Cold Email Compliance Decision Tree
Before sending a marketing email, classify the subscriber as corporate, individual or unknown. Then test the relevant PECR route, UK GDPR data-use position, transparency, opt-out and suppression controls. This guide helps a business decide whether it can proceed carefully, must check first or should not send yet.
Use this checklist before a cold-email campaign is approved. It is a practical operating tool, not legal advice. For high-volume, high-risk or unusual campaigns, confirm the current ICO guidance and take specialist advice.
The first decision is not whether the email address looks business-like. It is what type of subscriber you are contacting.
Stage 1 — What Are You Sending?
- □ The message purpose is recorded — sale, newsletter, event, guide, webinar or other promotion
- □ The team has considered whether the message is marketing rather than a genuine service or administrative notice
- □ The sender, campaign owner and mailing platform are documented
- □ The campaign audience and data source are documented before any send
Stage 2 — Classify the Subscriber
| Classify as | Examples | Decision |
|---|---|---|
| Corporate subscriber | Limited company, LLP, Scottish partnership, qualifying corporate body | Move to Stage 3A. Prior PECR email consent is generally not required, but identity, opt-out and UK GDPR checks still matter. |
| Individual subscriber | Sole trader, individual or some ordinary partnerships | Move to Stage 3B. Consent or a valid soft opt-in is generally needed for unsolicited marketing email. |
| Unknown | Legal structure cannot be confirmed from the available evidence | CHECK FIRST. Do not treat the contact as corporate until the structure is clear. |
A generic address does not settle the question. An address such as info@ may not identify a person, but PECR still depends on the subscriber's legal status.
Stage 3A — Corporate Subscriber Route
- □ Corporate status evidenced — do not rely only on the email domain
- □ Message clearly identifies the sending organisation
- □ Message includes a valid, working opt-out address or mechanism
- □ Campaign process can stop future marketing when the business or contact objects
- □ If using a named contact, a UK GDPR lawful basis and transparency approach are recorded
- □ The use is reasonable, relevant and not excessive for the contact's role
Stage 3B — Individual Subscriber Route
- □ Valid, specific consent for this marketing email is available; or
- □ The soft opt-in route has been tested: details obtained in a sale or genuine negotiation, similar products or services, easy refusal at collection and in every later message
- □ If neither route applies, the campaign does not send unsolicited marketing email to this contact
- □ Any named-contact data is handled under the wider UK GDPR controls
Soft opt-in is not a label for every previous contact. If the conditions are not clearly met, treat the route as unavailable.
Stage 4 — Data, Transparency and Legitimate Interests
- □ Source of each contact list documented
- □ Whether the address identifies a person considered
- □ UK GDPR lawful basis documented where personal data is processed
- □ Legitimate-interests assessment covers purpose, necessity, balance and safeguards where that basis is used
- □ Privacy information is available in an appropriate form
- □ Public availability of the contact details is not treated as automatic permission
- □ Bought-list supplier evidence and contract reviewed before use
Legitimate interests can be relevant to the UK GDPR question of why personal data is used. It does not disapply PECR. Treat the two as separate checks.
Stage 5 — Message and Control Checks
- □ Sender identity is accurate and not disguised
- □ Subject line and content accurately describe the message
- □ Opt-out is easy to find, works and does not require unnecessary friction
- □ Suppression list checked before send
- □ Opt-outs and objections are recorded promptly
- □ A minimal suppression record is retained only as needed to prevent future marketing
- □ Campaign records are retained appropriately and access is controlled
Decision Outcome
| Outcome | Use when | Next action |
|---|---|---|
| PROCEED CAREFULLY | Subscriber type and relevant PECR route are clear, and the data / opt-out controls are documented. | Send only through the approved process and monitor opt-outs or objections. |
| CHECK FIRST | Legal structure, list provenance, privacy information, consent evidence or data role is unclear. | Resolve the missing evidence before the contact is included. |
| DO NOT SEND YET | An individual subscriber has no clear consent or soft opt-in, or a contact has objected or is suppressed. | Exclude the contact from the campaign. |
If you cannot explain why a recipient is on the list, do not press send yet.
Official Guidance to Recheck
ICO: Business-to-business marketing →
Plain-English Takeaway
Classify the subscriber first. Corporate, individual and unknown recipients need different treatment. Then separate the PECR email question from the UK GDPR personal-data question, make opting out simple and ensure the suppression list is respected.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Operational Heartbeat Checklist
A plain-English checklist for business owners to assess whether their IT provider is monitoring the right things. Covers backups, servers, Microsoft 365, firewalls, security, certificates, storage and more.
View guideBusiness Browser Security Checklist
A practical checklist for securing Chrome on business Windows PCs: screen locking, individual user accounts, Windows Hello configuration, Chrome password autofill verification, payment autofill verification, saved card review, extension management, Google Account MFA and passkeys.
View guideCyber Essentials Readiness Checklist
Work through the key controls to review before applying for Cyber Essentials.
View guide