[codicts-css-switcher id=”346″]

Global Law Experts Logo
b2b email marketing rules uk

Our Expert in United Kingdom

B2B Email Marketing UK 2026: PECR vs UK GDPR, Consent, Legitimate Interests & Compliance Checklist

By Global Law Experts
– posted 2 hours ago

The b2b email marketing rules uk businesses must follow in 2026 sit at the intersection of two distinct legal frameworks: the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) and the UK GDPR as supplemented by the Data Protection Act 2018. As the deprecation of third‑party cookies pushes marketing budgets toward email, and as the Information Commissioner’s Office (ICO) sharpens its enforcement posture on direct marketing, commercial teams need answers that are legally defensible rather than merely tactical.

This guide explains when you can email a business without consent, how the soft opt‑in works in a B2B context, and when legitimate interests is the correct lawful basis, with a comparison table, a sample Legitimate Interests Assessment (LIA), a compliance checklist and draft contract clauses. It is written for in‑house counsel, compliance managers and SaaS vendors who need to make a lawful decision quickly and document it properly.

Note that the Data (Use and Access) Act 2025 received Royal Assent in June 2025 and introduces reforms to the UK data protection and PECR framework, some of which are being brought into force in stages. Organisations should check the current position with the ICO before finalising campaigns, as certain PECR provisions (including aspects of the soft opt‑in and penalty regime) are affected by that legislation.

Intro, TL;DR and what this guide covers

TL;DR: In the UK you can often send B2B marketing emails without prior consent, but only where two separate tests are satisfied, PECR permits the message and you have a valid lawful basis (usually legitimate interests) under the UK GDPR. The answer depends critically on whether the address is a corporate/generic inbox or the personal data of a named individual, and on whether the recipient is a sole trader or partner.

This is a practitioner-level explainer. It brings together the statutory framework, the ICO’s guidance, and the operational steps you need to implement. Bundled with this article are two downloadable assets referenced throughout: a fillable Legitimate Interests Assessment (LIA) template with guidance notes, and a compact pre‑send legal checklist. Both are designed to give you an audit trail that stands up to regulatory scrutiny. Given the trend of increased ICO activity on direct marketing, documentation is no longer optional, it is your primary defence.

Short answer: Can you email a business without consent?

The short answer is: it depends, but frequently yes, provided you clear two hurdles. PECR governs whether the electronic message may be sent at all, while the UK GDPR governs whether you may lawfully process the personal data used to send it. Under the b2b email marketing rules uk law imposes, the key distinguishing factor is who, or what, you are emailing.

  • Corporate subscribers vs individual subscribers. PECR’s strict consent requirement for unsolicited marketing emails applies to individual subscribers. A “corporate subscriber” (a limited company, LLP or public body) is treated differently, and marketing to a corporate subscriber is subject to a lighter regime under PECR.
  • Sole traders and partnerships. The ICO treats sole traders and non-LLP partnerships in England, Wales and Northern Ireland as individual subscribers for these purposes, so the stricter consent-or-soft-opt-in rules apply to them. (Partnerships in Scotland have separate legal personality and are treated as corporate subscribers.)
  • Named individuals are personal data. Even where PECR permits the send to a corporate address, if you are targeting a named person (john.smith@company.co.uk) you are processing personal data and need a lawful basis under the UK GDPR, typically legitimate interests supported by an LIA.

A quick three-step decision tree helps:

  1. Who is the recipient? A limited company/LLP corporate address, or an individual/sole trader/partnership? If the latter, PECR consent or soft opt‑in is required for email.
  2. Is personal data involved? If you target a named individual, you need a UK GDPR lawful basis and an LIA if relying on legitimate interests.
  3. Can you evidence it? Document your PECR analysis, your lawful basis and your LIA before you send.

Which law applies: PECR vs UK GDPR for b2b email marketing rules uk

Understanding which framework bites, and when, is the foundation of compliant B2B outreach. The two regimes overlap but do different jobs. PECR is the specialist rulebook for electronic marketing communications; the UK GDPR is the general data protection framework governing any processing of personal data. Both can apply to a single email campaign simultaneously.

When PECR is triggered

PECR applies whenever you send marketing by electronic means, email, SMS, automated calls and similar. Regulation 22 of PECR governs unsolicited marketing by electronic mail and sets the consent requirement for individual subscribers, together with the soft opt‑in exemption. The primary statutory text is set out in the Privacy and Electronic Communications (EC Directive) Regulations 2003. The ICO’s Guide to PECR explains how these rules apply in practice, including the distinction between corporate and individual subscribers. For B2B purposes, PECR’s crucial feature is that emails to corporate subscribers are not subject to the same strict consent rule that applies to consumers, but you must still identify yourself and provide a valid opt‑out.

When the UK GDPR is the deciding law

Even where PECR permits the send, the UK GDPR governs the underlying data. If the email address, name or job role constitutes personal data, as a named individual’s work address does, you must have a lawful basis to process it for marketing. The Data Protection Act 2018 supplements the UK GDPR domestically and sets out the ICO’s enforcement powers; see the Data Protection Act 2018. The ICO’s direct marketing guidance confirms that the two regimes must be read together: satisfying PECR does not remove your UK GDPR obligations, and vice versa. In practice this means that for cold email to a named decision-maker, you almost always need both a PECR-permitted send and a legitimate interests basis backed by an LIA.

PECR vs UK GDPR, comparison table

Feature Applies to B2B email? PECR requirement UK GDPR requirement Practical tip
Consent required Depends on recipient Required for individual subscribers (incl. sole traders and non-LLP partnerships); lighter regime for corporate subscribers Consent is one lawful basis; legitimate interests may substitute Classify each address as corporate or individual before sending
Soft opt‑in available Yes, in narrow cases Available where address obtained during a sale/negotiation of similar products, with opt-out offered Still needs a lawful basis and transparency Only use for existing customer relationships, not cold prospects
Lawful basis available Yes Not a PECR concept Legitimate interests or consent; LIA advisable for LI Document your LIA before the first send
Type of address Critical distinction Corporate subscriber treated more permissively than individual subscriber Named individual = personal data; generic inbox may not be Prefer generic corporate inboxes for cold outreach where possible
Opt-out required Always Mandatory simple, free opt-out in every message Right to object to direct marketing is absolute Honour opt-outs promptly and add to suppression list
Penalty risk Yes ICO can fine and issue enforcement notices ICO can fine and issue enforcement notices under DPA 2018 Maintain audit logs to evidence compliance

The table underlines a single practical message: the b2b email marketing rules uk teams must apply are not a single test but a layered analysis. PECR determines whether the channel is open; the UK GDPR determines whether the data may be used. Both must be satisfied, and both must be documented.

Consent vs Legitimate Interests, which lawful basis for B2B?

Once you have confirmed that PECR permits the send, the next question is your lawful basis under the UK GDPR. For B2B marketing, the two realistic options are consent and legitimate interests. Consent gives certainty but is operationally demanding, it must be freely given, specific, informed and unambiguous, and it must be as easy to withdraw as it was to give. Legitimate interests is more flexible and is frequently the appropriate basis for B2B email to named individuals, but it is not a free pass: it requires a documented three-part assessment.

Step-by-step LIA: purpose, necessity, balancing

The ICO’s legitimate interests guidance sets out the three-part test that every LIA should work through:

  • Purpose test. Identify the legitimate interest. For B2B marketing, this is typically promoting relevant products or services to businesses that may benefit from them. The ICO recognises direct marketing as a potential legitimate interest.
  • Necessity test. Ask whether the processing is necessary to achieve that interest, and whether a less intrusive method would achieve the same result. Emailing a named decision-maker about a genuinely relevant B2B solution will often pass; blanket, irrelevant outreach will not.
  • Balancing test. Weigh your interest against the individual’s rights, freedoms and reasonable expectations. A senior procurement contact receiving a targeted, relevant message at a work address will generally have a lower expectation of privacy than a consumer at a personal address, but the balance can tip if the messaging is intrusive, high-volume or irrelevant.

A worked mini-LIA for a cold email to a named IT director at a UK company might read: Purpose, to introduce a data security SaaS product to organisations likely to need it; Necessity, email to the relevant role-holder is the least intrusive way to reach the decision-maker, and no consent-based channel exists for a first contact; Balancing, the recipient’s role makes such contact reasonably expected, the volume is low, the message is targeted and a one-click opt-out is provided, so the balance favours the sender. Our downloadable LIA template walks through each of these fields in full.

Record-keeping for legitimate interests

A legitimate interests basis is only as strong as the record behind it. Complete and date your LIA before the first campaign, retain it, and review it if your targeting, volume or product changes materially. Under the accountability principle in the UK GDPR, you must be able to demonstrate the reasoning. If the ICO investigates, an undated or missing LIA leaves you poorly placed to demonstrate that you satisfied the balancing test.

When consent is necessary despite legitimate interests

Legitimate interests will not always be available. Where PECR requires consent, for example, marketing emails to individual subscribers such as sole traders, you cannot substitute legitimate interests to bypass the PECR consent rule. PECR sets a channel-specific bar that sits on top of the UK GDPR lawful basis. In those cases you need either valid consent or a properly satisfied soft opt‑in, discussed next.

The soft opt‑in: what it is and whether it applies in B2B

The soft opt‑in is a limited exemption under PECR that allows you to email marketing to existing customers without their prior consent, provided strict conditions are met. It is often misunderstood and over-relied upon in a B2B context, so precision matters. The ICO’s direct marketing guidance sets out the criteria in detail.

Conditions for the soft opt‑in

To rely on the soft opt‑in, all of the following must be satisfied:

  • You obtained the contact details in the course of a sale or negotiations for a sale of a product or service to that person.
  • You are marketing your own similar products or services.
  • You gave the person a simple opportunity to opt out both when you first collected the details and in every subsequent message.

Messaging and opt-out requirements

The soft opt‑in maps most naturally onto relationships with individual subscribers where a prior transaction or negotiation existed. In B2B it can apply, for example, where you sold to a sole trader and now wish to market a similar service to them. But it cannot be stretched to cover cold prospects, purchased lists, or contacts collected without any sale-related interaction. Critically, the soft opt‑in relaxes only the PECR consent requirement; you still need a UK GDPR lawful basis and you must provide a working opt-out in every message. If any of the three conditions fails, you are back to needing consent or, for corporate subscribers, the standard corporate regime plus a legitimate interests basis.

Practical compliance checklist for B2B email campaigns

Translating the b2b email marketing rules uk regulators enforce into operational practice requires disciplined processes across legal, marketing and technical teams. The following checklist mirrors the downloadable pre‑send checklist supplied with this article.

Pre-send legal checklist

  • Classify every address. Tag each record as corporate subscriber or individual subscriber (including sole traders and relevant partnerships) so the correct PECR rule applies.
  • Confirm the lawful basis. Record whether you are relying on consent, soft opt‑in or legitimate interests for each segment, and hold the evidence.
  • Complete and date the LIA. Where relying on legitimate interests, ensure the LIA is finalised, dated and stored before sending.
  • Check consent records. Where consent is the basis, verify it is specific, informed, unambiguous and freshly evidenced, not inherited from an unrelated context.
  • Verify sender identity. PECR requires that you do not disguise or conceal your identity and that a valid address for opt-out requests is provided.
  • Include a clear opt-out. Every message must offer a simple, free means to unsubscribe.
  • Screen suppression lists. Remove all previously unsubscribed and objecting contacts before deployment.
  • Consider TPS/CTPS relevance. If your campaign extends to telephone follow-up, check whether the Telephone Preference Service (TPS) or Corporate TPS (CTPS) rules apply to those channels.

Post-send obligations and audit logs

  • Log the send. Retain records of what was sent, to which segment, on which lawful basis and when.
  • Process opt-outs promptly. Add unsubscribes to your suppression list without undue delay and confirm they propagate across all systems.
  • Maintain a preference centre. A marketing preference centre lets recipients manage their choices and evidences your respect for their rights.
  • Review LIAs periodically. Re-run the balancing test if your volume, targeting or product set changes.

Sample wording you can adapt includes an unsubscribe line, “To stop receiving these emails, click unsubscribe. We will action your request promptly.”, and a consent statement, “I agree to receive marketing emails about similar products and services. I can opt out at any time.”, both of which are elaborated in the downloadable checklist.

Record-keeping, unsubscribe & suppression: what you must do

Record-keeping is where many otherwise compliant programmes fail. The ICO’s Guide to PECR makes clear that an opt-out must be simple and free to use and must be respected. The UK GDPR’s accountability principle requires you to be able to demonstrate compliance on request.

Record retention & audit trail

Keep a durable audit trail covering: the source of each contact, the PECR classification, the lawful basis, any consent captured (with timestamp and wording), each LIA, and every opt-out. Retain these records for as long as you continue to market to the individual and for a reasonable period afterward to defend against complaints, in line with the storage limitation principle. The Data Protection Act 2018 underpins the ICO’s power to require and scrutinise such records, so treat your logs as evidence, not administrative clutter.

Handling downstream suppression

Suppression is not complete until it reaches every system and every downstream party. When a recipient unsubscribes, the suppression must apply across all your platforms and any processors sending on your behalf. If you share lists with agencies or partners, contractually require them to honour your suppression list and to feed opt-outs back to you. An unsubscribe that is respected in your main platform but ignored by a connected sending tool is a breach in waiting.

Using purchased B2B lists & third‑party vendors

Buying B2B email lists is not automatically unlawful in the UK, but it carries significant risk and demands rigorous due diligence. The core problem is that PECR and UK GDPR obligations follow the data: if the list provider did not have a lawful basis to collect and share the data, you may not have one to use it.

Clauses to require in vendor contracts

Before using any purchased or rented list, obtain documented answers on data provenance, the lawful basis relied upon by the provider, whether individuals were told their data might be shared for third-party marketing, and how opt-outs are managed. Insist on contractual warranties confirming lawful sourcing, indemnities against claims arising from unlawful data, and audit rights so you can verify provenance. Where the provider claims consent, require evidence of the consent statement actually used. The ICO’s direct marketing guidance makes plain that you remain responsible for ensuring your own use is lawful, regardless of assurances from a supplier.

International transfers for data received from outside the UK

If the list originates outside the UK, or the vendor processes it abroad, you must consider the UK GDPR restrictions on international transfers and ensure an appropriate transfer mechanism is in place. Provenance from another jurisdiction does not relax the b2b email marketing rules uk law applies to your send; it adds a transfer-compliance layer on top.

Draft contractual wording & data processing checklist

The following short clauses are drafting starting points for marketing and data agreements. Each should be tailored to the specific arrangement and reviewed by qualified counsel before use.

  • Clause 1, Vendor warranty on lawful sourcing. “The Supplier warrants that all personal data supplied under this Agreement has been collected and may lawfully be processed and disclosed for the Client’s direct marketing purposes in compliance with PECR and the UK GDPR, and that all individuals were given the information and opt-out opportunities required by law.” Usage note: pair with an indemnity so the warranty has teeth.
  • Clause 2, Joint-controller allocation for marketing lists. “Where the parties jointly determine the purposes and means of processing shared marketing data, they shall document their respective responsibilities under Article 26 UK GDPR, including responsibility for transparency information and for handling data subject rights requests and opt-outs.” Usage note: use only where a genuine joint-controller relationship exists; otherwise treat as controller-to-controller or controller-to-processor.
  • Clause 3, Processor obligations for list processing & suppression. “The Processor shall process personal data only on the documented instructions of the Controller, shall apply and maintain the Controller’s suppression list across all sending systems, and shall feed all opt-out requests back to the Controller without undue delay.” Usage note: align with the Article 28 UK GDPR mandatory processor terms.

Enforcement, penalties and ICO action, trend snapshot

The ICO continues to take action against organisations for unlawful direct marketing, using both monetary penalties and non-monetary measures such as enforcement notices. Its published record of action is available on the ICO enforcement page. Note that reforms under the Data (Use and Access) Act 2025 are set to change certain PECR penalty provisions, potentially aligning higher fine ceilings with the UK GDPR regime; organisations should monitor the ICO for the current position. Industry observers expect the regulator’s focus on electronic direct marketing to continue as cookie deprecation drives more organisations toward email, making documented PECR and UK GDPR compliance a practical priority.

A simple risk matrix helps prioritise: cold email to named individuals without an LIA is high risk; soft opt‑in relied on beyond its conditions is medium-to-high risk; well-documented legitimate interests marketing to corporate subscribers with clean suppression is low risk.

Conclusion & recommended next steps

The b2b email marketing rules uk organisations must navigate reward preparation: classify your contacts, choose and document your lawful basis, and keep clean records. Three immediate steps: run an LIA for each cold-email segment using the downloadable template; update your vendor and marketing contracts with the sample clauses above; and implement robust unsubscribe handling with full audit logging. Doing so turns compliance from a liability into a defensible, repeatable process.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Nigel Miller at Fox Williams LLP, a member of the Global Law Experts network.

Sources

  1. The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  2. Data Protection Act 2018
  3. Data (Use and Access) Act 2025
  4. ICO, Direct marketing guidance
  5. ICO, Guide to PECR
  6. ICO, Legitimate interests guidance
  7. ICO, Enforcement and action we’ve taken

FAQs

Can I email a business without consent in the UK?
Often yes, but only if two conditions are met. PECR must permit the send, which it generally does for corporate subscribers such as limited companies, subject to identifying yourself and offering an opt-out, and you must have a UK GDPR lawful basis, usually legitimate interests supported by a documented LIA, where the address is a named individual’s personal data. Sole traders and non-LLP partnerships are treated as individual subscribers, so consent or the soft opt‑in applies.
PECR applies, but corporate subscribers are treated more permissively than individual subscribers, so the strict consent rule does not apply in the same way. You must still identify your organisation and provide a valid opt-out. Note that a generic inbox may not itself be personal data, but if a named individual is identifiable, the UK GDPR applies and you need a lawful basis.
The soft opt‑in is a PECR exemption allowing marketing to existing customers without prior consent, where you obtained their details during a sale or negotiation, you market similar products, and you offered an opt-out at collection and in every message. In B2B it can apply to prior customers such as sole traders, but not to cold prospects or purchased lists. It relaxes only PECR consent, you still need a UK GDPR lawful basis.
Legitimate interests is well suited to B2B email to named individuals at work addresses where PECR does not mandate consent. You should complete a three-part LIA covering purpose, necessity and balancing before sending, and retain it. Where PECR requires consent, for example, marketing to individual subscribers, legitimate interests cannot be used to bypass that requirement.
Every marketing email must include a simple, free means to opt out, and you must respect opt-out requests promptly. Add unsubscribes to a suppression list that propagates across all systems and any third-party senders. Keep records of opt-outs as part of your accountability audit trail, since the ICO can require evidence that requests were actioned.
It is not automatically unlawful, but it is high risk. You remain responsible for the lawfulness of your use, so conduct due diligence on the provider’s data provenance and lawful basis, obtain warranties and indemnities on lawful sourcing, secure audit rights, and confirm individuals were told their data could be shared for third-party marketing. If the data came from outside the UK, address international transfer requirements too.
The Telephone Preference Service (TPS) and Corporate TPS (CTPS) concern live marketing calls, not email, so they do not apply to a pure email campaign. However, if your outreach extends to telephone follow-up, check whether the TPS/CTPS and the relevant PECR rules for those channels apply before contacting recipients.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

B2B Email Marketing UK 2026: PECR vs UK GDPR, Consent, Legitimate Interests & Compliance Checklist

Send welcome message

Custom Message