Marketing to existing contacts — what the BrewDog story tells us about UK GDPR & PECR

What can we learn from the BrewDog shareholder emails? We outline key compliance risks and practical steps to consider before sending communications.
Talk to us: 0333 004 4488 | hello@brabners.com | Contact us
AuthorsPaddy FearnonSara Ludlam

Image credit: Tosh Lubek, stock.adobe.com
"It was only one email."
Organisations may assume that if they already hold someone's contact details, sending a marketing or stakeholder communication presents little regulatory risk. However, recent reports concerning BrewDog founder James Watt demonstrate that the position is far more complex.
According to The Guardian, complaints have been submitted to the ICO following emails sent to former BrewDog ‘Equity Punks’ shareholders in connection with Watt's proposed buy-back of BrewDog through a new venture called Second Best. Some recipients reportedly questioned how their data had been obtained, while Watt stated that the communications were sent using lawfully obtained information and were linked to shareholders' legitimate interests. The ICO has confirmed that it’s assessing the information provided.
Importantly, no findings have been made and no regulatory breaches have been established. However, the story provides a useful reminder that data protection compliance extends beyond identifying a lawful basis under UK GDPR. Organisations must also consider wider data protection principles and, crucially, whether the Privacy and Electronic Communications Regulations (PECR) apply to the communication that they intend to send.
Here, Paddy Fearnon and Sara Ludlam explain why a ‘legitimate interests’ assessment is only one part of the compliance exercise and outline the practical steps that organisations should take before contacting existing customers, members, investors or stakeholders.
Much of the discussion surrounding the BrewDog story has focused on the origins of the contact details and whether recipients expected to be contacted.
While these are important considerations, organisations should also ask themselves:
Even if you lawfully hold someone's personal data, can you use it for the communication that you want to send?
A business may possess personal data entirely lawfully. However, that doesn’t automatically mean that it can hold that data indefinitely or use it for any future purpose.
Before sending communications, organisations should consider whether the proposed use aligns with the data protection principles of transparency, fairness and purpose limitation. They should also consider whether the communication falls within the scope of PECR.
‘Legitimate interests’ is one of the six lawful bases available under UK GDPR and is often relied upon for business communications, customer relationship management and certain forms of marketing.
This lawful basis requires organisations to demonstrate and record:
Whether recipients would reasonably expect the communication and the potential impact on individuals are important questions. A useful rule of thumb is that if recipients are likely to be surprised by receiving the communication, additional scrutiny may be required.
UK GDPR requires personal data to be collected for specified, explicit and legitimate purposes. When an organisation wishes to use personal data for a different objective, it should assess whether that new use is compatible with the original purpose for which the information was collected.
In practice, organisations often encounter this issue when seeking to make further use of an existing marketing or stakeholder database to:
Before using existing contact details for a new purpose, organisations should ask:
If those questions can’t be answered appropriately, the organisation should pause before proceeding.
Perhaps the most significant lesson arising from the publicity surrounding the BrewDog complaints is that data protection compliance and marketing compliance aren’t the same thing.
PECR sits alongside the UK GDPR and the Data Protection Act 2018 — it’s not simply an extension of data protection law. Instead, it gives individuals and organisations specific privacy rights in relation to electronic communications, including marketing emails, texts, calls and similar communications.
PECR can apply even where personal data isn’t being ‘processed’ in the UK GDPR sense. Also, some PECR rules protect companies as well as individuals, meaning that businesses shouldn’t assume that it’s irrelevant simply because it’s using general business contact details (for example, info@abclimited.co).
Even where an organisation is comfortable that it’s identified an appropriate lawful basis under UK GDPR, it may still need to comply with PECR when sending electronic marketing communications.
Non-compliance can have significant consequences. The ICO has powers to investigate complaints, require organisations to change their practices and take regulatory action where it considers that data protection or electronic marketing laws have been breached.
Getting this wrong can result in more than an irritated recipient. Complaints can lead to ICO scrutiny, organisations being required to change their marketing practices, financial penalties and reputational damage.
Another common misunderstanding concerns the ‘soft opt-in’ exemption under PECR.
It’s a common misconception that holding a customer's contact details automatically entitles a business to send marketing communications. In reality, the soft opt-in is subject to specific conditions.
Broadly speaking, these are that:
This means that organisations should be cautious before relying on the soft opt-in for historic contacts, former stakeholders or individuals whose details were collected in an entirely different context. Just because an organisation already holds contact details, doesn’t automatically mean that it can market to that individual.
Organisations should also remember that the rules can apply differently depending on whether they’re communicating with an individual or a business. While B2B marketing communications may be subject to a different regulatory framework in some circumstances, PECR and UK GDPR obligations don’t disappear altogether.
For example, business marketing emails should still be relevant to the recipient's role and recipients should be provided with a clear opportunity to opt-out of future communications. Businesses should also take particular care when dealing with sole traders, who may be treated as individuals for data protection and marketing purposes.
The ICO's assessment of the BrewDog complaints is ongoing and it remains to be seen whether any further action will follow. However, organisations don’t need to wait for the outcome before taking practical lessons from the publicity surrounding the case.
The key takeaway is that possessing personal data and identifying a lawful basis to process it doesn’t automatically entitle an organisation to send marketing communications.
If your organisation uses customer, prospect, investor, donor, member or stakeholder databases for marketing or business development activities, now is a good opportunity to:
Our data protection team advises organisations on lawful basis assessments, PECR compliance, direct marketing activities, privacy notices, data sharing arrangements and regulatory investigations.
To discuss how this applies to your organisation, talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing our contact form.
Paddy Fearnon
Paddy is a Trainee Solicitor in our commercial and intellectual property team.
Read more
Sara Ludlam
Sara is a Partner and Chartered Trade Mark Attorney in our commercial and intellectual property (IP) team.
Read more
Loading form...

What can we learn from the BrewDog shareholder emails? We outline key compliance risks and practical steps to consider before sending communications.

We explore the allegations against Roblox, wider challenges of protecting children online and steps that platforms are expected to take.

We explore how the Housing Ombudsman’s role is changing and outline the practical steps to remain compliant.

We explain why uncontrolled use of public AI tools creates real confidentiality and data protection risks and outline how you can manage them safely.

We delve into the key changes coming into force on 19 June 2026 and explain how businesses should prepare.

We explore the implications of the attacks for UK businesses and outline the practical measures that can help to mitigate similar disruption.

We explore why retailers are particularly affected by deepfakes and the implications around data protection, IP, advertising compliance and more.

We explore how AI is transforming data protection, the risks that organisations now face and what effective compliance looks like today.

We break down what the ICO found and outline three key steps that UK businesses should take now.

We look at the UK GDPR and the Data Protection Act 2018 and outline how the GDPR can apply to both organisations and individuals as data controllers.

We break down the key proposed reforms in the Digital Omnibus Package and outline what businesses should do to prepare.

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

We explore the key developments that in-house lawyers should have on their radar and what they mean for your organisation in the year ahead.

We explain the impact of the cyber-attack on JLR's workforce and outline what to do to protect your business and minimise the impact if an incident occurs.

We outline eight key steps to put your organisation in the strongest position for a prompt and effective response to any cyber-attack.

We explore how charities will need to manage their marketing activities and supporter consent once the secondary legislation takes effect.

We explore how weak cybersecurity and slow responses can trigger major data breaches and resulting ICO fines.

The EU Data Act is a regulation designed to reshape the European data economy by establishing harmonised rules for data access, sharing and portability.

Designed to amend the UK’s existing data privacy regime, the DUA Act will affect the UK GDPR, PECR and the Data Protection Act 2018.

We delve further into cyber attacks on three major retailers and outline five key steps to take in any cyber-attack preparedness and response plan.

The EU Commission handed out fines of €500m and €200m to Apple and Meta respectively. We outline each fine and the legality of 'consent or pay' models.

Prevention is always better than cure. Assess your compliance with data protection law and the changes that could lie ahead in the year to come.

Athletes might be asked to provide highly sensitive forms of personal data when competing. Here's eight steps to comply with data protection legislation.

We explore the evolution of Spotify Wrapped and present five top tips for companies looking to use personal data for viral marketing campaigns.

The EU Artificial Intelligence Act is here and brings a number of considerations as to how businesses manage personal data, GDPR compliance and privacy policies.