Is Cold Email Legal in the UK? PECR, GDPR and B2B Exemptions Explained

TL;DR: UK B2B cold email depends on the recipient type and how the data is used. Corporate subscribers differ from sole traders and some partnerships under PECR. UK GDPR applies when personal data is processed. The checks below help you prepare a campaign; they are not a guarantee of compliance. Read the ICO’s current B2B marketing guidance alongside your circumstances.
The Question Every UK Business Owner Asks
You have heard this before: "Cold email is illegal in the UK."
The answer depends on who receives it. Unsolicited marketing to a limited company is treated differently from marketing to a sole trader, even when both addresses look like business email accounts.
Check the subscriber type first, then the data source, message and opt-out process. The sections below explain those decisions so you can assess an actual campaign.
Email marketing and cold outreach have different economics. Assess outcomes from your own campaign rather than importing a consumer-email return figure into a B2B forecast.
Use this as a practical starting point. The ICO guidance is under review following legislative changes, so check the current source and your specific circumstances before launching.
GDPR vs PECR: Understanding the Two Frameworks
This is where most people get confused. They assume GDPR is the only law governing email marketing in the UK. It is not. There are two distinct frameworks, and they work in parallel.
The UK General Data Protection Regulation (UK GDPR) governs how you collect, store, and process personal data. It applies to any information that can identify a living individual — names, email addresses, job titles, IP addresses.
The Privacy and Electronic Communications Regulations 2003 (PECR) governs how you send electronic communications — emails, texts, phone calls, cookies. PECR is the law that specifically addresses whether you can send an unsolicited email to someone.
Here is the critical distinction: GDPR tells you how to handle the data. PECR tells you whether you can send the message.
| Check | UK GDPR | PECR |
|---|---|---|
| Scope | Processing of personal data | Sending electronic communications |
| Applies to | Any organisation handling personal data | Any organisation sending emails, texts, calls |
| Key requirement | Appropriate lawful basis for processing | Consent or applicable exemption |
| B2B distinction | A lawful basis is needed when personal data is processed | Corporate subscribers differ from individual subscribers; soft opt-in is a separate conditional route |
| Enforced by | ICO | ICO |
| Came into force | 25 May 2018 (retained post-Brexit) | 11 December 2003 (amended multiple times) |
You need to comply with both. A cold email that satisfies PECR but ignores GDPR is still unlawful. An email that has a valid GDPR basis but violates PECR is equally problematic. Think of them as two gates — you need to pass through both.
The good news: for B2B cold email, both frameworks provide clear, workable paths to compliance.
The B2B Exemption: What PECR Regulation 22 Actually Says
PECR regulation 22 restricts unsolicited electronic marketing to individual subscribers. Establish subscriber type before deciding which consent requirements apply.
Regulation 22 distinguishes individual subscribers from corporate subscribers. The soft opt-in in regulation 22(3) is a separate, conditional route for individual subscribers; it is not the corporate-subscriber distinction.
Corporate subscribers include limited companies, LLPs and Scottish partnerships. Sole traders and some other partnerships are individual subscribers. An address ending in a business domain does not establish the subscriber type.
The distinction is based on subscriber status, not whether your offer sounds relevant or the recipient uses a company-style email address.
The ICO distinguishes the consent rules for individual subscribers from those for corporate subscribers. Other PECR requirements, including identifying the sender and providing a valid opt-out address, still apply to corporate marketing.
However — and this is the part most people skip — you still need to meet specific conditions.
For a deeper dive into building a complete cold email programme around this framework, read our pillar guide: Cold Email Lead Generation for UK Businesses: The 2026 Playbook.
Six Checks Before B2B Cold Email
These checks help assess a proposed corporate-subscriber campaign. They are not an exhaustive legal test. Where personal data is used, assess UK GDPR obligations separately from PECR.
1. You Are Emailing a Corporate Subscriber
Establish the legal status of the subscriber. Limited companies, LLPs and Scottish partnerships can be corporate subscribers; sole traders and some other partnerships are not. If the status is uncertain, do not assume that a business address removes the consent requirement.
Important nuance: Individual subscribers generally need consent or a valid soft opt-in for unsolicited electronic marketing. The soft opt-in has specific conditions; a purchased prospect list does not qualify simply because its contacts run businesses.
2. You Identify Yourself Clearly
Every cold email must clearly state who you are. Your company name, your real name, and your business must be identifiable. No fake sender names. No misleading "From" fields. No pretending to be someone you are not.
Where personal data is involved, provide the required privacy information too. UK GDPR transparency obligations differ depending on whether you obtained the data directly or from another source; an email signature alone does not settle them.
3. You Provide a Valid Contact Address
PECR requires a valid address through which the recipient can request that marketing stops, and the sender must not conceal its identity. Do not confuse that requirement with separate company-disclosure obligations or assume a postal address alone provides a usable opt-out.
4. You Offer a Clear Opt-Out Mechanism
Provide a clear, working opt-out route and apply objections promptly across the campaign. Check receiving-provider requirements separately, including one-click unsubscribe where applicable. Do not use a supposed grace period to continue marketing after an objection.
5. You Have a Lawful Basis Where Personal Data Is Used
PECR handles the "can I send this?" question. GDPR handles the "can I process this person's data?" question. Legitimate interests may be appropriate, but requires an assessment. It does not override a separate PECR consent requirement.
We cover this in detail in the next section.
6. You Honour Opt-Outs and Suppression Lists
If someone asks you to stop emailing them, stop and retain the minimum suppression information needed to prevent another send. Telephone outreach needs a separate assessment, including both the Telephone Preference Service (TPS) and Corporate TPS (CTPS) for live marketing calls. The ICO telephone guidance explains those checks.
| Condition | Requirement | Risk if Missed |
|---|---|---|
| Subscriber type | Establish corporate or individual status | Applying the wrong electronic-marketing rules |
| Sender identification | Company name + real identity visible | PECR violation + GDPR transparency breach |
| Contact address | Valid address for requesting that marketing stops | PECR violation |
| Opt-out mechanism | Clear, free, functional unsubscribe | PECR violation and complaints |
| GDPR lawful basis | Assess and document the appropriate basis | Unlawful processing of personal data |
| Suppression compliance | Opt-outs honoured, lists maintained | PECR violation + reputational damage |
These six checks are a starting point, not a legal certification. Assess the actual audience, data source, transparency information and campaign, and obtain specialist advice where the position is uncertain.
B2C Cold Email: A Different Story Entirely
Consumer recipients are individual subscribers. Sole traders and some partnerships also fall into that category, even when the message concerns their business.
For B2C, PECR regulation 22 requires explicit prior consent — the individual must have actively opted in to receive marketing emails from you. There is a narrow "soft opt-in" exception where you can email existing customers about similar products, but true cold email to consumers without consent is unlawful.
If your business serves consumers directly, cold email is not your channel. Focus on content marketing, SEO and answer engine optimisation, paid advertising, and inbound lead generation instead. You may also find that database reactivation — re-engaging existing customers who have already bought from you — is a more effective option where eligibility has been checked. Our ReFlow service is purpose-built for exactly this kind of GDPR-compliant database reactivation, helping businesses re-engage dormant contacts with eligibility and suppression reviewed before sending.
This article — and Ampliflow's SCALeMAIL service — focuses exclusively on compliant B2B cold email.
Legitimate Interest as a Lawful Basis Under UK GDPR
Where you propose to rely on legitimate interests, conduct and document a Legitimate Interests Assessment (LIA). Do not assume this basis is appropriate for every campaign.
A LIA has three parts:
Purpose test: Do you have a legitimate reason for contacting this person? Offering a relevant service is a proposed purpose to assess, not an automatic pass. An indiscriminate list does not establish a necessary or proportionate use of personal data.
Necessity test: Is cold email necessary to achieve this purpose? If there is a less intrusive way to reach the same outcome, you should use it. Document why the chosen approach is necessary and proportionate.
Balancing test: Do the individual's rights and interests override your legitimate interest? Assess expectations, impact and safeguards rather than assuming that a professional address makes the balance favour the sender.
Keep the assessment and review it when the audience or purpose changes. It records your reasoning; it does not certify the whole campaign as compliant.
Use the ICO’s guidance to assess the purpose, necessity and balancing tests.
Technical Compliance: SPF, DKIM, DMARC and Deliverability
Legal eligibility and technical sending requirements need separate checks. Satisfying one does not establish the other.
Check the current requirements of your sending provider and receiving services, including Gmail’s sender guidelines. Authentication and legal eligibility are separate checks. Neither guarantees inbox placement.
SPF (Sender Policy Framework): A DNS record that specifies which mail servers are authorised to send email on behalf of your domain. A missing or failing record can contribute to rejection or spam placement; receiving services assess other signals too.
DKIM (DomainKeys Identified Mail): A cryptographic signature that proves your email was not altered in transit. It ties each message to your domain with a verifiable digital signature.
DMARC (Domain-based Message Authentication, Reporting and Conformance): A policy and reporting mechanism built on aligned SPF or DKIM authentication. Check all legitimate senders before moving to an enforcement policy.
| Authentication | Purpose | Impact Without It |
|---|---|---|
| SPF | Authorises sending servers | SPF authentication cannot pass without a valid record |
| DKIM | Verifies signed parts of a message | The receiving service cannot verify that DKIM signature |
| DMARC | Defines alignment and a requested handling policy | No published DMARC policy or reporting route |
| Tracking | Use only where appropriate and legally assessed | Tracking can affect privacy and reliability |
| Sending IP | Choose suitable infrastructure for the volume and provider | A dedicated IP is not automatically better |
Authentication and sending requirements depend on the provider and campaign. A dedicated IP or tracking domain is not universally required. Infrastructure work is scoped explicitly; it is not included in every automation engagement by default.
What Happens if You Get It Wrong
The ICO has enforcement powers under both PECR and UK GDPR. And they use them.
Breaches can lead to enforcement and reputational consequences. The exact position depends on the conduct and applicable law.
Consult the ICO’s published enforcement records for verified examples; individual decisions are not a forecast of the consequences for another campaign.
Other possible consequences include:
- Delivery restrictions. Complaints and poor sending practices can damage reputation or trigger blocks. Recovery varies by provider and cause.
- Complaint investigation. A complaint may require you to explain your data sources, decisions and safeguards.
- Loss of sending access. Providers can restrict or terminate accounts that breach their rules.
- Reputational damage. ICO enforcement notices are public record. Your prospects can — and will — find them.
The message is straightforward: compliance is not a cost centre. It is the price of admission.
How to Build a Compliant Cold Email Programme
Use these steps to prepare a campaign for review.
Step 1: Define your Ideal Customer Profile (ICP). Describe the organisations you can help and why the offer fits. "UK-based accounting firms with 10–50 employees" is a research starting point, not a completed legal assessment. Our customer-profile guide explains the next checks.
Step 2: Source data compliantly. Use reputable B2B data providers that verify their data is collected lawfully. Check the source, licence, transparency arrangements and the intended use. Public availability or a supplier’s claim does not establish permission for your campaign.
Step 3: Conduct and document your LIA. Write out your purpose, necessity, and balancing tests. Keep the document accessible. Update it when your targeting changes.
Step 4: Set up the sending infrastructure. Agree a clear sending identity, authentication and monitoring with your provider. A separate domain is a design choice, not a legal requirement or permission to evade restrictions. Check readiness against provider requirements and observed sending health.
Step 5: Write relevant, personalised emails. Generic mail-merge templates sent to thousands of recipients are a compliance risk and a deliverability disaster. Every email should demonstrate that you understand the recipient's business and have a relevant reason for reaching out.
Step 6: Include all required elements. Your real name and company name. A valid contact address. A clear, working opt-out route, plus any unsubscribe mechanism required by the sending or receiving provider.
Step 7: Monitor and maintain. Apply opt-outs promptly and stop further marketing to those recipients. Maintain your suppression list. Monitor bounce rates and complaints. Adjust your approach based on engagement data.
See SCALeMAIL for our B2B outreach scope and the controls to agree before sending.
Where AI Can Help With Reviewed Outreach
AI can assist with preparation once the audience and rules are clear. The most practical uses are research summaries, draft messages and reviews of observed campaign results:
Reviewed research and drafting. A model can summarise public business information and suggest a relevant opening. Check the original source and date before using it. Do not let a draft invent familiarity, customer results or a private business problem.
Controlled checks. Fixed rules can check required fields and suppression records. A person still needs to assess eligibility and resolve uncertain cases; AI should not make the final legal decision.
Measured optimisation. Review actual replies, complaints and delivery problems before changing a campaign. Neither a model nor a timetable guarantees results.
Our SCALeMAIL service scopes B2B outreach around reviewed personalisation, sending controls, suppression and reply handling. Neither AI nor a platform can certify a campaign as lawful or remove compliance risk. Your organisation remains responsible for its decisions.
For a complete breakdown of the strategy behind this approach, see our guide: Cold Email Lead Generation for UK Businesses: The 2026 Playbook.
For help with the campaign workflow, Get unstuck. Obtain qualified legal advice where eligibility remains uncertain.
Key Takeaways
- Establish subscriber type first. Corporate subscribers differ from sole traders and some partnerships; the six checks are not a legal certification.
- Individual subscribers generally need consent or a valid soft opt-in. A cold prospect list does not automatically qualify.
- GDPR and PECR work in parallel. You need an appropriate lawful basis under UK GDPR where personal data is used and compliance with PECR's requirements. Both must be satisfied.
- Technical compliance is non-negotiable. Check SPF, DKIM and DMARC against your sending and receiving providers’ current requirements.
- Check current ICO guidance. Enforcement and legal obligations cannot be reduced to a campaign checklist.
- Documentation protects you. A written assessment records your reasoning; it does not certify compliance. Conduct one, file it, update it.
- AI does not certify compliance. Automated checks can support reviewed controls; campaign decisions still require accountable ownership.
Decide whether the actual recipient and campaign meet the rules before preparing a sending schedule.
FAQ
Is cold email legal in the UK for B2B outreach?
It can be. Corporate subscribers, such as limited companies and LLPs, differ from sole traders and some partnerships under PECR. Sender identification and a working opt-out still matter. Where personal data is processed, UK GDPR also applies. A business email address alone does not establish eligibility.
Do I need consent to send cold emails to businesses?
It depends on the subscriber. PECR does not require consent for electronic marketing to corporate subscribers, but sender identity and opt-out requirements still apply. Individual subscribers generally need consent or a valid soft opt-in. If personal data is processed, assess the appropriate UK GDPR lawful basis separately.
What is the difference between GDPR and PECR for cold email?
UK GDPR governs how you collect, store, and process personal data (including email addresses). PECR governs whether you can send the electronic communication itself. For cold email compliance, you need to satisfy both. GDPR requires a lawful basis for processing the data. PECR requires either consent or an applicable exemption (such as the corporate subscriber exemption) for sending the message.
Can the ICO fine me for sending cold emails?
Yes. Breaches of PECR or UK GDPR can result in enforcement. Consult the current ICO guidance and obtain specialist advice for a specific risk assessment.
Can I send cold emails to sole traders in the UK?
Sole traders are individual subscribers under PECR. Unsolicited marketing generally needs consent or a valid soft opt-in meeting all its conditions. A new cold prospect normally will not satisfy the soft opt-in merely because their details are public. Check the subscriber status rather than inferring it from the address.