The UK position confuses people because two regimes apply at once, and they answer different questions.

PECR governs whether you may send a marketing email at all. UK GDPR governs how you handle the personal data involved. You have to satisfy both, and each has its own answer.

This is general information rather than legal advice. For anything at scale, take proper advice.

PECR: the corporate subscriber distinction

PECR restricts unsolicited electronic marketing to individual subscribers. It does not extend the same restriction to corporate subscribers.

That single distinction decides most of the question.

Corporate subscribers include limited companies, limited liability partnerships, public bodies and other corporate bodies. Marketing email to them is permitted without prior consent.

Individual subscribers include consumers, sole traders and, in most cases, ordinary partnerships. These require consent.

The consequence is uncomfortable for anyone selling to trades and local services: a great many of your prospects are sole traders, and they sit on the protected side of the line. "It is B2B" is not a defence if the business is a sole trader.

You still must, in every case, identify yourself and provide a simple way to opt out.

How to tell which one you are looking at

Companies House is free and definitive for the corporate cases. If the business appears with a company number, it is a corporate subscriber. If it does not, treat it as an individual subscriber unless you have a good reason not to.

Practical signals that you are dealing with a sole trader: no company number, no "Ltd" or "Limited" in the trading name, an address that is residential, a personal mobile as the main contact number.

If you cannot tell, the cautious position is to treat it as an individual subscriber.

UK GDPR: the second question

Even where PECR permits the send, UK GDPR applies to the personal data involved.

A named work address is personal data. sarah.jones@company.co.uk identifies a person. That it belongs to a company changes nothing.

A generic address usually is not. info@company.co.uk, enquiries@, hello@ typically do not identify an individual, and using them keeps you out of most of UK GDPR's scope. This is a genuine practical advantage of targeting published business contact addresses rather than hunting named individuals.

Where personal data is involved, you need:

A lawful basis. Legitimate interest is normally the one, and it requires a recorded three-part assessment:

  1. Purpose: what is your legitimate interest? Promoting relevant business services is legitimate.
  2. Necessity: is direct contact necessary to achieve it? Usually yes for B2B outreach.
  3. Balancing: does your interest override the person's rights and reasonable expectations? This is the part that does the work. A relevant approach to someone whose role plainly involves buying what you sell passes far more easily than a blanket mail-out.

Write it down. An assessment you did in your head is one you cannot evidence.

Transparency. People must be able to find out where you got their data and what you are doing with it. In practice: a line in the email pointing to your privacy notice, and a privacy notice that actually explains your sourcing.

A right to object. Absolute for direct marketing. When someone objects, you stop, permanently and across all campaigns.

Data minimisation and retention. Hold what you need, for as long as you need it, then delete it. An indefinitely growing list of people who never replied is hard to justify.

A compliant UK cold email

  • Real name, real company, real domain
  • Subject that matches the content
  • A specific, relevant reason for writing to that business
  • Who you are and what you do
  • Where you got their details, in one short line
  • A link to your privacy notice
  • An easy opt-out, and a one-click unsubscribe header
  • Your company details and registered address

The "where we got your details" line is the one people leave out, and it is also the one that most improves how the email reads. "I found you in the trade directory for Manchester" is honest, verifiable and less unsettling than an email that appears from nowhere.

Practical rules that keep you out of trouble

Segment your list by jurisdiction before you send. UK, EU, US and Canada have materially different rules. A single global blast applies the loosest standard everywhere, which is the wrong direction.

Prefer generic business addresses. info@ and enquiries@ reduce your UK GDPR exposure and are often the address the business actually reads.

Check company status where it matters. For a high-volume campaign into a trades sector, the sole-trader question is not academic.

Honour objections globally and permanently. Not per campaign, not per domain.

Keep records. Source, date, lawful basis, consent where relied on, and every opt-out. The ICO's first question is always about provenance.

Where this leaves you

For most UK B2B outreach to limited companies using published business addresses, you are on solid ground: PECR permits it and UK GDPR is satisfied by legitimate interest, transparency and an easy exit.

The two ways people get this wrong are emailing sole traders as though they were companies, and relying on legitimate interest without ever performing the assessment.

For the EU position, which is stricter again in several member states, see our GDPR guide to cold outreach. For the US, where the default is opt-out rather than opt-in, see CAN-SPAM compliance.