What UK law allows for B2B cold email
UK law lets you send cold B2B email to a corporate subscriber — a limited company, an LLP or a Scottish partnership — without consent, because PECR regulation 22 applies its consent requirement only to individual subscribers. Sole traders and ordinary English, Welsh and Northern Irish partnerships are individual subscribers and do need consent. UK GDPR applies either way whenever the address names a person, so you still need a lawful basis, privacy information and a working opt-out.
The short version: two separate laws apply to the same email, and most of what is written about this on the internet only reads one of them. PECR governs the act of sending. UK GDPR governs the personal data you used to send it. PECR’s consent rule for email does not apply to corporate subscribers. UK GDPR has no B2B carve-out at all.
So "B2B is exempt" is wrong. What is true is narrower and more interesting: one specific rule, in one specific regulation, has a scope limit that happens to exclude companies. Everything else still applies.
Which laws apply to a UK B2B cold email?
Two, and they stack. The Privacy and Electronic Communications (EC Directive) Regulations 2003 — PECR — set rules for marketing by electronic mail, phone and fax. The UK GDPR sets rules for processing personal data, whoever it belongs to and whatever capacity they are acting in.
The ICO puts the relationship plainly on its business-to-business marketing page: "The UK GDPR still applies to B2B marketing if you are processing personal data. For example, if you hold the name of the individual who represents the business. It is the Privacy and Electronic Communications Regulations 2003 (as amended) (PECR) rules that may be different for B2B when compared to contacting individuals in their personal capacity."
PECR differs for B2B. UK GDPR does not. And PECR is the senior partner where they meet: the ICO is explicit that "If PECR require consent, you must not use legitimate interests as your lawful basis for using personal information for that purpose... Legitimate interests can’t legitimise unlawful processing."
What does PECR regulation 22 actually say?
Regulation 22 is the consent rule for marketing email. Almost everyone quotes paragraph (2) — the bit about needing prior consent — and skips paragraph (1), which is where the entire B2B question is decided.
22.—(1) This regulation applies to the transmission of unsolicited communications by means of electronic mail to individual subscribers.
PECR 2003, regulation 22(1)
Paragraph (2) then says a person shall not transmit unsolicited direct marketing by electronic mail "unless the recipient of the electronic mail has previously notified the sender that he consents". But (2) only has effect inside the scope (1) sets. No individual subscriber, no consent requirement. Do not take my word for it:
$ curl -s https://www.legislation.gov.uk/uksi/2003/2426/regulation/22 \
| grep -o 'This regulation applies[^<]*' \
| sed 's/
//'
This regulation applies to the transmission of unsolicited communications by means of electronic mail to individual subscribers.One more thing about regulation 22 that catches people out. The "soft opt-in" in 22(3) — the existing-customer exception — is not a cold email route. It requires that you obtained the contact details "in the course of the sale or negotiations for the sale of a product or service to that recipient", that you are marketing your own similar products, and that you offered an opt-out both at collection and in every message since. The ICO says flatly that it "does not apply to prospective customers or new contacts (eg from bought-in lists)".
Who counts as a corporate subscriber?
Regulation 2 defines a corporate subscriber as a subscriber who is a company within the meaning of section 735(1) of the Companies Act 1985, a company incorporated by royal charter or letters patent, "a partnership in Scotland", a corporation sole, or "any other body corporate or entity which is a legal person distinct from its members". The last limb is the one doing the work in practice. Limited liability partnerships are not named anywhere in regulation 2, but they are bodies corporate with legal personality distinct from their members, and the ICO’s B2B guidance lists them — along with Scottish partnerships and "some government bodies" — as corporate subscribers. That classification is the ICO’s, not the regulation’s.
The mirror-image definition is the one that does the damage. An "individual" under regulation 2 means "a living individual and includes an unincorporated body of such individuals". An ordinary partnership in England, Wales or Northern Ireland is exactly that — an unincorporated body of individuals — so it is an individual subscriber. A Scottish partnership has separate legal personality, so it is not.
The word "subscriber" also matters. It means the party to the contract with the communications provider — in practice, whoever is on the bill. The ICO spells out the consequence: "the email address or telephone number of an employee at a corporate body would constitute a corporate subscriber for the purposes of PECR because the ‘subscriber’ is their employer."
| Who you are emailing | PECR subscriber class | Consent needed to email? |
|---|---|---|
| Private or public limited company | Corporate | No |
| Limited liability partnership (LLP) | Corporate | No |
| Partnership constituted in Scotland | Corporate | No |
| Corporation sole | Corporate | No |
| Some government bodies (per ICO guidance) | Corporate | No |
| Sole trader | Individual | Yes — consent, or soft opt-in |
| Ordinary partnership in England, Wales or NI | Individual | Yes — consent, or soft opt-in |
| Any other unincorporated body of individuals | Individual | Yes — consent, or soft opt-in |
| An employee reached at a personal address | Individual | Yes — consent, or soft opt-in |
So is B2B cold email exempt from the rules?
No. Regulation 22 is one regulation. Regulation 23 sits immediately after it and has no subscriber-class limit whatsoever. It applies to every marketing email you send, to a company or to a person:
A person shall neither transmit, nor instigate the transmission of, a communication for the purposes of direct marketing by means of electronic mail — (a) where the identity of the person on whose behalf the communication has been sent has been disguised or concealed; (b) where a valid address to which the recipient of the communication may send a request that such communications cease has not been provided; (c) where that electronic mail would contravene regulation 7 of the Electronic Commerce (EC Directive) Regulations 2002; or (d) where that electronic mail encourages recipients to visit websites which contravene that regulation.
PECR 2003, regulation 23
Read (b) again. An unsubscribe address is not a courtesy you extend to consumers. It is a condition of sending the message at all, and it applies to the email you send the finance director of a limited company. Limb (c) imports regulation 7 of the Electronic Commerce (EC Directive) Regulations 2002, which requires a commercial communication to be "clearly identifiable as a commercial communication" and to "clearly identify the person on whose behalf the commercial communication is made", with any promotional offer clearly marked and its conditions accessible and unambiguous.
The practical read: a cold email that hides who sent it, or that pretends not to be selling anything, is a regulation 23 problem regardless of who received it. So is one with no way out.
From: Dana Whitfield <dana@example-msp.co.uk>
Reply-To: r+7f21ab2c@reply.example-msp.co.uk
To: sam@acme-manufacturing.example
Subject: Your Sage server backup window
List-Unsubscribe: <https://example-msp.co.uk/u/7f21ab2c>,
<mailto:unsub@example-msp.co.uk?subject=7f21ab2c>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
DKIM-Signature: v=1; a=rsa-sha256; d=example-msp.co.uk; s=sel1;
h=from:to:subject:list-unsubscribe:list-unsubscribe-post; ...
[body]
--
Example MSP Ltd, registered in England and Wales, company no. 00000000
14 Bridge Street, Leeds LS1 4DJ
I found your details on acme-manufacturing.example. Reply STOP or use
the link above and I will not contact you again.What lawful basis covers a cold email under UK GDPR?
If the address identifies a person — dana@, or an info@ box where you also hold the person’s name — you are processing personal data and you need a lawful basis from Article 6. The ICO says the two relevant ones in B2B marketing are consent and legitimate interests, and that where PECR does not require consent, "in many cases it is likely that legitimate interests will be the appropriate lawful basis. But there is no absolute rule."
Article 6(1)(f) is the legitimate interests basis. Article 6(11)(a) of the UK GDPR then lists, as an example of processing that may be necessary for a legitimate interest, "processing that is necessary for the purposes of direct marketing". The ICO’s gloss on that is worth quoting because it is the exact point where thin articles overclaim: "This means that direct marketing ‘may’ be a legitimate interest. However, the UK GDPR doesn’t say that direct marketing always constitutes a legitimate interest."
| Marketing method | Is legitimate interests likely to be appropriate? |
|---|---|
| Post | Yes |
| Live phone calls to TPS/CTPS registered numbers | No |
| Live phone calls to those who have objected to your calls | No |
| Live phone calls with no TPS/CTPS registration or objection | Yes |
| Automated phone calls | No |
| Emails or texts to people, obtained using a soft opt-in | Yes |
| Emails or texts to people, without a soft opt-in | No |
| Emails or texts to business contacts | Yes |
That last row is the one that makes B2B cold email workable in the UK. It is also the row that does the least work on its own: "likely to be appropriate" is not "is appropriate". You have to do the assessment.
What goes into a legitimate interests assessment?
A legitimate interests assessment (LIA) is a written record of a three-part test. The ICO says there is no defined process and no required form, but that you must address all three parts, you should record the outcome "including all the relevant factors, whether or not they support your conclusion", and you should do it before you start processing.
- Purpose test. Identify the legitimate interest, specifically. "Growing the business" is not a purpose; "finding UK manufacturers with 20-200 staff who run on-premise Sage and may need managed backup" is closer to one.
- Necessity test. The ICO’s standard: you must use the personal data "in a targeted and proportionate way", and legitimate interests does not apply "if you can reasonably achieve the same result in another less intrusive way". Emailing 40 researched contacts is a different answer to this question than emailing 40,000 scraped ones.
- Balancing test. Would they reasonably expect it, and does it cause unjustified harm? The ICO notes business contacts "are more likely to reasonably expect you to use their personal information in a business context", and that such use "is less likely to have a significant impact on them personally". That is the tailwind B2B gets. It is not a pass.
Two ICO instructions about the balancing test are easy to miss and cheap to follow. First: "you should focus your balancing test primarily on your own interests" and "should not rely on vague statements about wider presumed benefits" — claiming the recipient benefits from your marketing "is unlikely to have much impact on the outcome". Second: give people an easy, free way to object, at first contact if you did not collect the data from them, because "it’s more difficult to pass the balancing test if you don’t do this". The unsubscribe link is not only a regulation 23 obligation; it is evidence in your own LIA.
The ICO publishes a sample LIA template. Use it or don’t — but write something down. Under the accountability principle, an assessment you cannot produce is an assessment you did not do.
What must you tell someone whose email you found online?
This is the obligation most cold outbound quietly skips. When you get personal data from anywhere other than the person themselves — a company website, LinkedIn, Companies House, a data provider — Article 14 applies. You must tell them who you are, what you are doing with the data, your lawful basis and legitimate interests, how long you will keep it, their rights including the right to object, and, under Article 14(2)(f), "from which source the personal data originate, and if applicable, whether it came from publicly accessible sources".
Article 14(3) sets deadlines in three limbs — (a), (b) and (c) — and cold email hits the second. Paragraph (a) sets the outer limit: a reasonable period after obtaining the data, "at the latest within one month". Paragraph (b) then says that where the personal data "are to be used for communication with the data subject", the information is due "at the latest at the time of the first communication to that data subject". (Paragraph (c) covers disclosure to another recipient and is not usually the one in play.) If you obtained an address in order to email it, (b) applies and your deadline is that first email — not a month after you scraped the list. The ICO’s B2B page states the one-month limb for data collected from public or third-party sources. One line saying where you found them, plus a link to your privacy notice, discharges most of this. It also, not coincidentally, makes the email less creepy.
On public sources the ICO is direct: "you cannot assume that simply because an individual’s personal data is in the public domain they are agreeing to it being used for direct marketing purposes." Public is not consent, and scraping does not launder anything.
What happens when someone tells you to stop?
You stop. Article 21(2) gives an unqualified right to object to processing for direct marketing, and Article 21(3) says that once they object "the personal data shall no longer be processed for such purposes". The ICO’s wording: "This is an absolute right and there are no exemptions or grounds for you to refuse." You have one calendar month to respond to an objection.
A subtlety worth understanding rather than memorising: a company is not a data subject, so it has no Article 21 rights. The ICO’s own sentence is worth reading with its parenthetical attached: "if a business tells you that they object to your direct marketing, you are not required under the UK GDPR to comply with their objection (although you may be required to do so under PECR)." But the named human does have those rights, and any address identifying a person carries them. So the distinction almost never helps you, and the ICO adds that it "serves little purpose to continue to send direct marketing messages to a business that has asked you not to".
Suppress, do not delete. The ICO: "you should add the business or business contact’s details onto your ‘do not contact’ or suppression list instead of simply deleting all record of them. Doing this means that you can screen any new direct marketing lists against it." Deleting the record is how the same person gets emailed again in eight months when someone re-imports the list. Keeping a minimal suppression entry for the purpose of not contacting someone is the thing that actually honours the objection.
What changed on 5 February 2026?
The ceiling. Section 115 of, and Schedule 13 to, the Data (Use and Access) Act 2025 came into force on 5 February 2026 under SI 2026/82. Paragraph 18 of Schedule 13 modifies section 157 of the Data Protection Act 2018, substituting into section 157(2)(a) a list of PECR provisions — "regulation 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23 or 24" — whose breach attracts "the higher maximum amount". Regulations 22 and 23 are both on that list. Section 157(5) defines the higher maximum amount as, for an undertaking, £17,500,000 or 4% of its total annual worldwide turnover in the preceding financial year, whichever is higher; in any other case it is a flat £17,500,000. Before that, PECR enforcement ran through Part V and sections 55A to 55E of the Data Protection Act 1998, which PECR regulation 31 and its old Schedule 1 kept alive for PECR’s own purposes. The maximum monetary penalty there was £500,000, prescribed by regulation 2 of SI 2010/31.
The commencement regulations are careful about timing: an act or omission before 5 February 2026 is dealt with under PECR as it stood then, and only conduct on or after that date is exposed to the new maximum. This is a ceiling, not a tariff — penalties are set case by case.
The practical compliance checklist
Everything above, compressed into things you can actually do before you press send.
- Classify the entity, not the domain. Limited company, LLP or Scottish partnership: regulation 22 does not require consent. Sole trader or ordinary English, Welsh or NI partnership: it does. If you cannot tell, the ICO says treat it as an individual subscriber.
- Write the LIA before the first send, covering purpose, necessity and balancing, and record the factors that cut against you as well as the ones that help.
- Identify yourself truthfully. Real sender name, real company, no disguised From. Regulation 23(a) and regulation 7 of the E-Commerce Regulations both bite here.
- Say where you got the data, in the first message. Article 14(2)(f) requires the source, and where you obtained the address in order to contact the person, Article 14(3)(b) makes that first communication the deadline. The one month in Article 14(3)(a) is the outer limit, not the target.
- Link to a privacy notice that names your lawful basis and describes the right to object.
- Provide a working opt-out in every message — a valid cessation address is a regulation 23(b) condition of sending. RFC 8058 one-click headers, DKIM-signed, plus a footer link, covers the legal duty and also matches what Gmail requires of senders above 5,000 messages a day — a threshold most cold outbound is nowhere near, but the headers cost nothing to set now.
- Honour opt-outs promptly and centrally. One calendar month is the outer limit for responding to an objection; same-day is the standard your reputation is actually judged on.
- Keep a suppression list, screen every new import against it, and never delete your way out of an objection.
- If you are a UK company, put your registered details in the footer. Regulation 24(1)(g) of SI 2015/17 requires the registered name on "all other forms of its business correspondence and documentation"; regulation 25 requires the registered number, place of registration and registered office address on business letters, order forms and websites. Whether an email is a "business letter" is not spelled out — including the details costs you nothing.
A note on where tooling lands. Decknative sends through the customer’s own connected mailbox and takes replies on a Reply-To at its own domain rather than reading the inbox, so the sender is the identifiable human whose name is on the message and suppression state lives in one place across campaigns. That is a design that happens to fit the checklist; it is not a compliance product, and it will not classify your recipients’ legal entities for you.
Where this is genuinely unsettled
Four things that confident blog posts state as fact and that the primary sources do not settle.
- Personal-looking addresses. The subscriber is the bill-payer, so dana@company.co.uk is corporate even though it names a person. But the ICO’s own example flags the reverse: a delegate who "chose to use their personal email address instead of their work one" is an individual subscriber. You often cannot tell which you have.
- Whether role addresses are outside UK GDPR entirely. The ICO says if you do not know the name of the person you are emailing, "you are not processing personal data and the UK GDPR does not apply", giving info@ as an example. That is true only for as long as you genuinely hold no name — and enrichment tools attach names to role addresses by default.
- Professional networking sites. The ICO says people on them are "unlikely to be on the sites exclusively in their business capacity", and that messaging someone using such a platform in a personal, albeit professional, capacity "is not considered B2B marketing". How far that reasoning travels to an email address sourced from a profile is not spelled out.
- Whether an email counts as a "business letter" for the Companies Act trading disclosure rules. Regulation 25 of SI 2015/17 lists business letters, order forms and websites, and does not mention email. Regulation 24(1)(g) has a catch-all for "all other forms of its business correspondence and documentation", which reads as though it covers email, but that limb only requires the registered name — not the number, place of registration and registered office. The cautious answer and the cheap answer are the same one.
Where a source is ambiguous, the ICO’s repeated instruction is to take the more protective reading. That is also the reading that keeps you out of the position of arguing about scope definitions with a regulator, which is a bad position even when you are right.
Common questions
- Do I need consent to send a cold email to a UK limited company?
- Not under PECR. Regulation 22(1) limits the consent rule to unsolicited marketing email sent to individual subscribers, and a limited company is a corporate subscriber. UK GDPR still applies if the address identifies a named person, so you need a lawful basis, privacy information and an honoured right to object. This is not legal advice.
- Can I cold email a sole trader in the UK?
- Only with their consent, or where the soft opt-in in PECR regulation 22(3) applies. Sole traders are individual subscribers because regulation 2 defines "individual" to include an unincorporated body of individuals. The soft opt-in requires that you obtained the details during a sale or negotiation for a sale of your own similar product, so it does not cover cold prospects.
- Is an LLP a corporate subscriber or an individual subscriber under PECR?
- Corporate. A limited liability partnership is a body corporate with legal personality distinct from its members, which falls inside regulation 2’s definition of corporate subscriber, and the ICO lists LLPs explicitly as corporate subscribers. An ordinary partnership in England, Wales or Northern Ireland is not, and is treated as an individual subscriber.
- Does UK GDPR have a B2B exemption?
- No. UK GDPR applies to any processing of personal data, including data about someone acting in a business capacity. The ICO’s position is that a business contact’s name and work email are personal data and the full regime applies. What differs for B2B is PECR, not UK GDPR.
- Do I have to include an unsubscribe link in a B2B cold email?
- You must provide a valid address to which the recipient can send a request that the communications cease. PECR regulation 23(b) makes that a condition of sending any direct marketing email, with no corporate-subscriber exception. A reply-to address can satisfy it; RFC 8058 one-click headers plus a footer link go further, and Gmail requires them of senders above 5,000 messages a day.
- What is a legitimate interests assessment and do I have to write one down?
- An LIA records the three-part test — purpose, necessity, balancing — that Article 6(1)(f) requires. The ICO says there is no prescribed form but you must address all three parts, should record the factors on both sides, and should complete it before you start processing. Under the accountability principle you need to be able to produce it.
- How quickly must I honour an objection to direct marketing?
- The right to object to direct marketing under Article 21(2) is absolute, and Article 21(3) says the data must no longer be processed for that purpose once the objection is made. The ICO states you have one calendar month to respond. In practice, suppress immediately and treat the month as an outer limit rather than a target.
- How large can a PECR fine be now?
- For conduct on or after 5 February 2026, breaches of PECR regulations including 22 and 23 attract the higher maximum amount under section 157 of the Data Protection Act 2018. For an undertaking that is £17.5 million or 4% of total annual worldwide turnover in the preceding financial year, whichever is higher; in any other case it is a flat £17.5 million. Conduct before that date is judged under the previous regime, whose maximum monetary penalty was the £500,000 prescribed by regulation 2 of SI 2010/31. This is a statutory ceiling, not an expected penalty.
Sources
- PECR 2003, regulation 22 — use of electronic mail for direct marketing
- PECR 2003, regulation 23 — identity or address of sender concealed
- PECR 2003, regulation 2 — interpretation (corporate subscriber, individual)
- ICO — Business-to-business marketing
- ICO — Guide to PECR: electronic mail marketing
- ICO — When can we rely on legitimate interests?
- ICO — Legitimate interests (three-part test, necessity, record-keeping)
- ICO — How do we apply legitimate interests in practice? (the LIA)
- ICO — Right to object
- UK GDPR, Article 6 — lawfulness of processing
- UK GDPR, Article 14 — information where data not obtained from the data subject
- UK GDPR, Article 21 — right to object
- Data Protection Act 2018, section 157 — maximum amount of penalty
- Data (Use and Access) Act 2025, Schedule 13 — PECR enforcement powers
- SI 2026/82 — DUAA 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026
- PECR regulation 31 as it stood on 4 February 2026 — extension of Part V of the DPA 1998
- Electronic Commerce (EC Directive) Regulations 2002, regulation 7
- SI 2010/31, regulation 2 — £500,000 maximum monetary penalty (pre-2026 PECR cap)
- SI 2015/17, regulation 24 — disclosure of a company’s registered name
- SI 2015/17, regulation 25 — disclosure of a company’s registered particulars
- RFC 8058 — Signaling One-Click Functionality for List Email Headers
- Google — Email sender guidelines (one-click unsubscribe above 5,000/day)