Yes, for most business recipients. Sending an unsolicited sales email to a limited company, an LLP or another corporate body is lawful in the UK without asking permission first. It stops being lawful when the recipient is the wrong kind of subscriber, when the email hides who sent it, or when the personal data behind it is handled carelessly.
Two sets of rules apply. The Privacy and Electronic Communications Regulations 2003, known as PECR, decide whether you may send the email at all. UK GDPR decides how you may use the name and address you are sending it to. This article summarises both from the legislation and the regulator's own guidance, with a link for each rule. It is a practical summary, not legal advice, and the ICO marks its business-to-business guidance as under review following the Data (Use and Access) Act 2025, so check the current pages before you rely on any detail.
Who you are emailing decides the rule
PECR does not divide recipients into businesses and consumers. It divides them into corporate subscribers and individual subscribers, and its rule on unsolicited marketing email applies only to the second group.
The ICO's guidance on business-to-business marketing describes a corporate subscriber as a corporate body with separate legal status. That includes:
- companies
- limited liability partnerships
- Scottish partnerships
- some government bodies
- any other body that is a legal person distinct from its members
Individual subscribers are sole traders, certain other partnerships, such as ordinary English, Welsh and Northern Irish partnerships, and other unincorporated groups of individuals. PECR treats them the way it treats a member of the public.
One detail in the ICO's guidance settles most B2B questions. The email address of an employee at a corporate body counts as a corporate subscriber address, because the subscriber is the employer. A named address at a limited company is therefore covered by the corporate rules, not the individual ones.
Emailing companies: no consent needed under PECR
Because regulation 22 applies to individual subscribers, its requirement for prior consent does not apply when you email a corporate subscriber. The ICO's guide to electronic mail marketing confirms that you can send marketing emails to corporate bodies without consent, and recommends that you keep a list of businesses that ask you to stop.
No consent requirement is not the same as no rules. Two obligations apply to every marketing email whoever receives it, and UK GDPR applies whenever a real person is named. Both are covered below.
Sole traders and partnerships: where cold email stops
For individual subscribers, PECR allows marketing emails in only two situations: the person has specifically consented to receive them from you, or the soft opt-in applies.
The soft opt-in, in regulation 22(3), has three conditions, and all three must be met:
- You obtained the person's contact details in the course of a sale, or negotiations for a sale, of your product or service.
- You are marketing your own similar products or services.
- You gave a simple, free way to refuse marketing when you collected the details, and you give one again in every message.
A cold prospect cannot meet the first condition, because there has been no sale and no negotiation. In practice, a sole trader or an ordinary partnership should not receive a cold marketing email from you at all. They can still be telephoned, subject to the rules on B2B cold calling, which treat them differently again.
The hard part is spotting them. Consultants, tradespeople, small practices and anyone trading under their own name may be individual subscribers even when they look like established businesses. A useful working rule: if you cannot find a company or LLP registration for the business, treat it as a sole trader or partnership until you know otherwise, and keep it out of the email sequence. Check before the sequence starts, not after the complaint.
What every marketing email must include
Regulation 23 applies to all direct marketing by email, corporate recipients included. You must not send a marketing email that:
- disguises or conceals who it is from
- gives no valid address to which the recipient can send a request to stop
- breaches the rules on commercial communications in the Electronic Commerce Regulations 2002
- encourages the recipient to visit a website that breaches those rules
Under regulation 7 of those Electronic Commerce Regulations, a commercial communication must be clearly identifiable as one, and must clearly identify the person on whose behalf it is made. An email dressed up as a personal note fails the first test, and one sent for a client without naming the client fails the second.
In practice: send from a real person at a domain the recipient can connect to your company, name the company in the signature, and include a way to opt out that you actually honour. A plain line such as "Reply and let me know if you would rather not hear from me" works only if every reply is read and acted on.
UK GDPR: the part most B2B senders miss
The corporate rules in PECR say nothing about personal data. As soon as you email a named person, you are processing their personal data and UK GDPR applies. The ICO's business-to-business guidance is direct about it: if you collect someone's contact details in their business capacity and intend to send them marketing, you must tell them, and you must have a lawful basis for the processing.
The exception is narrow. If you email a generic address such as info@ without knowing who reads it, the ICO says you are not processing personal data, so UK GDPR does not apply to that message. The moment you add a name, it does.
Your lawful basis
For cold B2B email the realistic basis is legitimate interests, under Article 6(1)(f) of UK GDPR. Since 5 February 2026, Article 6(11) lists processing that is necessary for the purposes of direct marketing as an example of processing that may be necessary for a legitimate interest. That helps, but it is an example rather than an exemption. You still have to show that the processing is necessary and that your interest is not overridden by the person's own interests and rights.
The ICO's legitimate interests guidance sets out a three-part test of purpose, necessity and balance, and recommends writing down a legitimate interests assessment. For B2B outreach the balance usually turns on relevance. A message about someone's actual job, sent to their work address, is far easier to justify than a broad campaign to everyone whose address you could find.
Tell them where you got their details, in the first email
When you did not collect someone's details from them directly, Article 14 of UK GDPR requires you to give them privacy information, including where the data came from. If you use the details to contact the person, that information is due at the latest at the time of the first communication.
That does not mean pasting a privacy notice into a sales email. The common practical approach is one short line that says where you found their details, with a link to a privacy notice that covers the rest.
Make the right to object obvious
Under Article 21 of UK GDPR, a person can object at any time to their data being used for direct marketing, and once they do, that use must stop. There is no balancing test. Article 21 also requires the right to be brought to the person's attention explicitly, clearly and separately from other information, at the latest at the first communication.
That is why the opt-out line belongs in the first email, not just the last. It also means an objection has to reach every tool and every person working the account. An address removed from one sequence and still live in another is still being marketed to.
Bought and scraped lists
Buying data does not transfer responsibility for it. The ICO's guidance says that if you buy a list of business contacts for direct marketing, your use of any personal data on it must comply with UK GDPR. Before you load a list, ask how it was compiled, what the people on it were told, how recently it was checked, and whether sole traders and partnerships can be separated out. If the answers are vague, build the list yourself: the method in our guide to building a B2B prospect list records the source of every contact as you go.
What changed in 2026
Most of the Data (Use and Access) Act 2025 provisions that matter to marketers took effect on 5 February 2026. The ICO's statement on commencement confirms the change with the most practical weight: the ICO can now issue fines of up to £17.5 million or 4% of global turnover under PECR.
- Charities gained their own version of the soft opt-in, inserted into regulation 22. It does not change anything for commercial B2B senders.
- UK GDPR now names direct marketing as an example of a possible legitimate interest, as described above.
- The ICO has said it is developing separate guidance on the higher PECR fines, and its direct marketing guidance is under review.
Articles written before 2026 can therefore understate the risk of getting this wrong. The rules on who you may email did not loosen for businesses; the cost of breaking them rose.
Legal is not the same as delivered
Following the law does not get an email into an inbox. Mailbox providers apply their own requirements on authentication, complaint rates and unsubscribing, and those decide whether your message is seen at all. Our cold email deliverability rules cover that side. The two disciplines support each other: messages sent to well-chosen people, with an obvious way out, are easier to defend and less likely to be reported as spam.
A compliance checklist for B2B cold email
- Every recipient is a corporate subscriber, has consented, or meets all three soft opt-in conditions.
- Sole traders and ordinary partnerships are identified and removed before the sequence starts.
- Every email names the sender and the company, and gives a working way to opt out.
- The first email to a named person says where their details came from and links to your privacy notice.
- The right to object is stated clearly in the first email, and objections are honoured across every tool and channel.
- Your legitimate interests assessment is written down, and the targeting reflects it.
- Bought data has passed your own checks, with its source recorded against each contact.
- Someone rereads the ICO's guidance whenever your process changes, because it is under review.
Compliant is the floor, not the method
A lawful email to the wrong person is still a wasted email. In the cold email programmes we run, sequences are written by people against the buyer's real problems, recipient data is verified immediately before sending, and mail goes out from dedicated sending domains with SPF, DKIM and DMARC authentication and daily deliverability monitoring. The aim is a short list of people who have a reason to reply, not a large list of people who are merely lawful to contact.
Not legal advice
This article summarises the legislation and the ICO's published guidance as they stood on 7 October 2026. It is not legal advice. If you rely on consent or the soft opt-in, or your list includes sole traders or partnerships, take advice specific to your business.
Sources
- The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22, legislation.gov.uk (2003)
- The Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 23, legislation.gov.uk (2003)
- The Electronic Commerce (EC Directive) Regulations 2002, regulation 7, legislation.gov.uk (2002)
- UK GDPR, Article 6: lawfulness of processing, legislation.gov.uk (2016)
- UK GDPR, Article 14: information where personal data have not been obtained from the data subject, legislation.gov.uk (2016)
- UK GDPR, Article 21: right to object, legislation.gov.uk (2016)
- Business-to-business marketing, Information Commissioner's Office
- Electronic mail marketing, Guide to PECR, Information Commissioner's Office
- Legitimate interests, Information Commissioner's Office
- Statement on the commencement of the Data (Use and Access) Act, Information Commissioner's Office (2026)
- One year on: marking the 12-month commencement of the Data (Use and Access) Act, Information Commissioner's Office (2026)
Want this run for you?
Lead Conneqt gives B2B companies an outbound SDR function without building the team in house: ICP and account selection, prospect research and data preparation, cold email, LinkedIn, human telemarketing, reply handling, qualification and booked meetings, managed as one programme and reported on throughout.
Lead Conneqt Editorial
Outbound Growth Team. Lead Conneqt runs managed outbound programmes for B2B companies: telemarketing, email and LinkedIn outreach against one account list. About Lead Conneqt