The UK runs two rulebooks side by side for electronic marketing: the Privacy and Electronic Communications Regulations (PECR), which govern the mechanics of sending marketing messages, and UK GDPR, which governs the underlying personal data. Cold email into the UK has to satisfy both — and PECR has a genuinely useful carve-out for B2B that doesn't exist in most of the rest of the EU.
PECR sits alongside UK GDPR rather than replacing it. PECR answers "can I send this message at all," and UK GDPR answers "am I allowed to process this person's data." A message can clear PECR's rule and still need a lawful basis under UK GDPR for the personal data involved — the two questions are separate and both need an answer.
PECR's consent requirement for email marketing does not apply to corporate subscribers — companies, limited liability partnerships, Scottish partnerships, and similar corporate bodies. You can email a named contact at a company address without their prior consent under PECR, as long as you don't conceal or disguise your identity and you provide a valid address for the recipient to opt out.
This is the single biggest practical difference from the general EU legitimate-interest approach: in the UK, B2B email to a corporate address clears PECR without needing a balancing test at all. UK GDPR's lawful-basis requirement for the personal data still applies separately (see below).
The corporate subscriber exemption doesn't extend to sole traders or certain partnership structures — PECR treats them as individual subscribers with the same protection as a consumer. To email a sole trader or partner, you need either their consent or to qualify under the soft opt-in exception.
Soft opt-in lets you email an existing contact about similar products or services without fresh consent, provided all of these are true:
Soft opt-in is a relationship-continuation mechanism, not a cold-outreach tool — it requires a prior transaction or negotiation, so it doesn't help with a first-touch cold email to someone you've never dealt with.
Clearing PECR's corporate-subscriber exemption doesn't mean UK GDPR has nothing to say. If the message is directed at an identifiable individual — a named contact rather than a generic role address — you still need a lawful basis to process their personal data, and legitimate interest is the basis most UK B2B senders rely on, functioning the same way it does under EU GDPR (see our GDPR guide for how that balancing test works). The recipient also retains the right to object to direct marketing at any time.
In short: corporate subscriber + named individual contact = PECR clear, UK GDPR lawful basis still required. Role address (info@, sales@) with no named individual is the cleanest position under both.
PECR enforcement is changing sharply. Under the Data (Use and Access) Act 2025, being phased in between June 2025 and June 2026, the ICO's maximum PECR fine rises from a £500,000 cap to £17.5 million or 4% of global turnover, whichever is higher — the same ceiling that already applies to UK GDPR breaches. That's a roughly 35-fold increase in the statutory maximum, and it puts PECR violations like non-compliant email marketing on the same financial footing as major data protection breaches for the first time.
For most B2B cold email into the UK: target named individuals at corporate addresses, identify yourself clearly, provide a working opt-out, document a legitimate-interest rationale for the UK GDPR side, and treat sole traders and partnerships as requiring consent or a genuine soft opt-in relationship rather than cold outreach.
Not under PECR, if the recipient is a corporate subscriber — a company, LLP, or similar body. PECR's consent rule specifically doesn't apply to those. You still need a lawful basis (usually legitimate interest) under UK GDPR for the personal data of a named individual contact.
A PECR exception that lets you re-contact an existing customer about similar products without fresh consent, if you got their details during a sale or negotiation, offered an opt-out at the time, and offer one in every subsequent message. It requires a prior transaction, so it doesn't apply to first-touch cold outreach.
No. Sole traders and certain partnerships are treated as individual subscribers, the same as consumers, and need consent or a qualifying soft opt-in rather than falling under the corporate subscriber exemption.
Under the Data (Use and Access) Act 2025, phased in through June 2026, the maximum PECR fine rises from £500,000 to £17.5 million or 4% of global turnover, whichever is higher — aligning it with UK GDPR's penalty ceiling.
Related guides
Written by
Scott Holmes
AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has built PECR-aware outbound systems for UK-facing B2B campaigns.
Answer four quick questions and get a tool recommendation for your setup.