B2B is not exempt from GDPR. The ICO says directly that UK GDPR applies to B2B marketing whenever personal data is involved, including the name of a person who represents a business. What is different for B2B sits in PECR, the separate electronic-marketing rules, where the consent requirement for email does not apply to corporate subscribers.
This is not legal advice. It is a summary of what the regulators publish, with links so you can read the primary text. Get advice for your own situation.
The two laws, and why conflating them causes the confusion
Almost every wrong claim about B2B outbound comes from treating this as one rule rather than two.
UK GDPR governs the processing of personal data. A named person at a company is personal data. Their work email at a company is personal data if it identifies them. This applies to B2B, always, and there is no business-context carve-out.
PECR governs electronic marketing specifically: emails, texts, calls, faxes. It talks about subscribers rather than data subjects, and it distinguishes corporate from individual ones.
So "B2B is exempt" is a garbled version of a narrower true statement: PECR's consent rule for electronic mail does not apply to corporate subscribers. Everything GDPR requires still applies.
Who counts as a corporate subscriber
This is the distinction that decides your exposure, and it is not the one most people build their filters on.
Per the ICO, corporate subscribers are corporate bodies with separate legal status: companies, limited liability partnerships, Scottish partnerships, some government bodies, and any other entity that is a legal person distinct from its members. The ICO notes that an employee's work email at a corporate body counts as the corporate subscriber, because the subscriber is their employer.
Individual subscribers include sole traders, most partnerships, and other unincorporated bodies of individuals. PECR treats them the same as consumers. For them, email marketing needs specific consent, or the existing-customer soft opt-in.
That soft opt-in is narrower than people assume. The ICO is explicit that it applies to your own previous customers who bought or discussed buying something similar, were given a clear chance to opt out when you collected their details and in every message since. It does not apply to prospective customers or new contacts from bought-in lists.
The practical problem: no B2B dataset reliably tells you which of the two you are looking at. A two-person consultancy might be a limited company or might be a partnership, and the distinction is a legal one that headcount and industry filters do not capture. If a meaningful share of your ICP is very small businesses, that is a real gap in any list you buy, including ours.
What GDPR still requires, even for corporate subscribers
Four things, none of which PECR's corporate carve-out touches.
A lawful basis. Legitimate interests is what most B2B prospecting relies on. It is not a formality. It requires a documented assessment weighing your interest against the individual's rights, interests and reasonable expectations, and the assessment can conclude that you fail. The ICO publishes guidance on legitimate interests covering how to run and record it.
Privacy information. People whose data you process are entitled to know you are processing it, who you are, why, and on what basis. In practice this means a reachable privacy notice and, commonly, telling recipients where you got their details when they ask.
The right to object. Someone can tell you to stop, and you must. For direct marketing this is absolute: there is no balancing test to apply once they object.
Data minimisation and accuracy. Holding more than you need, or holding data you know is wrong, is a problem independent of how you use it.
Where the usual advice goes wrong
"We bought the list from a compliant vendor, so we're fine." A vendor's compliance covers the vendor's processing. When you export or receive data you are an independent controller of it and your own lawful basis is your own to establish. This is the most common misunderstanding we see, and it is the one that transfers risk to you invisibly.
"It's a work email, so it isn't personal data." firstname.lastname@company.com identifies a person. The ICO specifically flags data protection implications for emailing employees at corporate bodies who have personal corporate email addresses.
"Legitimate interests means we can do what we like." It means you did an assessment and concluded the balance favours you. If you have not done one, you do not have the basis; you have an intention.
"We're US-based so this doesn't apply." Territorial scope follows the people, not your office. Targeting individuals in the UK or EU brings you in.
The other jurisdictions, briefly
US, CAN-SPAM. No prior consent needed for commercial email, but the message must not use deceptive headers or subject lines, must identify itself as an advert, must include a valid physical postal address, must offer a working opt-out, and must honour it promptly. The FTC publishes a compliance guide.
Canada, CASL. Substantially stricter than either. It generally requires express or implied consent before sending commercial electronic messages, with specific rules on what counts as implied and how long it lasts. The Government of Canada's CASL site is the primary source.
EU. The ePrivacy Directive is PECR's parent, but member states implemented it differently, so the B2B position genuinely varies country to country. Do not assume the UK answer travels.
What good practice looks like regardless
Independent of what you are strictly required to do, and mostly because it costs nothing:
- Keep a suppression list and screen every new list against it. The ICO recommends exactly this for corporate subscribers even though PECR does not require it. It is also the difference between one complaint and a pattern of them.
- Make opting out one click, and honour it everywhere, not just in the tool that sent the message.
- Say where you got their details when someone asks. The answer being embarrassing is a signal worth listening to.
- Write the legitimate interests assessment down. A page. The exercise of writing it is what surfaces the cases where the answer is no.
- Do not email people at their personal addresses because a provider found one. Work address, work context.
What we do, and what remains yours
Signl provides business contact details for business-to-business prospecting. Where we process personal data of individuals in the UK or EEA, we rely on legitimate interests under Article 6(1)(f) UK GDPR. Deletion requests reaching us are actioned across our systems, and we keep a minimal suppression record afterwards so an erasure cannot be quietly undone by later processing.
Person-level content analysis constitutes profiling under Article 4(4) UK GDPR, so it sits behind its own switch rather than riding along with employment data, and person-level records are deleted on a fixed schedule: 90 days for public professional activity, 180 days for role-change signals.
What stays with you: you are an independent controller of anything you export, and your lawful basis, your privacy information and your opt-out handling are yours. Our privacy policy and fair use policy set out the full position.
Sources
All verified 25 August 2026.
- ICO, Business to business marketing. Source of the corporate versus individual subscriber definitions.
- ICO, Electronic mail marketing. Source of the soft opt-in scope.
- ICO, Legitimate interests.
- FTC, CAN-SPAM Act compliance guide.
- Government of Canada, CASL.
- EUR-Lex, Directive 2002/58/EC.