
Separate law, provider policy and recipient trust
PECR regulates electronic marketing channels and does not depend on whether an email contains personal data. UK GDPR and the Data Protection Act 2018 govern personal-data processing. Mailbox-provider terms add operational conditions but do not decide legality. The ICO places these duties together while keeping their roles distinct in its electronic-mail guidance and direct-marketing guidance.
The practical reframe is that authentication proves something about sending identity; it does not create permission, a lawful basis or relevance. A message can pass SPF, DKIM and DMARC yet still breach a marketing rule, ignore an objection or annoy the recipient. Conversely, a lawful campaign can be filtered. Record legal review, provider compliance and delivery evidence as separate decisions.
This is general operational information, not personalised legal advice. Facts such as the recipient’s legal form, how details were collected, message purpose and target country can change the analysis. Hold uncertain records out of sending while those facts are checked.
Identify the subscriber before calling outreach B2B
PECR distinguishes corporate subscribers from individual subscribers. Companies, limited liability partnerships and Scottish partnerships are examples of corporate subscribers; sole traders and some partnerships fall within the individual category. The ICO explains these distinctions in its PECR electronic-mail material. A work title or business-looking address does not prove legal form.
For unsolicited electronic mail to corporate subscribers, PECR does not impose the same consent or soft-opt-in condition that applies to individual subscribers. The sender must still identify itself and provide a valid opt-out address. Personal-data duties can also apply where the address identifies an employee. Treat “B2B” as a factual description, not an exemption.
Record organisation name, legal form, source used to classify it, recipient role, country and review date. If a sole trader trades under a company-like name, or a partnership type is unclear, stop that contact. Ask a competent privacy adviser for a documented view rather than guessing from the domain.
Define the audience and purpose before finding addresses
Write a narrow description of the problem, offer and roles likely to have a genuine business need. Explain why the proposed frequency and channel are proportionate. A broad claim that every director could benefit is not a relevance test. Exclude vulnerable contexts, sensitive sectors and recipients for whom contact could expose private circumstances.
Decide whether each message is direct marketing. Promotional content remains marketing even when it is personalised, sent one at a time or framed as networking. A service message can become marketing when it adds sales material. Classification follows purpose and content, not the name of the software used.
The trade-off is reach versus defensibility. A smaller, well-evidenced audience may produce fewer immediate opportunities, but it reduces unexpected contact, complaints and suppression work. Do not buy more data to compensate for weak relevance.
Check consent or every soft-opt-in condition
Unsolicited marketing email to an individual subscriber generally needs consent unless every relevant soft-opt-in condition is met. The ICO’s electronic-mail guidance explains that the ordinary products-and-services soft opt-in depends on obtaining details directly during a sale or sale negotiation, marketing your own similar offerings, and providing a refusal opportunity at collection and in every later message.
A past purchase alone is not enough if the collection notice and refusal opportunity were absent. A bought list does not inherit your customer relationship. Consent should be freely given, specific, informed and unambiguous, shown by affirmative action. Keep the wording, date, method, controller named and scope, not merely a CRM tick.
Corporate-subscriber treatment does not remove the identity and opt-out duties. As a safer operating rule, honour any clear refusal from any business recipient. Stop where consent evidence is incomplete, the soft-opt-in chain has a missing condition, or the list seller will not explain collection.
Choose and document a UK GDPR basis separately
When outreach uses an identifiable person’s details, identify a lawful basis and meet fairness, transparency, minimisation and rights duties. The ICO discusses consent and legitimate interests in direct-marketing contexts in its current guidance. Legitimate interests is an assessment, not a phrase pasted into a privacy notice.
A legitimate-interests assessment should define the interest, test whether processing is necessary and balance impact against the person’s rights and expectations. Consider source, role relevance, frequency, seniority, likely intrusion and available alternatives. It cannot override a PECR consent requirement. If consent is the PECR route, inconsistent UK GDPR reasoning needs specialist review.
Explain where the data came from, who controls it, intended use, retention and rights in accessible privacy information. If indirect collection triggers additional information duties, plan delivery before launch. Avoid enriching profiles with personal or sensitive details that are unnecessary for the business purpose.
Treat public and purchased data as evidence with limits
A public web page is not an invitation to any marketing use. Record the exact source, collection date and context, then ask whether the person would reasonably expect this use. Do not scrape personal biographies, infer protected characteristics or combine unrelated datasets merely because tools make it possible.
For a supplier list, obtain the provenance, collection wording, subscriber classification, consent evidence where claimed, permitted recipients, age, update process and suppression arrangements. Contract promises do not transfer away your duties. Test a sample against the documentation before import and quarantine fields that are not needed.
Stop if the supplier cannot name the source, claims universal permission, offers a “clean” list without explaining objections, or prohibits you from telling people where data came from. Escalate large-scale matching, monitoring, special-category inferences or international sourcing for data-protection review.
A lawful purpose does not guarantee inbox placement; the business email deliverability guide covers the separate delivery signals.
Make the message accurate, restrained and easy to refuse
Use the real organisation and sender identity, a monitored reply address and a subject that describes the message. Do not invent a prior conversation, false urgency or personal knowledge. Explain the relevance briefly, identify the data source where appropriate and link to clear privacy information.
Provide a prominent, functioning opt-out. Do not require an account, a sales call or a reason. Limit follow-ups and cancel queued messages when a refusal arrives. Silence is not renewed permission. Authentication, rotating domains and simulated engagement are not remedies for unwanted contact.
Check the rendered message on mobile, plain-text and common mail clients. A footer hidden by colour, image failure or clipping is not effective. Send to controlled addresses first and verify replies reach a staffed queue.
Pair this message discipline with a correctly implemented one-click unsubscribe and the PECR and UK GDPR email guide, so every opt-out route and lawful basis is covered.
Run a documented pre-send review
- Describe the purpose and audience. State message type, frequency, countries and expected benefit.
- Classify subscribers. Retain evidence of legal form and exclude uncertainty.
- Check PECR. Record consent, every soft-opt-in condition or the corporate-subscriber rationale.
- Check personal data. Document lawful basis, fairness, transparency, minimisation and rights handling.
- Verify provenance. Sample sources, collection wording, age and prior objections.
- Test the message. Confirm identity, relevance, privacy information, reply handling and opt-out.
- Test suppression. Use a controlled address and prove that queued and future messages stop.
- Approve or hold. Name the accountable decision-maker and retain the evidence date.
Monitor harm signals instead of chasing volume
Review objections, spam complaints, negative replies, source errors, bounces and recipient-domain patterns. Separate delivery metrics from lawfulness. A high open rate cannot cure missing consent, and an image proxy can make open data unreliable. Do not optimise around surveillance that recipients would not expect.
Pause a source or campaign when objections cluster around irrelevance, recipients deny the claimed relationship, opt-outs fail, evidence cannot be produced or complaints rise materially. Preserve the message, source record and system event before changing multiple controls.
Use data minimisation in incident files. Redact message content and addresses when full copies are unnecessary, restrict access and set a retention period. Report serious compliance concerns through the organisation’s privacy and governance routes.
Keep the review honest by writing down the outcome in ordinary language before you measure anything: what the audience is, why this person is in it, what would make them a wrong recipient and who is accountable for each decision. When a later complaint or objection arrives, you can point to that dated record instead of reconstructing intent from memory. It also stops one enthusiastic send from being described as a research project after the fact.
Monitor the sending route against current Gmail, Yahoo and Microsoft requirements without treating provider policy as legal permission.
Use explicit stop and escalation conditions
Stop sending to a person immediately when a clear direct-marketing objection is received. Stop the wider run if suppression is not synchronising, the sender identity is misleading, individual subscribers lack a valid PECR route, personal-data provenance is unknown or a platform cannot cancel queued follow-ups. Do not keep sending while asking recipients to clarify ordinary opt-out language.
Escalate novel subscriber classifications, political or charitable campaigning, special-category data, vulnerable audiences, large-scale profiling, cross-border outreach and disputed rights requests to a suitably qualified adviser. Give them the actual message, source, audience, systems and proposed timing, not a generic question.
Resume only after the defect is corrected, a controlled suppression test passes, affected records are excluded and the accountable owner records the basis for restarting. Keep the decision qualified: it supports the reviewed campaign configuration, not every future use of the list.
Verification note: keep a controlled seed address in every approved audience and confirm that its reply, footer opt-out and suppression event reach the named owner before any wider dispatch. This checks the actual campaign path without treating delivery as evidence of legal compliance.