The United Kingdom occupies a middle position: more permissive than much of the European Union for business-to-business email, considerably stricter than the United States. The distinction that decides most cases is who counts as a "corporate subscriber" — and it is narrower than most people assume.
UK GDPR governs the personal data. The Privacy and Electronic Communications Regulations — PECR — govern electronic marketing. Both apply to cold email, and the Information Commissioner's Office enforces them.
PECR's consent requirement for marketing email applies to individual subscribers. Corporate subscribers are treated differently, which is what makes B2B cold email workable in the UK.
| Recipient type | Treatment under PECR |
|---|---|
| Limited companies, LLPs, public bodies | Corporate subscriber — consent not required for marketing email |
| Sole traders | Treated as individual subscribers |
| Non-LLP partnerships | Treated as individual subscribers |
| Personal addresses of any kind | Individual subscriber |
The consequence is direct and easy to get wrong: emailing a limited company sits on much firmer ground than emailing a sole trader, and a great many small businesses — including most tradespeople, consultants and independent operators — are sole traders. You need to know the legal form of the business you are contacting, not just that it is a business.
Even where PECR permits the send, UK GDPR governs the underlying personal data. That means:
For corporate subscribers — limited companies, LLPs and public bodies — PECR does not require consent for marketing email. For sole traders and non-LLP partnerships, who are treated as individual subscribers, the position is much closer to requiring consent. Since many small businesses are sole traders, the legal form of the recipient matters before you send.
Check the company register. UK companies and LLPs are searchable on Companies House, and most businesses display their company number and registered form on their website footer as they are required to. If you cannot establish the legal form, the cautious approach is to treat the recipient as an individual subscriber.
Yes. UK GDPR requires you to inform people when you obtain their personal data from a source other than themselves, including the source. In practice this means a brief privacy notice or a clear link in your first message — and it is the most commonly omitted requirement in UK outreach.
The ICO can issue monetary penalties under PECR, and separately under UK GDPR where data protection obligations are breached. It publishes enforcement actions, and unsolicited marketing is a recurring category. Complaints from recipients are the usual starting point for an investigation.
The Cold Outreach Machine finds the companies you sell to, writes a different email for each one, and sends them on its own — paced, inside working hours. US$299.99, paid once, live setup call included.