The short answer is yes. Calling businesses to introduce a product or service is lawful in the UK without asking their permission first. What makes it lawful is not the fact that the call is business to business. It is following a small set of rules about who you may call, how you identify yourself and what you do when someone says no.
Those rules come mainly from the Privacy and Electronic Communications (EC Directive) Regulations 2003, usually shortened to PECR, and they are enforced by the Information Commissioner's Office. This article summarises what the ICO's own guidance says, with a link to the page for each rule. It is a practical summary, not legal advice, and the ICO currently marks its direct marketing guidance as under review following the Data (Use and Access) Act 2025, so check the current pages before you rely on any detail.
Which laws apply to a B2B sales call
Two sets of rules meet on every cold call, and it helps to keep them apart.
- PECR governs the marketing call itself: whether you may make it, to which numbers, and how you must identify yourself.
- UK GDPR governs the personal data behind the call: the name, role and direct line of the person you are calling, where you got them, and why you are allowed to use them.
A call can satisfy one and fail the other. A number that was correctly screened is still a problem if nobody can say where the name attached to it came from.
The TPS and the CTPS
The Telephone Preference Service and the Corporate Telephone Preference Service are statutory registers of people and organisations who do not want live marketing calls. The ICO describes them as working in the same way, with the CTPS being the version for corporate subscribers. It is free to register any number, including a mobile, and a number has to be on the register for 28 days before the registration takes effect, according to the ICO's guidance on live marketing calls.
The rule for callers is direct: you must not make an unsolicited live marketing call to a number registered with the TPS or the CTPS unless that person has specifically consented to calls from you. The ICO's guide to telephone marketing under PECR is explicit that this applies even to an existing customer, and that you must check numbers against the registers before you make the calls.
Screen close to the calling window
A register changes. A number screened months ago may have been registered since, and a registration takes effect 28 days after it is made. Screening each list before a calling period, rather than once when the data was bought, is the practical way to stay inside the rule.
Sole traders and partnerships: the common mistake
It is easy to assume that every business number sits on the CTPS, and to screen against that register alone. It does not. The ICO's telephone marketing guidance explains that some businesses, namely sole traders and some partnerships, register with the TPS, while companies, some partnerships and government bodies register with the CTPS. If your list includes consultants, tradespeople, small practices or anyone trading in their own name, screen against both registers.
When someone says no
Registration is not the only way someone opts out. Under PECR you must not make a live marketing call to anyone who has told you they do not want your calls, whether or not their number appears on either register. The ICO's guidance tells you to keep your own do-not-call list for exactly this reason.
In practice that list needs three properties. It has to be written to during the call, not reconstructed afterwards. It has to be checked before every campaign, including campaigns run by a different team or an outside provider. And it has to survive changes of tool: an objection recorded in one dialler and forgotten when the data moves to another is still an objection.
Identify yourself and show your number
The ICO's guidance, reflecting regulation 24 and regulation 21 of PECR, sets out three things every live marketing call must do:
- Say who is calling: the name of your organisation, and the organisation you are calling on behalf of if you are an agency.
- Display your number, or a valid alternative contact number, so the person can see it and call back.
- Provide a contact address or a freephone number for your organisation if you are asked for one.
Withheld numbers are therefore not an option for marketing calls, and neither is a number that goes nowhere when someone rings it back.
Calls with stricter rules
Two categories carry tighter restrictions in the ICO's guidance. Calls about claims management services may only be made to someone who has specifically consented to them. Calls about pensions are, in the ICO's words, very strict, and are only permitted in specific circumstances. If your product touches either, read the ICO's guidance on those categories before a single call is made.
UK GDPR still applies to the data behind the call
Calling a company switchboard involves very little personal data. Calling a named person on a direct line involves quite a lot, and UK GDPR requires a lawful basis for holding and using it. The ICO's guidance on legitimate interests addresses direct marketing directly, applies a three-part test of purpose, necessity and balance, and recommends recording a legitimate interests assessment so that you can show your reasoning later.
Whatever basis you rely on, two habits make the rest easier: record where every contact came from, and tell people how to object in plain words when they ask.
Buying a list does not buy compliance
If you buy or rent data, the obligations come with it. The ICO's page on using marketing lists makes the buyer responsible for checking the list properly, rather than relying on the seller's assurance that it is compliant. That means asking who compiled it, where the data came from, what people were told when it was collected, and whether the numbers have been screened against the TPS and CTPS and how recently. A list that cannot answer those questions is a risk you are choosing to take on. If you build the list yourself, the method in our prospect list guide records those answers as you go.
A compliance checklist for a B2B calling programme
- Every number is screened against both the TPS and the CTPS before the calling period starts.
- Your own do-not-call list is checked before every campaign and updated during calls, not after them.
- Anyone who specifically consented to your calls has a record of what they agreed to and when.
- Callers give the organisation's name, display a working number and can provide contact details on request.
- Every contact record shows where the data came from, and your lawful basis for using it is written down.
- Bought or rented data has passed your own due diligence, including evidence of recent TPS and CTPS screening.
- Someone checks the ICO's current guidance at least when your process changes, because it is under review.
Legal, and still worth doing well
Staying inside the rules is the floor, not the method. A lawful call to the wrong person, with no reason to talk, is still a wasted call. In the telemarketing we run, calls go to a researched account list, made by people briefed on the product and the buyer's likely objections, alongside email and LinkedIn working the same accounts. The phone is one channel among three rather than a separate campaign.
Not legal advice
This article summarises the ICO's published guidance as it stood on 28 September 2026. It is not legal advice. If your circumstances are unusual, or you are relying on consent or on one of the stricter categories, take advice specific to your business.
Sources
- The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 21, legislation.gov.uk (2003)
- The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 24, legislation.gov.uk (2003)
- Telephone marketing, Guide to PECR, Information Commissioner's Office
- What are the rules on live direct marketing calls?, Information Commissioner's Office
- Using marketing lists, Information Commissioner's Office
- Legitimate interests, Information Commissioner's Office (2026)
Want this run for you?
Lead Conneqt gives B2B companies an outbound SDR function without building the team in house: ICP and account selection, prospect research and data preparation, cold email, LinkedIn, human telemarketing, reply handling, qualification and booked meetings, managed as one programme and reported on throughout.
Lead Conneqt Editorial
Outbound Growth Team. Lead Conneqt runs managed outbound programmes for B2B companies: telemarketing, email and LinkedIn outreach against one account list. About Lead Conneqt