Stacked Creator

An independent publication on cold email, lead data and sales CRMs, edited in Japan.

No. 09 Guides, filed under Guide

Is Cold Email Legal in the UK? PECR, UK GDPR and the 2026 Changes

Yes to companies and LLPs without consent; sole traders and most partnerships need it. Notices, tracking pixels and fines under UK law on Oct 2, 2026.

On this page 14 sections

UK law sorts cold email by the recipient’s legal form: you can email a limited company or an LLP without consent, but not a sole trader or a partnership in England, Wales or Northern Ireland other than an LLP. Getting it wrong costs more since February 5, 2026: for a breach from that date, a business faces a maximum fine of £17.5 million or 4% of worldwide turnover, whichever is higher, up from £500,000.

Quick answer

Yes to a company, LLP or Scottish partnership: PECR needs no consent, just your identity and an opt-out address. Sole traders and other partnerships need consent. If the address names a person, UK GDPR adds a legitimate-interests test, honoring objections and a notice within a month of collection, or by your first email if sooner. Law checked October 2, 2026.

Not legal advice. No lawyer has reviewed this page. Law checked: October 2, 2026, on legislation.gov.uk and the ICO’s website. The ICO marks its business-to-business and electronic mail marketing pages as under review because of the Data (Use and Access) Act; read them again before you launch (see what changed in 2026 and what’s under review).

Outside this guide: UK consumers at personal addresses, charity fundraising, phone campaigns (one FAQ aside) and recipients in the EU (see consent rules for cold email in EU countries). Sending from the US, Canada or Australia? See what reaches senders abroad. For a ruling on one campaign, ask a UK data protection lawyer.

Step 1: Is the recipient a company or an “individual subscriber”?

PECR’s consent rule for marketing email covers only “individual subscribers” (regulation 22(1)4). So first sort each contact by the legal form of the business behind the address.

Corporate subscriber: no PECR consent needed for emailIndividual subscriber: consent needed for a cold email
Limited company (Ltd or PLC)Sole trader
Limited liability partnership (LLP)A partnership in England, Wales or Northern Ireland that isn’t an LLP, limited partnerships included
Scottish partnership, including a Scottish limited partnershipAny other unincorporated body of individuals
Royal charter company, corporation sole, or any other body that is a legal person distinct from its membersSomeone who gave you a personal address instead of a work one (an ICO example)
“Some government bodies” (the ICO’s B2B guidance)Anyone you can’t place: the ICO says to treat unclear details as belonging to an individual subscriber
An employee’s work address at any of the above: the subscriber is the employer

Based on the definitions in PECR regulation 21 and the ICO’s business-to-business marketing24 guidance, both checked October 2, 2026. The ICO page is marked as under review. The limited partnership entries are our reading of the ICO’s partnership categories (see below).

How to check. Look the business up on the Companies House register39. Company and LLP records show a “Company type” field, such as “Public limited Company” or “Limited liability partnership.”

One catch: the register also lists limited partnerships, as “Company type: Limited partnership,” and that label doesn’t tell you which side they’re on. Look at the registration number instead. Companies House uses LP for limited partnerships in England and Wales, SL for Scotland and NL for Northern Ireland. An SL partnership is a Scottish partnership, so it’s corporate. An LP or NL partnership is a partnership in England, Wales or Northern Ireland, which the ICO lists among individual subscribers.

A missing record doesn’t settle it either. GOV.UK says a sole trader can start trading without registering (Self Assessment aside) and that a partnership registers with HMRC. So no Companies House record is a sign, not proof, that you’re looking at an individual subscriber. Record the result in a column when you build the list, wherever the contacts come from (see where small teams get lead data).

A common misreading. Some guides call regulation 22(3) the B2B exemption. It isn’t: 22(3) is the soft opt-in for past customers. Companies fall outside the consent rule because 22(1) applies it only to individual subscribers.

Step 2a: What does PECR still require when you email a company or LLP?

You don’t need consent, but every marketing email must meet regulation 235 of PECR, which applies whoever the recipient is.

  • Don’t hide who is sending. You can’t disguise or conceal the identity of the person the email is sent on behalf of.
  • Give a valid opt-out address that the recipient can use to ask you to stop.
  • Make it recognizable as marketing. Regulation 23 also bars emails that break regulation 7 of the Electronic Commerce Regulations 200211. That rule says a commercial communication must be “clearly identifiable as a commercial communication” and must clearly identify who it’s sent on behalf of. Any promotional offer, such as a discount or gift, must be flagged, with its conditions easy to find. Emails that encourage people to visit websites breaking that rule are barred too.

Opt-outs from companies. PECR doesn’t say you must act on a company’s opt-out, but the ICO says you should. It advises keeping a “do not email or text” list of companies that object and screening every new list against it. If the address names a person, acting on the objection is required (Step 3).

Skipping these isn’t a technicality: breaking regulation 23 carries the same maximum fine as breaking the consent rule (see fines).

Step 2b: Can you cold email a sole trader or partnership?

Not without their consent. The only other route is the soft opt-in (regulation 22(3)). It covers people whose details you got while selling, or negotiating to sell, them something, and only for your own similar products, with an opt-out offered then and in every message. The ICO says it “does not apply to prospective customers or new contacts,” and gives bought-in lists as an example.

Consent has to meet the UK GDPR standard, which the ICO describes as freely given, specific, informed and unambiguous. If you can’t get it, leave these contacts out of email and LinkedIn campaigns. The ICO notes that post isn’t covered by PECR, and that live calls are possible after screening the phone registers (see the FAQ). The UK GDPR still applies to a named person’s data either way.

Step 3: Does the UK GDPR apply when the address names a person?

Yes. An address such as [email protected] identifies a person. So on top of PECR you need a lawful basis, a privacy notice by your first email or within a month of getting the data (whichever is sooner), and a way to honor objections. The ICO says this holds “even in a business context,” and even when you found the details on a company website, Companies House, social media or in press articles.

Lawful basis. The ICO says the two bases most relevant to B2B marketing are consent and legitimate interests. Where PECR doesn’t require consent, it says legitimate interests is likely to fit in many cases. That depends on a three-part test: identify the interest, show the processing is necessary for it, and balance it against the person’s interests, rights and freedoms.

  • Since February 5, 2026, article 6(11)13 of the UK GDPR names direct marketing among the kinds of processing that may count as necessary for a legitimate interest. The ICO says this “only gives you a possible answer to the purpose test.” You still do the other two parts, and you should record a legitimate interests assessment (LIA) before you use the data. The ICO offers a sample LIA template26 (a Word file).
  • The same Act added a separate basis for “recognised legitimate interests.” Its list in Annex 114 covers disclosures for public tasks, national security, public security and defense, emergencies, crime, and safeguarding vulnerable people. Marketing isn’t on it.

When the notice is due. If you didn’t get the data from the person, article 14(3)15 sets two outer limits: one month after you obtain it, and your first message if you use it to contact them. Both apply, so the earlier one is your deadline. The ICO’s B2B guidance puts it as “no later than one month from the date of collection.” A list you build in March and first email in May is late: the notice was due in April. The ICO’s right to be informed27 guidance lists a few exceptions, such as when the person already has the information.

What the notice has to cover (article 14(1)–(2), in short):

  • who you are and how to contact you, plus your UK representative if you have one (see sending from abroad)
  • why you’re using the data, your lawful basis, and the legitimate interest you rely on
  • what kinds of data you hold and where you got them, including whether they came from publicly accessible sources
  • who receives the data, any transfers outside the UK, and how long you keep it
  • their rights, including access, erasure and objection; the right to object must be presented “clearly and separately from any other information,” at the latest in your first message (article 21(4)16)
  • since June 19, 2026, the right to complain to you, alongside the right to complain to the ICO

What that looks like in a first email. The ICO suggests a layered approach: a short notice with the key points, and more detailed layers behind it (its right to be informed guidance, also under review). Its B2B guidance gives a similar example: a conference organizer emailing past delegates makes clear why they’re receiving the email, links to its updated privacy information and offers a clear unsubscribe. For a UK prospect, the short layer at the foot of a first email could read like this (our example, not ICO wording):

Why this email: I’m [name] at [company]. I found your work address on [source, such as your company’s website] and I’m writing because [the interest you rely on, in one line].

Your details: what we hold, how long we keep it and your rights are set out at [link to the full notice].

You can object to this marketing at any time. Reply “stop” and we’ll add you to our do-not-contact list.

Complaints: to us through [link to a complaint form], or to the ICO.

The short layer doesn’t replace the full notice; the linked page still has to cover the list above. Which items sit in the email and which behind the link is a judgment call, except the objection line: article 21(4) requires it clearly and separately by your first message.

Complaints to you. Since June 19, 2026, section 164A of the Data Protection Act 201819 requires you to make complaints easy to send, for example with a complaint form that can be completed electronically and by other means. You must acknowledge each complaint within 30 days, respond without undue delay and tell the person the outcome.

Objections. Once someone objects to direct marketing, you can no longer use their data for it (article 21(3)). The ICO calls this an absolute right with no grounds to refuse. It recommends moving the person to a suppression list rather than deleting them, so you can screen future lists against it.

Step 4: Do LinkedIn messages and open tracking fall under PECR?

They can. The ICO counts direct messages on social media as electronic mail. It also says PECR’s rule on storing or reading information on a device applies to tracking pixels in marketing emails, whoever the recipient is.

LinkedIn and similar sites. The ICO doesn’t name LinkedIn. It says people on professional networking sites are “unlikely to be on the sites exclusively in their business capacity.” If someone uses such a platform “in their personal, albeit professional, capacity,” marketing messages to them are “not considered B2B marketing.” Our reading: don’t rely on the company rule for a LinkedIn message to a UK prospect. Treat it like an email to an individual subscriber, which for a cold message means consent, or drop the LinkedIn step for UK contacts. The UK GDPR applies to the profile data you collect either way (ICO).

Open tracking. The ICO says the cookie rules apply when a pixel in your email stores information on the device used to open it, or reads information stored there, such as its location or operating system. It adds that they apply to all types of subscriber, companies included. The rule itself, PECR regulation 62, was replaced on February 5, 2026. Storing or accessing information on a device is now prohibited unless an exception in Schedule A17 applies. The exceptions are consent after clear information, transmitting a communication, what’s strictly necessary for a service the user asked for, some statistics and website-appearance uses, and emergency assistance.

Neither the ICO’s B2B page nor Schedule A1 says whether any exception other than consent covers an email open pixel. The ICO’s cookies page says it is based on the previous version of its guidance while a revised version is under consultation. The simplest option for UK lists is to switch open tracking off and measure replies instead (see why open data is unreliable). Check whether your sending tool tracks opens by default; the tools section shows what two vendors document.

Do UK rules apply if you email UK prospects from the US, Canada or Australia?

The UK GDPR can. It covers a business with no UK establishment when its processing relates to offering goods or services to people in the UK, or to monitoring their behavior there (article 3(2)12).

  • UK representative. Where article 3(2) applies, you must designate a representative in the UK in writing (article 2717). The exception is processing that is occasional and unlikely to result in a risk to people’s rights and freedoms, and that doesn’t include large-scale processing of special category or criminal offence data. Public bodies are also exempt. Whether a regular outbound campaign counts as occasional is a question for a UK data protection lawyer.
  • PECR. The ICO pages we read for this guide don’t say how PECR applies to a sender based outside the UK. Until you have advice that says otherwise, the cautious course is to follow Steps 1–4 for every UK recipient.
  • Your own country’s law. It may apply to the same email as well. This page doesn’t cover it; for the US, Canada and Australia, see which country’s law applies to your list.

What are the fines for breaking PECR since February 5, 2026?

For a breach on or after February 5, 2026, the most the ICO can fine a business under PECR is £17.5 million or 4% of its total annual worldwide turnover in the preceding financial year, whichever is higher. In any other case the maximum is £17.5 million (Data Protection Act 2018, section 157(5)18, applied by PECR Schedule 18).

QuestionAnswer on October 2, 2026
Which rules carry that maximum?The direct marketing rules (regulations 19–24), including consent (22) and sender identity and opt-out (23), plus the device rule behind tracking pixels (6) and a few others
What about a breach before that date?It’s handled under PECR as it stood before February 5, 2026, with a maximum of £500,000
Can a director be fined personally?Yes, when a company or Scottish partnership breaks the direct marketing rules with a director’s or other officer’s consent or connivance, or through their neglect

Checked on legislation.gov.uk, including the commencement notes, on October 2, 2026. Full list of rules: PECR Schedule 1, paragraph 18 (regulations 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23, 24 and 32B(4)–(5)). Earlier breaches: S.I. 2026/82, regulation 1122, and the old maximum in S.I. 2010/31, regulation 2. Directors: Schedule 1, paragraph 15. The ICO’s statement of February 5, 2026 gives the same new maximum.

These are ceilings, not tariffs. When deciding whether to fine and how much, the regulator must have regard to the factors listed in section 155(3) of the Data Protection Act 2018, as applied to PECR. GOV.UK’s direct marketing page37 still said “You can be fined up to £500,000 for each unsolicited phonecall” when we checked it on October 2, 2026; the page shows no update date. For a breach since February 5, 2026, the maximum above applies instead.

What recent fines look like. Two recent ICO penalties show how the rules get enforced:

  • ZMLUK Limited, £105,000 (December 2025). It sent 67,772,285 marketing emails between January and July 2023, using data from a third-party website. People signing up there saw a list of 361 “partner” companies with no way to choose among them, so the ICO found the consent invalid. The ICO said ZMLUK was responsible as the sender even though it sent on behalf of another company, and that it relied on third-party data without sufficient checks on how consent was obtained.
  • KRA Consultancy Ltd, £300,000 (May 2026). It sent 5,575,715 marketing texts between April 2022 and May 2025, breaching regulations 22 and 23; texts count as electronic mail under PECR. Because the breaches came before February 5, 2026, the penalty was issued under the old regime, with its £500,000 cap.

Both involved messages to members of the public. We didn’t find a published PECR fine for cold email to companies on the ICO’s site. For agencies, the lesson from the ZMLUK case is that sending for a client doesn’t move PECR responsibility off you.

What changed in 2026, and what the ICO is still rewriting

The Data (Use and Access) Act 2025 changes this page relies on came in three steps in 2026: most on February 5, the complaints rules on June 19, and the change of regulator on September 30.

DateChangeMore
February 5, 2026PECR’s maximum fine rose to £17.5 million or 4% of worldwide turnover, whichever is higher, for breaches from that dateFines
February 5, 2026PECR’s device rule was replaced: storing or reading information on a device is banned unless a Schedule A1 exception applies. The ICO applies it to email tracking pixelsStep 4
February 5, 2026The UK GDPR names direct marketing as a possible legitimate interest; the new “recognised legitimate interests” basis doesn’t cover marketingStep 3
February 5, 2026Charities got their own soft opt-in for email (PECR regulation 22(3A)); businesses didn’tStep 2b
June 19, 2026Privacy notices must mention the right to complain to you, and you must handle those complaints, with an acknowledgment within 30 daysStep 3
September 30, 2026The office of Information Commissioner was abolished and its functions passed to the Information Commission, which says it will keep the name ICO. Anything the Commissioner did or had under way, including legal proceedings, is treated as done by the Commission. On October 2, 2026, ico.org.uk called itself the Information Commission’s Office—

Dates from the commencement regulations on legislation.gov.uk (S.I. 2026/8222 for February 5 and June 19; S.I. 2026/101523 for September 30), the ICO’s summary of the Act’s PECR changes and its news of September 15, 2026, all checked again October 2, 2026. Some of these provisions took effect in 2025 for limited purposes; the dates are the ones on which they apply in full.

ICO guidance still under review

Four ICO pages this guide relies on say they are under review after the Act, and a fifth says it is based on the previous version of its guidance. The ICO’s plans pages give a season for each update, not a date.

ICO pageStatus on the pageICO’s planned update
Business-to-business marketing“Under review and may be subject to change”“PECR advice for small organisations update”: drafting, due Autumn 2026 (pages covered not stated)
Electronic mail marketingUnder reviewSame entry as above
Right to objectUnder reviewDrafting, due Autumn 2026
Right to be informedUnder reviewDrafting, due Spring 2027
Cookies and similar technologiesBased on the previous version; revised guidance under consultationNo entry on the direct marketing plans page
How do we apply legitimate interests in practice?No review notice; already covers recognised legitimate interests—

Status as shown on each page on October 2, 2026. None of the “under review” notices carries a date. When the ICO publishes its revised PECR guidance, the rules on this page may change.

How we researched this

Each step goes back to the UK text on legislation.gov.uk, first read on September 29, 2026 and checked again on October 2, 2026: PECR, the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025. For the 2026 dates and the line between the new fines and the old £500,000 cap, we followed the commencement and transitional notes into two sets of commencement regulations and the 2010 penalty regulations; for regulation 23, into the Electronic Commerce Regulations 2002. From the ICO we used its guidance, news, February 5 statement, plans pages and two monetary penalty notices; from GOV.UK, three pages; from Companies House, four register records and its guide to number prefixes. The tool rows come from lemlist’s and Instantly’s help centers and Instantly’s pricing page, whose feature table we viewed in a browser, all read the same day; on September 30, 2026 we read the three Instantly pages behind the blocklist plan question again, the pricing table in the page’s HTML, and GOV.UK’s direct marketing page. On October 2, 2026 we opened every source listed below again, the pricing table once more in the page’s HTML, and found one change that affects this page: the name ico.org.uk uses for itself.

No UK campaign was sent and neither tool’s settings were tried for this guide. Two errors that recur in UK guides, calling regulation 22(3) a B2B exemption and quoting £500,000 as the cap for new breaches, are corrected here from the legislation itself; no commercial or law-firm guide is relied on for a rule. The ICO expects to publish updated PECR advice for small organizations in autumn 2026, so re-read its pages before a campaign. No UK solicitor or other lawyer has reviewed this guide.

What to check before emailing a UK list

Run each contact through Steps 1–4 before it goes into a sequence. A “no” in the middle column means fix it first or leave the contact out.

StepCheckIf not
Step 1Company, LLP or Scottish partnership, SL-numbered limited partnerships included?Sole trader, other partnership, personal address or can’t tell: no cold email or LinkedIn message without consent (Step 2b)
Step 2aSender named, email recognizable as marketing, working opt-out address, and the company not on your do-not-email list?Fix it before the send; breaking regulation 23 carries the same maximum fine as sending without consent
Step 3If the address names a person: LIA recorded, and a notice by the first email or within a month of collection, with the objection line on its own and a way to complain to you?Hold the send until the notice is ready; put anyone who objects on a suppression list rather than deleting them
Step 4No LinkedIn message to a UK contact without consent, and open tracking off unless the person consented to it after clear information (Schedule A1)?Drop the LinkedIn step for UK contacts; switch tracking off and count replies instead
From abroadSending from outside the UK: checked whether article 27 means you need a UK representative?Ask a UK data protection lawyer before a regular campaign

If most of a UK list lands on the individual side of Step 1, email isn’t the channel for those contacts until they say yes.

Setting up your sending tool for a UK list

Steps 1–4 decide whether an email may go out; no setting in a sending tool changes that answer.

Each row starts from a UK rule on this page and shows what it takes by hand, then the matching feature in lemlist and Instantly, with any plan condition their own pages state. Neither help center says its tool can tell a company from a sole trader, so the Step 1 sort happens in your list before you import it. For how the two compare beyond these rules, on channels and price, see how Instantly and lemlist differ for email-only and multichannel sequences. If you’re weighing lemlist alone, see what lemlist’s email-only and multichannel plans cost.

UK ruleBy hand, from your own mailboxlemlistInstantly
A company or LLP that asks you to stop: the ICO advises a do-not-email list of such companies, screened against every new list (Step 2a)A “do not email” tab of company domains in the sheet that holds your Step 1 column; match every new list against it before the first sendAdd the domain as @company.co.uk under Unsubscribe variables, which the help center says excludes the entire domain from all campaigns and channels (help41). Its Unsubscribes section lists this system on all plans (help41)Enter the domain without the @ in the Global Blocklist, which is checked at upload and in running campaigns (help42). Plan: Instantly’s pages disagree (below)
A sole trader or a partnership in England, Wales or Northern Ireland you have no consent from: an individual subscriber under PECR regulation 22 (Step 1)Delete the row when you sort the list, and add the domain or address to the same tab, so the next list you build or import can’t bring it backThe same list before the first send: their domain, or just the address if it’s on a shared webmail domain, so a later import can’t reach themThe same Global Blocklist entry, domain or address; it also takes one entry per row from a file or a Google Sheet
An opt-out address in every email (PECR regulation 23, Step 2a)Your reply address, named in each email as the place to send “stop,” in a mailbox someone readsYou insert the link yourself (“Add unsubscribe link”); a click stops that campaign and every other one the lead is in (help41)“Insert unsubscribe link” in the sequence editor; the lead’s status changes to “Unsubscribed” (help42)
A named person objects: stop without undue delay and within one month at the latest, however the objection arrives; the ICO says it can be made verbally or in writing, to anyone in your organization (UK GDPR article 21(3), Step 3)A second tab of named people who objected, with the date each objection arrived, however it came in; check it before every send“Do not contact” blocks the person on every lemlist channel in every campaign; an objection that arrives by reply or phone you add by hand under Unsubscribe variables, one value per line; all plans (help41)An objection by reply or phone you add by hand, in the Blocklist tab or from the reply in Unibox (which removes that reply; help42). Automatic adds carry plan conditions, set out below the table
Tracking pixels: the device rule in force since February 5, 2026 (PECR regulation 6 and Schedule A1, Step 4)No open tracking: if a mail-merge or tracking add-on puts a pixel in your emails, switch that offTracks opens and clicks by default; switch opens off in each campaign’s Settings > Tracking. With tracking on, sending needs a verified custom tracking domain (help41)An “Open tracking” option in each campaign, plus a global “Disable Open Tracking” setting; the article doesn’t say which state is the default (help42)

Help-center articles read September 29, 2026 and checked again October 2, 2026. lemlist: unsubscribe links (updated July 23, 2026), Unsubscribes section (updated September 24, 2026), tracking (July 15, 2026). Instantly: Global Blocklist (July 13, 2026), unsubscribe link (July 8, 2026), open tracking (June 29, 2026). Plan conditions move often, so confirm each row in your own account before you rely on it.

Which Instantly plan includes the Global Blocklist? Instantly’s own pages disagree, in three places. We read all three on September 29 and 30, 2026 and again on October 2, 2026, and found the same each time:

  • Pricing page. The “Compare features” table on instantly.ai/pricing44 has two columns, Growth and Hypergrowth, and ticks “Global block list” under Hypergrowth only.
  • Help-center plan comparison. The Email Outreach Plans Comparison43, updated July 13, 2026, marks “Global block list” “Yes” on Growth, HyperGrowth and Light Speed, and “No” on the free trial.
  • Automatic adds. The Global Blocklist article42, also updated July 13, 2026, puts three triggers under “AI Blocklist Triggers,” a section that opens with the note “Available to Hyper Growth and above plans.” Two of them, leads in specific statuses and replies containing specific phrases, repeat that label. The third, a toggle that adds unsubscribed leads to the blocklist, doesn’t, so the article leaves its plan open.

If you’d count on the blocklist on Growth, ask Instantly’s support to confirm it for your plan before paying, and ask in the same message whether that plan includes the unsubscribe toggle.

The by-hand column holds up while one person sends a few UK emails a week and checks both tabs before each one. It gives way when lists arrive faster than you can match them: a sole trader you left out in March comes back in a May list, and nothing stops the send unless you remember the tab. In a sending tool the check runs without you: lemlist’s help center says one @company.co.uk entry excludes the whole domain from all campaigns, and Instantly’s Global Blocklist, checked at upload and in running campaigns, takes bare domains too, once you’ve settled the plan question above.

lemlist

Best fit if your UK list has whole domains to hold back: companies that opted out and sole traders you have no consent to email. lemlist’s help center says one entry such as @company.co.uk keeps the entire domain out of your campaigns. Opens are tracked until you switch that off per campaign (checked October 2026).

Visit lemlist

Ad · Paid link: we earn a commission if you sign up through this link. It doesn’t change our recommendation.

FAQ

Can I email info@ or sales@ addresses without the UK GDPR applying?

Usually. The ICO says that if you don’t know the name of the person you’re emailing, as with an address like info@, you’re not processing personal data and the UK GDPR doesn’t apply. PECR still does: the email must identify you and give an opt-out address (Step 2a).

Can I rely on a list seller’s promise that the contacts consented?

Not for sole traders and other individual subscribers. The ICO says a buyer would breach PECR by emailing them, because consent has to be given to the buyer as the sender; regulation 22(2) likewise requires that the recipient told the sender they consent.

Do the TPS and CTPS apply to cold email?

No. They’re for live marketing calls (PECR regulation 213), and the ICO says there is no email or text preference service; your own do-not-contact list does that job. If you add calls, the ICO says to screen against both registers: sole traders and some partnerships register with the TPS, other businesses with the CTPS. When you call, you must show your number or one you can be reached on.

How fast must I act when someone objects?

The ICO says without undue delay and at the latest within one month of receiving the objection, counted to the same date in the next month. If your systems need a fixed number of days, it suggests 28.

Can a recipient sue me under PECR?

Yes, if they suffer damage: anyone harmed by a breach can bring proceedings for compensation. It’s a defense to prove you took the care that was reasonably required to comply (PECR regulation 306).

Sources

  1. PECR 2003, regulation 2 (interpretation) — legislation.gov.uk, accessed October 2, 2026
  2. PECR 2003, regulation 6 (storing information in terminal equipment) — legislation.gov.uk, accessed October 2, 2026
  3. PECR 2003, regulation 21 (calls for direct marketing) — legislation.gov.uk, accessed October 2, 2026
  4. PECR 2003, regulation 22 (electronic mail for direct marketing) — legislation.gov.uk, accessed October 2, 2026
  5. PECR 2003, regulation 23 (concealed identity or address) — legislation.gov.uk, accessed October 2, 2026
  6. PECR 2003, regulation 30 (compensation) — legislation.gov.uk, accessed October 2, 2026
  7. PECR 2003, Schedule A1 (exceptions to regulation 6) — legislation.gov.uk, accessed October 2, 2026
  8. PECR 2003, Schedule 1 (enforcement powers), current version — legislation.gov.uk, accessed October 2, 2026
  9. PECR 2003, Schedule 1 as it stood on February 4, 2026 — legislation.gov.uk, accessed October 2, 2026
  10. Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010, regulation 2 (as made) — legislation.gov.uk, accessed October 2, 2026
  11. Electronic Commerce (EC Directive) Regulations 2002, regulation 7 — legislation.gov.uk, accessed October 2, 2026
  12. UK GDPR, article 3 (territorial scope) — legislation.gov.uk, accessed October 2, 2026
  13. UK GDPR, article 6 (lawfulness of processing) — legislation.gov.uk, accessed October 2, 2026
  14. UK GDPR, Annex 1 (recognised legitimate interests) — legislation.gov.uk, accessed October 2, 2026
  15. UK GDPR, article 14 (information where data not obtained from the data subject) — legislation.gov.uk, accessed October 2, 2026
  16. UK GDPR, article 21 (right to object) — legislation.gov.uk, accessed October 2, 2026
  17. UK GDPR, article 27 (representatives) — legislation.gov.uk, accessed October 2, 2026
  18. Data Protection Act 2018, section 157 (maximum amount of penalty) — legislation.gov.uk, accessed October 2, 2026
  19. Data Protection Act 2018, section 164A (complaints to controllers) — legislation.gov.uk, accessed October 2, 2026
  20. Data (Use and Access) Act 2025, section 112, section 114 and section 115, with commencement notes — legislation.gov.uk, accessed October 2, 2026
  21. Data (Use and Access) Act 2025, section 117, section 118 and section 119 — legislation.gov.uk, accessed October 2, 2026
  22. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (S.I. 2026/82), including regulations 2, 3 and 11 — legislation.gov.uk, accessed October 2, 2026
  23. The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026 (S.I. 2026/1015), regulations 2 and 3 and the explanatory note — legislation.gov.uk, accessed October 2, 2026
  24. Business-to-business marketing — ICO, accessed October 2, 2026
  25. Electronic mail marketing — ICO, accessed October 2, 2026
  26. How do we apply legitimate interests in practice? — ICO, accessed October 2, 2026
  27. Right to be informed — ICO, accessed October 2, 2026
  28. Right to object — ICO, accessed October 2, 2026
  29. Cookies and similar technologies — ICO, accessed October 2, 2026
  30. The Data Use and Access Act 2025 (DUAA): summary of the changes to data protection law – Privacy and electronic communications — ICO, accessed October 2, 2026
  31. Statement on the commencement of the Data (Use and Access) Act (DUAA), February 5, 2026 — ICO, accessed October 2, 2026
  32. ICO governance changes confirmed for 30 September 2026, September 15, 2026 (updated September 17) — ICO, accessed October 2, 2026
  33. ICO home page (name shown: Information Commission’s Office) — ICO, accessed October 2, 2026
  34. Our plans for new and updated guidance: direct marketing and PECR and general data protection — ICO, accessed October 2, 2026
  35. ZMLUK Limited (monetary penalty, December 11, 2025) and Fines of £225,000 for nuisance marketing messages, January 20, 2026 — ICO, accessed October 2, 2026
  36. KRA Consultancy Ltd and its monetary penalty notice, May 20, 2026 — ICO, accessed October 2, 2026
  37. Marketing and advertising: the law – Direct marketing (no update date shown) — GOV.UK, accessed October 2, 2026
  38. Set up a business (business structures) and Set up a business partnership — GOV.UK, accessed October 2, 2026
  39. Find and update company information (four records viewed: two for the “Company type” of a company and an LLP, and two limited partnerships, one numbered LP and one SL) — Companies House, accessed October 2, 2026
  40. Uniform Resource Identifiers (URI) Customer Guide, version 1.1 (May 2012), “List of Company Numbers and Prefixes” (PDF) — Companies House, accessed October 2, 2026
  41. How to add and manage unsubscribe links (updated July 23, 2026), Use the Unsubscribes section (updated September 24, 2026) and Disable tracking (updated July 15, 2026) — lemlist help center, accessed October 2, 2026
  42. How to add unsubscribe link (updated July 8, 2026), Global Blocklist (updated July 13, 2026) and Open tracking (June 29, 2026) — Instantly help center, accessed October 2, 2026
  43. Email Outreach Plans Comparison — Instantly help center, updated July 13, 2026, accessed October 2, 2026
  44. Pricing (feature table under “Compare features”) — Instantly, accessed October 2, 2026