---name: uk-pecr-cold-email-checkerdescription: Screens a UK B2B prospect list and a draft cold email against PECR and the UK GDPR before anything is sent. Classifies each recipient by legal form, because that is what decides whether you may email them at all, and checks the message itself against the sender-identity and opt-out rules. Use before loading a list, or when auditing a campaign that is already running.license: MIT--- # UK cold email checker: PECR and UK GDPR **This is not legal advice.** It is a structured check written by people whosend cold email in the UK, citing primary legislation you can read yourself.Every citation below is to legislation.gov.uk. Follow them. If the answermatters commercially, take advice. Two separate regimes apply to a UK cold email and people routinely conflatethem: - **PECR**, the Privacy and Electronic Communications (EC Directive) Regulations 2003, decides whether you may send the message at all. It turns on what the recipient legally *is*.- **The UK GDPR** decides whether you may hold and use their data. It applies whenever the address identifies a person, which for cold B2B email is nearly always. Clearing one does not clear the other. Work through both. ## Step 1: classify every recipient by legal form This is the step almost everyone skips, and it is the one that decides theoutcome. PECR reg 22 restricts unsolicited marketing email to **individualsubscribers**. It does not restrict it to **corporate subscribers** in the sameway. So the first question is never "is this a business address" but "what kindof legal person is behind it". Reg 2(1) defines a corporate subscriber. Read against that definition: | What you are contacting | PECR classification | Why ||---|---|---|| Registered company, Ltd or PLC | Corporate subscriber | reg 2(1)(a), a company within the Companies Act definition || Limited liability partnership | Corporate subscriber | reg 2(1)(e), a body corporate and a legal person distinct from its members || Partnership in Scotland | Corporate subscriber | reg 2(1)(c), named in the definition explicitly || Company by royal charter or letters patent | Corporate subscriber | reg 2(1)(b) || Corporation sole | Corporate subscriber | reg 2(1)(d) || Sole trader | **Individual subscriber** | not within the corporate definition || General partnership in England, Wales or Northern Ireland | **Individual subscriber** | reg 2(1) defines "individual" as a living individual and includes an unincorporated body of such individuals | Two of those rows surprise people every time. **A Scottish partnership is a corporate subscriber and an English one is not.**Scottish partnerships have separate legal personality and the definition namesthem. The identical business, same trade, same size, one on each side of theborder, gets a different answer. **An LLP is not a partnership for this purpose.** The name misleads. It is abody corporate, so it falls in with the companies. One quirk worth knowing when you read the source: reg 2(1)(a) still citessection 735(1) of the Companies Act **1985**, which has been superseded. Thepractical effect is unchanged, registered companies are corporate subscribers,but do not be thrown when the cross-reference points at a repealed Act. ### How to establish the legal form Do not infer it from the domain, the email address, or how the website iswritten. A one-person consultancy with a polished site is very often a soletrader, and that is the case where getting it wrong costs you. Check the register. A UK company or LLP has a company number and appears onCompanies House. If there is no registration, you are almost certainly lookingat a sole trader or an unincorporated partnership, which means an individualsubscriber. Absence of evidence is the answer here, not a reason to guess. Record the classification against every row before the list is loaded, not as aspot check afterwards. If your CRM has no field for it, add one: this is thefield that decides which channel a prospect is even eligible for. ## Step 2: apply the consequence **Corporate subscriber.** Reg 22 does not prohibit the send. You still have UKGDPR obligations if the address identifies a person, which afirstname.lastname address plainly does. Go to step 4. **Individual subscriber.** Reg 22(2) prohibits unsolicited electronic mail fordirect marketing unless the recipient has previously notified you that theyconsent to it. A cold prospect has not. The one exception, at reg 22(3), is the soft opt-in, and it does not help you.It requires that the contact details were obtained "in the course of the saleor negotiations for the sale of a product or service" to that person. Apurchased list, a scraped list, or any list of people you have never transactedwith cannot satisfy that wording, however the vendor describes it. Read thewords: the test is about a sale to that recipient, not about the data beingbusiness data or lawfully sourced. So the honest conclusion for an individual subscriber on a cold list is: **donot email them.** Suppress the row. Reach them another way, or not at all. There is a charity-specific provision at reg 22(3A), added in February 2026. Ifyou are a charity, read it. This check assumes you are not. **On the alternative channels**, be careful about swapping one problem foranother. Telephone marketing has its own PECR rules, including screeningagainst the Telephone Preference Service and its corporate register, and thisskill does not cover calls. Check them separately before you route a suppressedrow to a phone list. ## Step 3: check the message, not just the list Reg 23 applies to the email itself, and it applies to corporate and individualrecipients alike. A message must not be sent where: - the identity of the sender is disguised or concealed, or- there is no valid address to which the recipient can send an opt-out request. Check the draft for all of these: - [ ] The sending identity reconciles with a real, checkable business. If the mail goes out from a secondary domain, the body must still make clear who is actually writing. This is the rule that a bare first-name signature on an unfamiliar domain fails.- [ ] There is a working reply path, and a reply asking to stop is honoured. An unsubscribe link that goes nowhere is worse than none.- [ ] Opt-outs are actioned promptly and permanently. The ICO's expectation is that this happens as soon as possible. There is no 28 day grace period in PECR, and anyone who tells you there is has confused it with something else.- [ ] The opt-out is recorded somewhere that survives a change of tool. A suppression list held only inside a sending platform is one migration away from re-contacting someone who asked you not to. ## Step 4: the UK GDPR obligations that apply regardless These are not optional because the recipient is a company. They attach topersonal data, and a named person's work address is personal data. - [ ] **A lawful basis.** For cold B2B the usual basis is legitimate interests, Article 6(1)(f). That requires a balancing test written down before you send, not reconstructed afterwards if someone complains. Direct marketing can be a legitimate interest; it is not automatically a winning one.- [ ] **Article 14 transparency.** You obtained the data from somewhere other than the person. That triggers a duty to tell them what you hold, where it came from and what you are doing with it, normally within a month or at first contact. In practice this is a line in the email linking to a privacy notice that actually names your sources.- [ ] **The right to object.** Under Article 21 an objection to direct marketing is absolute. There is no balancing exercise once it is made.- [ ] **Data minimisation and retention.** Decide how long a non-responder stays on the list, write it down, and delete on that schedule. ## Step 5: check your own disclosures If you trade under a name that is not the proprietors' own surnames, Chapter 2of Part 41 of the Companies Act 2006 requires you to disclose the name of eachproprietor and a UK address at which documents can be served. Note where that obligation actually lands, because it is widely misquoted.s.1202(1) lists business letters, written orders for goods or services,invoices and receipts, and written demands for payment. s.1204 covers a noticeat business premises. **Websites are not in the list.** s.1202(2) additionallyrequires the information to be given immediately, in writing, to anyone in thecourse of business who asks for it. So the check is: does your invoice carry it, and would you produce it onrequest. A footer on the website is good practice and reassures a recipientthat you are real, which helps with reg 23, but it is not what Part 41 isasking for. **The author of this skill currently fails part of this check.** TheCold.Ai isa partnership trading under a name that is not the partners' surnames. Thepartners are named, but no address for service has been published yet, becauseno business address exists and publishing a home address was declined. That isa known gap being closed, and it is stated here because a compliance checkerthat hides its own author's failure is worth nothing. ## What the check should report For a list, per row: the legal form, the classification, the verdict, and wherethe classification came from. Then a count of rows suppressed and why. If youcannot establish the legal form for a row, that row is not "probably fine": sayunknown, and treat unknown as individual until someone checks. For a message: each reg 23 item as pass or fail, each UK GDPR item as presentor missing, and the specific sentence you would change. Never report a percentage compliant. A list is not 94% sendable. The rows thatfail are the whole finding. ## What is at stake Since 5 February 2026 the Information Commissioner can fine PECR breaches onthe UK GDPR scale. Section 115 of, and Schedule 13 to, the Data (Use andAccess) Act 2025 substitute a new Schedule 1 into PECR, applying the maxima insection 157 of the Data Protection Act 2018. The higher maximum there, ats.157(5), is £17,500,000 or 4% of total annual worldwide turnover in thepreceding financial year, whichever is higher. Schedule 13 came into force on5 February 2026 by S.I. 2026/82, regulation 2(z14). Before that date PECR penalties were capped far lower. If you last read aboutthis more than a year ago, the number you are carrying around is out of date. ## Sources Read these rather than trusting the summary above: - PECR 2003, reg 2, definitions, including "corporate subscriber" and "individual": legislation.gov.uk/uksi/2003/2426/regulation/2- PECR 2003, reg 22, unsolicited electronic mail: legislation.gov.uk/uksi/2003/2426/regulation/22- PECR 2003, reg 23, sender identity and opt-out address: legislation.gov.uk/uksi/2003/2426/regulation/23- Companies Act 2006, s.1202: legislation.gov.uk/ukpga/2006/46/section/1202- Data Protection Act 2018, s.157: legislation.gov.uk/ukpga/2018/12/section/157- Data (Use and Access) Act 2025, Schedule 13: legislation.gov.uk/ukpga/2025/18/schedule/13- The ICO's guidance on electronic mail marketing, at ico.org.uk, for the regulator's own reading of all of the above. Citations checked against the legislation on 3 September 2026. Legislationchanges; check the "latest available" version before relying on any of it. ## Not for you if - You want permission to email a list you already know is wrong. The check will not give it to you, and the soft opt-in will not either.- You are marketing to consumers. The individual subscriber rules apply, but consumer marketing has more to it than this covers.- You are outside the UK and not targeting UK recipients. Other regimes differ substantially, particularly on whether business addresses are treated separately at all.- You want legal advice. Read the sources, then get some. --- Written by TheCold.Ai, a B2B outbound agency in Middlesbrough, England.Not affiliated with Anthropic. Not legal advice. Whether you may send a cold email in the UK does not depend on whether the address is a business address. It depends on what the recipient legally is. PECR restricts unsolicited marketing email to individual subscribers, and sole traders and ordinary English partnerships are individual subscribers. Most lists are loaded without anybody checking, because the check requires knowing each prospect's legal form and no list vendor supplies it. This skill makes Claude do that classification first and suppress the rows that fail.
The classification table, from the definition itself
Companies, LLPs, chartered bodies, corporations sole and partnerships in Scotland are corporate subscribers. Sole traders and general partnerships in England, Wales and Northern Ireland are individual subscribers, because the regulation defines an individual to include an unincorporated body of individuals. Each row cites the sub-paragraph it comes from.
Two answers that catch people out
A Scottish partnership is a corporate subscriber and an English one is not: Scottish partnerships have separate legal personality and are named in the definition. And an LLP is not a partnership for this purpose at all, it is a body corporate, so it goes in with the companies. Same trade, same size, different answer.
Why the soft opt-in cannot rescue a cold list
The exception requires the details to have been obtained in the course of the sale, or negotiations for the sale, of a product or service to that person. A purchased or scraped list cannot meet that wording whatever the vendor calls it. The skill quotes the test rather than paraphrasing it, because the paraphrases in circulation are what create the confusion.
The message, not just the list
Sender identity must not be disguised or concealed and there must be a valid address for opt-out requests. Opt-outs are actioned as soon as possible: there is no 28 day grace period in PECR, and the skill says so, because that particular myth is everywhere.
The obligations that survive a corporate classification
Clearing PECR does not clear the UK GDPR. A named person's work address is personal data, so a lawful basis, a written balancing test, Article 14 transparency about where the data came from, and an absolute right to object all still apply.
Written here, from the first line. Nothing to credit, which is worth saying out loud on a page where most of the other files do have somebody to credit.
| Field | Value |
|---|---|
| Based on | Nothing. Written by TheCold.Ai from the first line. |
| Published | 2026-09-03, and revised in place since. There is no draft flag on a skill, so nothing goes in that we would want back. |
| This file's licence | MIT. Copy it, change it, use it with your own clients. |
This is not worth your time if any of these is true. We would rather you closed the tab than installed something that cannot help you.
- You want permission to send to a list you already suspect is wrong. The check will not give it, and neither will the soft opt-in.
- You are marketing to consumers. The individual subscriber rules apply, but consumer marketing has more to it than this covers.
- You are outside the UK and not targeting UK recipients. Other regimes differ substantially on whether business addresses are treated separately at all.
- You want legal advice. Read the sources it cites, then get some.
Want it run for you instead?
These files are the judgement. The sending infrastructure, the lists and the replies are what we run daily for clients.
Questions about this skill
Straight answers. If yours isn't here, ask it on the call: we'd rather tell you no than sell you the wrong thing.
Is this legal advice?
How do I find out whether a prospect is a sole trader?
What happens to the rows that fail?
Has the penalty for getting this wrong changed?
Does the skill hold its author to the same standard?
The rest of measuring, capacity and compliance: inbox-capacity-planner and outbound-analyst. Everything sits on the library page, next to The capacity planner, which is the one people usually want after this. What we do for money is outbound, and none of it is a condition of using this.
Claude is a product of Anthropic. TheCold.Ai is not affiliated with, endorsed by or connected to Anthropic.