Is cold email legal in the UK? PECR, UK GDPR and telesales, explained
The short answer
The UK is the most B2B-permissive of the four European markets we cover on this point. Regulation 22 of the Privacy and Electronic Communications Regulations (PECR) requires consent to email an individual, but the ICO's own guidance confirms that this consent rule does not apply to electronic mail sent to a corporate subscriber, meaning a company, LLP, Scottish partnership or certain government bodies. Sole traders and some partnerships are treated as individuals and still need consent. Even where PECR asks for nothing, UK GDPR still applies whenever the message touches an identifiable person's data, and that person can object at any time. Telesales is a separate rule: you cannot call numbers registered with the Corporate Telephone Preference Service (CTPS) or the Telephone Preference Service (TPS) unless the business has consented. This page is general information, not legal advice.
Teams that have run outbound into Germany or France often arrive at a UK campaign expecting the same consent wall. It genuinely is not there in the same way, and knowing exactly why saves a lot of unnecessary caution, and a few genuine mistakes about who is protected and who is not.
Note: this is general information for orientation, not legal advice, and it is not a compliance opinion on your situation. The ICO itself flags that this area is under review following the Data (Use and Access) Act, so check for updates before relying on any single page, including this one, and get a written view from a qualified UK data-protection adviser before you send at scale.

On this page
- Two regimes: PECR and UK GDPR
- The corporate subscriber exemption
- Who does not get the exemption
- UK GDPR still applies underneath
- GDPR and telesales in the UK
- Who enforces this, and what does it cost?
- What compliant UK outbound looks like
- Does using an agency move the legal risk?
- How we handle the UK
Two regimes: PECR and UK GDPR
Since Brexit, the UK runs its email-marketing rules through two separate instruments rather than one EU regulation. The Privacy and Electronic Communications Regulations 2003 (PECR), as amended, is the UK's own retained version of the old EU ePrivacy rules and governs direct marketing by phone, fax and electronic mail. UK GDPR, sitting alongside the Data Protection Act 2018, governs the processing of personal data generally. They ask different questions and can give different answers for the same message.
The ICO, the UK's data-protection and PECR regulator, currently flags on its own guidance pages that this area is under review following the Data (Use and Access) Act, so treat the detail here as a snapshot and check the ICO's site for updates before relying on it for a live campaign.
The corporate subscriber exemption
This is the feature that makes the UK different from Germany, Austria and Switzerland on this specific point. PECR's rules refer to "subscribers", and it splits them into two kinds. A corporate subscriber, per the ICO's own guidance, is a corporate body with separate legal status: companies, limited liability partnerships, Scottish partnerships, corporations sole, and some government bodies. The email address of an employee at such a body counts as belonging to the employer, the corporate subscriber, not to the individual.
Per PECR regulations 22 and 23, the consent requirement for direct marketing by electronic mail does not apply to corporate subscribers. In the ICO's own words, you can send B2B direct marketing emails or texts to any corporate body without needing PECR consent to do so. That single fact is why generic UK B2B outreach is materially less constrained at the PECR layer than the equivalent message into Germany, Austria or Switzerland.
Two duties survive regardless: you must not disguise or conceal your identity, and you must give a valid address the business can use to opt out or unsubscribe. The ICO also says that although PECR does not explicitly force you to honour a corporate subscriber's opt-out on the electronic-mail point, the requirement to give an opt-out address shows the clear intent that one should work, so you should comply with it in practice.
Who does not get the exemption
The corporate subscriber category has real edges, and getting them wrong is the main way a UK campaign trips over PECR.
- Sole traders are treated as individual subscribers, with the full PECR consent protection.
- Certain types of partnership, specifically non-limited-liability partnerships and other unincorporated English, Welsh and Northern Irish partnerships, are also individual subscribers. Scottish partnerships are the exception and count as corporate subscribers.
- Any other unincorporated body of individuals is treated the same way, as an individual subscriber.
The ICO's own advice for a genuinely uncertain case is to default to the stricter rule: if you cannot tell whether an address belongs to a corporate or an individual subscriber, treat it as an individual subscriber and make sure you have consent, or that the soft opt-in for existing customers applies, before you send.
UK GDPR still applies underneath
The corporate subscriber exemption is a PECR answer, not a UK GDPR one, and the two do not merge. If the email you hold identifies a person, for instance an address in the pattern firstname.lastname@company.co.uk, or your list carries the person's name alongside it, you are processing personal data and UK GDPR applies in full, in a business context exactly as it would in a personal one.
That means you need a lawful basis, most commonly legitimate interests under Article 6(1)(f) with a documented three-part test, you must give the person the required privacy information under Article 13 or 14, and that person keeps an absolute right under Article 21(2) to object to direct marketing at any time, with no exception for how PECR classified their employer.
GDPR and telesales in the UK
| Rule | What the ICO guidance says (checked 6 October 2026) |
|---|---|
| Registers | You cannot call numbers registered with the Corporate Telephone Preference Service (CTPS) or the Telephone Preference Service (TPS) unless the business has consented. Screen against both, because some businesses register with CTPS while sole traders use TPS. |
| Email exemption does not carry over | "The rule on marketing by electronic mail (eg email or text message) doesn't apply to corporate subscribers." The corporate subscriber exemption above is an email rule, not a telephone rule. |
| UK GDPR applies to calls | If you are processing personal data when making a marketing call to another business, you need to comply with the UK GDPR, for example because you know the name of the person you are calling. |
| Caller duties | Display your number, identify yourself and give contact details if asked. Do not call businesses that have previously objected. |
So a UK B2B telesales campaign has two checks that email does not: a register screen before every dial, and the UK GDPR duties whenever you hold a named contact. The source is the ICO's own page on business-to-business marketing. The wider European picture for calls is in European Telemarketing Law: Is B2B Cold Calling Legal?, and the scripting side is in The Cold Calling Script That Sounds Human.
Who enforces this, and what does it cost?
The Information Commissioner's Office, the ICO, enforces both PECR and UK GDPR, and it is the single regulator across both questions, unlike the split we describe on the Germany and Austria pages between competition-law and data-protection routes.
- PECR breaches, for example emailing a sole trader or an individual subscriber without consent or a valid soft opt-in, or concealing your identity when emailing anyone, fall within the ICO's PECR enforcement powers.
- UK GDPR breaches, such as processing an identifiable business contact's data without a lawful basis, ignoring an Article 21(2) objection, or failing to give required privacy information, fall within the ICO's separate UK GDPR enforcement powers.
- Corporate-to-corporate marketing email that respects the exemption's own conditions, honest sender identification and a working opt-out, sits outside PECR's consent requirement entirely, which is the point of this page.
We are not quoting a specific typical fine figure here, because enforcement outcomes vary by case and the ICO's own guidance on this exact area is under active review; check the ICO's published enforcement action pages directly for current examples rather than relying on a number repeated secondhand.
What compliant UK outbound looks like
- Classify the recipient correctly before sending. Confirm the target is a company, LLP, Scottish partnership or qualifying government body, not a sole trader or a non-LLP partnership, before relying on the corporate subscriber exemption.
- Never disguise the sender, and always give a working reply or unsubscribe address, both required regardless of subscriber type.
- Document a legitimate-interests balancing test for any message that identifies a named individual, since that is a UK GDPR question the PECR exemption does not touch.
- Give the required privacy information to individuals whose data you collected from a source other than themselves, within a reasonable period and no later than one month under UK GDPR Article 14(3)(a). Where that data will be used to communicate with the individual, which a cold email is, Article 14(3)(b) moves the deadline earlier: the information is due at the latest at that first communication, so the disclosures need to sit in the email itself rather than a later notice.
- Action every objection immediately and permanently, and keep a suppression list you screen new lists against, treating corporate opt-outs as binding in practice even though PECR's wording is not fully explicit on the point.
- Check the ICO's site before a large send, since the regulator itself says this guidance may change following the Data (Use and Access) Act.
Does using an agency move the legal risk?
Not entirely. As the business whose product or service is being promoted, you remain responsible for having a lawful UK GDPR basis for any personal data used, and for the marketing being properly targeted and consented to wherever PECR does require it. An agency that claims to absorb all of the compliance exposure on your behalf is overstating what it can actually take off your hands.
What you can reasonably expect instead: full visibility of the list and copy before anything sends, a clear statement of which contacts are being treated as corporate versus individual subscribers and why, documented data sources, and immediate opt-out handling, the same standard we set out for other markets in our agency red-flag guide.
How we handle the UK
Ripe Leads runs UK campaigns with the corporate subscriber classification checked before a single email sends, not assumed. Where a contact is a sole trader, a qualifying partnership, or otherwise uncertain, we treat it as an individual subscriber and require the same consent standard we would apply anywhere else in Europe. Where UK GDPR applies, which is most of the time once a named contact is involved, we document the legitimate-interests basis, give the required privacy information, and action every objection permanently. The final call on risk belongs to the client and their counsel, not to us. Our pricing and engagement terms are public and the first call is a working session.
Frequently asked
Is cold email legal in the UK?
What is a corporate subscriber under PECR?
Do I need consent to email a company in the UK?
Does UK GDPR still apply if PECR does not require consent?
Can a business object to my marketing email even if PECR did not require its consent?
How can I prospect into UK companies compliantly?
Does using an agency shift the legal risk away from my company?
Does GDPR apply to B2B telesales in the UK?
Do I need to check the CTPS before cold calling UK companies?
Is the corporate subscriber exemption a telesales exemption too?
Want the UK market handled properly?
We classify subscriber type before a single email sends, document our UK GDPR basis, and honour every opt-out. You get the accurate picture of the risk, then decide.
Book a strategy call Or get a free target list first