Legal Guide to Email Marketing: Staying Compliant When Using Email Outreach In Your Business

Email marketing and compliance can be a real minefield, and marketing professionals must ensure they know the rules around email outreach, especially when sending unsolicited emails. There are also data protection and opt-in and opt-out requirements you’ll need to meet when managing email subscribers.
In the UK, you need to comply with UK GDPR (General Data Protection Regulation) and PECR (Privacy and Electronic Communications Regulations), but you’ll also want to follow best practice.
Cold emailing and mass email marketing have a reputation for being intrusive, but they can be very good for businesses and even welcomed by clients/customers as a way to stay informed. Automated emails are also relied on by community groups and membership organisations to alert members to new activity and keep them engaged. So, whilst we’ll certainly cover the legal musts and must-nots of email marketing in this guide, we’ll also look at how email can be used responsibly and effectively to optimise your marketing communications.
Is Cold Emailing Legal in the UK?
Generally speaking, yes. However, there are regulations organisations must comply with when sending unsolicited emails.
Cold emailing is defined as sending an email without prior consent having been given, so this doesn’t include those who have subscribed or consented to hear from your company.
Unsolicited emails may be sent individually by one organisation representative to another after finding their email address on a company website, or they may involve mass scraping of business contact information for mass emailing. Although these seem wildly different in terms of business ethics, essentially the same rules apply legally.
Under GDPR and PECR, you must have a lawful basis for contacting someone. The three acceptable and legally compliant reasons outlined are as follows –
Consent: You may of course contact a person if they have given explicit consent for you to do so. We’ll explain the parameters of this further down.
Contractually Necessary: Another obvious one, though this won’t generally apply to email marketing. You may cold email someone in relation to an existing contract or legal obligations.
Legitimate Interest: This one is far more ambiguous, although legitimate interest cannot be used as a lawful reason to contact a consumer. It can be used as a lawful basis to contact a business though, and this legitimate interest can be as simple as you believe they might be interested in your product or services. However, you will need to meet some criteria, and to document this.
Note on email scraping - Since we’ve touched on email scraping in this section, we should clarify that it is not illegal for B2B purposes so long as you’re compliant with UK GDPR and PECR. However, you must also adhere to the Computer Misuse Act 1990, which makes it a criminal offence to bypass security or breach website terms of service to obtain information. We must be especially mindful of this when using automated scraping tools or AI, because it’s the user and not the technology who is held legally responsible for breaches.
Legitimate Interest Assessment (LIA) for Email Marketing
If you are sending B2B emails without prior consent, you may use the legitimate interest clause in UK GDPR. This clause exists to allow businesses to conduct outreach in a way that is fair, reasonable and respectful of individual rights.
To ensure you meet the criteria to argue this lawful basis though, you’ll need to conduct a Legitimate Interest Assessment (LIA). Within this, you must be able to specify –
Purpose - Give a legitimate reason for making contact. This should be specific to your business and theirs.
Example: You may be reaching out to a pet store owner to introduce your pet-related product with the goal being that they’ll consider stocking it.
Necessity - Justify why you have chosen this method of contact. How does it help you reach your goal? Is email a less intrusive means of making contact than other available options?
Balancing - The balance test is about recognising and respecting the privacy rights of the receiver and ensuring you meet those. This will include an unsubscribe or opt-out option in your email and limiting how many follow-ups are sent. You must also be absolutely sure you’re contacting a business through a business email address, as you cannot use the legitimate interest basis for sending communications to personal email accounts.
Your LIA must be documented so you can produce it should your emailing practices be brought into question. It’s also an assessment you may have to reconduct for each campaign, as the legitimate interest may differ from one email outreach campaign to another. Although this may feel like extra work, generally all of the above will have been decided when you defined the purpose and goals of the marketing campaign.

B2C Email Marketing Compliance
Email marketing is a highly effective tool. It’s an excellent way to share offers, build brand recognition, showcase new products, keep your customers updated and make personalised recommendations. For community groups and memberships, it’s fairly essential for keeping your community active, especially if they’ve opted out of notifications, as many do since they’re generally more intrusive. However, requesting and processing personal information for email marketing purposes comes with legal obligations.
You must protect personal data as stipulated by UK GDPR. This means you’ll need a Privacy Policy that informs users what personal information you collect, the purpose for this, how information will be used, how it’s kept secure and how long it will be stored. You must link to your privacy policy every time you request personal information. However, it’s also good practice to add a privacy policy link to marketing emails, and some email platforms, including Mailchimp, make this a requirement in their terms of service.
If using a marketing email platform, you’ll also need to comply with the platform’s terms, and you’ll need to flag this in your privacy policy, since they’ll be processing client data as a third party.
An opt-out or unsubscribe must be included in every marketing email you send, and this must be actioned immediately, as sending further marketing communications after may breach data protection.Transparency is crucial to staying compliant. Always display your business name and/or logo clearly so the receiver can see instantly who the email is from, and don’t attempt to misrepresent content that is promotional.
Can My Business Send Marketing Emails To Customers Without Consent?
Technically, no. Businesses should not be sending marketing emails without explicit consent. Doing so will put you in breach of data protection regulations. However, the ICO does allow a ‘soft opt-in’ exemption.

The soft opt-in exemption can be applied to previous customers/clients who have made purchases from your business before. You may add these contacts to your subscriber list or to an email workflow, provided you only send them communications about the same or similar goods/services that they purchased before and you offer a clear option for them to easily opt out or unsubscribe at any time.
Service Emails vs Marketing Emails
Companies are allowed to send service emails to customers who have not given consent to receive marketing emails. Service emails deemed necessary to send might include updates to terms and conditions, tariff changes, notice of service being affected, etc. Generally, this would be handled by customer care teams and not marketing personnel. In smaller businesses, though, responsibilities may fall to the same person or department, and there may be a temptation to make a product recommendation or encourage the customer to consider moving to a more expensive package; then it becomes a marketing email. That then means you cannot send it to anyone who has not opted in to marketing communications. Keep it simple and keep marketing or promotional content completely out of service emails.
Obtaining Consent To Send Direct Marketing Emails
Consent is nearly always required when sending direct marketing emails. The rules around this are outlined in the PECR standard of consent and include the following:
Consent must be explicitly given via an affirmative action. Therefore, consent cannot be implied when someone agrees to your terms and conditions. Instead, a dedicated form or a tick box option (that must not be set to pre-ticked) may be used.
When requesting consent, a link to your privacy policy should be displayed so users can make an informed decision.
Consent must be freely given without coercion, so you may not, for instance, attach a discount or special offer that is dependent on giving consent to receive marketing communications.
Wording must be unambiguous and not include double negatives.
Even when consent has been given, each marketing email you send thereafter must carry an option to opt out or unsubscribe. In email marketing, this is usually included in the footer, making it easier for marketing professionals to ensure it’s always included in the email template.
Help With Email Marketing Compliance
If you’re unsure of whether your privacy policy covers your email marketing, or if your consent opt-ins meet with UK GDPR, then please get in touch with Aubergine Legal, and we’ll be happy to advise you.
You can also find marketing checklists, guides and videos in the Marketing Legal Services section of our website. If you’re looking for everything you need to stay compliant with your business marketing, though, you should check out our Marketing Legal Toolkit - this contains all the key legal documents you need to run your marketing business and to ensure you are protected legally, including:
A Welcome Guide explaining how to use the toolkit and the documents contained within it.
Marketing Services Client Agreement Template
Marketing Services Online T&Cs Template
Marketing Power Hour T&Cs
Marketeers Privacy Policy
Marketing Website Terms & Conditions Template
Marketeers Cookie Policy Template
Marketing Supplier Agreement
Freelance Marketeer Start-Up Checklist
Trade Mark Checklist for Marketeers
AI Compliance Checklist for Businesses
GDPR Guidance
All legal agreements are in Word format for you to edit and add your business logo.




