---
name: uk-pecr-cold-email-checker
description: Screens a UK B2B prospect list and a draft cold email against PECR and the UK GDPR before anything is sent. Classifies each recipient by legal form, because that is what decides whether you may email them at all, and checks the message itself against the sender-identity and opt-out rules. Use before loading a list, or when auditing a campaign that is already running.
license: MIT
---

# UK cold email checker: PECR and UK GDPR

**This is not legal advice.** It is a structured check written by people who
send cold email in the UK, citing primary legislation you can read yourself.
Every citation below is to legislation.gov.uk. Follow them. If the answer
matters commercially, take advice.

Two separate regimes apply to a UK cold email and people routinely conflate
them:

- **PECR**, the Privacy and Electronic Communications (EC Directive)
  Regulations 2003, decides whether you may send the message at all. It turns
  on what the recipient legally *is*.
- **The UK GDPR** decides whether you may hold and use their data. It applies
  whenever the address identifies a person, which for cold B2B email is nearly
  always.

Clearing one does not clear the other. Work through both.

## Step 1: classify every recipient by legal form

This is the step almost everyone skips, and it is the one that decides the
outcome. PECR reg 22 restricts unsolicited marketing email to **individual
subscribers**. It does not restrict it to **corporate subscribers** in the same
way. So the first question is never "is this a business address" but "what kind
of legal person is behind it".

Reg 2(1) defines a corporate subscriber. Read against that definition:

| What you are contacting | PECR classification | Why |
|---|---|---|
| Registered company, Ltd or PLC | Corporate subscriber | reg 2(1)(a), a company within the Companies Act definition |
| Limited liability partnership | Corporate subscriber | reg 2(1)(e), a body corporate and a legal person distinct from its members |
| Partnership in Scotland | Corporate subscriber | reg 2(1)(c), named in the definition explicitly |
| Company by royal charter or letters patent | Corporate subscriber | reg 2(1)(b) |
| Corporation sole | Corporate subscriber | reg 2(1)(d) |
| Sole trader | **Individual subscriber** | not within the corporate definition |
| General partnership in England, Wales or Northern Ireland | **Individual subscriber** | reg 2(1) defines "individual" as a living individual and includes an unincorporated body of such individuals |

Two of those rows surprise people every time.

**A Scottish partnership is a corporate subscriber and an English one is not.**
Scottish partnerships have separate legal personality and the definition names
them. The identical business, same trade, same size, one on each side of the
border, gets a different answer.

**An LLP is not a partnership for this purpose.** The name misleads. It is a
body corporate, so it falls in with the companies.

One quirk worth knowing when you read the source: reg 2(1)(a) still cites
section 735(1) of the Companies Act **1985**, which has been superseded. The
practical effect is unchanged, registered companies are corporate subscribers,
but do not be thrown when the cross-reference points at a repealed Act.

### How to establish the legal form

Do not infer it from the domain, the email address, or how the website is
written. A one-person consultancy with a polished site is very often a sole
trader, and that is the case where getting it wrong costs you.

Check the register. A UK company or LLP has a company number and appears on
Companies House. If there is no registration, you are almost certainly looking
at a sole trader or an unincorporated partnership, which means an individual
subscriber. Absence of evidence is the answer here, not a reason to guess.

Record the classification against every row before the list is loaded, not as a
spot check afterwards. If your CRM has no field for it, add one: this is the
field that decides which channel a prospect is even eligible for.

## Step 2: apply the consequence

**Corporate subscriber.** Reg 22 does not prohibit the send. You still have UK
GDPR obligations if the address identifies a person, which a
firstname.lastname address plainly does. Go to step 4.

**Individual subscriber.** Reg 22(2) prohibits unsolicited electronic mail for
direct marketing unless the recipient has previously notified you that they
consent to it. A cold prospect has not.

The one exception, at reg 22(3), is the soft opt-in, and it does not help you.
It requires that the contact details were obtained "in the course of the sale
or negotiations for the sale of a product or service" to that person. A
purchased list, a scraped list, or any list of people you have never transacted
with cannot satisfy that wording, however the vendor describes it. Read the
words: the test is about a sale to that recipient, not about the data being
business data or lawfully sourced.

So the honest conclusion for an individual subscriber on a cold list is: **do
not email them.** Suppress the row. Reach them another way, or not at all.

There is a charity-specific provision at reg 22(3A), added in February 2026. If
you are a charity, read it. This check assumes you are not.

**On the alternative channels**, be careful about swapping one problem for
another. Telephone marketing has its own PECR rules, including screening
against the Telephone Preference Service and its corporate register, and this
skill does not cover calls. Check them separately before you route a suppressed
row to a phone list.

## Step 3: check the message, not just the list

Reg 23 applies to the email itself, and it applies to corporate and individual
recipients alike. A message must not be sent where:

- the identity of the sender is disguised or concealed, or
- there is no valid address to which the recipient can send an opt-out request.

Check the draft for all of these:

- [ ] The sending identity reconciles with a real, checkable business. If the
      mail goes out from a secondary domain, the body must still make clear who
      is actually writing. This is the rule that a bare first-name signature on
      an unfamiliar domain fails.
- [ ] There is a working reply path, and a reply asking to stop is honoured.
      An unsubscribe link that goes nowhere is worse than none.
- [ ] Opt-outs are actioned promptly and permanently. The ICO's expectation is
      that this happens as soon as possible. There is no 28 day grace period in
      PECR, and anyone who tells you there is has confused it with something
      else.
- [ ] The opt-out is recorded somewhere that survives a change of tool. A
      suppression list held only inside a sending platform is one migration
      away from re-contacting someone who asked you not to.

## Step 4: the UK GDPR obligations that apply regardless

These are not optional because the recipient is a company. They attach to
personal data, and a named person's work address is personal data.

- [ ] **A lawful basis.** For cold B2B the usual basis is legitimate interests,
      Article 6(1)(f). That requires a balancing test written down before you
      send, not reconstructed afterwards if someone complains. Direct marketing
      can be a legitimate interest; it is not automatically a winning one.
- [ ] **Article 14 transparency.** You obtained the data from somewhere other
      than the person. That triggers a duty to tell them what you hold, where
      it came from and what you are doing with it, normally within a month or
      at first contact. In practice this is a line in the email linking to a
      privacy notice that actually names your sources.
- [ ] **The right to object.** Under Article 21 an objection to direct
      marketing is absolute. There is no balancing exercise once it is made.
- [ ] **Data minimisation and retention.** Decide how long a non-responder
      stays on the list, write it down, and delete on that schedule.

## Step 5: check your own disclosures

If you trade under a name that is not the proprietors' own surnames, Chapter 2
of Part 41 of the Companies Act 2006 requires you to disclose the name of each
proprietor and a UK address at which documents can be served.

Note where that obligation actually lands, because it is widely misquoted.
s.1202(1) lists business letters, written orders for goods or services,
invoices and receipts, and written demands for payment. s.1204 covers a notice
at business premises. **Websites are not in the list.** s.1202(2) additionally
requires the information to be given immediately, in writing, to anyone in the
course of business who asks for it.

So the check is: does your invoice carry it, and would you produce it on
request. A footer on the website is good practice and reassures a recipient
that you are real, which helps with reg 23, but it is not what Part 41 is
asking for.

**The author of this skill currently fails part of this check.** TheCold.Ai is
a partnership trading under a name that is not the partners' surnames. The
partners are named, but no address for service has been published yet, because
no business address exists and publishing a home address was declined. That is
a known gap being closed, and it is stated here because a compliance checker
that hides its own author's failure is worth nothing.

## What the check should report

For a list, per row: the legal form, the classification, the verdict, and where
the classification came from. Then a count of rows suppressed and why. If you
cannot establish the legal form for a row, that row is not "probably fine": say
unknown, and treat unknown as individual until someone checks.

For a message: each reg 23 item as pass or fail, each UK GDPR item as present
or missing, and the specific sentence you would change.

Never report a percentage compliant. A list is not 94% sendable. The rows that
fail are the whole finding.

## What is at stake

Since 5 February 2026 the Information Commissioner can fine PECR breaches on
the UK GDPR scale. Section 115 of, and Schedule 13 to, the Data (Use and
Access) Act 2025 substitute a new Schedule 1 into PECR, applying the maxima in
section 157 of the Data Protection Act 2018. The higher maximum there, at
s.157(5), is £17,500,000 or 4% of total annual worldwide turnover in the
preceding financial year, whichever is higher. Schedule 13 came into force on
5 February 2026 by S.I. 2026/82, regulation 2(z14).

Before that date PECR penalties were capped far lower. If you last read about
this more than a year ago, the number you are carrying around is out of date.

## Sources

Read these rather than trusting the summary above:

- PECR 2003, reg 2, definitions, including "corporate subscriber" and
  "individual": legislation.gov.uk/uksi/2003/2426/regulation/2
- PECR 2003, reg 22, unsolicited electronic mail:
  legislation.gov.uk/uksi/2003/2426/regulation/22
- PECR 2003, reg 23, sender identity and opt-out address:
  legislation.gov.uk/uksi/2003/2426/regulation/23
- Companies Act 2006, s.1202: legislation.gov.uk/ukpga/2006/46/section/1202
- Data Protection Act 2018, s.157: legislation.gov.uk/ukpga/2018/12/section/157
- Data (Use and Access) Act 2025, Schedule 13:
  legislation.gov.uk/ukpga/2025/18/schedule/13
- The ICO's guidance on electronic mail marketing, at ico.org.uk, for the
  regulator's own reading of all of the above.

Citations checked against the legislation on 3 September 2026. Legislation
changes; check the "latest available" version before relying on any of it.

## Not for you if

- You want permission to email a list you already know is wrong. The check will
  not give it to you, and the soft opt-in will not either.
- You are marketing to consumers. The individual subscriber rules apply, but
  consumer marketing has more to it than this covers.
- You are outside the UK and not targeting UK recipients. Other regimes differ
  substantially, particularly on whether business addresses are treated
  separately at all.
- You want legal advice. Read the sources, then get some.

---

Written by TheCold.Ai, a B2B outbound agency in Middlesbrough, England.
Not affiliated with Anthropic. Not legal advice.
