Leadistry
Log inGet 10 free leads

Cold email and UK GDPR: what legitimate interest actually requires

LT
Leadistry Team29 JUL 2026 · 7 MIN READ

Legitimate interest is the lawful basis almost every UK B2B cold email relies on, and it is not a loophole. It asks for three things: an interest you can name, evidence the emailing is necessary, and a documented balancing exercise.

Legitimate interest is the lawful basis almost every UK B2B cold email relies on, and it is not a loophole. To use it properly you need three things: a genuine interest you can name, evidence that the emailing is necessary for it, and a balancing exercise showing the recipient's interests do not override yours. The ICO frames this as a three-part test, and it expects you to record the answers in a legitimate interests assessment before you send, not after someone complains.

This is not legal advice. It is an operator's summary of the rules we follow ourselves to keep the Leadistry database compliant, and part of our wider UK B2B data compliance guide.

Where legitimate interest fits in the law

UK GDPR requires a lawful basis for any processing of personal data, and a named business email like jane.smith@acmeltd.co.uk is personal data because it identifies a living person (we cover that fully in is a business email personal data?). Of the available bases, consent is impractical for cold outreach by definition, which leaves legitimate interest, Article 6(1)(f): processing that is necessary for your legitimate interests, except where the individual's interests or rights override them.

Helpfully, the law acknowledges the use case. Recital 47 of the GDPR states that processing for direct marketing purposes "may be regarded as carried out for a legitimate interest". Note the word may. It is an available basis, not an automatic one: you still have to pass the test for your specific processing.

The three-part test, in plain English

The ICO's guidance breaks legitimate interest into three questions, and all three need a yes:

  • Purpose: are you pursuing a legitimate interest? Growing your business by introducing a relevant product to companies that plausibly need it is a legitimate interest. Name it specifically: "introducing our bookkeeping service to newly incorporated companies in the North West" is a purpose; "marketing" is not.
  • Necessity: is the processing necessary for that purpose? Necessary means proportionate and targeted, not indispensable. Emailing named decision-makers at companies matching your customer profile passes. Blasting an entire purchased list of everyone with an email address does not, because a narrower, better-targeted approach would achieve the same purpose.
  • Balancing: do the individual's interests override yours? Consider what the recipient would reasonably expect. A director who has published a business email, receiving one relevant, clearly identified B2B message with a working opt-out, is inside reasonable expectations. A personal address harvested from a social profile, hit with a daily sequence, is not.

The LIA: write it down before you send

The legitimate interests assessment is simply the three answers above, recorded. The ICO expects organisations relying on legitimate interest to keep an LIA as evidence that the thinking happened. In practice a page covering these points is enough for a typical B2B campaign:

  • The specific interest being pursued, and who benefits
  • Why email to these recipients is necessary and proportionate for it
  • Where the data came from and what it contains
  • The balancing factors: business context, published contact details, relevance of the offer, ease of opting out
  • The safeguards: suppression lists, verification, sending limits, prompt handling of objections

Keep it with the campaign. If a recipient or the ICO ever asks "what was your lawful basis?", the answer is a document, not a scramble.

PECR sits on top

Passing the three-part test is necessary but not sufficient, because the Privacy and Electronic Communications Regulations apply to the sending itself. The two regimes stack:

  • UK GDPR governs holding and using the personal data (the named email address). Legitimate interest is your basis there.
  • PECR governs the marketing message. For email, corporate subscribers (limited companies, LLPs) can be emailed without prior consent; sole traders and ordinary partnerships count as individuals and need consent or the soft opt-in. The full split is in can you email sole traders?.

Every message must also identify who you are and carry a valid opt-out route. And since February 2026, under the Data (Use and Access) Act, the maximum PECR penalty is £17.5 million or 4% of turnover, the same ceiling as UK GDPR, so the sending rules are not the junior partner any more.

The absolute right to object

One right cuts through every balancing argument: an individual's right to object to direct marketing is absolute. There is no override, no "but our interest is strong". If someone objects or opts out, you stop, permanently, and your suppression list is what makes "permanently" true. A one-off deletion that lets the same contact re-enter through next month's data import is a breach waiting to happen.

What this looks like as a working routine

  • Target companies, not people: build lists from the public record so every recipient is at an incorporated business.
  • Use published, named business emails, verified before sending, never guessed patterns.
  • Write the LIA once per campaign type and review it when your targeting changes.
  • Identify yourself in every message, with a real reply route and a one-click opt-out.
  • Suppress objections account-wide and forever.

How Leadistry is built around this

The data side of that routine is the product. Every Leadistry lead is an incorporated company traced to its Companies House record, with a business email published by the company itself, screened against sole traders and freemail. Built-in outreach adds the sending safeguards: identification and opt-out in every message, one-click unsubscribe honoured across the account, and a permanent removal route for any company. Your legitimate interest and your LIA are yours, but the data underneath them starts defensible.

Start free with 10 leads and see exactly what a filing-traced, compliance-first lead looks like.

PUT THIS INTO PRACTICE

Filter 5 million UK companies by SIC code, region and incorporation date, enriched and ready to contact.

Run it on your free 10 →
NO CARD · 10 FREE LEADS · COUNTS ARE FREE
LT
The Leadistry Team

Leadistry maintains a live database of 5 million UK companies, enriched from the Companies House register with verified websites, business emails and social profiles. We write about the craft of finding and reaching the right businesses, first.

See how Leadistry works →
KEEP READING
Can You Legally Email Sole Traders in the UK? Corporate vs Individual SubscribersUK BUSINESSIs a Business Email Address Personal Data Under UK GDPR?UK BUSINESSThe Complete Guide to SIC Codes for UK B2B Lead GenerationUK BUSINESS

Five million companies. Ten introductions, free.

Start free with 10 leads →

No card  ·  10 free leads  ·  Cancel anytime