Rules and ethics
How ICO rules change UK local SEO lead capture and review collection
Local SEO lead capture and review collection must satisfy ICO consent rules, UK GDPR and PECR before any email or SMS is sent to UK customers.
What to take away
- Local SEO lead capture now needs a named lawful basis, and the ICO consent standard means a pre-ticked box will not do.
- Legitimate interest can cover some B2B follow-up, but PECR still blocks cold email and SMS to sole traders and partnerships without consent.
- Review requests to past customers sit under the soft opt-in, and every message needs a working opt-out.
- Your agency owes a data protection fee to the ICO unless an exemption applies, and you must answer subject access requests within one month.
- Document the lawful basis in the client contract before the campaign starts, not after a complaint arrives.
What the ICO consent standard means for UK local SEO lead capture
The ICO sets the bar for consent in UK marketing, and its guidance applies to every form on a local SEO landing page. Any consent has to be given freely, be specific, informed and clear. Silence, pre-ticked boxes and bundled terms do not count.
For a local SEO campaign, that means a plumbing enquiry form cannot bury marketing permission inside a privacy policy link. The opt-in needs its own unticked box, plain wording, and a record of when and how it was given.
Consent also has to be separable. A visitor who asks for a quote has not agreed to a monthly newsletter. If you want both, ask twice. The ICO's organisation guidance covers this distinction across marketing activities.
Local SEO lead capture often runs through call tracking, chat widgets and gated guides. Each channel is a separate collection point. Each needs its own notice and its own lawful basis recorded.
Consent can be withdrawn at any time, and withdrawal must be as easy as giving it. A reply-to-unsubscribe line is not enough if the original sign-up was a single click. Build a one-click withdrawal route into the CRM.
Where a form is aimed at business contacts, the rules do not soften. A sole trader's work email is personal data. A named person at a limited company is still a person.
Record keeping is where most agencies slip. If the ICO asks, you need to show who consented, to what, when, and on which page. Store the form version alongside the contact record.
Legitimate interest versus consent for local SEO forms and call tracking
Legitimate interest is a lawful basis under UK GDPR, but it is not a free pass for marketing. The ICO expects a three-part test: a real interest, necessity, and a balancing exercise against the individual's rights.
For local SEO agencies, the strongest legitimate interest cases are fraud prevention, service delivery and answering an enquiry the customer started. Marketing to new prospects is a weaker case, and PECR often overrides it.
The ICO's guidance on choosing a lawful basis makes the split clear. Consent is the default for electronic marketing to individuals. Legitimate interest can support the processing around it, such as suppressing unsubscribes.
Call tracking is a common trap. Recording inbound calls captures personal data, and the caller may not expect it. A short recorded notice at the start of the call, plus a published retention period, keeps the practice defensible.
If you rely on legitimate interest, you must complete a legitimate interests assessment. Write it down. A one-page LIA per campaign is enough, but an undocumented decision is hard to defend later.
B2B email in the UK is not exempt from PECR. You may email a corporate body, but not a sole trader or an unincorporated partnership, without consent. Many local SEO prospect lists mix the two, so segment before sending.
Balance the test honestly. A garage owner who enquired about a website has a reasonable expectation of a reply. They do not expect to be added to a training webinar list for two years.
UK GDPR and Data Protection Act 2018 duties that touch review collection
Review collection is personal data processing, and the Data Protection Act 2018 sits alongside UK GDPR as the framework for handling it. The duties are ordinary, but they bite at scale.
You need a lawful basis for contacting past customers, a retention period for their details, and a route for them to object. You also need to be transparent about where the review will appear.
Transparency is the duty most often missed. A customer asked for a Google review should know their name and words may be published publicly. Say so in the request.
Data minimisation matters too. You do not need a customer's full address history to ask for a review. Keep the contact record to what the task needs.
Accuracy is a live duty in review work. If a customer asks you to correct a fact you hold about them, you must act. That can include internal notes attached to their record.
The same duties apply to review gating, where only happy customers are asked. The ICO does not ban it outright, but the ASA and CMA watch for misleading practice. Keep the process honest and documented.
Retention should be deliberate. Set a period for review request data, delete on schedule, and log the deletion. Indefinite storage is the easiest finding to avoid.
Building a compliant review request workflow under PECR and the ICO guide
PECR and direct marketing rules govern emails and SMS to past customers. The soft opt-in allows contact where you obtained details in a sale, for similar services, and offered an opt-out at collection and in every message.
That covers most review requests. It does not cover a purchased list, a scraped directory, or a customer who bought something unrelated. Those need consent.
Follow these steps for a defensible workflow.
- Check the lawful basis for each contact before the campaign runs, and record it against the segment.
- Confirm the soft opt-in conditions: details collected in a sale, similar service, opt-out offered at collection.
- Send the request with a clear identity, a reason for contact, and a working opt-out in the same message.
- Suppress anyone who has opted out, objected, or asked for deletion, across every channel.
- Log the send, the consent or soft opt-in basis, and any opt-out, then review the log monthly.
Use this checklist before any review request goes out.
- Lawful basis recorded per contact, not per campaign.
- Opt-out offered when the details were first collected.
- Opt-out repeated in the review request itself.
- Sender identity and postal address included.
- Suppression list applied to email and SMS.
- Retention period set and logged.
- Review platform named in the message.
A worked example shows the difference. A dental practice in Leeds emails patients seen in the last 90 days, offering a Google review link and a one-click opt-out. That fits the soft opt-in. The same practice emailing a bought list of local residents does not.
Keep the sequence short and the exit obvious. Every extra message raises the chance of a complaint, and a complaint to the ICO costs more time than the review was worth.
Cookies, analytics and storage technologies in local SEO tracking
Cookie consent sits under PECR, not UK GDPR alone. Analytics cookies that identify a device need consent before they are set, unless they are strictly necessary for a service the user requested.
Most local SEO tracking is not strictly necessary. Heatmaps, session recordings, call tracking scripts and remarketing pixels all need prior consent. That means no script fires before the banner choice.
Consent mode in analytics tools helps, but it does not replace a proper banner. You still need a reject option as prominent as accept, and no dark patterns.
The Data (Use and Access) Act 2025 changes parts of the marketing and analytics picture, so check current ICO guidance rather than relying on older templates. Rules on cookies and nuisance contacts have been under review.
For local SEO agencies, the practical fix is a consent management platform that blocks tags by default. Test it. A tag that fires on page load before consent is a breach waiting to be reported.
Server-side tracking does not remove the duty. If the data identifies a person, the same rules apply, whatever the transport.
Keep a record of your cookie audit and re-run it when you add a tool. New scripts arrive with new clients, and each one needs a category.
Data protection fee, subject access requests and small agency obligations
Most agencies that process personal data must pay the ICO data protection fee. It is an annual charge, tiered by size and turnover, with limited exemptions. Check your status rather than assuming you are too small.
Non-payment can attract a penalty, and the fee is separate from any breach. It is the cheapest compliance task on this list, so do it first.
A subject access request can arrive by any channel, including a social media message. You must respond within one month, and you can extend by two months for complex requests.
You cannot charge in most cases. You must verify identity if you doubt it, and you must search all systems, including CRM notes, call recordings and email inboxes.
For a small agency, the work is in the search. Keep a data map so you know where client and prospect data lives. Without it, a subject access request becomes a fire drill.
Personal data breaches must be reported to the ICO within 72 hours where they pose a risk to rights and freedoms. Have a one-page incident process ready, with named owners.
If you handle data for clients, you are likely a processor and need a written contract with each controller. That contract should set out instructions, security and breach notification.
Documenting lawful basis in a local SEO client contract
Put the lawful basis in writing before work starts. The contract should name who is controller, who is processor, and which basis applies to each activity.
Lead capture, call tracking, review requests and analytics each need a line. Vague clauses about compliance in general will not help when a complaint lands.
Set out retention periods, deletion duties and who answers subject access requests. If the client is the controller, they answer, and you assist.
Agree the opt-out handling process. Who suppresses the contact, in which system, and how quickly. A shared spreadsheet is not a suppression list.
Record the client's instructions for any transfer outside the UK, and the safeguards used. UK GDPR does not stop transfers, but it requires a mechanism.
Review the schedule annually. A campaign that adds SMS or a new review platform changes the processing, and the contract should change with it.
This is where a local SEO disclosure policy and a clear local SEO rules and ethics position help. Clients increasingly ask for both before signing.
Agencies that map local SEO UK regulations properly win trust in pitches. Buyers in regulated sectors, from finance to healthcare, will ask for your lawful basis before they ask for your rankings. Your local SEO data protection duties belong in the onboarding pack, not in a drawer.
Common questions
Do I need consent to email a past customer for a review? Not always. The soft opt-in under PECR allows it where you collected their details in a sale, offer similar services, and gave an opt-out at collection and in every message.
Can I rely on legitimate interest for local SEO lead follow-up? For answering an enquiry, usually yes, with a documented assessment. For adding that person to a marketing list, consent is the safer basis and often the only lawful one under PECR.
Is a sole trader's business email covered by UK GDPR? Yes. A sole trader or unincorporated partnership is treated as an individual for PECR purposes, so you need consent before sending marketing email.
We must respond to a subject access request within one month of receiving it, though this can be extended by two months for complex requests. You must search all systems that hold the person's data, including call recordings and inboxes.
Does our small agency need to pay the ICO data protection fee? Most agencies that process personal data do, unless a narrow exemption applies. The fee is annual and tiered, and non-payment can lead to a penalty.
Do analytics cookies need consent before they fire? Yes, unless they are strictly necessary for a service the user requested. Most local SEO tracking, including heatmaps and remarketing pixels, needs prior consent.


