Outbound Atlas

Atlas/The law/Europe

UK: PECR and DUAA 2025

The UK lets you cold email companies without consent, but sole traders and some partnerships count as individuals, and since 2025–26 PECR fines run to £17.5m or 4% of turnover.

Lawmedium confidence7 minupdated 2026-10-055 sources
Jurisdiction
United Kingdom
Regime
Mixed
Cold B2B email
Allowed without consent to corporate subscribers (opt-out); sole traders and some partnerships need consent or soft opt-in
Penalty
PECR fines up to £17.5m or 4% of worldwide turnover after the Data (Use and Access) Act 2025; UK GDPR fines on top
Enforced by
Information Commissioner's Office (ICO)

The UK is the largest European market where B2B cold email is plainly legal. Under regulation 22 of the Privacy and Electronic Communications Regulations (PECR), the consent rule protects "individual subscribers". Companies, LLPs, Scottish partnerships and government bodies are "corporate subscribers" and can be emailed without prior consent, provided you identify yourself and offer an opt-out. Two traps sit inside that rule: sole traders and some partnerships are individuals, and named employees are still protected by the UK GDPR.

What changed is the penalty ceiling. The Data (Use and Access) Act 2025 (DUAA) moved PECR enforcement onto the Data Protection Act 2018 penalty regime. Breaches of regulation 22 now attract the "higher maximum amount", which is £17.5m or 4% of worldwide turnover.

The rule, as the ICO states it

The ICO's guidance (last updated 19 November 2024 and flagged as "under review" for the DUAA) says (ICO):

RecipientRule
Corporate body: company, LLP, Scottish partnership, government bodyCan be emailed without consent; keeping a "do not email" list is best practice
Sole traderTreated as an individual: needs specific consent or the soft opt-in (bought a similar product, did not opt out)
"Some partnerships" (English/Welsh/NI general partnerships)Treated as individuals
Employee at a corporate body with a personal work address (jane.doe@acme.co.uk)PECR allows it; UK GDPR still applies to the personal data
All recipientsDo not conceal identity; give a valid address to opt out
Sole-trader trap

Much of the UK small-business market is sole traders: tradespeople, freelancers, consultants. A list of "UK SMBs" from a data vendor mixes limited companies and sole traders. Emailing the sole traders without consent breaches PECR. Few sequencers or data vendors flag legal form at the contact level.

UK GDPR still applies

A named business email is personal data. The UK GDPR keeps legitimate interests (Art. 6(1)(f)) as the realistic basis for B2B prospecting, the Art. 14 notice duty for data not collected from the person, and the unconditional right to object to direct marketing. The DUAA adds a list of "recognised legitimate interests" and states in statute that direct marketing may be a legitimate interest. That second point largely confirms what recital 47 already said.

Not verified

We confirmed the DUAA's PECR penalty and charity provisions from the statute (below). We did not fetch the exact statutory wording of the "direct marketing may be a legitimate interest" provision in this pass. Treat that sentence as unverified.

What the Data (Use and Access) Act 2025 changed

ChangeEffect for cold emailSource
PECR enforcement moved onto DPA 2018 penalty regime (Sch. 13)Breaches of regs 5–8, 14, 19–24 (incl. reg 22 email marketing) attract the "higher maximum amount": £17.5m or 4% of worldwide turnoverDUAA 2025 Sch. 13
"Call" and "communication" include those transmitted whether or not they reach the recipientBounced or filtered sends count. Enforcement can be based on volume sentDSIT PECR factsheet
Soft opt-in extended to charities (s.114)Not relevant to B2B sellersDUAA s.114
New cookie exemptions (analytics, service improvement)Tracking pixels in emails remain a separate questionDSIT factsheet

Timing: the ICO says DUAA changes were "phased in between June 2025 and June 2026" and that all its data protection provisions were in force as of 19 June 2026 (ICO).

Not verified

The previous PECR maximum was £500,000. That figure is from prior knowledge and was not re-fetched. The exact commencement date of Schedule 13 is also unverified. The ICO says only that all provisions were in force by 19 June 2026.

The numbers

A 35x jump: from a £500,000 cap to £17.5m, or 4% of global turnover where that is higher. For a $100M-ARR sending platform, 4% is $4M. For a sender, it means PECR penalties are now sized like GDPR penalties.

ICO enforcement

The ICO's PECR enforcement has historically targeted nuisance calls and B2C text and email campaigns, not B2B email to corporate subscribers. Its "sent, not received" counting and the new ceiling make high-volume campaigns the obvious target if it turns to email.

Gap in the record

We could not load the ICO enforcement database (it renders client-side), so we could not list 2025–2026 PECR penalties or confirm whether any concerned B2B email or sole traders. Check https://ico.org.uk/action-weve-taken/enforcement/ before relying on "the ICO doesn't fine B2B".

UK vs EU in one table

QuestionUKGermanyFrance
Cold email to a companyAllowed (opt-out)Consent requiredAllowed if relevant to role
Cold email to sole traderConsent / soft opt-inConsentAllowed if relevant (pro address)
Max regulatory fine£17.5m / 4% (PECR)GDPR 4%; UWG via civil suitsGDPR 4% + CPCE
Main enforcerICORecipients and competitors in courtCNIL

See Germany, France and EU/EEA country matrix.

What this means for an entrant

  • The UK is the natural first market for a Europe-based outbound product. It is the largest European market where B2B cold email is clearly lawful, it is English-speaking, and it has a dense agency scene. See Lead-gen agencies and Non-English markets.
  • Legal-form detection is a real feature. Flag sole traders and general partnerships in UK lists using Companies House data (limited company present or not) and route them to consent-only flows. Data vendors and sequencers do not do this today. That claim is not verified across every vendor, so check Built-in lead database and Contact data and enrichment.
  • Volume is now a legal risk, not just a deliverability risk. With communications counted as sent, a platform that encourages blasting unverified lists exposes its customers. Bounce protection and verification also limit regulatory exposure. See Built-in email verification and Bounce protection.
  • Keep an auditable opt-out trail. Show that the opt-out was offered in every message and honoured across campaigns. That is the cheapest defence if the ICO asks.
  • Expect ICO guidance updates. The email-marketing guidance was marked "under review" after the DUAA. Watch for B2B-specific changes before building UK-specific logic into rules that are hard to change.
5 sources cited on this page · 3 domains
  1. ICO ico.org.uk
  2. DUAA 2025 Sch. 13 legislation.gov.uk
  3. DSIT PECR factsheet gov.uk
  4. DUAA s.114 legislation.gov.uk
  5. ICO ico.org.uk