UK outreach rules
Is cold email legal in the UK?
Yes to a company, and usually no to a sole trader. UK law splits the people you might email into corporate subscribers and individual subscribers, and that one distinction decides almost everything. Most guidance skips it and tells you business email is exempt. It is not. The exemption belongs to the company, not to the fact that you are selling something.
General information, not legal advice. Checked against the ICO on 22 September 2026. For Australia, see the Spam Act rules.
The distinction that decides it
Corporate subscriber, or individual subscriber
PECR does not divide the world into businesses and consumers. It divides it into corporate subscribers and individual subscribers, and some businesses sit on the individual side.
| Corporate subscriber | Individual subscriber |
|---|---|
| Limited companies | Sole traders |
| Limited liability partnerships | Partnerships that are not LLPs |
| Scottish partnerships | Unincorporated associations |
| Corporation soles and government bodies | Any other unincorporated body of individuals |
An employee's work address belongs to a corporate subscriber, because the subscriber is the employer rather than the person reading the email. So name@limitedcompany.co.uk is a corporate subscriber and name@soletraderbusiness.co.uk is an individual subscriber, and nothing about the two addresses tells you which is which.
That is the whole problem with UK list building. The distinction is legally decisive and invisible from the address, so it has to be established from the company register rather than guessed from the domain.
What each one allows
Two different rules, from the same list
The gap between them is large. One needs no permission at all and the other needs the same permission a consumer would give.
| The question | The answer |
|---|---|
| Consent to email a company? | No. PECR’s electronic mail rule does not apply to corporate subscribers. |
| Consent to email a sole trader? | Yes, or a genuine soft opt-in. They are an individual subscriber. |
| Identify yourself? | Always, to both. You may not disguise or conceal who is sending. |
| Provide a way to opt out? | Always, to both. A valid address for a company, an opt-out in every message to an individual. |
| Honour an opt-out? | Always, to both, and under UK GDPR the right to object is absolute. |
The ICO puts the permissive half plainly: “you can send B2B direct marketing emails or texts to any corporate body. You do not need their consent under PECR to send such messages.” What it does not say, and what a great many pages imply, is that this covers every business.
On opt-outs the guidance goes slightly further than the letter of the rule: you should honour an opt-out request from a corporate subscriber even though PECR does not strictly require it. That is worth doing anyway, because an ignored opt-out is the fastest way to turn a cold email programme into a complaint.
The narrow exception
The soft opt-in is smaller than it sounds
It is often described as a general B2B workaround. It is not. All four conditions have to have been true at the time you collected the details, which means it can never be claimed retrospectively.
- Obtained during a sale. You got the contact details in the course of a sale, or the negotiation of one.
- Similar products only. You are marketing similar products or services, not your whole range.
- A refusal offered at the time. You gave a clear opportunity to refuse when you collected the details.
- An opt-out every time. Every message since has carried a way to opt out.
A list you bought, scraped or built from a company register meets none of these, so the soft opt-in has nothing to say about cold outreach to sole traders. For them it is consent or nothing.
The layer above
UK GDPR applies as well, and separately
PECR governs the sending. UK GDPR governs the personal data you used to send it. Satisfying one says nothing about the other, and a page that covers only PECR has told you half the rule.
UK GDPR engages whenever you can identify a person directly or indirectly. A firstname.lastname address does that, so nearly every B2B list is personal data. You need a lawful basis. Where PECR does not require consent, the ICO says legitimate interests is likely to be the appropriate one, which means actually running the three-part test: identify the interest, show the processing is necessary for it, and balance it against the rights of the person.
Two obligations follow that catch people out. You have to provide privacy information about the marketing use, at collection, or within one month when the data came from somewhere else, which for a purchased list means within a month of buying it. And the right to object to direct marketing is absolute. There is no balancing exercise on an objection and no threshold to meet. They say stop, you stop.
When you cannot tell
The ICO answers this one for you
If you are unsure whether a contact is a corporate or an individual subscriber, the guidance says to treat the details as belonging to an individual subscriber and comply with the stricter rules on electronic mail.
That is an instruction rather than a cautious reading, and it is the practical answer to the whole page. Since the address does not tell you, and since Companies House does, the honest workflow is to check the register rather than reason about the domain.
One more thing worth knowing, because a lot of outbound quietly depends on the opposite. The ICO notes that someone on a professional networking site may be acting in a personal, albeit professional, capacity. Finding a contact on LinkedIn does not make the message business-to-business. What the subscriber is decides that, and nothing else does.
Before you send
A checklist you can work through
Six things. If all six are true, the mechanics are in order, which is most of what compliance is in practice.
- Every contact is classified as a corporate or an individual subscriber, from the register rather than the domain.
- Anyone we could not classify is being treated as an individual subscriber.
- Sole traders and non-LLP partnerships are only being emailed with consent or a genuine soft opt-in.
- We have picked a lawful basis under UK GDPR, and where it is legitimate interests we have written the three-part test down.
- Privacy information has been provided, or will be within a month of getting the data.
- Every message identifies us and carries a working opt-out, and objections are actioned without argument.
Where software helps, and where it does not
What Empiraa Signal does about this
Signal sends from your own inbox and domain, so your normal business identification travels with the message. It adds the unsubscribe link, hosts the opt-out page and stops sending to anyone who uses it, so the opt-out obligation is handled rather than left to a footer somebody has to remember.
What it does not do, and this matters more than the part it does: Signal does not tell you whether a contact is a corporate or an individual subscriber, it does not run your legitimate interests assessment, and it does not screen against the Telephone Preference Service or its corporate register if you also ring people. Those are yours. Any vendor whose software claims to make you compliant is selling you something, because the obligation sits with the sender.
The sending side is at sequences. For Australia, the email rules are at is cold email legal in Australia and the phone rules at cold calling rules in Australia. The UK phone rules are at cold calling rules in the UK. All three markets are compared side by side in cold email laws by country.
Questions people actually ask
UK cold email, answered
Is cold email legal in the UK?
Yes, to a company. PECR’s electronic mail rule does not apply to corporate subscribers, so you may email a limited company, a limited liability partnership or a government body without consent, provided you do not disguise who you are and you give a valid address to opt out. Emailing a sole trader is different: they count as an individual subscriber and need consent or the soft opt-in. UK GDPR applies on top in both cases. The ICO’s B2B guidance.
What is a corporate subscriber?
A corporate body with separate legal status. Limited companies, limited liability partnerships, Scottish partnerships, corporation soles and government bodies. An employee’s work address belongs to a corporate subscriber, because the subscriber is the employer rather than the person.
Can I cold email a sole trader in the UK?
Only with consent or under the soft opt-in. Sole traders, partnerships that are not limited liability partnerships, and unincorporated associations are individual subscribers under PECR and get the same protection as consumers. This is the single most common mistake in UK outbound, because a sole trader’s address usually looks exactly like a company’s.
What if I cannot tell whether a contact is a company or a sole trader?
Treat them as an individual subscriber. That is the ICO’s own instruction, not a cautious reading of it. If you cannot establish which a contact is, the safe route is to apply the stricter rule.
Does UK GDPR apply to B2B email as well as PECR?
Yes, whenever you can identify a person directly or indirectly, which a firstname.lastname address does. You need a lawful basis, and where PECR does not require consent the ICO says legitimate interests is likely to be the appropriate one. That means running the three-part test, providing privacy information, and honouring the absolute right to object to direct marketing.
Is the soft opt-in a way around consent?
Rarely, because it is narrower than it sounds. You must have obtained the details during a sale or the negotiation of a sale, you may only market similar products or services, you must have given a clear chance to refuse at the point you collected them, and you must give an opt-out in every message. You cannot decide after the fact that an old contact qualifies.
I found them on LinkedIn, so it is business-to-business, isn’t it?
Not automatically. The ICO notes that someone on a professional networking site may be acting in a personal, albeit professional, capacity. Where you found a contact does not decide their status under PECR. What the subscriber is decides it.
How do the UK rules compare with Australia?
They run in different directions. Australia requires consent before you send, though for business-to-business it can often be inferred from a conspicuously published work address. The UK requires no consent at all to email a corporate subscriber, and full consent to email a sole trader. Neither resembles the United States, where CAN-SPAM broadly permits the first message and requires you to honour opt-outs afterwards. The Australian rules, in plain English.
Question not answered here? Ask ANI and get a straight answer.
Show your working
Primary source
Checked against this on 22 September 2026. It is the authority; this page is a plain-English reading of it, and it is general information rather than legal advice.
- Information Commissioner's Office, business-to-business marketing for the corporate and individual subscriber distinction, the electronic mail rule, the soft opt-in conditions, the interaction with UK GDPR, and the telephone rules including the Telephone Preference Service and its corporate register.
