Business Compliance ChecklistChecklist and Decision Guide

Cold Email Compliance Decision Tree

7 minutes to completeEvergreen guide — kept up to date

Before sending a marketing email, classify the subscriber as corporate, individual or unknown. Then test the relevant PECR route, UK GDPR data-use position, transparency, opt-out and suppression controls. This guide helps a business decide whether it can proceed carefully, must check first or should not send yet.

Use this checklist before a cold-email campaign is approved. It is a practical operating tool, not legal advice. For high-volume, high-risk or unusual campaigns, confirm the current ICO guidance and take specialist advice.

The first decision is not whether the email address looks business-like. It is what type of subscriber you are contacting.

Stage 1 — What Are You Sending?

  • □ The message purpose is recorded — sale, newsletter, event, guide, webinar or other promotion
  • □ The team has considered whether the message is marketing rather than a genuine service or administrative notice
  • □ The sender, campaign owner and mailing platform are documented
  • □ The campaign audience and data source are documented before any send

Stage 2 — Classify the Subscriber

Classify asExamplesDecision
Corporate subscriberLimited company, LLP, Scottish partnership, qualifying corporate bodyMove to Stage 3A. Prior PECR email consent is generally not required, but identity, opt-out and UK GDPR checks still matter.
Individual subscriberSole trader, individual or some ordinary partnershipsMove to Stage 3B. Consent or a valid soft opt-in is generally needed for unsolicited marketing email.
UnknownLegal structure cannot be confirmed from the available evidenceCHECK FIRST. Do not treat the contact as corporate until the structure is clear.

A generic address does not settle the question. An address such as info@ may not identify a person, but PECR still depends on the subscriber's legal status.

Stage 3A — Corporate Subscriber Route

  • □ Corporate status evidenced — do not rely only on the email domain
  • □ Message clearly identifies the sending organisation
  • □ Message includes a valid, working opt-out address or mechanism
  • □ Campaign process can stop future marketing when the business or contact objects
  • □ If using a named contact, a UK GDPR lawful basis and transparency approach are recorded
  • □ The use is reasonable, relevant and not excessive for the contact's role

Stage 3B — Individual Subscriber Route

  • □ Valid, specific consent for this marketing email is available; or
  • □ The soft opt-in route has been tested: details obtained in a sale or genuine negotiation, similar products or services, easy refusal at collection and in every later message
  • □ If neither route applies, the campaign does not send unsolicited marketing email to this contact
  • □ Any named-contact data is handled under the wider UK GDPR controls

Soft opt-in is not a label for every previous contact. If the conditions are not clearly met, treat the route as unavailable.

Stage 4 — Data, Transparency and Legitimate Interests

  • □ Source of each contact list documented
  • □ Whether the address identifies a person considered
  • □ UK GDPR lawful basis documented where personal data is processed
  • □ Legitimate-interests assessment covers purpose, necessity, balance and safeguards where that basis is used
  • □ Privacy information is available in an appropriate form
  • □ Public availability of the contact details is not treated as automatic permission
  • □ Bought-list supplier evidence and contract reviewed before use

Legitimate interests can be relevant to the UK GDPR question of why personal data is used. It does not disapply PECR. Treat the two as separate checks.

Stage 5 — Message and Control Checks

  • □ Sender identity is accurate and not disguised
  • □ Subject line and content accurately describe the message
  • □ Opt-out is easy to find, works and does not require unnecessary friction
  • □ Suppression list checked before send
  • □ Opt-outs and objections are recorded promptly
  • □ A minimal suppression record is retained only as needed to prevent future marketing
  • □ Campaign records are retained appropriately and access is controlled

Decision Outcome

OutcomeUse whenNext action
PROCEED CAREFULLYSubscriber type and relevant PECR route are clear, and the data / opt-out controls are documented.Send only through the approved process and monitor opt-outs or objections.
CHECK FIRSTLegal structure, list provenance, privacy information, consent evidence or data role is unclear.Resolve the missing evidence before the contact is included.
DO NOT SEND YETAn individual subscriber has no clear consent or soft opt-in, or a contact has objected or is suppressed.Exclude the contact from the campaign.

If you cannot explain why a recipient is on the list, do not press send yet.

Official Guidance to Recheck

ICO: Business-to-business marketing

ICO: PECR electronic-mail marketing rules

Read the full IT Club cold-email guide

Plain-English Takeaway

Classify the subscriber first. Corporate, individual and unknown recipients need different treatment. Then separate the PECR email question from the UK GDPR personal-data question, make opting out simple and ensure the suppression list is respected.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Free to ask. No credit card. No sales pressure. Fair usage applies.