30 July 2026 · 5 min read
Is PECR cold email legal in the UK?
Is PECR cold email legal in the UK? What PECR and UK GDPR actually allow for B2B outreach, and why sole traders are treated differently to limited companies.
“Is PECR cold email legal in the UK?” is one of the first questions a freelance web designer asks once outreach turns from an idea into an actual list of businesses to email. The short answer is that PECR, the Privacy and Electronic Communications Regulations, treats a marketing email to a limited company very differently to one sent to a sole trader, and getting that distinction wrong is the easiest way to email a list of prospects and unknowingly break the rules on some of them.
What PECR actually governs
PECR sits alongside UK GDPR rather than replacing it. Where UK GDPR governs how personal data is processed generally, PECR's regulation 22 deals specifically with unsolicited marketing sent by electronic mail. It splits recipients into two categories, individual subscribers and corporate subscribers, and the consent rules for cold, unsolicited marketing are different for each.
Corporate subscribers: where cold email is straightforward
A corporate subscriber, in the ICO's language, is a body with its own separate legal status: most commonly a limited company, an LLP, a Scottish partnership or a public body. Regulation 22's consent requirement does not apply to these. You can email a limited company at a generic address such as info@ or enquiries@ without needing prior opt-in consent, and the same applies to a named person at that company's own domain, provided the message is otherwise honest about who is sending it and why.
Sole traders and personal addresses change the answer
The exemption stops at the company's edge. Sole traders and ordinary partnerships in England and Wales are not corporate bodies under PECR, so they are treated as individual subscribers in the same way a private person is. Cold emailing them without consent relies on the soft opt-in exception, which only applies where you already have a relevant existing relationship, such as a previous enquiry or sale, are marketing similar products or services, and gave a clear chance to opt out at the point their details were collected. A first cold email to a plumber or a hairdresser who has never dealt with you before does not usually meet that bar. The address itself matters too: a personal account such as a gmail or hotmail address is an individual subscriber's address regardless of what business sits behind it, even where that business is a limited company, so a director emailing from a personal account rather than the company domain shifts which rules apply to that particular address.
UK GDPR keeps applying either way
None of the above switches off UK GDPR. A named person's work email address is still their personal data, and processing it still needs a lawful basis, most realistically legitimate interests, which means being able to justify that the marketing is proportionate and something the person could reasonably expect. That basis carries obligations with it: being clear about who is contacting them and why, and stopping the moment someone objects or asks to be removed, not just from that one email but from the list going forward.
The practical rules that apply to every message
Whichever category a prospect falls into, a handful of habits keep outreach on the right side of both PECR and UK GDPR. State clearly who you are and which business you are writing from, never a disguised or misleading sender name. Give a working reply address rather than a no-reply one, since a genuine opt-out has to go somewhere and actually be acted on. Treat an opt-out as permanent rather than campaign-specific, and keep it that way even if the same business turns up again in a later search. Build the list from your own research rather than a bought or scraped set of personal addresses, since a list you cannot account for is a list you cannot defend if someone complains.
Knowing who you are emailing before you send
The practical difficulty is rarely the law itself, it is knowing which category a given prospect falls into before the first email goes out. A search for tradespeople in a UK town turns up a mix of limited companies, sole traders and the occasional partnership, and that is not always obvious from the website alone. This is one of the reasons Patchscout attaches Companies House data to every business it audits when you search a trade and a location, so the company status sits next to the website findings rather than needing a separate lookup before the first message goes out. The observation-and-offer structure covered in cold email for web designers: one observation, one offer still applies regardless of who you are emailing, but knowing whether you are looking at a limited company or a sole trader changes whether that first email can lean on the corporate exemption or needs an existing relationship to justify it instead.
Patchscout drafts that first email itself, grounded in the specific audit findings for each business, and sends it from your own mailbox rather than a shared one, so a reply or an opt-out request lands with you directly rather than disappearing into an inbox somebody else manages. Getting the PECR and GDPR position right on paper matters less if opt-outs then get lost, which is also where a clear approach to a follow-up email after no response matters: chasing a non-reply is a different thing entirely from continuing to email someone who has actually asked you to stop. The three free searches on Patchscout are enough to see how the businesses in your own town split between limited companies and sole traders, before you write a single cold email.