Guide

Cold email rules for UK small businesses: PECR explained simply

What UK electronic marketing law actually requires before you email a business you've never spoken to, and where B2B differs from B2C.

Published 15 August 2026 · Scoutline

Short answer: PECR — the Privacy and Electronic Communications Regulations 2003 — is the UK law that governs unsolicited marketing email. It treats an individual subscriber (which includes sole traders and some small partnerships) differently from a genuinely corporate recipient like a limited company: individuals generally need consent or a valid 'soft opt-in' first, while purely corporate marketing sits outside that specific consent rule. Either way, every message needs a clear sender identity and a working way to opt out. This is general information, not legal advice — check the ICO's own guidance before relying on it.

If you're pitching websites to local businesses cold, by email, PECR is the law that actually applies — not UK GDPR directly, though the two sit alongside each other. It has a reputation for being confusing, mostly because the rule genuinely does depend on who you're emailing, not just what you're saying.

This section is general information, not legal advice, and the detail matters enough that you should check the ICO's own guidance directly rather than relying on a summary.

Individual subscribers vs corporate subscribers

PECR's consent requirement for marketing email applies to individual subscribers — and that category is broader than "a person's personal email address." It generally includes sole traders and some small partnerships, which covers a large share of exactly the kind of local business this guide is about. A genuinely corporate body, like a limited company, is generally treated differently: PECR's specific consent rule for individual subscribers doesn't apply to marketing sent to the company itself, though you're still expected to identify yourself clearly, and UK GDPR still applies to any personal data of a named individual you hold and use to do it.

What that means in practice

  • Emailing a sole trader or small partnership cold — a huge share of local trades — generally needs either their consent or a valid "soft opt-in" first.
  • Emailing a limited company at a general or role-based address is generally outside that specific consent rule, though basic transparency and opt-out rules still apply.
  • Either way, you must not conceal or disguise your identity, and every message needs a genuine, working way to opt out of further contact.

The "soft opt-in" exception

This lets you email someone you've had a genuine prior sales relationship with, about similar products or services, provided you gave them a clear chance to opt out when you collected their details and in every message since. It doesn't apply to a business you've never dealt with before — which is most of what a genuinely cold pitch is, so most cold outreach can't rely on it.

What a compliant message actually needs

  • A real, identifiable sender — your name or business, not a disguised or anonymous address.
  • A clear, working way to say "don't contact me again," and you have to actually honour it going forward.
  • Honest content — PECR sits alongside general consumer protection law, which already bans misleading claims.

Where Scoutline fits

Scoutline only ever drafts an outreach email — it's written from a business's own real, public facts and handed back to you to review and send yourself, from your own inbox. There's no send button anywhere in the product. That's deliberate: you're the one actually sending it, so PECR responsibility for that message sits with you, and a draft-only tool can't quietly make that decision on your behalf.

Common questions

Questions people actually ask

Is cold emailing a business illegal in the UK?

Not automatically. PECR (the Privacy and Electronic Communications Regulations 2003) is the relevant law, and it treats emailing an individual subscriber — which includes sole traders and some small partnerships — differently from emailing a genuinely corporate body like a limited company. Sole traders generally need consent or a valid soft opt-in first; purely corporate recipients are usually outside that specific consent rule, though you still have to identify yourself clearly and give a working way to opt out. This isn't legal advice — check the ICO's guidance before relying on it.

What is the PECR 'soft opt-in'?

It's an exception that lets you email someone you've had a genuine prior sales relationship with, about similar products or services, provided you gave them a clear chance to opt out when you collected their details and in every message since. It doesn't apply to a business you've never dealt with, which is why a genuinely cold pitch usually can't rely on it.

Does Scoutline send cold emails for me?

No — Scoutline only drafts them. Every draft is written from a business's own real, public facts and handed back to you to review and send yourself from your own inbox. You're the sender, so PECR responsibility sits with you, which is also why the tool never sends on your behalf.