Is cold email legal in the UK?
Short answer: yes, in most B2B cases, and the reason is narrower than people think. Cold email to a limited company is lawful in the UK without prior consent, because the consent rule for marketing by electronic mail applies to individual subscribers and not to corporate ones. That exemption is real, it is written down by the regulator, and it is also easy to fall out of without noticing.
This article sets out what the rules actually say, who the exemption does not cover, what UK data protection law adds on top, and what the enforcement record looks like once you get past the headline fine figures. It is general information, not legal advice. If you are making a decision that carries real commercial risk, take advice from a solicitor or a data protection specialist on your own facts.
The rule that does the work: corporate subscribers
The relevant law is the Privacy and Electronic Communications Regulations, usually shortened to PECR. PECR is what creates the consent requirement most people associate with marketing email. The Information Commissioner's Office, which enforces it, states in its business-to-business marketing guidance that the rule on marketing by electronic mail "doesn't apply to corporate subscribers".
A corporate subscriber means one of the following:
- a body corporate, which in practice means a limited company
- a limited liability partnership
- a Scottish partnership
- a public body
If the organisation you are emailing is one of those, you do not need consent, and you do not need a prior relationship, to send B2B marketing email to it. That is the whole basis of lawful cold email in the UK. It is not a loophole and it is not a grey area. It is the regulator's own published position.
Two duties survive the exemption, and they are the ones agencies most often break. Under PECR regulations 22 and 23, you must not disguise or conceal the identity of the sender, and you must provide a valid address to which the recipient can send an opt-out request. In practical terms: the from name and the sending domain must be honest about who is contacting them, and a reply of "take me off this list" must reach a real inbox that a real person reads.
The question that decides most UK cold email cases is not whether you had consent. It is whether the recipient is a company, whether you were honest about who you are, and whether an opt-out actually works.
The sole trader trap
Here is where lists go wrong. Sole traders and most ordinary partnerships are treated as individual subscribers, not corporate ones. The consent rule applies to them in full, which means you need consent or the soft opt-in before you email them.
This matters because sole traders do not look like consumers in a prospect list. They have a business name, a business website, a business email address and sometimes a team page. Nothing in the data tells you the legal form unless you go and check.
| Legal form of the recipient | Treated as | Consent needed for marketing email? |
|---|---|---|
| Limited company | Corporate subscriber | No |
| Limited liability partnership | Corporate subscriber | No |
| Scottish partnership | Corporate subscriber | No |
| Public body | Corporate subscriber | No |
| Sole trader | Individual subscriber | Yes (consent or soft opt-in) |
| Ordinary partnership (most) | Individual subscriber | Yes (consent or soft opt-in) |
The fix is unglamorous and it is the single highest-value compliance step available to a UK sender: screen your list by legal form at Companies House before you load it. If a prospect does not resolve to a company or an LLP on the register, it does not go into the cold sequence. In a sector with a long tail of one-person operations, that check can remove a meaningful slice of a raw list, and it removes precisely the slice that carries the risk.
What UK GDPR adds on top
PECR is not the only thing in play. UK GDPR applies separately and simultaneously, because an address in the form [email protected] identifies a named individual and is therefore personal data. The company might be a corporate subscriber for PECR purposes while the person behind the inbox still has data protection rights.
That means you need a lawful basis for processing. For B2B prospecting the normal basis is legitimate interests, and legitimate interests is not a box you tick. It is a balancing exercise you are expected to have carried out and written down, in the form of a documented Legitimate Interests Assessment. The assessment should record the purpose, why email is a proportionate way to achieve it, and what you have done to limit the impact on the individual.
Three further duties follow from UK GDPR and apply to essentially every cold email programme:
- Privacy information. Where you have obtained the data from a third party rather than from the individual, and bought or scraped lists are exactly that, you must supply privacy information to the individual within one month.
- The right to object. There is an absolute right to object to direct marketing. There is no balancing test and no discretion. When someone objects, you stop, and you make sure they are not re-enrolled by the next list refresh.
- Accuracy and minimisation. Hold the fields you actually need to personalise and qualify, and keep them current.
A compliance checklist you can actually run
None of this requires a legal department. It requires a short standing process attached to every campaign.
- Screen every prospect by legal form at Companies House. Companies and LLPs proceed. Sole traders and ordinary partnerships are excluded from cold sending.
- Send from a domain and a from name that plainly identify the sender. No lookalike domains, no invented personas, no disguised identity.
- Use a reply-to address that a human monitors, and treat an opt-out reply as a hard suppression, not a pause.
- Keep one suppression list across all sending domains, inboxes and tools, and check new lists against it before upload.
- Write a Legitimate Interests Assessment once per programme or per niche, date it, and revisit it when the targeting changes.
- Make sure privacy information is available and reachable, so the one month obligation for third party sourced data is satisfied.
- Record where each list came from and when, so you can answer a complaint with facts rather than a reconstruction.
- Remember that liability attaches to whoever transmits or instigates the message. The agency and the client are both exposed, so the client should ask to see the screening and suppression process, and the agency should expect to show it.
What the enforcement record actually shows
The headline numbers look alarming. Maximum PECR fines rose from £500,000 to £17.5 million or 4% of global turnover under the Data (Use and Access) Act 2025. That is a very large ceiling.
The observed reality is different in scale and in subject matter. Since March 2022 there have been 49 PECR fines totalling £4.63 million, which averages roughly £95,000. In January 2026 ZMLUK Ltd was fined £105,000 in connection with 67 million emails sent without valid consent.
| Measure | Figure |
|---|---|
| Previous PECR maximum fine | £500,000 |
| New maximum under the Data (Use and Access) Act 2025 | £17.5 million or 4% of global turnover |
| PECR fines since March 2022 | 49, totalling £4.63 million |
| Average fine over that period | About £95,000 |
| January 2026, ZMLUK Ltd | £105,000, 67 million emails without valid consent |
Read the pattern rather than the ceiling. Enforcement has been overwhelmingly about consumer or individual-subscriber data, usually at volume, usually without valid consent. It has not been about corporate B2B email that identifies its sender and honours a working opt-out. That is not a guarantee, and a new maximum exists for a reason, but it does tell you where the attention sits: volume sending into individual subscribers, and senders who hide.
Sending into the US and the EU
The UK position does not travel. If your campaign crosses a border, the rules change under you.
- The CAN-SPAM regime is opt-out based and does not require prior consent. It does require accurate headers, a physical postal address in the message, and opt-out requests honoured within 10 business days.
- Germany and Austria. Prior consent is required even for B2B. Cold email in the UK sense is not available to you there.
- Denmark. Prior consent is required for business recipients too.
The practical consequence is that a single pan-European list is usually the wrong unit of work. Segment by country and let each segment follow its own rules, rather than applying the most permissive rule you can find to the whole file.
The honest summary
UK B2B cold email is lawful, and it is lawful for a specific reason that you can lose by being careless. Target companies and LLPs, screen out sole traders at the register, be honest about who is sending, let people leave in one reply, document your legitimate interests, and segment by jurisdiction before you send abroad. Do those six things and you are operating inside the rules that the regulator has actually published and actually enforces.
Again, and it matters: this is general information rather than legal advice, and it does not take account of your circumstances. Take proper advice before you rely on any of it.
If you would rather not run this yourself
Camley Outbound builds and runs the whole cold email operation for B2B clients, including the Companies House screening and suppression discipline described above, with pricing published openly at £300 for a four week pilot and then £1,500 per month plus £200 per qualified meeting. If that is useful, the pilot is the sensible place to start.
Camley Outbound builds and runs cold email operations for B2B firms, and books qualified meetings into their calendars. Pricing is published on the site: a $400 four-week pilot, then $2,000 a month plus $250 per qualified meeting.
Book a twenty-minute call and I will bring a sample of the companies I would approach for you, along with the exact messages I would send.