Yes. In the UK you can send marketing emails to people at limited companies, LLPs and public bodies without their prior consent, as long as you say who you are, give a valid address for opting out and honour every opt-out. Sole traders and some partnerships are different: they need consent. UK GDPR applies too, usually through legitimate interests.

What is the short answer?

Two sets of rules apply to a B2B cold email. The Privacy and Electronic Communications Regulations 2003 (PECR) decide whether you may send the email at all. UK GDPR decides whether you may use the person’s name and address to send it.

Under PECR, the consent rule for marketing email is in regulation 22, and it applies to “individual subscribers”. Corporate subscribers are outside it. The ICO’s guide puts it plainly: you can email or text any corporate body. Whoever you write to, regulation 23 says you must not disguise who you are and must give a valid address for opting out.

Source: ICO, Guide to PECR, electronic mail marketing; legislation.gov.uk, PECR regulations 22 and 23 (latest version, 5 February 2026). Checked 1 October 2026.

The ICO notes that its PECR guidance is under review because of the Data (Use and Access) Act 2025, so check the page itself before relying on any detail.

Who counts as a corporate subscriber?

The ICO lists them: a company, a Scottish partnership, a limited liability partnership or a government body. So a limited company that makes switchgear, an LLP of consulting engineers and an NHS trust’s estates team are all corporate subscribers.

Sole traders and some partnerships are treated as individuals. The ICO says you can only email or text them if they have specifically consented, or if they bought a similar product from you in the past. That second route, the soft opt-in, covers your own customers only. It does not apply to prospective customers or to contacts from bought-in lists.

In practice, this means checking every firm on a cold list before you write. Companies House shows whether a firm is a limited company or an LLP. Anything you can’t confirm, leave out.

What does UK GDPR add?

A named person’s work email, such as firstname.lastname@firm.co.uk, is personal data. To use it you need a lawful basis, and for B2B outreach that is normally legitimate interests.

Since the Data (Use and Access) Act 2025, UK GDPR Article 6(11) lists processing necessary for direct marketing as an example of a legitimate interest. That is an example, not a free pass. The ICO’s guidance still asks you to pass a three-part test:

  1. Purpose. Do you have a legitimate interest in using the information?
  2. Necessity. Is using it necessary for that purpose?
  3. Balance. Do the person’s interests, rights or freedoms override yours?

The ICO says UK GDPR doesn’t require a legitimate interests assessment, but that you should do one anyway and record it with the outcome. It also says that where PECR requires consent, you must not use legitimate interests instead. So legitimate interests covers the email to a director at a limited company, and never the email to a sole trader.

Source: legislation.gov.uk, UK GDPR Article 6 (latest version, 5 February 2026); ICO, legitimate interests guidance, three pages. Checked 1 October 2026.

A reasonable balance usually looks like this: you write to someone about work their role covers, at a firm that plausibly buys what you sell, not too often, and you stop the moment they ask.

What must every email carry?

  • Who you are. The sending firm’s real name, never a disguised sender or a made-up company.
  • A valid address to opt out. A working unsubscribe link or reply address. We also put the firm’s postal address in the footer, which the B2B buyer reasonably expects to see.
  • A way to make the opt-out stick. The ICO calls it good practice, and good business sense, to keep a “do not email” list of businesses that object. An opt-out that only removes someone from one campaign isn’t really honoured.

What are the fines now?

They went up. Since 5 February 2026 the Information Commissioner can fine up to £17.5 million or 4 percent of global turnover under PECR, whichever is higher. That is the ICO’s own statement on the commencement of the Data (Use and Access) Act.

On legislation.gov.uk the mechanism is this: the amended Schedule 1 to PECR applies section 157 of the Data Protection Act 2018, and for breaches of regulations including 22 and 23 the maximum is “the higher maximum amount”. Section 157 defines that, for an undertaking, as £17,500,000 or 4 percent of total annual worldwide turnover in the preceding financial year, whichever is higher. The amended Schedule 1 is in force from 5 February 2026 under S.I. 2026/82.

Source: ICO, Statement on the commencement of the Data (Use and Access) Act, 5 February 2026; legislation.gov.uk, PECR Schedule 1 paragraph 18 and Data Protection Act 2018 section 157. Checked 1 October 2026.

These are maximums, not typical fines. The point for a small B2B sender is that a careless list, one with sole traders on it and no working opt-out, now faces the same maximum as the most serious UK GDPR breaches.

What about phone calls and LinkedIn?

Phone. Marketing calls have their own registers. The Telephone Preference Service (TPS) holds numbers that have opted out, and so does the Corporate Telephone Preference Service (CTPS). The ICO says that when calling businesses you need to screen against both, plus your own “do not call” list, because sole traders and some partnerships register with the TPS while companies, some partnerships and government bodies register with the CTPS.

LinkedIn. This is a contract question, not PECR. LinkedIn’s User Agreement, effective 3 November 2025, forbids using bots or other unauthorised automated methods to add or download contacts or to send or redirect messages. Automation tools that send connection requests and messages for you break those terms and put the profile at risk.

Source: ICO, Guide to PECR, telephone marketing; LinkedIn User Agreement, effective 3 November 2025. Checked 1 October 2026.

What rules does KS Media send by?

The law sets the floor. Our own rules, for our outreach and for clients’ outreach in the Pipeline Engine:

  1. Limited companies only. Sole traders and partnerships are filtered out before anyone is written to, even where a partnership might count as corporate.
  2. A separate sending domain. Outreach goes from its own domain, authenticated, never from the main business domain.
  3. Name, postal address and opt-out on every email. No exceptions for follow-ups.
  4. A suppression list kept indefinitely. An opt-out is honoured for good, because keeping the address on a suppression list is the only way to be sure it is never written to again.
  5. Outbound contact records kept for 24 months from last contact, then deleted.
  6. Legitimate interests as the lawful basis. KS Media keeps a written legitimate interests assessment for its own outreach and reviews it before each new campaign. Our privacy notice explains where business contact details come from and how to object.
  7. LinkedIn by hand. Connection requests and messages are sent from a real person’s profile, without automation tools.

No, but it decides whether a lawful email arrives. These are our sending rules, not legal requirements:

  • SPF, DKIM and DMARC set on every sending domain, and two to three weeks of warm-up before the first send.
  • Every address verified before it is used, with bounces kept under 2 percent. Above that, sending stops until the list is cleaned.
  • No more than about 30 emails per inbox per day.

A list that bounces badly is usually a list nobody checked, and a list nobody checked is the one most likely to contain sole traders.

Where to start

If you are planning outreach, start with the list: confirm every firm is a limited company or LLP, and write down your legitimate interests assessment before the first send. If you would rather have it run for you, the outbound workstream of the Pipeline Engine sends from a domain in your firm’s name under the rules above, and our outbound page explains how it works.

Quick answers

Yes, to corporate bodies. The ICO’s guidance says you can email any corporate body, meaning a company, a Scottish partnership, a limited liability partnership or a government body, without prior consent, as long as you do not hide your identity and you give a valid address for opting out. Because named employees’ details are personal data, UK GDPR also applies, usually on the legitimate interests basis. This is not legal advice.

Not without consent. Under PECR, sole traders and some partnerships are treated as individuals, so the ICO says you can only email them if they have specifically consented, or if they bought a similar product from you before. The soft opt-in for existing customers does not cover new prospects.

Not for emails to people at corporate bodies, where PECR does not require consent. UK GDPR still needs a lawful basis for using a named person’s details, and legitimate interests is the usual one: UK GDPR now lists direct marketing as an example. You still have to pass the ICO’s three-part test, and the ICO says you should record a legitimate interests assessment.

Under regulation 23 of PECR, you must not disguise or conceal who is sending it, and you must give a valid address the recipient can use to opt out. In practice that means the firm’s real name, a postal address and a working unsubscribe link, with every opt-out honoured and kept on a suppression list.

They are the Telephone Preference Service and the Corporate Telephone Preference Service, the registers of numbers that have opted out of marketing calls. The ICO says calls to businesses must be screened against both, because sole traders and some partnerships register with the TPS while companies, some partnerships and government bodies register with the CTPS.

Sources

  1. Information Commissioner’s Office, Guide to PECR: electronic mail marketing, checked 1 Oct 2026.
  2. Information Commissioner’s Office, Guide to PECR: telephone marketing, checked 1 Oct 2026.
  3. Information Commissioner’s Office, Legitimate interests: what is the legitimate interests basis?, checked 1 Oct 2026.
  4. Information Commissioner’s Office, Legitimate interests: when can we rely on legitimate interests?, checked 1 Oct 2026.
  5. Information Commissioner’s Office, Legitimate interests: how do we apply legitimate interests in practice?, checked 1 Oct 2026.
  6. Information Commissioner’s Office, Statement on the commencement of the Data (Use and Access) Act (DUAA), 5 February 2026, checked 1 Oct 2026.
  7. legislation.gov.uk, Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 22, checked 1 Oct 2026.
  8. legislation.gov.uk, Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 23, checked 1 Oct 2026.
  9. legislation.gov.uk, Privacy and Electronic Communications (EC Directive) Regulations 2003, Schedule 1 (as amended, version from 5 February 2026), checked 1 Oct 2026.
  10. legislation.gov.uk, Data Protection Act 2018, section 157: maximum amount of penalty, checked 1 Oct 2026.
  11. legislation.gov.uk, UK GDPR, Article 6 (as amended, version from 5 February 2026), checked 1 Oct 2026.
  12. legislation.gov.uk, The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, checked 1 Oct 2026.
  13. LinkedIn, User Agreement (effective 3 November 2025), checked 1 Oct 2026.