Meetings and pipeline · Guide 1 of 1

Is cold emailing other businesses legal in the UK?

You can email people at UK companies without consent, but sole traders, bought lists and fines of up to 4% of global turnover change the picture. The rules in plain English.

A founder in his fifties and a compliance manager in her forties reviewing a printed email draft together at a meeting table in a bright UK office, a pen marking the page, a lime-green highlighter beside the papers, soft morning light.
On this page · 12 sections
  1. Is cold emailing a business legal in the UK?
  2. Who counts as a corporate subscriber, and who counts as an individual?
  3. What is a legitimate interests assessment, in plain terms?
  4. What changed with the Data (Use and Access) Act 2025?
  5. Can we buy a list or use scraped contacts?
  6. What must a compliant first email contain?
  7. What should we do when someone objects?
  8. What records should we keep?
  9. What does this mean for how you run outbound?
  10. What to do this month
  11. Questions founders ask
  12. Sources

Most founders who ask this have heard two opposite answers. One adviser says any unsolicited email breaks GDPR. A lead generation agency says business email is exempt from everything. Neither is right, and the gap between them is where firms get into trouble.

The short version: you can email people at UK companies and LLPs without asking first, as long as you say who you are, give them a working way to opt out and have a fair reason to contact them. Sole traders and most ordinary partnerships are different, because the law treats them like consumers. The stakes also went up this year. Since 5 February 2026, fines under the Privacy and Electronic Communications Regulations (PECR) can reach £17.5 million or 4% of global annual turnover, up from £500,000, under the Data (Use and Access) Act 2025 (Clifford Chance, February 2026).

This guide sets out the rules in plain English, based on the ICO's business-to-business marketing guidance and the changes the new Act brought in. It is not legal advice: if your situation is unusual, or you plan to email at scale, take advice from a data protection lawyer.

Yes, for most businesses. Two sets of rules apply, and a compliant email has to pass both.

PECR decides whether you may send marketing by email at all. It draws its line by the type of recipient, not by whether the message feels like business to business. UK GDPR decides whether you may use a person's details, and it applies whenever the address or your records identify an individual. The ICO is plain about this: "If you are processing personal data when sending marketing by electronic mail to another business, you need to comply with the UK GDPR." It gives jane.smith@company.com as an example of an address that identifies a person.

So "B2B is exempt from GDPR" is wrong, and so is "you need consent to email anyone". For a named contact at a limited company: no consent under PECR, legitimate interests under UK GDPR, and your identity plus an opt-out in every message.

Who counts as a corporate subscriber, and who counts as an individual?

The ICO calls the recipients you may email without consent "corporate subscribers". Everyone else is an "individual subscriber", even if they run a business.

Recipient How PECR treats them What you need before emailing
Limited company or plc Corporate subscriber No consent. Identify yourself and give a valid opt-out address.
Limited liability partnership (LLP) Corporate subscriber No consent. Identify yourself and give a valid opt-out address.
Scottish partnership Corporate subscriber No consent. Identify yourself and give a valid opt-out address.
Some government bodies Corporate subscriber No consent. Identify yourself and give a valid opt-out address.
Sole trader Individual subscriber Consent, or the soft opt-in
Ordinary partnership in England, Wales or Northern Ireland Individual subscriber Consent, or the soft opt-in
Other unincorporated bodies of individuals Individual subscriber Consent, or the soft opt-in

The soft opt-in rarely helps with cold email. It covers people whose details you collected during a sale or the negotiation of a sale, for your own similar products and services, where you gave them a clear chance to opt out. A prospect you have never dealt with is not covered.

Check before you send. The ICO warns: "If you are unsure whether the contact details belong to an individual subscriber or a corporate subscriber this puts you at risk of breaching PECR." In practice that means confirming "Ltd", "plc" or "LLP" on Companies House or the firm's own website before a contact goes on your list, and leaving out anyone you cannot confirm. Freelancers, consultants and small professional practices are the usual trap.

What is a legitimate interests assessment, in plain terms?

It is a short written record showing you thought about the person on the receiving end before you emailed them. Where PECR does not require consent, the ICO says "in many cases it is likely that legitimate interests will be the appropriate lawful basis", and it describes three tests: identify the interest, show the processing is necessary, and balance it against the person's interests, rights and freedoms. Write your answers down once for each target market. One page is usually enough.

Step 1: Name the interest

Say what you want to achieve, for example offering a compliance service to finance directors at UK fund administrators. The Data (Use and Access) Act 2025 now says that direct marketing can be a legitimate interest. The ICO groups this with changes that make the law easier to follow "without materially changing how you can use personal information", so it does not remove the next two tests.

Step 2: Show that email to this person is necessary

Explain why emailing this person is a reasonable way to reach that goal. Relevance does most of the work. A message to the person who owns the problem, about that problem, is easy to justify. The same message sent to everyone with a job title is not.

Step 3: Balance it against the person's interests

Ask whether someone in that role would reasonably expect to hear from a firm like yours at their work address, whether you are using only work contact details, and whether opting out is easy. In our view, if the answers are yes, the balance usually favours you. If you are emailing personal addresses, or writing to people about decisions outside their role, it does not.

What changed with the Data (Use and Access) Act 2025?

The basic line between corporate and individual subscribers did not move. Three things did.

Change When What it means for your outbound
Maximum PECR fine raised to £17.5 million or 4% of global annual turnover, from £500,000 5 February 2026 A breach of the email marketing rules now carries penalties on the same scale as UK GDPR.
Direct marketing named as something that can be a legitimate interest In force; the ICO confirmed on 19 June 2026 that all the Act's data protection provisions had commenced Clearer footing for legitimate interests, but you still need the necessity and balancing tests.
A duty to handle data protection complaints 19 June 2026 You must help people complain, for example with an electronic complaints form, acknowledge complaints within 30 days and respond without undue delay.

One more thing to watch: the ICO's own B2B page now opens with the note that "Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change." Check it again before any large campaign.

Can we buy a list or use scraped contacts?

You can, but it moves the risk onto you, and it rarely pays. PECR does not ban bought lists of corporate subscribers. UK GDPR still applies to every named contact on them, and the ICO's B2B guidance says that if you buy a list of business contacts, "you must also tell people that you have obtained their data". Its guidance on the right to be informed sets the deadline: if you use the data to contact someone, you must give them privacy information "at the latest, when the first communication takes place", including where the data came from.

There are three further problems:

  • Bought lists mix in sole traders and partnerships, who need consent. You inherit the seller's mistakes.
  • Scraping LinkedIn breaks LinkedIn's rules. Its help centre says it does not permit software that scrapes the site, and that members who use such tools "risk having their accounts restricted or shut down" (LinkedIn Help).
  • Mailbox providers treat bought addresses as a warning sign. Google's email sender guidelines say: "Don't purchase email addresses from other companies."

If you use a list, ask the supplier in writing where each record came from, when it was collected, what people were told and whether sole traders were removed. Better still, build the list yourself, one checked firm and person at a time.

What must a compliant first email contain?

Keep it short, but these elements have to be there.

Include Avoid
Your real name, your firm's name and a way to contact you A disguised sender or a "From" line that hides who you are
A working opt-out, such as "reply 'no thanks' and we will not contact you again" An opt-out that needs a login or a long form, or that does not work
A line on where you got their details, with a link to your privacy notice Silence about where the data came from
One clear reason you are writing to this person, in their role A generic pitch that could go to anyone
A plain subject line that matches the message "Re:" or "Fwd:" on a first email, which Google's guidelines also warn against
Work contact details only Personal email addresses

The first three rows are legal requirements for most cold emails to named people. The rest are what keep your legitimate interests assessment honest.

What should we do when someone objects?

Stop, record it and never contact them again. Under UK GDPR the right to object to direct marketing is absolute; the ICO says "there are no grounds for you to refuse". For corporate subscribers under PECR, the ICO says "you should comply with a corporate subscriber's opt-out request" as well.

Do not simply delete them. The ICO advises adding the business or contact to a "do not contact" or suppression list "instead of simply deleting all record of them", because a deleted contact can reappear in the next list you build or buy. Share that list with anyone who sends on your behalf, and check every new list against it before sending.

If someone complains about how you used their data, the Act now requires you to acknowledge the complaint within 30 days and deal with it without undue delay. A named owner and a simple complaints route in your privacy notice cover it.

What records should we keep?

Record Why it matters
Your legitimate interests assessment Shows you considered the recipient before sending
The source and date for each contact Needed for privacy information and for answering any complaint
How you screened out sole traders and partnerships Shows you applied PECR's line
The privacy notice in use at the time Shows what people were told
A dated suppression list Proves opt-outs were honoured
A complaints log Meets the 30-day acknowledgement duty
Your agency's written terms on data and compliance Your firm's name is on the emails, whoever sends them

What does this mean for how you run outbound?

The law and good selling point the same way. A message written by a person, to someone checked against a clear brief, with an honest opt-out, is easy to justify and rarely draws complaints. A tool firing templated emails at a bought list is where most of the risk sits.

That is how we run Pipeline That Fills: researched outbound where a person writes and approves every message. It reaches buyers before any AI assistant is asked who to hire. If you have avoided outbound because it feels like spam, that worry is common, and it is a good instinct to keep. If you are weighing up outside help, see how we compare with a lead generation agency.

What to do this month

  1. Go through your current prospect list and mark each contact as company, LLP, sole trader or partnership, removing anyone you cannot confirm.
  2. Write a one-page legitimate interests assessment for your main target market.
  3. Add a line to your email template saying where you found the person's details, with a link to your privacy notice.
  4. Test your own opt-out: reply "no thanks" to one of your emails and check the address lands on your suppression list.
  5. Name one person to own complaints, so any complaint is acknowledged within 30 days.
  6. If an agency sends for you, ask in writing where its data comes from and how opt-outs reach your suppression list.

Frequently asked questions

Is cold emailing illegal under GDPR?

No. UK GDPR does not ban cold email; it requires a lawful basis for using a person's details, and legitimate interests usually fits business outreach. You must also tell people where you got their details and let them object. PECR then decides whether you need consent, which depends on whether the recipient is a corporate subscriber.

Can we email generic addresses like info@ or sales@?

Yes, if the business is a corporate subscriber, and you still identify yourself and offer an opt-out. A generic address that does not identify a person is usually not personal data. Generic inboxes rarely reach the person who decides, though.

Yes, unless the soft opt-in applies, which means you collected their details while selling to them or negotiating a sale. The ICO treats sole traders and ordinary partnerships in England, Wales and Northern Ireland as individual subscribers. Many freelancers, consultants and small practices fall into this group, so check before they go on a list.

Who carries the risk if an agency sends the emails for us?

Your firm's name is on every message, so treat the agency's compliance as your own risk. Ask where its data comes from, how it screens out sole traders and how opt-outs reach your suppression list, and put the answers in the contract. If the agency cannot answer clearly, that tells you what you need to know.

Do the same rules apply when we email businesses abroad?

No. This guide covers UK rules. Other countries set their own rules for email marketing, and some are stricter about business email, so take local advice before emailing prospects outside the UK.

If you want outbound that stays on the right side of these rules and still fills the diary, see Pipeline That Fills, or book a free Growth Review for three fixes in writing across your website, reputation and pipeline.

Sources

David Adams
Written by

David Adams

Co-founder and CEO, Fortitude Media · AI and automation

David spent thirteen years in SaaS, from retention calls to COO and then CRO of a £30 million partner-led business. He runs Fortitude, builds the tools behind it and runs Pipeline That Fills.

  • Websites
  • Getting named by AI
  • The business case
  • Meetings and pipeline
More from David

Ready to find out where you stand?

Book a free Growth Review.

Book your Growth Review ↗