
Rules and ethics
How UK GDPR and PECR shape every scheduled social post for British teams
UK GDPR social scheduling means choosing a lawful basis, applying PECR consent and soft opt-in rules, and controlling cookies before any post goes out.
What to take away
- UK GDPR social scheduling needs a lawful basis per purpose, not one blanket choice for every channel.
- PECR sits on top of UK GDPR for electronic marketingconsent or soft opt-in, plus sender identity and opt-out in every message.
- Cookies, pixels and scheduling tool dashboards trigger storage and access rules, so consent is needed before non-essential tracking.
- The ICO expects a controller and processor distinction in vendor contracts, with transfer and security terms written down.
- Accountability records should show the basis, the audience, the consent source and the review date for each scheduled post.
Where UK GDPR ends and PECR begins for a scheduled post
A scheduled post looks like one action in a content calendar. Legally it is at least two. UK GDPR governs the personal data you process to plan, target and measure the post. PECR governs the electronic marketing itself, including unsolicited messages and the technologies that sit on a recipient's device.
UK GDPR vs PECR for a post
UK GDPR
- Question asked
- Lawful basis?
- Covers
- Planning, targeting, measuring
- Organic post
- Applies
- Promoted post
- Applies
- Enforcer
- ICO
PECR
- Question asked
- May you send?
- Covers
- Electronic marketing, device storage
- Organic post
- Usually not marketing
- Promoted post
- Applies
- Enforcer
- ICO
That split matters because the two regimes have different tests. UK GDPR asks whether you have a lawful basis for processing. PECR asks whether you may send the message or store information on a device in the first place. A post can pass one and fail the other.
The ICO treats these as separate UK legal questions, which is why a single consent checkbox rarely covers a full campaign. A scheduled organic post to your own followers is usually not electronic marketing in the PECR sense. A promoted post aimed at a purchased or matched audience is.
British teams also work under the Data Protection Act 2018, which supplements UK GDPR and sets out some exemptions and enforcement powers. The ICO enforces both. The Advertising Standards Authority covers the content claims in the post, not the data law behind it.
For scheduling, the practical boundary is this: what data do you hold, why do you hold it, and does the post amount to direct marketing to an individual? Answer those three and you know which regime leads.
The three questions before you schedule
- Does the post promote a product or service, or aim to solicit commercial engagement?
- Are you sending it to a named or identifiable individual, or only publishing it publicly?
- Does the scheduling tool store or read information on a user's device beyond what is strictly necessary?
If the answer to question one or two is yes, PECR applies. If question three is yes, storage and access rules apply.
Lawful basis choices for scheduling: consent, legitimate interests and the ICO guide
Every processing activity behind a scheduled post needs a lawful basis. The ICO's A guide to lawful basis sets out the six options, and the key point for social teams is that the basis must be chosen before processing starts.
Choosing a lawful basis
Organic posts
- Basis
- Legitimate interests
- Record
- Balancing test
- Opt-out
- Opt-out route
- Timing
- Before processing
Built list campaign
- Basis
- Consent
- Record
- Source, wording, date
- Opt-out
- Consent wording
- Timing
- Before processing
For most organic scheduling, legitimate interests is the workable basis. You are publishing to an audience that chose to follow you, and you have a commercial interest in doing so. That interest must be balanced against the individual's rights, and the ICO expects a legitimate interests assessment to be recorded.
Consent is the safer basis when you build a list, run a lead form, or target people who have not asked to hear from you. UK GDPR requires consent to be freely given, specific, informed and unambiguous. Pre-ticked boxes and bundled terms do not qualify.
Some processing needs no basis choice because it falls outside UK GDPR, such as genuinely anonymous analytics. Most scheduling data does not. Account names, handles, engagement records and audience lists are personal data.
Lawful basis choices for scheduling
| Scheduling purpose | Typical lawful basis | What to record |
|---|---|---|
| Publishing organic posts to followers | Legitimate interests | Balancing test and opt-out route |
| Sending a campaign to a built list | Consent | Source, wording and date of consent |
| Existing customer marketing by email or SMS | Soft opt-in | Sale details and opt-out at collection |
| Audience matching and retargeting | Consent | Platform terms and notice text |
| Analytics on post performance | Legitimate interests or consent | Whether data is aggregated |
The ICO does not accept a basis chosen by channel. A team that uses legitimate interests on LinkedIn and consent on email needs a reason for the difference. The Data protection for social scheduling approach is one row per purpose, with the basis named for each.
Legitimate interests in practice
A legitimate interests assessment is not a long document. It records the interest, the necessity of the processing, the balancing exercise and the safeguards. For scheduling, safeguards include easy opt-out, no sensitive data in audience lists, and retention limits on engagement records.
If someone objects to processing based on legitimate interests, you must stop unless you can show compelling grounds. For social scheduling, that usually means suppressing the handle from future campaigns.
PECR consent and soft opt-in rules for scheduled electronic marketing
PECR applies to electronic marketing by email, SMS, and similar messages, and to some social media activity. The ICO's Guide to Privacy and Electronic Communications Regulations | ICO explains the scope, and the Electronic and telephone marketing | ICO page covers consent and the soft opt-in in detail.
PECR consent or soft opt-in?
Did you get details in a sale or negotiations?
Soft opt-in may apply
You need specific consent
The default rule is consent. You need specific consent from the individual before sending unsolicited electronic marketing. That consent must meet the UK GDPR standard, so keep the wording and the time it was given.
Soft opt-in is the main exception. It applies when you obtained the person's details in the course of a sale or negotiations for a sale, you are marketing similar products or services, and you offered a simple opt-out at collection and in every message. It does not apply to cold lists or to data bought from a third party.
For social scheduling, the soft opt-in question usually arises with direct messages, inbox campaigns and retargeting to a customer list. A scheduled organic post to your page is not electronic marketing to an individual, so PECR consent is not the test. A scheduled direct message to a customer is.
Every electronic marketing message must identify the sender and include a valid opt-out. That applies even when the message is scheduled through a tool and sent by a platform. The opt-out must be free and easy to use.
A worked example
A Manchester retailer schedules a post promoting a new range to its Instagram followers. That is organic publishing, covered by legitimate interests. The same retailer schedules a direct message to customers who bought last year, promoting the new range. Soft opt-in can cover that if the customers were told they would receive similar offers and were given an opt-out.
If the retailer buys a list and schedules the same message, neither consent nor soft opt-in applies. The campaign should not run.
Cookies, pixels and storage and access technologies in scheduling tools
Scheduling tools rely on cookies and similar technologies. Some are essential, such as login sessions and security tokens. Others are not, including analytics, advertising pixels and social platform tracking.
Storage and access rules apply when you store information on a user's device or read what is already there. The ICO's Guidance on the use of storage and access technologies | ICO sets that out, with consent required unless the technology is strictly necessary.
For a UK social media manager, that means the consent banner on your own website and the tracking on your landing pages. It also means the pixels embedded in a scheduling tool's preview or link shortener. If a pixel drops before consent, that is a breach.
Consent for cookies must meet the UK GDPR standard. Implied consent from continued browsing is not enough. Users must be able to refuse as easily as they accept, and consent must be granular where purposes differ.
Cookie and pixel checks
- Check each cookie or pixel is strictly necessary
- Confirm banner allows refusal as easily as acceptance
- Record consent text and date shown
- Check pixels do not fire before consent
- Review third-party tools for their own storage
Cookies inside the scheduler itself
Your scheduling tool may set cookies on your own team's devices. Those are usually essential for the service, so consent may not be needed for the tool's core function. Analytics cookies inside the tool are a different matter and should be covered by the tool's own notice to your organisation.
Controller and processor roles when a UK team uses a non-UK scheduler
When a British team uses a scheduling tool, the team is usually the controller. It decides why the posts go out and what audience data is used. The tool provider is usually the processor. The ICO's Controllers and processors | ICO guidance explains the distinction and the contract terms that must be in place.
Controller vs processor roles
UK team (controller)
- Decides
- Why posts go out
- Audience data
- Sets purposes
- Breach duty
- Notify ICO in 72 hours
- Contract
- Data processing agreement
Scheduler (processor)
- Decides
- Acts on instructions
- Audience data
- Cannot use for own ends
- Breach duty
- Tell controller without delay
- Contract
- Named purposes, retention, security
A processor acts only on the controller's instructions. That means the tool cannot use your audience data for its own purposes, such as improving its own advertising, unless the contract allows it and you have a lawful basis. Many standard terms do allow some aggregated use, so read them.
The distinction also affects breach handling. If the processor suffers a breach affecting your data, it must tell you without undue delay, and you then assess whether to notify the ICO within 72 hours.
If the tool provider decides how data is used, it becomes a controller for that processing. Joint controllership is possible too. The roles should be written into the contract, not assumed from the tool's marketing page.
What to put in the contract
A UK team should have a data processing agreement with the scheduler. It should name the processing purposes, the retention period, the security measures, the sub-processors and the transfer mechanism. Without it, the team carries the risk.
International transfers and security duties for audience and account data
Many scheduling tools are hosted outside the UK. Sending personal data to a third country needs a transfer mechanism. For UK controllers, that usually means an adequacy regulation, the International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses.
Audience lists, engagement records and account credentials are all personal data. A transfer assessment should cover where the data is stored, where support staff can access it, and whether the destination has adequate protection.
Security duties under UK GDPR require appropriate technical and organisational measures. For scheduling, that means strong authentication on the tool, role-based access, and a limit on who can export audience lists. Passwords and API keys should not be shared in team chats.
Retention is part of security. Engagement data kept indefinitely is a risk with no benefit. Set a retention period for audience lists and post analytics, and delete what you no longer need.
A short transfer checklist
Transfer and security checklist
- Identify every country storing audience data
- Confirm transfer mechanism for each
- Check sub-processors and their locations
- Record security measures in the contract
- Set retention periods and deletion routine
- Review access rights every quarter
Documenting accountability so a scheduled post can be defended
Accountability records per campaign
- Record the lawful basis
- Record the audience
- Record the consent source
- Record the retention period
- Record the review date
A disclosure procedure helps here. It sets out who approves a post, what is disclosed about paid promotion, and where the data protection check sits in the workflow. Approving on the preview rather than the draft catches tracking pixels and audience mistakes before publication.
The GDPR, DPA and PECR framework should be mapped to your tools. Keep a simple register that names each tool, its role, the data it touches and the contract in place.
High risk processing means you must carry out a data protection impact assessment. Large-scale profiling or systematic monitoring of a public area can trigger it. Most routine scheduling does not, but retargeting at scale might.
Records that survive a complaint
If someone complains to the ICO, the first request is usually for your records. A team that can produce the basis, the consent wording and the retention decision is in a much stronger position than one that cannot.
Keep records for the retention period you set, and no longer. A record kept forever becomes its own liability.



