UK GDPR and PECR: a checklist for cold outreach
Most guidance on this is written for the US and quietly assumes CAN-SPAM, which is a far more permissive regime. If you are sending into the UK or EU, the rules are different and the exposure is real. This is a practical checklist, not legal advice — take the specifics to a solicitor before you rely on them.
Two regimes, not one
UK cold email sits under two instruments and people routinely forget the second.
UK GDPR governs processing personal data — which a work email address containing someone’s name is. You need a lawful basis to process it at all.
PECR (the Privacy and Electronic Communications Regulations) governs the act of sending electronic marketing. It sits on top of GDPR and has its own separate requirements. Being GDPR-compliant does not make you PECR-compliant.
The corporate subscriber distinction
This is the part that makes UK B2B outbound viable. PECR’s consent requirement for unsolicited marketing email applies to individual subscribers — consumers, sole traders and, in most readings, partnerships. It does not apply in the same way to corporate subscribers: limited companies, LLPs and public bodies.
So emailing name@somelimitedcompany.co.uk without prior consent is generally permissible under PECR, provided you meet the other conditions below. Emailing a sole trader or a personal address is a different matter and needs consent.
GDPR still applies either way. The usual lawful basis for B2B outbound is legitimate interests, which requires you to have actually performed and documented a legitimate interests assessment weighing your interest against the recipient’s rights. “Everyone does it” is not an assessment.
The six-point checklist
1. Document your lawful basis
Write the legitimate interests assessment down before you send, not after a complaint. It should cover the purpose, why direct email is necessary, and why a reasonable recipient would not be surprised to hear from you. Relevance is doing real work here: emailing a plausible buyer about a plausible problem is defensible, blasting a scraped list is not.
2. Identify yourself properly
Every marketing email must clearly say who is sending it and include a valid postal address. No disguised or concealed sender identity, no reply-to that goes nowhere. This is a hard PECR requirement, not a nicety.
3. Provide a working opt-out in every message
Every message, not just the first. It must be simple and free. One-click is best practice and increasingly an expectation of the mailbox providers as well as the regulator. Honour it immediately — and honour it across every sequence, not just the one they replied to.
4. Maintain a real suppression list
Opt-outs, bounces, complaints and anyone who has asked you to stop, held permanently and checked before every send. This must survive changing tools. A suppression list that lives only inside a platform you might cancel is not a suppression list.
5. Be able to answer a subject access or erasure request
Individuals can ask what you hold on them and ask you to delete it, and you have one month. You need to be able to find every record for a person across your stack and act on it. Practise this once before you receive a real one.
6. Tell people where you got their data
Under Article 14, when you collect personal data from somewhere other than the person, you generally have to tell them — including the source — typically within a month or at first contact. In practice this means your privacy notice must describe your sourcing, and your first email should link to it.
Volume is an aggravating factor. So is fabrication: an email asserting something false about a person is a data accuracy problem under GDPR as well as an embarrassment. If an AI writes your outreach, you need to be able to show what constrains it to true, sourced statements.
What good looks like in the product
| Requirement | What to look for in a tool |
|---|---|
| Suppression | Global do-not-contact list checked before every send, exportable |
| Unsubscribe | One-click, automatic, applied across all sequences instantly |
| Sender identity | Physical address enforced in the footer, not optional |
| Data provenance | A record of where each contact came from |
| Accuracy | Claims in copy grounded in cited evidence; no fabrication |
| Erasure | Find-and-delete a person across all records in one action |
| Residency | Where data is stored, and which processors it passes through |
Common mistakes
- Assuming B2B is exempt from GDPR. It is not. The corporate subscriber carve-out is a PECR concept and it does not disapply GDPR.
- Treating
info@as a free pass. Generic role addresses are lower risk, but a named mailbox is personal data regardless of the domain. - Buying a list and assuming consent transferred. Consent is rarely transferable, and the seller’s assurance is not your defence.
- Only honouring opt-outs in one sequence. Suppression is account-wide or it is nothing.
- Never testing erasure. The one-month clock starts whether or not you are ready.
This is general information, not legal advice. The ICO publishes direct marketing guidance covering PECR and UK GDPR, and it is worth reading in full before you scale outbound.
GTMHack is built for UK senders
Global suppression, one-click unsubscribe, enforced address footers and grounded copy that cannot invent claims about a person.
See the security posture← All guides · Cold email deliverability · How to evaluate AI SDR alternatives