Cold Email in the UK After Brexit: UK GDPR, PECR, and What Changed for B2B
March 15, 2026 · 5 min read · by Ahmet Faruk Yilmaz, Founder of Asphia
TL;DR
B2B cold email in the UK is still legal after Brexit under UK GDPR and PECR, provided you have a legitimate interest basis, target relevant business contacts, and give a clear opt-out. Brexit did not relax the rules; it created a parallel UK regime that mirrors EU GDPR in most respects.
B2B cold email in the UK is still legal after Brexit. The short answer: the UK retained GDPR as domestic law (UK GDPR) and PECR continues to apply alongside it. The rules are strict but they do permit legitimate outreach, and understanding the two-regulation framework is the key to running compliant campaigns.
What Brexit Actually Changed (and What It Did Not)
When the UK left the EU, it did not scrap GDPR. It incorporated the regulation into UK law via the Data Protection Act 2018, creating UK GDPR. The ICO (Information Commissioner’s Office) now enforces this UK version, not the European Data Protection Board.
For senders based in the EU targeting UK contacts: EU GDPR governs how you process the data on your side, and UK GDPR governs the rights of the UK data subjects. In practice the rules are parallel enough that a compliant EU programme is very likely compliant in the UK too.
For senders based in the UK targeting EU contacts: you need to comply with EU GDPR for those contacts. Brexit did not create a loophole in either direction.
What did change: you now have two separate regulators to consider (ICO and your relevant EU DPA), and the UK has more flexibility to diverge from EU GDPR over time, though it has not done so materially for cold email purposes as of early 2026.
The Two Rules You Must Satisfy: UK GDPR and PECR
Cold email in the UK must comply with two separate pieces of law simultaneously.
UK GDPR requires a lawful basis for processing personal data. For B2B cold email, that basis is almost always legitimate interest. The three-part test is: (1) you have a genuine commercial interest in contacting this person, (2) the processing is necessary to pursue that interest, and (3) your interest is not overridden by the individual’s privacy rights.
Practically: send to contacts whose job role is directly relevant to your product or service. A message about HR software to an HR Director satisfies the balancing test more cleanly than the same message to a CFO. Document your reasoning before the campaign, not after.
PECR (Privacy and Electronic Communications Regulations) adds a layer on top. For limited company employees (the most common B2B target), PECR does not require prior consent if the message is relevant to the business. For sole traders and some partnerships, PECR treats them closer to consumers and the standard is tighter.
Always include a clear opt-out mechanism in every email. This is non-negotiable under both regimes.
For a broader treatment of building GDPR-native outbound systems, see our guide on GDPR-compliant cold email agency practices.
Brexit moved the regulator, not the regulation. UK GDPR and EU GDPR are twins with different passports.
What a Compliant UK B2B Cold Email Looks Like
The compliance requirements translate into specific operational steps, not vague intentions.
Data sourcing: use sources with documented provenance. LinkedIn, company websites, and reputable B2B data providers are standard. Keep records of where each record came from, when it was collected, and what the legal basis is for each segment.
Targeting: match your offer to the recipient’s role. The balancing test under UK GDPR becomes easier to satisfy when the relevance is obvious. Bulk generic blasts to purchased lists with no segmentation are the highest-risk pattern.
Content of the email: be honest about who you are, why you are contacting them, and what you want. Include your company name, contact details, and an unsubscribe or opt-out link. The ICO looks unfavourably on disguised commercial emails.
Suppression management: honour opt-outs immediately and keep a suppression list. Re-emailing suppressed contacts is one of the fastest routes to an ICO complaint.
Data retention: do not keep personal data longer than necessary. If someone never replies over multiple touches, review whether continued processing is justified.
Our done-for-you cold email service builds all of these steps into the workflow by default, because treating compliance as a checklist item is how programmes get it wrong.
Common Mistakes UK Senders Make
Assuming Brexit removed the rules. It did not. Senders sometimes believe leaving the EU means leaving GDPR behind. UK GDPR is effectively the same regulation enforced by a UK body.
Ignoring PECR for sole traders. Sole traders are treated more like consumers under PECR. If your list contains sole traders (common in agency, consulting, and freelance markets), you need consent or a very clear soft opt-in basis.
No legitimate interest assessment on file. If the ICO investigates, they will ask for your LIA (Legitimate Interest Assessment) documentation. Campaigns that cannot produce one are immediately vulnerable.
Sending from infrastructure with no deliverability hygiene. Compliance failures and deliverability problems often arrive together. Sending from warmed domains, using reputable infrastructure, and keeping bounce rates low is not separate from compliance. It reflects the same underlying discipline.
For UK-focused outbound programmes, see how we approach B2B cold email for UK-based clients and the infrastructure choices that support both deliverability and regulatory hygiene.
How Asphia Approaches UK Compliance
Every campaign we build or run uses legitimate interest as the documented basis, with targeting criteria recorded before launch. Suppression lists are applied before each send, opt-out links are present in every message, and data sourcing is logged.
The human approval gate in our workflow means no email reaches a contact until someone has reviewed it. That is not just a quality control step; it is also the practical enforcement of proportionality under the legitimate interest test.
If you are running outbound to UK audiences and want to review how your current process maps to UK GDPR and PECR, our done-with-you outbound engagement starts with exactly that audit.
For authoritative UK guidance, the ICO publishes direct marketing guidance at ico.org.uk which is the primary reference for PECR interpretation.
Get the signal tier list in your inbox.
We rank signals from S to D to decide who gets a cold email and who does not. You get the list once. No follow-up emails.
Request received. The list lands in your inbox within 24 hours.
One more step: send the prepared request to [email protected]
FAQ
Is cold email legal in the UK after Brexit?
Yes. B2B cold email remains legal in the UK under UK GDPR and PECR. You must have a legitimate interest basis, the email must be relevant to the recipient's role, and you must provide a clear way to opt out. Brexit created a separate UK regime but did not loosen the core rules.
What is the difference between UK GDPR and EU GDPR for cold email?
UK GDPR and EU GDPR are nearly identical in structure. The main difference is jurisdiction: EU GDPR covers EEA countries, UK GDPR covers the UK. If you send to both UK and EU contacts, both regimes apply to their respective populations. Legitimate interest logic works the same way in both.
Does PECR apply to business email addresses in the UK?
PECR applies to all electronic marketing to individuals, including sole traders and some partnerships, but it has a softer standard for corporate subscribers (limited companies). For limited company employees, PECR is satisfied if the message is relevant to their business role. UK GDPR still applies on top of PECR regardless.
What does legitimate interest mean for B2B cold email under UK GDPR?
Legitimate interest means you have a genuine business reason to contact the person, the contact is necessary to pursue that purpose, and the person's privacy rights do not override it. In practice: send only to contacts whose role is plausibly relevant to your offer, document your reasoning, and always provide an opt-out.
Do I need a data transfer agreement to send cold email from the EU to UK contacts after Brexit?
The UK is currently recognised by the EU as having adequate data protection (adequacy decision). EU-to-UK transfers do not require standard contractual clauses at the moment, though you should monitor ICO and European Commission updates as adequacy decisions can change.
What happens if I ignore UK GDPR when cold emailing UK businesses?
The ICO (Information Commissioner's Office) enforces UK GDPR and PECR. Fines can reach 17.5 million GBP or 4 percent of global annual turnover for serious breaches. PECR violations carry separate fines up to 500,000 GBP. Non-compliance also damages sender reputation and deliverability.
Ahmet Faruk Yilmaz
Founder of Asphia. He builds and runs signal-based B2B outbound engines for lean teams, and has booked meetings with teams at companies across five markets. Writes about cold email, Clay, deliverability, and GTM engineering.
Want this run for you?
Get a free GTM analysis. We show you the exact engine we would build.
Get your free GTM analysis →