Is Your Cold Email Legal? A UK Business Guide to GDPR and PECR

The rules for UK cold email depend on the recipient. Corporate subscribers, sole traders, ordinary partnerships and named business contacts can be treated differently under PECR and UK GDPR. Use this practical decision framework to classify the recipient, check consent or soft opt-in where relevant, consider the personal-data rules and make objections easy to honour.
A business buys or builds a prospect list. It contains info@company.co.uk, jane@company.co.uk, john@soletrader.co.uk and hello@partnership.co.uk. Someone asks: “Can we just email all of these?”
Not without classifying them first. The same email can be lawful to send to one recipient and unlawful to send to another. The sender needs to consider the Privacy and Electronic Communications Regulations (PECR) and, where personal data is used, UK GDPR.
Cold email is not automatically legal or illegal. The first question is who you are emailing.
The Quick Answer
PECR's electronic-mail consent rule generally does not apply to corporate subscribers, such as limited companies, LLPs, Scottish partnerships and certain public bodies. It generally does apply to individual subscribers, including sole traders and some ordinary partnerships. That is not the end of the analysis: if a message uses identifiable contact data, UK GDPR still applies.
For a corporate prospect, the question is usually whether you have handled the personal data properly, identified yourself and made it easy to object. For an individual subscriber, consent or the specific soft opt-in exception is normally the starting point before sending unsolicited marketing email.
Start With the Recipient, Not the Email Address
An address that looks business-like does not settle the question. PECR distinguishes between corporate subscribers and individual subscribers. The legal structure behind the recipient matters more than whether the address contains a person's name.
| Recipient type | PECR email starting point | What still needs checking |
|---|---|---|
| Limited company, LLP, Scottish partnership or qualifying corporate body | Prior consent is generally not required for unsolicited marketing email. | Identify the sender, provide a valid opt-out, honour objections and comply with UK GDPR if personal data is used. |
| Sole trader or some ordinary partnerships | Treat as an individual subscriber: consent is generally required unless the soft opt-in applies. | Check the conditions for consent or soft opt-in, plus UK GDPR where personal data is processed. |
| Legal structure unknown | Do not guess from the address alone. | Check the entity and subscriber type before treating it as a corporate prospect. |
ICO: Business-to-business marketing →
Get the recipient category right before you send anything. ICO guidance is being updated following changes made by the Data (Use and Access) Act, so check the current position for material or high-volume campaigns.
The IT Club Cold Email Decision Framework
This is a practical triage tool, not a substitute for legal assessment. It is deliberately designed to produce three outcomes: proceed carefully, check first or do not send yet.
| Question | If the answer is yes | If the answer is no or unknown |
|---|---|---|
| Are you sending a message intended to promote your organisation, service, event or resource? | Treat it as marketing and apply the checks below. | Confirm it is genuinely a service or administrative message, not promotion in disguise. |
| Is the subscriber a corporate body with separate legal personality? | Prior PECR email consent is usually not required. Continue with identity, opt-out and UK GDPR checks. | Check whether it is an individual subscriber, including a sole trader or relevant partnership. |
| For an individual subscriber, do you have valid consent? | Usually proceed, provided the consent covers this marketing and the wider data-protection requirements are met. | Check the soft opt-in precisely. If it does not apply, do not send the unsolicited marketing email yet. |
| Are you using a named person's business contact details? | Document a UK GDPR lawful basis, provide the required privacy information and honour an objection. | A generic address may not identify a person, but PECR still depends on the subscriber type. |
The decision framework does not create permission. It helps surface the checks the business must be able to explain.
Corporate Subscribers: Usually a PECR Route, Not a Free Pass
The ICO describes corporate subscribers as bodies with separate legal status. Examples include limited companies, LLPs, Scottish partnerships and some government bodies. For electronic mail marketing, the PECR consent rule generally does not apply to those corporate subscribers.
That does not mean “email any address you can find”. The sender must not disguise or conceal its identity and must provide a valid address for opt-out requests. If the message uses a named person's contact details, the organisation is also processing personal data and needs to comply with UK GDPR.
Corporate email rules may let you send the message. UK GDPR still governs how you use the person's data.
Generic Business Addresses Do Not Have Generic Legal Status
Addresses such as info@, hello@ or sales@ do not necessarily identify an individual. If the address is not personal data, UK GDPR may not apply to the address itself. But PECR still turns on the subscriber type: a generic inbox at a limited company and one used by a sole trader are not automatically treated the same way.
Generic address does not mean generic legal status.
Named Contacts at Limited Companies
Take jane.smith@limitedcompany.co.uk. The subscriber may be the limited company, so PECR's electronic-mail consent rule generally does not apply. But Jane is identifiable, which means the contact details are personal data.
The business should identify a UK GDPR lawful basis, give the person appropriate privacy information and respect the right to object to direct marketing. Legitimate interests is often considered for this type of activity, but it requires a genuine purpose, necessity and a fair balance with the person's interests and expectations.
Sole Traders and Partnerships: Do Not Assume B2B Means Corporate
Sole traders are individual subscribers under PECR. A business email address does not automatically make someone a corporate subscriber. For unsolicited marketing email, the usual position is that the sender needs valid consent or needs to satisfy the soft opt-in conditions.
Partnerships need care. The ICO says Scottish partnerships are corporate subscribers, while sole traders and other types of partnership are treated as individual subscribers. If the structure is unclear, check it rather than relying on the domain name, job title or a directory label.
If the legal structure is unclear, check before treating the recipient as a corporate subscriber.
Soft Opt-In Is Specific, Not a Shortcut
The soft opt-in can provide a limited route to send marketing to individual subscribers without fresh consent. In broad terms, the contact details must have been obtained during a sale or genuine negotiation for a sale, the marketing must cover similar products or services, and the person must have had a simple way to refuse marketing both when their details were collected and in every later message.
Soft opt-in is a specific exception, not a general permission to email previous contacts.
ICO: PECR electronic-mail marketing rules and soft opt-in →
Publicly Available Does Not Mean Legally Unrestricted
An address appearing on a company website, LinkedIn, Companies House, a directory or social profile does not automatically create permission to market to that person. When the details identify an individual, using them is personal-data processing and UK GDPR still applies. A public listing may inform the business's assessment of reasonable expectations, but it does not remove the need for a lawful basis, transparency and objection handling.
Publicly available does not mean legally unrestricted.
Legitimate Interests and PECR Answer Different Questions
UK GDPR asks why the organisation can process personal data. PECR asks whether it can send this kind of unsolicited electronic marketing to this kind of subscriber. Both can apply to the same campaign.
The Data (Use and Access) Act changed parts of the UK data-protection framework, including the treatment of recognised legitimate interests. The ICO's current guidance continues to identify consent and legitimate interests as the lawful bases most likely to arise in direct marketing. That does not override PECR's separate electronic-mail restrictions.
| IT Club practical test | Question to ask |
|---|---|
| Purpose | Is there a real, documented business reason for this contact? |
| Necessity | Do you need to use this contact data for that purpose, or is there a less intrusive route? |
| Balance | Would this person reasonably expect the contact in this context, and what impact could it have? |
| Safeguards | Can the person easily understand the use, object and be suppressed from future contact? |
Legitimate interests is not a magic permission slip for email marketing.
ICO: Choosing your lawful basis for direct marketing →
What Counts as Marketing?
Marketing is broader than “buy now”. A sales offer, newsletter, event invitation, promotional guide, commercial webinar or resource designed to promote the organisation can all be marketing. An operational update about an existing service may be different, but adding promotional content can change the character of the message.
If the purpose is to promote your organisation, the ICO may treat it as marketing even if there is no price in the email.
The same caution applies to permission campaigns. You cannot always solve a consent problem by sending a marketing email asking whether someone would like marketing emails. That request can itself be direct marketing.
Opt-Outs and Suppression Lists
A relevant B2B marketing message needs a genuine opt-out route. If the business uses personal data, an objection to direct marketing must be respected. The operational answer is not simply to delete the address and hope it never appears again: a small, controlled suppression record can be necessary to make sure an opted-out person is not re-added from a later list.
An unsubscribe request is not a lead-nurture challenge. It is a stop instruction.
Store only what is needed to honour the objection, protect the list, restrict access and review the suppression process as part of the campaign controls.
Bought Lists and Researched Contacts
Buying a list does not transfer legal responsibility. Before using it, ask where the data came from, which privacy information was given, which subscriber type each entry represents, what consent or objection information exists, whether the details are accurate and whether the supplier contract supports the intended use.
The same applies to named contacts researched online. Finding a contact is not the same as proving that a campaign can use the data in the intended way. Do not collect more than is relevant, record the source and make the required privacy information available.
A list supplier can sell you data. They cannot sell you immunity from GDPR or PECR.
The Quick Business Check Before Sending
- 1What legal entity is the recipient?
- 2Is the address generic or personally identifiable?
- 3Does PECR consent apply to this subscriber type?
- 4If it does, do we have valid consent or a valid soft opt-in?
- 5If we use personal data, what is our UK GDPR lawful basis?
- 6Have we provided the appropriate privacy information?
- 7Is there an easy, working opt-out?
- 8Is the recipient already on a suppression list?
- 9Can we show where the data came from and why we are using it?
- 10Would we be comfortable explaining this campaign to the ICO?
If you cannot explain why the recipient is on the list, do not press send yet.
Common Myths
| Myth | Practical reality |
|---|---|
| “GDPR banned cold email.” | No. The rules depend on the recipient, the channel, the data used and the campaign context. |
| “B2B email does not need GDPR.” | Named business contacts can still be personal data. |
| “Anything on LinkedIn is fair game.” | Publicly available identifiable data remains subject to data-protection rules. |
| “Limited companies always need opt-in.” | PECR's electronic-mail consent rule generally does not apply to corporate subscribers. |
| “Sole traders are B2B, so the same rule applies.” | PECR treats sole traders as individual subscribers. |
Four Practical Examples
| Contact | Likely starting point | Next check |
|---|---|---|
| info@limitedcompany.co.uk | Likely corporate subscriber. | Prior PECR consent is generally not required, but give a real opt-out and identify the sender. |
| jane@limitedcompany.co.uk | Corporate subscriber for PECR may be likely; Jane is identifiable. | Check UK GDPR lawful basis, privacy information and objection handling. |
| john@johnsplumbing.co.uk, sole trader | Individual subscriber. | Consent or the soft opt-in is generally required for unsolicited marketing email. |
| A contact at a business with unclear legal structure | Unknown. | Stop and check first; do not assume the domain makes it corporate. |
What About LinkedIn Messages?
Direct messages and other stored electronic messages can raise PECR and data-protection issues as well as platform terms. Do not assume that a channel is exempt because it is social rather than email. Check current ICO guidance and the platform rules before building an outreach process around it.
A Practical Compliance Checklist
- Recipient: legal entity identified and subscriber type understood
- Data: source recorded, lawful basis identified and privacy information considered
- PECR: consent requirement checked and soft opt-in tested where relevant
- Message: sender identified, purpose clear and an easy opt-out included
- Control: suppression list maintained, objections honoured and campaign records retained appropriately
Related IT Club Reading
Cold outreach and email security overlap in the real world. A legitimate message still needs good delivery and domain-protection controls, while a compliant data process should be part of the wider way a business handles online information.
Could Someone Be Sending Fake Emails as Your Business? →
Why Your Business Needs DMARC →
Privacy-First Web Verification: A Practical GDPR View →
Important Disclaimer
IT Club provides practical technology and business guidance, not legal advice. If a campaign is high-volume, high-risk, uses sensitive data, relies on unusual data sources or crosses borders, take specialist data-protection or legal advice. Always check the current ICO guidance before acting.
Frequently Asked Questions
Is cold email illegal in the UK?
No. The answer depends on the recipient, the type of communication and the data used. For unsolicited marketing email, PECR is generally stricter for individual subscribers than for corporate subscribers. UK GDPR can also apply where personal data is used.
Can I email a limited company without consent?
PECR's electronic-mail consent rule generally does not apply to corporate subscribers such as limited companies. You still need to identify yourself, provide a valid opt-out address, honour objections and meet UK GDPR duties when using identifiable contact data.
Can I cold email a sole trader?
Treat a sole trader as an individual subscriber for PECR. For unsolicited marketing email, valid consent or the limited soft opt-in route is generally required. Do not assume a business-looking email address changes that position.
Does a public email address mean I can market to it?
No. Public availability does not itself create permission. If the details identify a person, UK GDPR still applies, and the PECR position still depends on the subscriber type.
Can I send an email asking for marketing consent?
Be careful. The ICO warns that a message asking someone to receive marketing can itself be direct marketing. It is not a reliable way to bypass a consent requirement.
What is the soft opt-in?
It is a narrow exception that can apply to existing customers or people in genuine sales negotiations. The details must have been collected in the right context, the marketing must be for similar products or services, and an easy opt-out must have been available at collection and in every later message.
Does legitimate interests override PECR?
No. A UK GDPR lawful basis and PECR compliance are separate questions. Legitimate interests may be relevant to processing personal data, but it does not remove PECR's electronic-marketing restrictions.
Should I delete an address after an opt-out?
Do not keep using it for marketing. In practice, a minimal suppression record may be needed to ensure the address is not accidentally added back to a future campaign. Limit what is retained and protect it.
Are bought marketing lists safe to use?
They require careful due diligence. The buyer remains responsible for checking data source, accuracy, privacy information, consent where needed, objection records, subscriber type and the supplier terms. A vendor statement alone is not a compliance programme.
Where should we check the latest official position?
Start with the ICO's direct-marketing, B2B marketing and PECR electronic-mail guidance. As this area is being updated after the Data (Use and Access) Act, high-risk or material campaigns should also take specialist advice.
Talk to an IT Club Advisor
Need a practical review of how your contact data, email platforms, domain controls and opt-out process work together? We can help you map the technology and operating controls. We do not replace specialist legal advice.
Plain-English Takeaway
Cold email is not automatically legal or illegal. The first question is who you are emailing. A limited company, a sole trader, an ordinary partnership and a named contact can each bring different PECR and UK GDPR questions. Classify the recipient before you send, document the reason for using the data, give a real opt-out and treat objections as a stop instruction.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
How Can YouTube Help Your Business Appear in AI Search?
Research from Ahrefs found that YouTube brand mentions had a stronger statistical relationship with visibility across several AI search systems than traditional backlink measures. This article explains what that finding means, why correlation does not prove causation, why backlinks still matter, and what smaller businesses can realistically do to improve their chances of being understood and mentioned by AI search systems.
Read articleWhat Do Customers See When They Search for Your Business?
Your website is only one part of your online presence. This practical guide explains how to check what potential customers see and identify information that may be costing you trust or enquiries.
Read articleWhy CAPTCHAs Are Being Replaced – And Why Business Owners Should Care
Traditional CAPTCHAs are being replaced by privacy-first website verification. Here is how the modern alternatives work and what business owners should check.
Read article