The UK is the largest European market where B2B cold email is plainly legal. Under regulation 22 of the Privacy and Electronic Communications Regulations (PECR), the consent rule protects "individual subscribers". Companies, LLPs, Scottish partnerships and government bodies are "corporate subscribers" and can be emailed without prior consent, provided you identify yourself and offer an opt-out. Two traps sit inside that rule: sole traders and some partnerships are individuals, and named employees are still protected by the UK GDPR.
What changed is the penalty ceiling. The Data (Use and Access) Act 2025 (DUAA) moved PECR enforcement onto the Data Protection Act 2018 penalty regime. Breaches of regulation 22 now attract the "higher maximum amount", which is £17.5m or 4% of worldwide turnover.
The rule, as the ICO states it
The ICO's guidance (last updated 19 November 2024 and flagged as "under review" for the DUAA) says (ICO):
| Recipient | Rule |
|---|---|
| Corporate body: company, LLP, Scottish partnership, government body | Can be emailed without consent; keeping a "do not email" list is best practice |
| Sole trader | Treated as an individual: needs specific consent or the soft opt-in (bought a similar product, did not opt out) |
| "Some partnerships" (English/Welsh/NI general partnerships) | Treated as individuals |
Employee at a corporate body with a personal work address (jane.doe@acme.co.uk) | PECR allows it; UK GDPR still applies to the personal data |
| All recipients | Do not conceal identity; give a valid address to opt out |
Much of the UK small-business market is sole traders: tradespeople, freelancers, consultants. A list of "UK SMBs" from a data vendor mixes limited companies and sole traders. Emailing the sole traders without consent breaches PECR. Few sequencers or data vendors flag legal form at the contact level.
UK GDPR still applies
A named business email is personal data. The UK GDPR keeps legitimate interests (Art. 6(1)(f)) as the realistic basis for B2B prospecting, the Art. 14 notice duty for data not collected from the person, and the unconditional right to object to direct marketing. The DUAA adds a list of "recognised legitimate interests" and states in statute that direct marketing may be a legitimate interest. That second point largely confirms what recital 47 already said.
We confirmed the DUAA's PECR penalty and charity provisions from the statute (below). We did not fetch the exact statutory wording of the "direct marketing may be a legitimate interest" provision in this pass. Treat that sentence as unverified.
What the Data (Use and Access) Act 2025 changed
| Change | Effect for cold email | Source |
|---|---|---|
| PECR enforcement moved onto DPA 2018 penalty regime (Sch. 13) | Breaches of regs 5–8, 14, 19–24 (incl. reg 22 email marketing) attract the "higher maximum amount": £17.5m or 4% of worldwide turnover | DUAA 2025 Sch. 13 |
| "Call" and "communication" include those transmitted whether or not they reach the recipient | Bounced or filtered sends count. Enforcement can be based on volume sent | DSIT PECR factsheet |
| Soft opt-in extended to charities (s.114) | Not relevant to B2B sellers | DUAA s.114 |
| New cookie exemptions (analytics, service improvement) | Tracking pixels in emails remain a separate question | DSIT factsheet |
Timing: the ICO says DUAA changes were "phased in between June 2025 and June 2026" and that all its data protection provisions were in force as of 19 June 2026 (ICO).
The previous PECR maximum was £500,000. That figure is from prior knowledge and was not re-fetched. The exact commencement date of Schedule 13 is also unverified. The ICO says only that all provisions were in force by 19 June 2026.
A 35x jump: from a £500,000 cap to £17.5m, or 4% of global turnover where that is higher. For a $100M-ARR sending platform, 4% is $4M. For a sender, it means PECR penalties are now sized like GDPR penalties.
ICO enforcement
The ICO's PECR enforcement has historically targeted nuisance calls and B2C text and email campaigns, not B2B email to corporate subscribers. Its "sent, not received" counting and the new ceiling make high-volume campaigns the obvious target if it turns to email.
We could not load the ICO enforcement database (it renders client-side), so we could not list 2025–2026 PECR penalties or confirm whether any concerned B2B email or sole traders. Check https://ico.org.uk/action-weve-taken/enforcement/ before relying on "the ICO doesn't fine B2B".
UK vs EU in one table
| Question | UK | Germany | France |
|---|---|---|---|
| Cold email to a company | Allowed (opt-out) | Consent required | Allowed if relevant to role |
| Cold email to sole trader | Consent / soft opt-in | Consent | Allowed if relevant (pro address) |
| Max regulatory fine | £17.5m / 4% (PECR) | GDPR 4%; UWG via civil suits | GDPR 4% + CPCE |
| Main enforcer | ICO | Recipients and competitors in court | CNIL |
See Germany, France and EU/EEA country matrix.
What this means for an entrant
- The UK is the natural first market for a Europe-based outbound product. It is the largest European market where B2B cold email is clearly lawful, it is English-speaking, and it has a dense agency scene. See Lead-gen agencies and Non-English markets.
- Legal-form detection is a real feature. Flag sole traders and general partnerships in UK lists using Companies House data (limited company present or not) and route them to consent-only flows. Data vendors and sequencers do not do this today. That claim is not verified across every vendor, so check Built-in lead database and Contact data and enrichment.
- Volume is now a legal risk, not just a deliverability risk. With communications counted as sent, a platform that encourages blasting unverified lists exposes its customers. Bounce protection and verification also limit regulatory exposure. See Built-in email verification and Bounce protection.
- Keep an auditable opt-out trail. Show that the opt-out was offered in every message and honoured across campaigns. That is the cheapest defence if the ICO asks.
- Expect ICO guidance updates. The email-marketing guidance was marked "under review" after the DUAA. Watch for B2B-specific changes before building UK-specific logic into rules that are hard to change.