Compliance

Is cold email legal in the UK? PECR, UK GDPR and telesales, explained

Published 26 September 2026 · 7 min read · By Ripe Leads

The short answer

The UK is the most B2B-permissive of the four European markets we cover on this point. Regulation 22 of the Privacy and Electronic Communications Regulations (PECR) requires consent to email an individual, but the ICO's own guidance confirms that this consent rule does not apply to electronic mail sent to a corporate subscriber, meaning a company, LLP, Scottish partnership or certain government bodies. Sole traders and some partnerships are treated as individuals and still need consent. Even where PECR asks for nothing, UK GDPR still applies whenever the message touches an identifiable person's data, and that person can object at any time. Telesales is a separate rule: you cannot call numbers registered with the Corporate Telephone Preference Service (CTPS) or the Telephone Preference Service (TPS) unless the business has consented. This page is general information, not legal advice.

Teams that have run outbound into Germany or France often arrive at a UK campaign expecting the same consent wall. It genuinely is not there in the same way, and knowing exactly why saves a lot of unnecessary caution, and a few genuine mistakes about who is protected and who is not.

Note: this is general information for orientation, not legal advice, and it is not a compliance opinion on your situation. The ICO itself flags that this area is under review following the Data (Use and Access) Act, so check for updates before relying on any single page, including this one, and get a written view from a qualified UK data-protection adviser before you send at scale.

Is cold email legal in the UK? PECR and UK GDPR, explained
On this page
  1. Two regimes: PECR and UK GDPR
  2. The corporate subscriber exemption
  3. Who does not get the exemption
  4. UK GDPR still applies underneath
  5. GDPR and telesales in the UK
  6. Who enforces this, and what does it cost?
  7. What compliant UK outbound looks like
  8. Does using an agency move the legal risk?
  9. How we handle the UK

Two regimes: PECR and UK GDPR

Since Brexit, the UK runs its email-marketing rules through two separate instruments rather than one EU regulation. The Privacy and Electronic Communications Regulations 2003 (PECR), as amended, is the UK's own retained version of the old EU ePrivacy rules and governs direct marketing by phone, fax and electronic mail. UK GDPR, sitting alongside the Data Protection Act 2018, governs the processing of personal data generally. They ask different questions and can give different answers for the same message.

The ICO, the UK's data-protection and PECR regulator, currently flags on its own guidance pages that this area is under review following the Data (Use and Access) Act, so treat the detail here as a snapshot and check the ICO's site for updates before relying on it for a live campaign.

The corporate subscriber exemption

This is the feature that makes the UK different from Germany, Austria and Switzerland on this specific point. PECR's rules refer to "subscribers", and it splits them into two kinds. A corporate subscriber, per the ICO's own guidance, is a corporate body with separate legal status: companies, limited liability partnerships, Scottish partnerships, corporations sole, and some government bodies. The email address of an employee at such a body counts as belonging to the employer, the corporate subscriber, not to the individual.

Per PECR regulations 22 and 23, the consent requirement for direct marketing by electronic mail does not apply to corporate subscribers. In the ICO's own words, you can send B2B direct marketing emails or texts to any corporate body without needing PECR consent to do so. That single fact is why generic UK B2B outreach is materially less constrained at the PECR layer than the equivalent message into Germany, Austria or Switzerland.

Two duties survive regardless: you must not disguise or conceal your identity, and you must give a valid address the business can use to opt out or unsubscribe. The ICO also says that although PECR does not explicitly force you to honour a corporate subscriber's opt-out on the electronic-mail point, the requirement to give an opt-out address shows the clear intent that one should work, so you should comply with it in practice.

Who does not get the exemption

The corporate subscriber category has real edges, and getting them wrong is the main way a UK campaign trips over PECR.

The ICO's own advice for a genuinely uncertain case is to default to the stricter rule: if you cannot tell whether an address belongs to a corporate or an individual subscriber, treat it as an individual subscriber and make sure you have consent, or that the soft opt-in for existing customers applies, before you send.

UK GDPR still applies underneath

The corporate subscriber exemption is a PECR answer, not a UK GDPR one, and the two do not merge. If the email you hold identifies a person, for instance an address in the pattern firstname.lastname@company.co.uk, or your list carries the person's name alongside it, you are processing personal data and UK GDPR applies in full, in a business context exactly as it would in a personal one.

That means you need a lawful basis, most commonly legitimate interests under Article 6(1)(f) with a documented three-part test, you must give the person the required privacy information under Article 13 or 14, and that person keeps an absolute right under Article 21(2) to object to direct marketing at any time, with no exception for how PECR classified their employer.

One exemption, one absolute rightPECR's corporate subscriber rule removes a consent requirement. UK GDPR's right to object removes nothing: it is absolute, and it survives the PECR exemption entirely.

GDPR and telesales in the UK

RuleWhat the ICO guidance says (checked 6 October 2026)
RegistersYou cannot call numbers registered with the Corporate Telephone Preference Service (CTPS) or the Telephone Preference Service (TPS) unless the business has consented. Screen against both, because some businesses register with CTPS while sole traders use TPS.
Email exemption does not carry over"The rule on marketing by electronic mail (eg email or text message) doesn't apply to corporate subscribers." The corporate subscriber exemption above is an email rule, not a telephone rule.
UK GDPR applies to callsIf you are processing personal data when making a marketing call to another business, you need to comply with the UK GDPR, for example because you know the name of the person you are calling.
Caller dutiesDisplay your number, identify yourself and give contact details if asked. Do not call businesses that have previously objected.

So a UK B2B telesales campaign has two checks that email does not: a register screen before every dial, and the UK GDPR duties whenever you hold a named contact. The source is the ICO's own page on business-to-business marketing. The wider European picture for calls is in European Telemarketing Law: Is B2B Cold Calling Legal?, and the scripting side is in The Cold Calling Script That Sounds Human.

Who enforces this, and what does it cost?

The Information Commissioner's Office, the ICO, enforces both PECR and UK GDPR, and it is the single regulator across both questions, unlike the split we describe on the Germany and Austria pages between competition-law and data-protection routes.

We are not quoting a specific typical fine figure here, because enforcement outcomes vary by case and the ICO's own guidance on this exact area is under active review; check the ICO's published enforcement action pages directly for current examples rather than relying on a number repeated secondhand.

What compliant UK outbound looks like

Not entirely. As the business whose product or service is being promoted, you remain responsible for having a lawful UK GDPR basis for any personal data used, and for the marketing being properly targeted and consented to wherever PECR does require it. An agency that claims to absorb all of the compliance exposure on your behalf is overstating what it can actually take off your hands.

What you can reasonably expect instead: full visibility of the list and copy before anything sends, a clear statement of which contacts are being treated as corporate versus individual subscribers and why, documented data sources, and immediate opt-out handling, the same standard we set out for other markets in our agency red-flag guide.

How we handle the UK

Ripe Leads runs UK campaigns with the corporate subscriber classification checked before a single email sends, not assumed. Where a contact is a sole trader, a qualifying partnership, or otherwise uncertain, we treat it as an individual subscriber and require the same consent standard we would apply anywhere else in Europe. Where UK GDPR applies, which is most of the time once a named contact is involved, we document the legitimate-interests basis, give the required privacy information, and action every objection permanently. The final call on risk belongs to the client and their counsel, not to us. Our pricing and engagement terms are public and the first call is a working session.

Frequently asked

Is cold email legal in the UK?
For genuine B2B email, yes, more often than in most EU markets, though UK GDPR still has to be satisfied. The Privacy and Electronic Communications Regulations 2003 (PECR) require consent to email an individual subscriber under regulation 22, but the ICO's own guidance confirms that this consent rule does not apply to electronic mail sent to a corporate subscriber, meaning a company, LLP, Scottish partnership or certain government bodies. Sole traders and some partnerships are treated as individual subscribers and do need consent or the soft opt-in. Even where PECR does not require consent, UK GDPR still requires a lawful basis whenever the message involves an identifiable person's personal data, and that person keeps an absolute right to object. This is general information, not legal advice.
What is a corporate subscriber under PECR?
The ICO defines a corporate subscriber as a corporate body with separate legal status, covering companies, limited liability partnerships, Scottish partnerships, corporations sole, some government bodies, and any other body corporate that is a legal person distinct from its members. The email address of an employee at such a body counts as belonging to a corporate subscriber, because the subscriber in PECR's sense is the employer, not the individual. Sole traders and most other types of partnership are instead treated as individual subscribers, with the full consent protections that gives them.
Do I need consent to email a company in the UK?
Not under PECR's electronic-mail rule, if the recipient is genuinely a corporate subscriber. PECR regulations 22 and 23 mean the consent requirement for electronic mail marketing does not apply to corporate subscribers, so you may send B2B marketing email to a corporate body without PECR consent. You must still not disguise or conceal your identity, and you must give a valid address for the business to opt out or unsubscribe. If you are unsure whether an address belongs to a corporate or an individual subscriber, the ICO advises treating it as an individual subscriber to stay on the safe side.
Does UK GDPR still apply if PECR does not require consent?
Yes. PECR and the UK GDPR are separate regimes. Whenever an email you send identifies a person, for example an address in the form firstname.lastname@company.co.uk, you are processing personal data and need a lawful basis under UK GDPR, typically legitimate interests with a documented balancing test, must give the required privacy information, and must honour that person's absolute right under Article 21(2) to object to direct marketing at any time, regardless of whether they count as a corporate or individual subscriber under PECR.
Can a business object to my marketing email even if PECR did not require its consent?
Yes, and you should stop. PECR does not explicitly say a corporate subscriber's electronic-mail opt-out must be honoured, but the ICO's own guidance says it clearly intended to allow one, since it requires you to give a valid opt-out address in the first place, and it serves no purpose to keep sending after an objection. Where the message involves an identifiable individual's personal data, UK GDPR's right to object is absolute and has no PECR-style carve-out at all.
How can I prospect into UK companies compliantly?
Confirm the address genuinely belongs to a corporate subscriber, not a sole trader or a qualifying partnership, before relying on the PECR exemption; if there is doubt, treat it as an individual subscriber and get consent or use the soft opt-in. Separately, satisfy UK GDPR: work from publicly available business data, document a legitimate-interests balancing test, give the required privacy information, and action every objection immediately and permanently. Screen new lists against your own suppression list before every send.
Does using an agency shift the legal risk away from my company?
Not entirely. As the business whose product or service is being promoted, you remain responsible for having a lawful basis for any personal data used and for the marketing being properly directed and consented to where PECR requires it. An agency that claims it takes on all of the compliance exposure is overstating what it can absorb on your behalf. Expect instead full visibility of the list and copy before anything sends, a clear statement of which contacts are treated as corporate versus individual subscribers, documented data sources, and immediate opt-out handling.
Does GDPR apply to B2B telesales in the UK?
Yes, whenever you process personal data to make the call. The ICO says that if you are processing personal data when making a marketing call to another business, you need to comply with the UK GDPR, for example because you know the name of the person you are calling. That means a lawful basis, usually legitimate interests with a documented balancing test, and the right to object.
Do I need to check the CTPS before cold calling UK companies?
Yes. The ICO says you cannot call numbers registered with the Corporate Telephone Preference Service (CTPS) or the Telephone Preference Service (TPS) unless the business has consented. Screen against both registers, because some businesses register with CTPS while sole traders use TPS.
Is the corporate subscriber exemption a telesales exemption too?
No. The ICO states that the rule on marketing by electronic mail does not apply to corporate subscribers, and that is an email and text rule. Live telephone marketing to a business has its own register check and caller duties.

Want the UK market handled properly?

We classify subscriber type before a single email sends, document our UK GDPR basis, and honour every opt-out. You get the accurate picture of the risk, then decide.

Book a strategy call Or get a free target list first