Is Cold Email Legal in the UK? A Plain-English PECR Guide
What PECR actually says about B2B cold email, what counts as a corporate subscriber, and the practical rules that keep outbound compliant. Not legal advice.
The short answer
Cold email to UK businesses is generally lawful. PECR's consent requirement for unsolicited marketing email applies to individual subscribers, which includes sole traders and most partnerships, but not to corporate subscribers such as limited companies and public bodies. UK GDPR still applies separately whenever the address identifies a person, so a named business address needs a lawful basis, usually legitimate interests, plus transparency and an easy opt-out. This is a summary, not legal advice.
Key takeaways
- PECR distinguishes corporate subscribers from individual subscribers. Limited companies are corporate; sole traders and most partnerships are treated as individuals and need consent.
- PECR is not the whole picture. A named address like jane@company.com is personal data, so UK GDPR applies alongside it.
- Legitimate interests is the usual lawful basis for B2B outreach, and it requires you to have actually done the balancing test, not just to have named it.
- Every marketing email must identify the sender and offer a working, honoured opt-out. Suppression is a legal obligation, not a courtesy.
Yes, B2B cold email is generally legal in the UK, provided it’s sent to a business contact for a genuinely business-relevant reason, and includes a clear way to opt out. The rules that govern it sit in two places: UK GDPR, which covers the personal data involved, and PECR (the Privacy and Electronic Communications Regulations), which adds specific rules for electronic marketing.
Not legal advice
This is general information, not legal advice for your specific business or market. If compliance is a hard requirement, get advice from a solicitor familiar with UK marketing law.
Why B2B email isn’t a free-for-all under UK law
A common assumption is that PECR and GDPR only cover consumer marketing, and business email is exempt. That’s not accurate. A named individual’s business email address is still personal data, and PECR’s marketing rules still apply to it. What changes for B2B, specifically, is one important carve-out: corporate subscribers.
Corporate subscribers, explained
PECR treats “corporate subscribers”, broadly, limited companies and similar organisations, differently from individual consumers. Marketing email to a named person at a corporate subscriber doesn’t require the same prior opt-in consent that consumer marketing does. This is the specific reason B2B cold email is workable at all under UK law. Sole traders and some partnerships, however, are generally treated closer to individual consumers rather than as corporate subscribers, and the consent rules for those cases are stricter.
What still applies, regardless of corporate subscriber status
- GDPR’s data protection principles. The business email address is still personal data, and processing it still needs a lawful basis (commonly, legitimate interests for relevant B2B marketing) and needs to be handled proportionately.
- An identifiable sender.The email must clearly identify who’s sending it.
- A working opt-out. Every marketing email needs a straightforward way to say no to future contact, and that request needs to be honoured.
What makes an email more likely to be compliant, practically
- Targeting a real, relevant business role, not a scattershot list.
- A message that’s actually about a business matter relevant to that role.
- Using verified, not scraped-and-guessed, contact data.
- An immediate, working opt-out mechanism, honoured without delay.
- No special category data used for targeting.
What makes an email more likely to cause a problem
- Contacting a sole trader or partnership as though they were a corporate subscriber.
- Ignoring or delaying an opt-out request.
- Sending at a volume or frequency disproportionate to any genuine business relevance.
- Misrepresenting who the sender is.
Where GDPR fits into all of this
PECR governs the marketing communication itself. GDPR governs the personal data behind it, including where it came from and how long it’s kept. See GDPR and B2B cold outreach for how the two interact in practice.
Working out which side of the line a prospect falls on
Because the consent rule turns on subscriber type, the practical question for every address on your list is: is this a corporate subscriber or an individual one? The ICO treats limited companies, LLPs in most cases, and public bodies as corporate subscribers. It treats sole traders and most ordinary partnerships as individual subscribers, which means the stricter consent rules apply to them.
| Prospect | Generally treated as | Practical consequence |
|---|---|---|
| Limited company (Ltd, PLC) | Corporate subscriber | Relevant B2B marketing email without prior consent is generally workable. |
| Limited liability partnership | Corporate subscriber in most cases | Same as a limited company, but worth checking the entity. |
| Public body | Corporate subscriber | Same, though many have their own procurement rules. |
| Sole trader | Individual subscriber | Consent rules apply. Do not treat as B2B by default. |
| Ordinary partnership | Individual subscriber in most cases | Consent rules generally apply. |
| A personal address at any of the above | Individual | Treat as consumer marketing regardless of what they do for work. |
This is checkable rather than guessable: a UK company register lookup on the domain will usually tell you the entity type in seconds, and it is worth building that check into list building rather than into a later apology.
The obligation people miss: telling them where you got their details
PECR governs the sending. UK GDPR governs the data, and it carries a transparency obligation that most cold outreach quietly ignores: when you obtain personal data from somewhere other than the person themselves, they are entitled to be told that you hold it, what you are doing with it, and where it came from.
In practice that means a line in the email, or a clearly linked privacy notice, that says plainly how you found them. It costs one sentence and it is also, incidentally, good outreach, since “I found you via your careers page” reads as candour rather than compliance.
The legitimate interests assessment
Legitimate interests is the lawful basis most B2B outreach relies on, and relying on it is a thing you have to actually do rather than merely name. The test has three parts and it should exist as a written record before you send, not after a complaint:
- Purpose.What is the legitimate interest? “Marketing a relevant business service to people whose role covers this problem” is one; “growing our pipeline” on its own is weaker.
- Necessity. Is processing this data necessary to achieve it, and is there a less intrusive route to the same outcome?
- Balance.Weighed against the individual’s rights and reasonable expectations, does the interest still hold? A relevant email to a work address a person uses for exactly this kind of enquiry sits very differently from a personal address scraped from somewhere they did not expect.
Write it down once, revisit it when the targeting changes materially, and keep it. A documented assessment is the difference between a defensible position and an assertion.
Suppression, in practice
An opt-out or objection must be honoured promptly and permanently. Three things this implies that teams routinely get wrong:
- It survives tooling changes. A suppression list that lived inside a sending platform you have since left is not a suppression list. Keep it somewhere you own.
- It applies across campaigns, not per campaign. Someone who opted out of one sequence has not opted into the next one.
- A reply saying “not interested, stop” is an opt-out, even though it did not arrive through a link. Objections do not have to use your preferred mechanism.
A pre-send checklist
- Entity type checked, and sole traders and partnerships handled under the stricter rules.
- Address verified, and the role genuinely relevant to what you are writing about.
- Lawful basis identified and the legitimate interests assessment written down.
- Sender clearly identified, with an accurate from-address and subject line.
- A statement of where the data came from, or a linked privacy notice that says so.
- A working opt-out, and a suppression list you own and check before every send.
- No special category data used for targeting.
For how the same questions look under GDPR specifically, see GDPR and B2B cold outreach, and our own GDPR and PECR approach for how this is handled here.
This is the part of outbound No Stress Agents runs for its clients: per-account research, verified contacts, and a drafted email you approve before it sends.
Read our GDPR and PECR approach