Skip to content
← BlogCompliance

Cold email in the UK post-Brexit: UK GDPR, PECR, and the corporate-subscriber rule

UK GDPR started as a copy of EU GDPR but is diverging under the Data (Use and Access) Act 2025. Here's what changed, and PECR's corporate vs. individual subscriber split for B2B email.

By Gabriel Lara, Developer Relations, Norbelys

Founder-reviewed ·How we research and correct articles

Brexit didn’t delete the UK’s data protection law — it forked it. The day the UK left the EU’s legal framework, EU GDPR became UK GDPR: the same regulation, retained in domestic law, now enforced entirely by the UK’s own regulator, the Information Commissioner’s Office (ICO), instead of by an EU authority. For a while the two were near-identical twins. They’re no longer guaranteed to stay that way, and 2025 is the year that stopped being theoretical.

Same starting point, separate regulator, separate trajectory

UK GDPR is, structurally, EU GDPR minus the parts that only made sense inside the EU’s institutional machinery (references to EU bodies, one-stop-shop cross-border mechanisms, and so on) — everything else, including Article 6’s lawful bases and Article 21’s right to object, carried over. If you already understand how legitimate interest and the balancing test work under EU GDPR — covered in depth in cold email rules: the EU’s GDPR — you understand most of UK GDPR’s baseline for B2B outreach, because for years it was the identical text with a different enforcer.

That’s changing. The Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025, amends both UK GDPR and PECR, and its provisions are commencing in phases through 2026. Two changes from the DUAA matter directly for cold email:

  • A statutory basis for treating direct marketing as a legitimate interest. UK GDPR now gives direct marketing (alongside intra-group data sharing and network security) explicit statutory footing as a legitimate interest under Article 6 — separate from, and in addition to, the existing “recognised legitimate interests” category the Act also created for a specific list of public-interest purposes (things like safeguarding and crime prevention) that don’t require a balancing test at all. Direct marketing sits in the former group: you still need to run the balancing test, but Parliament has now said explicitly that it can qualify.
  • PECR’s penalty ceiling jumped to match UK GDPR’s. Before the DUAA, the maximum fine the ICO could issue for a PECR breach — unsolicited electronic marketing included — was capped at £500,000. Under the DUAA, that cap now matches UK GDPR’s own tier: up to £17.5 million or 4% of global annual turnover, whichever is higher. For a large sender, that’s not a rounding-error difference — it changes what “a PECR breach” can realistically cost.

Both are real, current divergences from EU GDPR, which has no exact equivalent legislative event on this timeline. This is the practical answer to “is UK GDPR still the same as EU GDPR”: mostly yes on structure, no longer identical on specifics, and the gap is a live, moving target rather than a settled one.

PECR: the UK’s version of ePrivacy

Where UK GDPR governs data processing generally, the Privacy and Electronic Communications (EC Directive) Regulations 2003 — PECR — is the UK’s implementation of the ePrivacy Directive, and it’s PECR, not UK GDPR directly, that sets the specific rule for sending unsolicited marketing email. This is the same GDPR/ePrivacy split covered for the EU in cold email rules: the EU’s GDPR — the UK just runs its own statutory instrument instead of a Directive transposed by a member state.

The rule that actually matters for B2B: corporate vs. individual subscribers

Here’s PECR’s most consequential feature for B2B senders, and it’s one EU GDPR doesn’t map onto cleanly: Regulation 22, the consent requirement for unsolicited marketing by electronic mail, applies to individual subscribers — in practice, natural persons, sole traders, and unincorporated partnerships — but according to ICO guidance on business-to-business marketing, it does not apply to corporate subscribers: incorporated bodies with their own separate legal personality — limited companies, LLPs, and Scottish partnerships, broadly.

Practically: a cold email sent to a role-based or personal address tied to an incorporated company’s own email account and domain is sent to a corporate subscriber, and Regulation 22’s opt-in requirement doesn’t bind you the way it would for an individual subscriber. This is a materially different starting point than GDPR’s legitimate-interest analysis, which turns on whether the message is addressed to an identifiable individual regardless of what kind of entity employs them.

That said, “doesn’t apply” is not “no rules apply.” Two things stay true regardless of subscriber type, per the same ICO guidance:

  • Regulation 23 prohibits disguising or concealing your identity as the sender, for both corporate and individual subscribers, solicited or unsolicited.
  • You must provide a valid address for opt-out requests, again for both subscriber types.

And critically: PECR’s corporate-subscriber exemption doesn’t switch off UK GDPR. If the message is directed at, or the sending process involves processing, a named individual’s personal data — which most B2B cold email does, since you’re targeting a person’s role at the company — UK GDPR’s lawful-basis requirement (legitimate interest, with its balancing test) and the individual’s right to object under Article 21 still apply on top of PECR. The corporate-subscriber carve-out narrows PECR’s opt-in requirement; it does not narrow UK GDPR.

Soft opt-in: PECR’s exception for individual subscribers

For the individual subscribers PECR’s Regulation 22 does cover, there’s a narrow exception commonly called the “soft opt-in,” and ICO guidance sets out four conditions that all have to be met:

  1. The contact details were collected in the course of a sale or negotiations for a sale of a product or service.
  2. The marketing is only for the sender’s own similar products or services.
  3. The recipient was given a simple opportunity to opt out when their details were collected, and didn’t take it.
  4. Every subsequent marketing message gives an easy way to opt out.

The soft opt-in is built for existing or prospective customers you already had a sales relationship with — it doesn’t extend to a purchased list or a cold contact you’ve never transacted with, corporate subscriber exemption or not.

What this looks like in practice

A UK-aware B2B cold-email program tends to check three things per campaign, not one:

  • Is the recipient at a corporate or individual subscriber address? Corporate narrows PECR’s Regulation 22 exposure; individual doesn’t.
  • Does UK GDPR’s legitimate-interest test hold up regardless? Since most B2B outreach still processes a named person’s data, this check runs even when PECR’s opt-in rule doesn’t apply.
  • Is sender identity clear and is there a working opt-out address, unconditionally, because Regulation 23 and basic UK GDPR transparency obligations don’t carve out an exception for corporate subscribers.

Since UK GDPR shares its lawful-basis and balancing-test structure with EU GDPR, read cold email rules: the EU’s GDPR for the mechanics of that part in full. And because sender identification and unsubscribe hygiene are universal requirements across every jurisdiction in this series, see built on U.S. anti-spam law for how the same category of rule plays out under CAN-SPAM, and DMARC monitoring for keeping the domain behind your identity claim authenticated.

Frequently asked questions

Is UK GDPR the same as EU GDPR?

It started as an identical copy, retained in UK law after Brexit and enforced by the ICO instead of an EU authority. It is now diverging: the Data (Use and Access) Act 2025 amended UK GDPR with a statutory basis for treating direct marketing as a legitimate interest and raised PECR's maximum penalty to match UK GDPR's own tier. Structurally similar, no longer guaranteed identical.

Can I cold email a company's generic or role-based inbox without consent under UK law?

PECR's Regulation 22 consent requirement for unsolicited electronic mail applies to individual subscribers, not corporate subscribers such as incorporated companies, according to ICO guidance. That narrows PECR's opt-in requirement for genuinely corporate addresses, but UK GDPR's lawful-basis requirements still apply if the message targets an identifiable person's data, and Regulation 23's ban on disguising sender identity applies regardless of subscriber type.

What is the PECR soft opt-in?

A narrow exception letting a business email existing or recent customers without fresh consent, provided the contact details came from a sale or sale negotiation, the marketing covers only similar products or services, the recipient had a chance to opt out at collection and didn't take it, and every message includes an easy opt-out. It does not extend to cold contacts with no prior sales relationship.

Did PECR penalties change recently?

Yes. The Data (Use and Access) Act 2025 raised the maximum penalty the ICO can issue for a PECR breach from £500,000 to match UK GDPR's tier — up to £17.5 million or 4% of global annual turnover, whichever is higher. This is a substantial increase in the ICO's enforcement ceiling for unsolicited electronic marketing violations.