the legal bit
GDPR did not ban cold email
Somebody told you it did. They were guessing, and it's cost their company more than any regulator would.
It comes down to one distinction
corporate subscribers
Ltd companies & LLPs
Email a named person there about their job. No consent needed. PECR's consent rule was never about them.
individual subscribers
Sole traders & partnerships
Legally individuals, consent required. If you sell to plumbers, one-person consultancies or shops trading in their own name — that's your whole problem, and it needs solving before anything else.
Parliament looked at extending the rule to corporate subscribers in the Data (Use and Access) Act 2025 and chose not to. This isn't a loophole nobody's spotted.
Four things you do have to do
UK GDPR still applies — it's someone's personal data.
Say who you are
Real company. No disguised sender.
Honour opt-outs
An unsubscribe nobody reads is worse than none.
Keep a suppression list
And check every new list against it.
Write it down
Where the data came from and why you're allowed to use it. An afternoon's work. It's the difference between a short conversation and a long one.
What actually gets people fined
Allay Claims, January 2026. Consumer-facing, millions of messages, no records.
ZMLUK, same month, same story. Neither was B2B outbound.
The new PECR maximum from 5 Feb 2026 — up from £500,000. Thirty-five times bigger.
The maximum doesn't change what's allowed. It changes what carelessness costs.
Nobody gets fined for emailing forty finance directors.
Enforcement follows volume, complaints and missing paperwork. The people who get caught send enormous numbers to people who never wanted it, with no records and a broken unsubscribe. That isn't what we build.
Written by someone who does this for a living, not a lawyer. Not legal advice, and it's a summary. The ICO publishes its own guidance on direct marketing and PECR. If your targets are mostly sole traders, get proper advice.