Guide

UK GDPR and PECR: a checklist for cold outreach

What the rules actually say about B2B email, and the six things to have in place

Most guidance on this is written for the US and quietly assumes CAN-SPAM, which is a far more permissive regime. If you are sending into the UK or EU, the rules are different and the exposure is real. This is a practical checklist, not legal advice — take the specifics to a solicitor before you rely on them.

Two regimes, not one

UK cold email sits under two instruments and people routinely forget the second.

UK GDPR governs processing personal data — which a work email address containing someone’s name is. You need a lawful basis to process it at all.

PECR (the Privacy and Electronic Communications Regulations) governs the act of sending electronic marketing. It sits on top of GDPR and has its own separate requirements. Being GDPR-compliant does not make you PECR-compliant.

The corporate subscriber distinction

This is the part that makes UK B2B outbound viable. PECR’s consent requirement for unsolicited marketing email applies to individual subscribers — consumers, sole traders and, in most readings, partnerships. It does not apply in the same way to corporate subscribers: limited companies, LLPs and public bodies.

So emailing name@somelimitedcompany.co.uk without prior consent is generally permissible under PECR, provided you meet the other conditions below. Emailing a sole trader or a personal address is a different matter and needs consent.

GDPR still applies either way. The usual lawful basis for B2B outbound is legitimate interests, which requires you to have actually performed and documented a legitimate interests assessment weighing your interest against the recipient’s rights. “Everyone does it” is not an assessment.

The six-point checklist

1. Document your lawful basis

Write the legitimate interests assessment down before you send, not after a complaint. It should cover the purpose, why direct email is necessary, and why a reasonable recipient would not be surprised to hear from you. Relevance is doing real work here: emailing a plausible buyer about a plausible problem is defensible, blasting a scraped list is not.

2. Identify yourself properly

Every marketing email must clearly say who is sending it and include a valid postal address. No disguised or concealed sender identity, no reply-to that goes nowhere. This is a hard PECR requirement, not a nicety.

3. Provide a working opt-out in every message

Every message, not just the first. It must be simple and free. One-click is best practice and increasingly an expectation of the mailbox providers as well as the regulator. Honour it immediately — and honour it across every sequence, not just the one they replied to.

4. Maintain a real suppression list

Opt-outs, bounces, complaints and anyone who has asked you to stop, held permanently and checked before every send. This must survive changing tools. A suppression list that lives only inside a platform you might cancel is not a suppression list.

5. Be able to answer a subject access or erasure request

Individuals can ask what you hold on them and ask you to delete it, and you have one month. You need to be able to find every record for a person across your stack and act on it. Practise this once before you receive a real one.

6. Tell people where you got their data

Under Article 14, when you collect personal data from somewhere other than the person, you generally have to tell them — including the source — typically within a month or at first contact. In practice this means your privacy notice must describe your sourcing, and your first email should link to it.

Where AI raises the stakes

Volume is an aggravating factor. So is fabrication: an email asserting something false about a person is a data accuracy problem under GDPR as well as an embarrassment. If an AI writes your outreach, you need to be able to show what constrains it to true, sourced statements.

What good looks like in the product

RequirementWhat to look for in a tool
SuppressionGlobal do-not-contact list checked before every send, exportable
UnsubscribeOne-click, automatic, applied across all sequences instantly
Sender identityPhysical address enforced in the footer, not optional
Data provenanceA record of where each contact came from
AccuracyClaims in copy grounded in cited evidence; no fabrication
ErasureFind-and-delete a person across all records in one action
ResidencyWhere data is stored, and which processors it passes through

Common mistakes

This is general information, not legal advice. The ICO publishes direct marketing guidance covering PECR and UK GDPR, and it is worth reading in full before you scale outbound.

GTMHack is built for UK senders

Global suppression, one-click unsubscribe, enforced address footers and grounded copy that cannot invent claims about a person.

See the security posture

← All guides · Cold email deliverability · How to evaluate AI SDR alternatives