B2B lead generation

Is cold outreach legal in the UK? Mostly yes, with two rules people break

Cold email and cold calling are lawful in Britain if you understand who you are contacting. Almost every business that gets into trouble broke the same two rules, and both are avoidable.

21 August 2026 4 minute read Design Surrey · Woking
In short
  • Under PECR, whether you may email someone depends on whether they are a corporate subscriber (limited companies, LLPs) or an individual subscriber (sole traders, ordinary partnerships).
  • Sole traders and ordinary partnerships are individual subscribers — you generally cannot cold email them without consent, even at a business address.
  • Every number must be screened against both TPS and CTPS, every time. Screening only CTPS because "it is B2B" is the most common failure, and you cannot tell which register applies from the number.
  • Screen at the point of dial, not monthly. PECR reg 21(3) gives a 28-day grace, and the ICO warns an older check can miss a newly-active registration.
  • The ICO fined Energy Prices Direct £160,000 in May 2026 for calling TPS and CTPS-registered numbers without screening first.

There is a persistent belief among small businesses that cold outreach is basically illegal now, and a second, equally confident belief that anything is fine as long as it is business-to-business.

Both are wrong, and the gap between them is where the fines live.

The actual position is that cold email and cold calling are lawful in the United Kingdom, subject to rules that are specific, knowable and mostly about who you are contacting rather than what you say to them.

The rules are not about your message. They are about the legal form of the person receiving it.

The distinction everything else hangs on

The Privacy and Electronic Communications Regulations divide the world into corporate subscribers and individual subscribers. Get this wrong and everything downstream is wrong.

A corporate subscriber is a body with separate legal status — a limited company, a limited liability partnership, a Scottish partnership, and certain public bodies. These may lawfully receive unsolicited marketing email.

An individual subscriber is everybody else, and the phrase is misleading because it includes plenty of businesses. Sole traders are individual subscribers. So are ordinary partnerships — a two-person plumbing firm trading as a partnership is an individual subscriber under these rules, however commercial the address on the invoice.

Which means the marketing email you may lawfully send to Smith Roofing Limited you may not lawfully send to Smith Roofing, the sole trader down the road, and there is nothing about their websites that will tell you which is which.

2The number of preference registers you must screen every phone number against — TPS and CTPS — because a telephone number does not tell you which kind of subscriber is on the end of it.

How you find out which one you are dealing with

Companies House. It is a public register, published under the Open Government Licence, and it states the company type in plain terms.

A business that does not appear on it at all is, for practical purposes, an unregistered trader — which means individual subscriber, which means phone only. That is the safe default and it should be the automatic one: if you cannot establish the subscriber type, treat it as individual.

The first rule people break: screening only CTPS

The Corporate Telephone Preference Service is for corporate subscribers, the Telephone Preference Service for individual ones. The reasoning that follows seems sound and is not: we are calling businesses, so we screen against CTPS.

It fails because sole traders and ordinary partnerships are individual subscribers and therefore register on TPS, not CTPS — and you cannot tell from a phone number which you are looking at. Screen only CTPS and you will call TPS-registered sole traders all day long, entirely unaware.

The ICO puts it plainly in its own guidance: you need to screen against the CTPS and TPS registers, as well as your own do-not-call list. Both. Every number. Every time.

In May 2026 the ICO fined Energy Prices Direct £160,000 for calling numbers registered with TPS and CTPS without screening first. That is what this failure costs when it is found.

The second rule people break: screening once a month

A business downloads a list, screens it thoroughly, and then calls from it for four weeks. It feels diligent. It is the second most common way to end up in front of the regulator.

PECR regulation 21(3) provides that calling a number registered for fewer than 28 days is not a contravention. That grace period is the whole reason monthly screening is dangerous: a check performed on the first of the month is, by the twenty-eighth, at the very edge of what it can defend, and the ICO has warned that a check older than that can miss a newly-active registration.

The fix is to screen at the point of dial. At thirty calls a day an API check costs single-figure pounds a month. There is no economic argument for the risk.

What the fines actually are now

This changed recently and a lot of published advice has not caught up, including, for a period, the ICO's own guidance pages.

The maximum PECR penalty used to be £500,000. The Data (Use and Access) Act 2025 raised it, and the relevant provisions commenced on 5 February 2026. The ceiling is now broadly aligned with UK GDPR: up to £17.5 million or 4% of global turnover, whichever is higher.

No small Surrey business is going to be fined £17.5 million. The reason the number matters is what it says about the direction of enforcement, and because the fines that are actually being issued — the £160,000 above — are already at a level that ends a small company.

What lawful outreach looks like in practice

  • Source from public records. Companies House under the Open Government Licence, plus what the business publishes on its own website. Both are defensible and you can evidence where every field came from.
  • Route by subscriber type. Limited companies and LLPs: email and phone. Sole traders and ordinary partnerships: phone only, screened.
  • Screen both registers at the point of dial. Not weekly. Not monthly.
  • Give something before you ask for anything. Ours is a free performance audit of their own website. It is genuinely useful whether or not they ever speak to us, and it means the call two days later is a follow-up rather than an interruption.
  • Honour a no immediately and permanently. One suppression list, covering phone, email and domain, checked before every campaign, updated the same minute somebody asks.
  • Keep the record. Where the data came from, when it was screened, by whom, and what was sent. If you are ever asked, the answer needs to exist already.

The uncomfortable conclusion

Most bought lead lists cannot meet this standard. They arrive without provenance, without subscriber type, and frequently scraped from sources whose terms prohibit it. The seller carries none of the risk; you are the controller and it is entirely yours.

Which is the real argument for building the list yourself from public records. It is not primarily about compliance, though it is compliant. It is that a list you built is a list you can explain — and the explanation is the only thing that helps you if somebody ever asks.

Questions we get asked

Is cold emailing businesses legal in the UK?

It depends on the type of business. Under PECR, corporate subscribers — limited companies, LLPs, Scottish partnerships and some public bodies — may receive unsolicited business-to-business marketing email. Individual subscribers, which includes sole traders and ordinary partnerships, may not without consent. The distinction is about the legal form of the subscriber, not whether the address looks like a work address.

Do I need to check TPS or CTPS before calling a business?

Both, every time. TPS is the register for individual subscribers and CTPS for corporate ones, and you cannot tell from a telephone number which category a business falls into. The ICO's own guidance says you need to screen against the CTPS and TPS registers as well as your own do-not-call list.

How often do I need to re-screen a calling list?

Immediately before dialling, in practice. PECR regulation 21(3) provides that a number registered for fewer than 28 days is not a contravention, but the ICO warns that a screening check older than that can miss a newly-active registration. Screening is inexpensive; a fine is not.

What is the maximum fine for breaking PECR?

The maximum was raised from £500,000 by the Data (Use and Access) Act 2025, which commenced on 5 February 2026, bringing PECR penalties broadly into line with UK GDPR at up to £17.5 million or 4% of global turnover. Note that the ICO's own guidance pages were slower to update than the law.

Can I buy a list of leads and email it?

Not safely. A purchased list gives you no reliable way to establish subscriber type, no evidence of consent where consent is required, and no defensible record of where the data came from — and you remain the controller responsible for all of it. Building from public sources such as Companies House, under the Open Government Licence, is both cheaper and defensible.

B2B lead generation

Outbound that does not get you fined.