
The Guide to PECR (under review) is firmer: "You must not simply delete their details altogether". Someone who objected cannot be contacted later "to ask if they’ve changed their mind". Our migration guide covers moving the suppression list from HubSpot to GoHighLevel.
What every reactivation message carries
Regulation 23 covers every marketing email or text. Who it is from must not be "disguised or concealed", and there must be "a valid address" to ask you to stop. Soft opt-in contacts get a way to refuse in every message.
Clinics, dental practices and salons
The CAP Code covers all three. The GDC's guidance covers dental professionals.
Marketing emails and texts can be adverts
The CAP Code covers ads in "e-mails, text transmissions (including SMS and MMS)". It does not cover "correspondence between organisations and their customers about existing relationships or past purchases". CAP's advice does not bind the Advertising Standards Authority (ASA). But it says a standard message urging a number of people to buy something different, or take up an offer, is "likely" to be covered.
On 27 May 2026, the ASA upheld a complaint about an online pharmacy's emails. They went to people who had opted in to marketing, but that "did not mean recipients had made a specific enquiry about named POMs" (prescription-only medicines). The emails broke rule 12.12.
Promote the consultation, not the medicine
Rule 12.12 reads:
"Prescription-only medicines or prescription-only medical treatments may not be advertised to the public."
Our standard for clinic copy: a reactivation message promotes the consultation. It never names or hints at a prescription-only medicine. Our guide to aesthetic clinic adverts has more.
Dental practices and the GDC
The GDC's guidance on advertising does not say whether it covers marketing emails or texts. Our reading is that its rules still reach them, starting with this one.
"All information or publicity material regarding dental services should be legal, decent, honest and truthful."
Information containing a registrant's name must also carry their GDC registration number.
Treatment history can be health data
Under UK GDPR Article 4(15), health data includes "the provision of health care services, which reveal information about his or her health status". The ICO says you "could reasonably infer health data from an individual’s list of appointments at an osteopath clinic" (under review). For such data in direct marketing, it says "You should have “explicit consent”". Whether a list of cosmetic treatments counts is unsettled. Our reading is to treat it as health data.
Penalties since 5 February 2026
A higher maximum penalty applies to breaches on or after 5 February 2026 (SI 2026/82, reg 11(2)). The maximum for breaking regulations including 19, 21, 22 and 23 is the "higher maximum amount" (PECR Schedule 1, para 18). For an undertaking, the Data Protection Act 2018, s.157(5) sets that amount at:
"£17,500,000 or 4% of the undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher"
In any other case, it is £17,500,000. If someone else sends for you, the ICO says "you are still responsible" (Guide to PECR).
A checklist before any reactivation send
- Tag each record company or person; treat unknown as a person (ICO, under review).
- Give each person a dated basis: consent, or the soft opt-in with the refusal offered.
- Have someone review the dates and run the suppression list before the send (our standard).
- Leave out bought or scraped records (our standard). Send no email or text to pile three.
- Post: a lawful basis, privacy information, suppression and MPS checks.
- Calls: screen first; nothing recorded or AI-voiced without consent covering automated calls.
- Keep offers out of service messages (reminders and recalls).
- Name yourself and give a working opt-out in every message.
- Clinics: promote the consultation, and never name or hint at a prescription-only medicine.
Where to start
- Tag the companies, then sort every person into the three piles; our B2B outreach guide covers companies and calls.
- Build the checks into the system. In our CRM and automation service, sequences check before they send, and migrations carry the consent. We do not buy, rent or supply lists, and we will not import one you were sold.
- Get in touch with what you run now and what you want it to do.