Check the business behind the address
The ICO distinguishes corporate subscribers, such as limited companies and limited liability partnerships, from individual subscribers, including sole traders and certain partnerships. Under its B2B guidance, PECR does not require consent for marketing emails to corporate subscribers. Senders must still identify themselves and provide a valid opt-out address. Named work contacts can also be personal data under the UK GDPR.
Sole traders and some partnerships generally need specific consent unless the soft opt-in applies. That exception has several conditions, including obtaining the details during a sale or sales negotiation for your own similar products or services and offering an opt-out when collecting them and in each message. If subscriber status is uncertain, the ICO advises treating the address as an individual subscriber. Record the evidence behind your classification. A company-sounding trading name is insufficient.
Write down the reason for using personal data
Where PECR does not require consent, legitimate interests may be available. The ICO's assessment asks you to identify the interest, establish why the processing is necessary and weigh it against the person's rights and expectations. Keep the assessment before using the data. Legitimate interests cannot replace consent where PECR requires it.
For an illustrative procurement conference, the record should explain why a particular purchasing role is relevant to the programme. An unrelated personal address or an unclear source deserves further investigation. Give the reviewer enough information to reject unsuitable records without having to reconstruct the research.
Make the privacy information part of the first contact
The ICO's right-to-be-informed guidance sets deadlines for information obtained elsewhere: within a reasonable period, no later than a month, and by the first communication if that happens sooner. Earlier disclosure can also trigger the deadline. Exceptions exist, but a routine campaign should have an approved notice and a clear way for the recipient to find it.
Check that the notice describes the actual sender and use of the data. A generic website link is little help if the notice describes only website enquiries while the team is researching and inviting event delegates. Keep the source and collection date with each record.
Carry objections into every follow-up
People have an absolute right to object to use of their personal data for direct marketing. Retaining a minimal suppression record helps prevent another import from contacting them again. Assign someone to process replies and test that a removal reaches queued follow-ups.
For EU recipients, review the applicable electronic marketing rules alongside GDPR. The European Commission specifically includes ePrivacy requirements in its advice on acquired marketing lists. A UK list review does not clear a cross-border campaign. The ICO also flags its B2B guidance as under review following the Data (Use and Access) Act. Recheck it when preparing an actual campaign and obtain advice for unresolved cases.
Sources and further reading
- ICO: business-to-business marketing
- ICO: legitimate interests
- ICO: right to be informed
- ICO: right to object
- European Commission: using third-party data for marketing
Sources checked 27 September 2026. Guidance can change. This article combines cited source information with Summitrix’s proposed working approach.