Cold B2B email is lawful in the UK when two conditions line up: the Privacy and Electronic Communications Regulations (PECR) allow marketing to that recipient without consent, and you hold a lawful basis under UK GDPR, usually legitimate interests, for any personal data you process. You still need clear sender identity and a working opt-out on every message, and a documented Legitimate Interests Assessment when you email a named person. Get those pieces right and your outreach stands up to scrutiny.
TL;DR:
- Sending cold emails to limited companies or Scottish partnerships is lawful under PECR without consent, but personal data use still requires a lawful basis under UK GDPR.
- Emails to sole traders or traditional partnerships generally need GDPR consent unless relying on a narrow soft opt-in for existing customers.
- Every marketing message must clearly identify the sender and include a functional opt-out link, regardless of the legal basis used.
- A documented Legitimate Interests Assessment is mandatory when emailing named individuals, covering purpose, necessity, and privacy impact.
- Maintaining accurate contact classification, source records, and campaign logs is essential to demonstrate compliance and avoid ICO enforcement.
Table of Contents
- What laws apply to cold emailing in the UK: PECR and UK GDPR in plain terms
- PECR vs UK GDPR: the differences that change how you prospect
- How to apply the legitimate interests test to cold outreach
- Who counts as a corporate subscriber when you’re building lists
- Practical compliance checklist before you run a cold email campaign
- How to draft a compliant cold email: must-have elements and structure
- Sourcing contact data and timing privacy information correctly
- Recordkeeping and audit trails that demonstrate compliance
- Common pitfalls, ICO enforcement risks and what to do after a complaint
- How we build lawful outreach into a working sales process
- Our take: stop treating compliance as a one-off legal exercise
- Make compliant outreach part of how your team sells
- FAQ
- Sources
What laws apply to cold emailing in the UK: PECR and UK GDPR in plain terms
Two separate laws govern what lands in a UK inbox, and most of the confusion we hear from sales teams comes from treating them as one rule rather than two.
PECR deals with electronic marketing itself: the channel, the timing, the opt-out. It carries a corporate-subscriber exemption, set out in Regulation 22, that lets you market to certain company addresses without prior consent. UK GDPR deals with something different: the processing of personal data belonging to identifiable individuals. The two regimes often apply to the same email, but not always, and that distinction decides what paperwork you need before you hit send.
Here’s the practical split. Email a generic inbox like info@company.co.uk and you’re likely only in PECR territory, since no named individual’s personal data is directly in play. Email jane.smith@company.co.uk and you’ve triggered both regimes at once: PECR governs whether you can send unsolicited marketing to that address, and UK GDPR governs your right to hold and use Jane’s name and email address in the first place. According to ICO guidance on business-to-business marketing, PECR allows electronic marketing to corporate subscribers without consent, but UK GDPR still applies wherever personal data is processed, so you need to satisfy both.
This is why “it’s a business email, so GDPR doesn’t apply” is one of the most repeated and most wrong assumptions in B2B prospecting. The exemption covers the marketing rules. It says nothing about your obligation to have a lawful basis for processing someone’s name.

PECR vs UK GDPR: the differences that change how you prospect
Once you understand that these are two separate tests, the practical question becomes simple: who are you emailing, and which rule actually bites?
PECR does not require consent when you’re marketing to a corporate body. ICO guidance confirms that Regulation 22 permits unsolicited electronic marketing to corporate subscribers, meaning limited companies, limited liability partnerships and Scottish partnerships, without prior consent. That exemption has limits, though: it covers the corporate subscriber’s address, not every individual associated with it, and it never overrides your UK GDPR duties.

PECR does require consent in other cases, chiefly sole traders and ordinary partnerships, who are treated as individuals rather than corporate subscribers. For these contacts, you generally need GDPR-standard consent before marketing, or you need to rely on the narrow soft opt-in for existing customers, which does not stretch to cover cold prospecting.
Whichever basis applies, every message carries the same per-message obligations. PECR Regulation 23 requires that unsolicited marketing never conceals the sender’s identity and always provides a valid address where the recipient can opt out or ask you to stop. Strip out the branding and the sales copy, and this is the non-negotiable floor: say who you are, and give a real way to say no.
How to apply the legitimate interests test to cold outreach
When you’re emailing a named individual, legitimate interests is almost always the lawful basis sales teams reach for, and it is a genuinely workable one for B2B outreach. But it only holds up when you can show your working, not just assert it after the fact.
ICO guidance on legitimate interests sets this out as a three-part test, and each part needs a documented answer before the campaign goes live, not a retrospective justification.
- Purpose test: write down the specific business purpose, such as offering a relevant product or service to a genuine decision-maker in a role connected to that offer.
- Necessity test: explain why email is a proportionate way to reach this purpose, and why a less intrusive channel wouldn’t do the job as well.
- Balancing test: list the likely impact on the recipient’s privacy, how you limit that impact, and why your interest isn’t overridden by theirs.
The recipient’s right to object to direct marketing under legitimate interests is absolute, and that single fact should shape every LIA you write. Record the purpose statement, the necessity rationale, the balancing notes and any mitigations (frequency caps, easy opt-out, no sensitive personal data) in one document, attached to the campaign, not buried in someone’s inbox.
Who counts as a corporate subscriber when you’re building lists
Getting the classification right at list-building stage saves a lot of cleanup later, because it decides whether a contact needs consent or falls under the PECR exemption.
Limited companies, limited liability partnerships and Scottish partnerships qualify as corporate subscribers, which is why the PECR exemption applies to addresses tied to those entities. Sole traders and ordinary English or Welsh partnerships do not qualify: the law treats them like individuals, so you need consent unless a genuine soft opt-in applies, and cold prospecting rarely qualifies for that.
A short screening checklist keeps this consistent across your CRM:
- Check Companies House status to confirm the entity type behind the domain.
- Flag sole traders and ordinary partnerships separately from limited entities.
- Tag each contact record with its legal classification before it enters an outreach sequence.
- Re-check the tag whenever a contact changes role or company.
Our guide to the lead qualification process covers the wider screening steps that sit alongside this legal check.
Practical compliance checklist before you run a cold email campaign
Treat this as the sequence to work through before a single email goes out, not a box-ticking exercise after the fact.
- Validate and record where every contact came from; opaque “bought lists” with no provenance are a liability, not a shortcut.
- Draft the LIA for the campaign and attach it to the campaign brief so it travels with the data.
- Prepare a first-contact privacy note covering identity, source, lawful basis and rights, if the data came from a third party.
- Confirm every template includes clear sender identity, a real business contact address and a working unsubscribe link.
- Build a suppression list and treat it as the single source of truth inside your CRM, not a spreadsheet nobody updates.
- Cross-check new contacts against the suppression list before each send.
- Log who authorised the campaign and who sent it, using tools like Ampwise AI – Merge your Email and ERP to integrate your email system with campaign records.
- Store copies of the messages sent, the LIA and opt-out records together for later audit.
- Review the suppression list and campaign logs weekly while the campaign runs.
Pro Tip: Put the LIA and the campaign brief in the same folder, named with the campaign date. If anyone asks you to prove you thought this through, you want the answer in one place, not scattered across three people’s inboxes.
Our sales prospecting guidance for UK growth walks through how these steps fit into a wider outreach workflow.
How to draft a compliant cold email: must-have elements and structure
The legal requirements translate into a handful of concrete lines in the email itself, not a wall of legal text.
- Open with a clear sender identity: your name, your company, and why you’re writing to this specific person.
- Add a one-line relevance statement that shows you know who they are and why this matters to their role.
- State the purpose plainly: what you’re offering and why.
- Include a one-sentence privacy note or link where Article 14 applies, so the recipient can see how you got their details.
- Finish with a visible unsubscribe route or reply-to contact that actually works when tested.
Keep personalisation proportionate. A first name, a job title and a relevant observation about their company are fine; anything that strays into sensitive personal data has no place in a cold email.
A simple skeleton works for most campaigns: subject line signalling intent, one line of relevance, the reason for contact, a short privacy line where needed, a clear call to action, and the opt-out. Our examples of lead generation that actually work show templates built around this structure.
Sourcing contact data and timing privacy information correctly
When contact data comes from a third party rather than your own collection, UK GDPR’s Article 14 kicks in, and timing matters as much as content.
You must provide the required privacy information by the time of your first communication with that person, not weeks later once they’ve replied. That notice should identify who you are, the categories of data held, the original source, your lawful basis and the recipient’s right to object. Leaving this out of the first email is one of the most common gaps we see in outreach audits.
Before you buy or licence a list, ask the supplier three things: where the data came from, what consent or legitimate basis was used to collect it, and whether a data-processing agreement is in place. Skipping that due diligence pushes the compliance risk straight onto you, not the vendor.
Recordkeeping and audit trails that demonstrate compliance
If the ICO or a recipient ever asks how a campaign was run, the answer should take minutes to pull together, not days.
Keep the LIA, the campaign brief, sample messages sent, the data-source records and the opt-out log in one place, filed under a consistent naming convention tied to the campaign date. Treat your suppression list as the single canonical version across every tool your team touches, never a copy that drifts out of sync.
If a campaign raises genuine doubt, whether over provenance, consent or the balancing test, pause and get legal counsel involved before continuing rather than after a complaint lands.
Common pitfalls, ICO enforcement risks and what to do after a complaint
The same handful of mistakes come up repeatedly: no documented LIA, bought lists with no provenance trail, an opt-out that’s missing or doesn’t work, and sole traders mistakenly treated as corporate subscribers.
The ICO’s possible responses range from informal warnings to investigations, enforcement notices and fines, on top of the reputational and deliverability damage that follows a public complaint. ICO guidance on PECR soft opt-ins is a useful reminder that the exceptions are narrower than many marketers assume, and leaning on an exception that doesn’t apply is a frequent trigger for complaints.
If a complaint arrives, pause the campaign immediately, preserve every record you have, remove the contact from future sends, respond to the individual promptly, and log exactly what you did and when.
How we build lawful outreach into a working sales process
Training a sales team to screen contacts, own the LIA for their own campaigns and check the suppression list before every send turns compliance from a legal afterthought into a habit that protects pipeline. We build authorisation gates, campaign logs and weekly suppression reviews into the sales processes we coach, because the teams that treat these as routine steps convert better and get fewer complaints.
— Jerry
Our take: stop treating compliance as a one-off legal exercise
The research behind this piece points to one consistent gap: teams write a policy document once, then run campaigns for years without touching it again. That’s backwards. The LIA isn’t a certificate you file and forget, it’s a working document that should change when your targeting, your list source or your message does.
The conventional advice, “get a privacy policy and you’re covered”, undersells the real risk, which sits in the operational detail: who checked the suppression list this week, who can prove where a list came from, who owns the LIA for a specific campaign. Those questions, not the policy itself, are what an ICO investigation actually tests.
If you take one thing from this article, make it this: assign ownership. A named person should sign off every cold email campaign’s lawful basis before it launches, the same way someone signs off the budget. Treat it as a routine sales operations task, not a once-a-year compliance review, and the risk shrinks considerably.
Make compliant outreach part of how your team sells
Getting the legal basis right is only half the job. The harder part is making screening, LIA ownership and suppression checks stick as habits across a sales team that’s focused on hitting target, not reading regulation. That’s the gap we work in: our Sales Training Cohorts build process discipline, including the authorisation and recordkeeping habits this article describes, directly into how reps prospect day to day.
For teams that want a fully bespoke build, our team-based coaching and consultancy engagements run from £4,500 to £8,500 as a one-off, and our solo sales acceleration track for solo service businesses and consultants runs from £2,995 to £5,995. Alongside training, our Fractional Sales Director service can own this kind of process build for you directly.
- Sales Training Cohorts: team-based training that embeds compliant prospecting habits.
- Bespoke coaching and consultancy: a fully customised build for your specific sales process.
- Solo sales acceleration: a lighter track for solo consultants and small service businesses.
We’re not a substitute for legal advice on your specific campaigns, but we are the team that makes sure the process actually gets followed once the legal sign-off is in place. Visit our main site to see which package fits your team.
FAQ
Is cold emailing illegal in the UK?
No, cold emailing is not illegal in the UK when it meets PECR’s conditions, including the corporate-subscriber exemption for certain business addresses, and when you hold a lawful basis under UK GDPR for any personal data involved. The email must still identify the sender clearly and provide a working opt-out under PECR Regulation 23.
What are the GDPR rules for sending emails?
UK GDPR requires a lawful basis, most commonly legitimate interests for B2B outreach, documented through a three-part test covering purpose, necessity and balancing, as set out in ICO guidance on legitimate interests. Recipients retain an absolute right to object to direct marketing, and you must act on that objection immediately.
What is the 30/30/50 rule for cold emails?
This is not a recognised legal or regulatory standard under UK GDPR or PECR; it appears in some sales and marketing commentary as a rough split of effort between list quality, subject lines and message content, but definitions vary and no official source defines it. For compliance purposes, the tests that matter are PECR’s sender identity and opt-out rules and UK GDPR’s lawful basis requirement.
Is cold emailing illegal?
Cold emailing is not inherently illegal in the UK, but it becomes a compliance risk when it ignores PECR’s rules on sender identity and opt-outs or skips the lawful basis required under UK GDPR. ICO guidance on business-to-business marketing sets out when the corporate-subscriber exemption applies and when it doesn’t.
What makes a bought email list risky under UK rules?
A bought list is risky when you cannot trace where the data came from or what lawful basis or consent applied to its collection, since that gap undermines both your LIA and your Article 14 obligations. Ask every supplier for provenance, consent evidence and a data-processing agreement before you use their list.
Sources
- Business-to-business marketing | ICO
- Legitimate interests | ICO
- The Privacy and Electronic Communications (EC Directive) Regulations 2003 – Regulation 23
