← Insights
6 October 2026  ·  7 min read

Is cold email legal in the UK?

Short answer: yes, in most B2B cases, and the reason is narrower than people think. Cold email to a limited company is lawful in the UK without prior consent, because the consent rule for marketing by electronic mail applies to individual subscribers and not to corporate ones. That exemption is real, it is written down by the regulator, and it is also easy to fall out of without noticing.

This article sets out what the rules actually say, who the exemption does not cover, what UK data protection law adds on top, and what the enforcement record looks like once you get past the headline fine figures. It is general information, not legal advice. If you are making a decision that carries real commercial risk, take advice from a solicitor or a data protection specialist on your own facts.

The rule that does the work: corporate subscribers

The relevant law is the Privacy and Electronic Communications Regulations, usually shortened to PECR. PECR is what creates the consent requirement most people associate with marketing email. The Information Commissioner's Office, which enforces it, states in its business-to-business marketing guidance that the rule on marketing by electronic mail "doesn't apply to corporate subscribers".

A corporate subscriber means one of the following:

If the organisation you are emailing is one of those, you do not need consent, and you do not need a prior relationship, to send B2B marketing email to it. That is the whole basis of lawful cold email in the UK. It is not a loophole and it is not a grey area. It is the regulator's own published position.

Two duties survive the exemption, and they are the ones agencies most often break. Under PECR regulations 22 and 23, you must not disguise or conceal the identity of the sender, and you must provide a valid address to which the recipient can send an opt-out request. In practical terms: the from name and the sending domain must be honest about who is contacting them, and a reply of "take me off this list" must reach a real inbox that a real person reads.

The question that decides most UK cold email cases is not whether you had consent. It is whether the recipient is a company, whether you were honest about who you are, and whether an opt-out actually works.

The sole trader trap

Here is where lists go wrong. Sole traders and most ordinary partnerships are treated as individual subscribers, not corporate ones. The consent rule applies to them in full, which means you need consent or the soft opt-in before you email them.

This matters because sole traders do not look like consumers in a prospect list. They have a business name, a business website, a business email address and sometimes a team page. Nothing in the data tells you the legal form unless you go and check.

Legal form of the recipientTreated asConsent needed for marketing email?
Limited companyCorporate subscriberNo
Limited liability partnershipCorporate subscriberNo
Scottish partnershipCorporate subscriberNo
Public bodyCorporate subscriberNo
Sole traderIndividual subscriberYes (consent or soft opt-in)
Ordinary partnership (most)Individual subscriberYes (consent or soft opt-in)

The fix is unglamorous and it is the single highest-value compliance step available to a UK sender: screen your list by legal form at Companies House before you load it. If a prospect does not resolve to a company or an LLP on the register, it does not go into the cold sequence. In a sector with a long tail of one-person operations, that check can remove a meaningful slice of a raw list, and it removes precisely the slice that carries the risk.

What UK GDPR adds on top

PECR is not the only thing in play. UK GDPR applies separately and simultaneously, because an address in the form [email protected] identifies a named individual and is therefore personal data. The company might be a corporate subscriber for PECR purposes while the person behind the inbox still has data protection rights.

That means you need a lawful basis for processing. For B2B prospecting the normal basis is legitimate interests, and legitimate interests is not a box you tick. It is a balancing exercise you are expected to have carried out and written down, in the form of a documented Legitimate Interests Assessment. The assessment should record the purpose, why email is a proportionate way to achieve it, and what you have done to limit the impact on the individual.

Three further duties follow from UK GDPR and apply to essentially every cold email programme:

A compliance checklist you can actually run

None of this requires a legal department. It requires a short standing process attached to every campaign.

What the enforcement record actually shows

The headline numbers look alarming. Maximum PECR fines rose from £500,000 to £17.5 million or 4% of global turnover under the Data (Use and Access) Act 2025. That is a very large ceiling.

The observed reality is different in scale and in subject matter. Since March 2022 there have been 49 PECR fines totalling £4.63 million, which averages roughly £95,000. In January 2026 ZMLUK Ltd was fined £105,000 in connection with 67 million emails sent without valid consent.

MeasureFigure
Previous PECR maximum fine£500,000
New maximum under the Data (Use and Access) Act 2025£17.5 million or 4% of global turnover
PECR fines since March 202249, totalling £4.63 million
Average fine over that periodAbout £95,000
January 2026, ZMLUK Ltd£105,000, 67 million emails without valid consent

Read the pattern rather than the ceiling. Enforcement has been overwhelmingly about consumer or individual-subscriber data, usually at volume, usually without valid consent. It has not been about corporate B2B email that identifies its sender and honours a working opt-out. That is not a guarantee, and a new maximum exists for a reason, but it does tell you where the attention sits: volume sending into individual subscribers, and senders who hide.

Sending into the US and the EU

The UK position does not travel. If your campaign crosses a border, the rules change under you.

The practical consequence is that a single pan-European list is usually the wrong unit of work. Segment by country and let each segment follow its own rules, rather than applying the most permissive rule you can find to the whole file.

The honest summary

UK B2B cold email is lawful, and it is lawful for a specific reason that you can lose by being careless. Target companies and LLPs, screen out sole traders at the register, be honest about who is sending, let people leave in one reply, document your legitimate interests, and segment by jurisdiction before you send abroad. Do those six things and you are operating inside the rules that the regulator has actually published and actually enforces.

Again, and it matters: this is general information rather than legal advice, and it does not take account of your circumstances. Take proper advice before you rely on any of it.

If you would rather not run this yourself

Camley Outbound builds and runs the whole cold email operation for B2B clients, including the Companies House screening and suppression discipline described above, with pricing published openly at £300 for a four week pilot and then £1,500 per month plus £200 per qualified meeting. If that is useful, the pilot is the sensible place to start.

Camley Outbound builds and runs cold email operations for B2B firms, and books qualified meetings into their calendars. Pricing is published on the site: a $400 four-week pilot, then $2,000 a month plus $250 per qualified meeting.

Book a twenty-minute call and I will bring a sample of the companies I would approach for you, along with the exact messages I would send.