Skip to main content
Back to Read
Cold Email6 March 2026Updated 21 September 202613 min read

Is Cold Email Legal in the UK? PECR, GDPR and B2B Exemptions Explained

Natural editorial photograph of a white British man in his sixties wearing glasses, reading a single printed customer record at an open filing cabinet in a small UK back office lit by window light.
Illustrative scene.

TL;DR: UK B2B cold email depends on the recipient type and how the data is used. Corporate subscribers differ from sole traders and some partnerships under PECR. UK GDPR applies when personal data is processed. The checks below help you prepare a campaign; they are not a guarantee of compliance. Read the ICO’s current B2B marketing guidance alongside your circumstances.

The Question Every UK Business Owner Asks

You have heard this before: "Cold email is illegal in the UK."

The answer depends on who receives it. Unsolicited marketing to a limited company is treated differently from marketing to a sole trader, even when both addresses look like business email accounts.

Check the subscriber type first, then the data source, message and opt-out process. The sections below explain those decisions so you can assess an actual campaign.

Email marketing and cold outreach have different economics. Assess outcomes from your own campaign rather than importing a consumer-email return figure into a B2B forecast.

Use this as a practical starting point. The ICO guidance is under review following legislative changes, so check the current source and your specific circumstances before launching.

Get unstuck

GDPR vs PECR: Understanding the Two Frameworks

This is where most people get confused. They assume GDPR is the only law governing email marketing in the UK. It is not. There are two distinct frameworks, and they work in parallel.

The UK General Data Protection Regulation (UK GDPR) governs how you collect, store, and process personal data. It applies to any information that can identify a living individual — names, email addresses, job titles, IP addresses.

The Privacy and Electronic Communications Regulations 2003 (PECR) governs how you send electronic communications — emails, texts, phone calls, cookies. PECR is the law that specifically addresses whether you can send an unsolicited email to someone.

Here is the critical distinction: GDPR tells you how to handle the data. PECR tells you whether you can send the message.

CheckUK GDPRPECR
ScopeProcessing of personal dataSending electronic communications
Applies toAny organisation handling personal dataAny organisation sending emails, texts, calls
Key requirementAppropriate lawful basis for processingConsent or applicable exemption
B2B distinctionA lawful basis is needed when personal data is processedCorporate subscribers differ from individual subscribers; soft opt-in is a separate conditional route
Enforced byICOICO
Came into force25 May 2018 (retained post-Brexit)11 December 2003 (amended multiple times)

You need to comply with both. A cold email that satisfies PECR but ignores GDPR is still unlawful. An email that has a valid GDPR basis but violates PECR is equally problematic. Think of them as two gates — you need to pass through both.

The good news: for B2B cold email, both frameworks provide clear, workable paths to compliance.

The B2B Exemption: What PECR Regulation 22 Actually Says

PECR regulation 22 restricts unsolicited electronic marketing to individual subscribers. Establish subscriber type before deciding which consent requirements apply.

Regulation 22 distinguishes individual subscribers from corporate subscribers. The soft opt-in in regulation 22(3) is a separate, conditional route for individual subscribers; it is not the corporate-subscriber distinction.

Corporate subscribers include limited companies, LLPs and Scottish partnerships. Sole traders and some other partnerships are individual subscribers. An address ending in a business domain does not establish the subscriber type.

The distinction is based on subscriber status, not whether your offer sounds relevant or the recipient uses a company-style email address.

The ICO distinguishes the consent rules for individual subscribers from those for corporate subscribers. Other PECR requirements, including identifying the sender and providing a valid opt-out address, still apply to corporate marketing.

However — and this is the part most people skip — you still need to meet specific conditions.

For a deeper dive into building a complete cold email programme around this framework, read our pillar guide: Cold Email Lead Generation for UK Businesses: The 2026 Playbook.

Six Checks Before B2B Cold Email

These checks help assess a proposed corporate-subscriber campaign. They are not an exhaustive legal test. Where personal data is used, assess UK GDPR obligations separately from PECR.

1. You Are Emailing a Corporate Subscriber

Establish the legal status of the subscriber. Limited companies, LLPs and Scottish partnerships can be corporate subscribers; sole traders and some other partnerships are not. If the status is uncertain, do not assume that a business address removes the consent requirement.

Important nuance: Individual subscribers generally need consent or a valid soft opt-in for unsolicited electronic marketing. The soft opt-in has specific conditions; a purchased prospect list does not qualify simply because its contacts run businesses.

2. You Identify Yourself Clearly

Every cold email must clearly state who you are. Your company name, your real name, and your business must be identifiable. No fake sender names. No misleading "From" fields. No pretending to be someone you are not.

Where personal data is involved, provide the required privacy information too. UK GDPR transparency obligations differ depending on whether you obtained the data directly or from another source; an email signature alone does not settle them.

3. You Provide a Valid Contact Address

PECR requires a valid address through which the recipient can request that marketing stops, and the sender must not conceal its identity. Do not confuse that requirement with separate company-disclosure obligations or assume a postal address alone provides a usable opt-out.

4. You Offer a Clear Opt-Out Mechanism

Provide a clear, working opt-out route and apply objections promptly across the campaign. Check receiving-provider requirements separately, including one-click unsubscribe where applicable. Do not use a supposed grace period to continue marketing after an objection.

5. You Have a Lawful Basis Where Personal Data Is Used

PECR handles the "can I send this?" question. GDPR handles the "can I process this person's data?" question. Legitimate interests may be appropriate, but requires an assessment. It does not override a separate PECR consent requirement.

We cover this in detail in the next section.

6. You Honour Opt-Outs and Suppression Lists

If someone asks you to stop emailing them, stop and retain the minimum suppression information needed to prevent another send. Telephone outreach needs a separate assessment, including both the Telephone Preference Service (TPS) and Corporate TPS (CTPS) for live marketing calls. The ICO telephone guidance explains those checks.

ConditionRequirementRisk if Missed
Subscriber typeEstablish corporate or individual statusApplying the wrong electronic-marketing rules
Sender identificationCompany name + real identity visiblePECR violation + GDPR transparency breach
Contact addressValid address for requesting that marketing stopsPECR violation
Opt-out mechanismClear, free, functional unsubscribePECR violation and complaints
GDPR lawful basisAssess and document the appropriate basisUnlawful processing of personal data
Suppression complianceOpt-outs honoured, lists maintainedPECR violation + reputational damage

These six checks are a starting point, not a legal certification. Assess the actual audience, data source, transparency information and campaign, and obtain specialist advice where the position is uncertain.

B2C Cold Email: A Different Story Entirely

Consumer recipients are individual subscribers. Sole traders and some partnerships also fall into that category, even when the message concerns their business.

For B2C, PECR regulation 22 requires explicit prior consent — the individual must have actively opted in to receive marketing emails from you. There is a narrow "soft opt-in" exception where you can email existing customers about similar products, but true cold email to consumers without consent is unlawful.

If your business serves consumers directly, cold email is not your channel. Focus on content marketing, SEO and answer engine optimisation, paid advertising, and inbound lead generation instead. You may also find that database reactivation — re-engaging existing customers who have already bought from you — is a more effective option where eligibility has been checked. Our ReFlow service is purpose-built for exactly this kind of GDPR-compliant database reactivation, helping businesses re-engage dormant contacts with eligibility and suppression reviewed before sending.

This article — and Ampliflow's SCALeMAIL service — focuses exclusively on compliant B2B cold email.

Legitimate Interest as a Lawful Basis Under UK GDPR

Where you propose to rely on legitimate interests, conduct and document a Legitimate Interests Assessment (LIA). Do not assume this basis is appropriate for every campaign.

A LIA has three parts:

Purpose test: Do you have a legitimate reason for contacting this person? Offering a relevant service is a proposed purpose to assess, not an automatic pass. An indiscriminate list does not establish a necessary or proportionate use of personal data.

Necessity test: Is cold email necessary to achieve this purpose? If there is a less intrusive way to reach the same outcome, you should use it. Document why the chosen approach is necessary and proportionate.

Balancing test: Do the individual's rights and interests override your legitimate interest? Assess expectations, impact and safeguards rather than assuming that a professional address makes the balance favour the sender.

Keep the assessment and review it when the audience or purpose changes. It records your reasoning; it does not certify the whole campaign as compliant.

Use the ICO’s guidance to assess the purpose, necessity and balancing tests.

Technical Compliance: SPF, DKIM, DMARC and Deliverability

Legal eligibility and technical sending requirements need separate checks. Satisfying one does not establish the other.

Check the current requirements of your sending provider and receiving services, including Gmail’s sender guidelines. Authentication and legal eligibility are separate checks. Neither guarantees inbox placement.

SPF (Sender Policy Framework): A DNS record that specifies which mail servers are authorised to send email on behalf of your domain. A missing or failing record can contribute to rejection or spam placement; receiving services assess other signals too.

DKIM (DomainKeys Identified Mail): A cryptographic signature that proves your email was not altered in transit. It ties each message to your domain with a verifiable digital signature.

DMARC (Domain-based Message Authentication, Reporting and Conformance): A policy and reporting mechanism built on aligned SPF or DKIM authentication. Check all legitimate senders before moving to an enforcement policy.

AuthenticationPurposeImpact Without It
SPFAuthorises sending serversSPF authentication cannot pass without a valid record
DKIMVerifies signed parts of a messageThe receiving service cannot verify that DKIM signature
DMARCDefines alignment and a requested handling policyNo published DMARC policy or reporting route
TrackingUse only where appropriate and legally assessedTracking can affect privacy and reliability
Sending IPChoose suitable infrastructure for the volume and providerA dedicated IP is not automatically better

Authentication and sending requirements depend on the provider and campaign. A dedicated IP or tracking domain is not universally required. Infrastructure work is scoped explicitly; it is not included in every automation engagement by default.

What Happens if You Get It Wrong

The ICO has enforcement powers under both PECR and UK GDPR. And they use them.

Breaches can lead to enforcement and reputational consequences. The exact position depends on the conduct and applicable law.

Consult the ICO’s published enforcement records for verified examples; individual decisions are not a forecast of the consequences for another campaign.

Other possible consequences include:

  • Delivery restrictions. Complaints and poor sending practices can damage reputation or trigger blocks. Recovery varies by provider and cause.
  • Complaint investigation. A complaint may require you to explain your data sources, decisions and safeguards.
  • Loss of sending access. Providers can restrict or terminate accounts that breach their rules.
  • Reputational damage. ICO enforcement notices are public record. Your prospects can — and will — find them.

The message is straightforward: compliance is not a cost centre. It is the price of admission.

How to Build a Compliant Cold Email Programme

Use these steps to prepare a campaign for review.

Step 1: Define your Ideal Customer Profile (ICP). Describe the organisations you can help and why the offer fits. "UK-based accounting firms with 10–50 employees" is a research starting point, not a completed legal assessment. Our customer-profile guide explains the next checks.

Step 2: Source data compliantly. Use reputable B2B data providers that verify their data is collected lawfully. Check the source, licence, transparency arrangements and the intended use. Public availability or a supplier’s claim does not establish permission for your campaign.

Step 3: Conduct and document your LIA. Write out your purpose, necessity, and balancing tests. Keep the document accessible. Update it when your targeting changes.

Step 4: Set up the sending infrastructure. Agree a clear sending identity, authentication and monitoring with your provider. A separate domain is a design choice, not a legal requirement or permission to evade restrictions. Check readiness against provider requirements and observed sending health.

Step 5: Write relevant, personalised emails. Generic mail-merge templates sent to thousands of recipients are a compliance risk and a deliverability disaster. Every email should demonstrate that you understand the recipient's business and have a relevant reason for reaching out.

Step 6: Include all required elements. Your real name and company name. A valid contact address. A clear, working opt-out route, plus any unsubscribe mechanism required by the sending or receiving provider.

Step 7: Monitor and maintain. Apply opt-outs promptly and stop further marketing to those recipients. Maintain your suppression list. Monitor bounce rates and complaints. Adjust your approach based on engagement data.

See SCALeMAIL for our B2B outreach scope and the controls to agree before sending.

Where AI Can Help With Reviewed Outreach

AI can assist with preparation once the audience and rules are clear. The most practical uses are research summaries, draft messages and reviews of observed campaign results:

Reviewed research and drafting. A model can summarise public business information and suggest a relevant opening. Check the original source and date before using it. Do not let a draft invent familiarity, customer results or a private business problem.

Controlled checks. Fixed rules can check required fields and suppression records. A person still needs to assess eligibility and resolve uncertain cases; AI should not make the final legal decision.

Measured optimisation. Review actual replies, complaints and delivery problems before changing a campaign. Neither a model nor a timetable guarantees results.

Our SCALeMAIL service scopes B2B outreach around reviewed personalisation, sending controls, suppression and reply handling. Neither AI nor a platform can certify a campaign as lawful or remove compliance risk. Your organisation remains responsible for its decisions.

For a complete breakdown of the strategy behind this approach, see our guide: Cold Email Lead Generation for UK Businesses: The 2026 Playbook.

For help with the campaign workflow, Get unstuck. Obtain qualified legal advice where eligibility remains uncertain.

Key Takeaways

  1. Establish subscriber type first. Corporate subscribers differ from sole traders and some partnerships; the six checks are not a legal certification.
  2. Individual subscribers generally need consent or a valid soft opt-in. A cold prospect list does not automatically qualify.
  3. GDPR and PECR work in parallel. You need an appropriate lawful basis under UK GDPR where personal data is used and compliance with PECR's requirements. Both must be satisfied.
  4. Technical compliance is non-negotiable. Check SPF, DKIM and DMARC against your sending and receiving providers’ current requirements.
  5. Check current ICO guidance. Enforcement and legal obligations cannot be reduced to a campaign checklist.
  6. Documentation protects you. A written assessment records your reasoning; it does not certify compliance. Conduct one, file it, update it.
  7. AI does not certify compliance. Automated checks can support reviewed controls; campaign decisions still require accountable ownership.

Decide whether the actual recipient and campaign meet the rules before preparing a sending schedule.

FAQ

It can be. Corporate subscribers, such as limited companies and LLPs, differ from sole traders and some partnerships under PECR. Sender identification and a working opt-out still matter. Where personal data is processed, UK GDPR also applies. A business email address alone does not establish eligibility.

It depends on the subscriber. PECR does not require consent for electronic marketing to corporate subscribers, but sender identity and opt-out requirements still apply. Individual subscribers generally need consent or a valid soft opt-in. If personal data is processed, assess the appropriate UK GDPR lawful basis separately.

What is the difference between GDPR and PECR for cold email?

UK GDPR governs how you collect, store, and process personal data (including email addresses). PECR governs whether you can send the electronic communication itself. For cold email compliance, you need to satisfy both. GDPR requires a lawful basis for processing the data. PECR requires either consent or an applicable exemption (such as the corporate subscriber exemption) for sending the message.

Can the ICO fine me for sending cold emails?

Yes. Breaches of PECR or UK GDPR can result in enforcement. Consult the current ICO guidance and obtain specialist advice for a specific risk assessment.

Can I send cold emails to sole traders in the UK?

Sole traders are individual subscribers under PECR. Unsolicited marketing generally needs consent or a valid soft opt-in meeting all its conditions. A new cold prospect normally will not satisfy the soft opt-in merely because their details are public. Check the subscriber status rather than inferring it from the address.

Get unstuck

B2B email outreach

Start with a relevant audience and a clear offer

Most cold email gets ignored or lands in spam. We manage the targeting, copy, sending controls and follow-up around a clearly defined audience and offer.

Done-for-you cold email
Tight targeting & ICP
Sending health monitored
Relevant replies tracked
Get unstuck

Audience, scope and reply handling come before campaign volume.