Under PECR you can email UK companies without consent, but sole traders and some partnerships are treated like individuals and usually need consent or a soft opt-in.
Key points
- PECR regulation 22 requires consent for marketing email to individual subscribers, with a narrow soft opt-in exception for existing customers [1][2].
- Corporate subscribers, such as limited companies and LLPs, can receive B2B marketing email without prior Consent [3].
- Sole traders and some partnerships count as individual subscribers, so Cold Email to them follows the stricter consumer rules [3].
- Every marketing email must identify the sender and give a valid address for recipients to Opt-Out; the ICO recommends honoring B2B opt-outs even where PECR does not strictly require it [3].
- PECR does not replace the UK version of the GDPR: an email naming a person at a company is still Personal Data, so you also need a lawful basis such as Legitimate Interest [3].
- The Data (Use and Access) Act 2025 raises the maximum PECR fine from 500,000 pounds to the UK GDPR level of 17.5 million pounds or 4% of global turnover as its provisions take effect [4].
What PECR covers
PECR implements the EU ePrivacy Directive in UK law and was kept after Brexit [2]. It covers marketing by phone, email, text and fax, the use of cookies and similar tracking, and the security of public communications services. For email, the core provision is regulation 22: you must not send unsolicited marketing email to an individual subscriber unless they have consented, or unless the soft opt-in applies [1]. The soft opt-in covers people whose details you collected during a sale or negotiation of a sale, marketing your own similar products, with a chance to refuse at collection and in every message. Regulation 23 adds that you must never disguise your identity and must give a valid address for opt-out requests [2]. These rules sit on top of Email Deliverability basics, not in place of them.
The B2B distinction
The practical question for Outbound Sales is who the subscriber is. The ICO explains that the consent rule in regulation 22 applies to individual subscribers, which includes sole traders and some partnerships, while corporate subscribers such as limited companies, LLPs, Scottish partnerships and government bodies are not covered by it [3]. So a message to a named employee at a limited company does not need prior consent under PECR. It still has to identify you and carry a working opt-out. Because the email is addressed to a real person, the UK GDPR also applies, which means a documented lawful basis, a privacy notice and prompt handling of objections [3]. Checking the company type during Lead Qualification helps avoid emailing sole traders as if they were corporations.
Enforcement and recent changes
The ICO enforces PECR and regularly fines companies for unsolicited marketing, often after complaints. The Data (Use and Access) Act 2025, which received Royal Assent on June 19, 2025, aligns PECR penalties with the UK GDPR, raising the ceiling from 500,000 pounds to 17.5 million pounds or 4% of worldwide turnover, and makes other changes that come into force in stages [4]. ICO guidance on B2B marketing notes it is under review because of the Act [3]. To stay on safe ground, keep a Suppression List that covers every opt-out, treat even a Role-Based Email Address address at a very small business with care, since the business may be a sole trader, and review the current ICO pages before a large campaign. This summary is general information, not legal advice.
Related terms
Outreach without the busywork.
PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.
Start free with 100 credits →