- Two rulebooks, not one. UK GDPR decides whether you may process someone as personal data at all. PECR decides whether you may send them a particular kind of message. You need both answers, and a corporate email address only ever answers the second.
- The PECR question is subscriber type, not email domain. Companies, LLPs and Scottish partnerships are corporate subscribers; sole traders, ordinary partnerships and other unincorporated bodies are individual subscribers, whatever their address looks like.
- The products-and-services soft opt-in is an existing-customer exception, not the corporate-subscriber rule. They are separate PECR concepts, and the ICO is explicit that it does not reach cold prospects or bought-in lists.
- PECR and UK GDPR are separate decisions. PECR needing consent for a message does not mean consent is the only available lawful basis for the underlying processing.
- Scoring and segmentation is usually profiling because it evaluates or predicts personal aspects. The ADM provisions (articles 22A-22D since the Data (Use and Access) Act 2025) are narrower: a solely automated decision with a legal or similarly significant effect.
This article is general information about how UK data protection and marketing rules apply to AI-assisted outreach. It is not legal advice, and it is not a compliance certification for any particular workflow. Positions here are drawn from published ICO guidance, which the ICO itself notes is under review following the Data (Use and Access) Act. Take advice on your own processing.
Most B2B teams carry a vague sense that “legitimate interests covers our outbound.” Some hold opt-in consent for parts of a list. Many have neither written down, and send anyway.
When outreach was manual, that ambiguity stayed small. Mistakes usually propagated more slowly and were easier to review individually.
AI agents change the arithmetic. An agent that enriches a record, segments it by persona, scores it for fit, writes a personalised opener, and triggers a multi-channel sequence has carried out several distinct processing operations before anyone reads a message. Each one needs a basis. “We assume legitimate interests covers it” is an assumption, not a lawful basis.
Two separate rulebooks, and the order you answer them in
The single most common mistake in this area is treating UK GDPR and PECR as one question. They are not, and they can give different answers about the same person.
UK GDPR governs whether you may process personal data at all: collecting a name, enriching a record, storing it, scoring it, writing copy from it. You need a lawful basis for each purpose, plus transparency about what you are doing. The ICO is explicit that this applies in a business context — if you hold the name of the individual who represents the business, you are processing personal data.
PECR governs whether you may send a particular kind of message down a particular channel: live calls, automated calls, email and other electronic mail. PECR talks about subscribers — the customer named on the bill for the line or connection — and divides them into corporate and individual.
So the order is: does UK GDPR let me process this person’s data for this purpose, and separately, does PECR let me use this channel to reach them? A corporate email address may answer the second question favourably while doing nothing at all for the first.
Subscriber, channel, and processing decision matrix
Two tables, because there are two decisions to make about every record: which channel you may use, and what you are allowed to do to the data before you use it.
Part A — subscriber type and channel. Work out the subscriber first, then read across. The PECR column and the UK GDPR column are deliberately separate: they are two decisions, and clearing one does not answer the other.
| Record and channel | PECR subscriber class | What PECR requires for the message | Screening before send | Possible UK GDPR basis to assess for the processing | Evidence and safeguards to retain |
|---|---|---|---|---|---|
| Email to a named employee at a company, LLP, or Scottish partnership | Corporate subscriber — the subscriber is the employer | The electronic mail rule in regulation 22 does not apply to corporate subscribers, so prior consent is not required for the message itself | Your own suppression list | Legitimate interests is the usual candidate; assess purpose, necessity, and the balancing test rather than assuming it | Completed LIA, privacy information, working opt-out, record of source |
| Email to a sole trader, ordinary partnership, or other unincorporated body | Individual subscriber — treated the same as an individual | Consent, or a genuinely applicable products-and-services soft opt-in | Your own suppression list | Consent or legitimate interests, depending on purpose, necessity, expectations, risk, and safeguards — PECR requiring consent for the message does not decide this | Consent or soft opt-in evidence, LIA where relied on, opt-out record |
| Email to a personal address | Individual subscriber | Consent, or a genuinely applicable products-and-services soft opt-in | Your own suppression list | Consent or legitimate interests, assessed on the same factors — not automatically consent | Consent or soft opt-in evidence, LIA where relied on |
| Live marketing call, any B2B number | Either — follows the subscriber, not how the number looks | No call to anyone who has objected, and no call to a registered number without the required consent | Both TPS and CTPS, plus your own do-not-call list | Legitimate interests is the usual candidate, assessed and documented | Completed LIA, screening result and timestamp, do-not-call record |
| Automated call playing a recorded message | Either | Consent that specifically covers automated calls; general marketing consent or consent to live calls is not enough | Consent record, then TPS and CTPS | Consent for the processing tied to that purpose | Consent evidence naming automated calls, screening record |
| LinkedIn or other platform direct message | Electronic mail rules apply to direct messaging via social media | Answer the subscriber question as for email; platform terms apply on top of PECR, not instead of it | Your own suppression list | Legitimate interests is the usual candidate, assessed and documented | Completed LIA, record of what the platform terms permit |
Part B — processing stage worksheet. Everything below happens before or around the send, and each row needs its own answer.
Two columns need reading carefully. Profiling is not a property of the stage — it depends on whether the automated processing evaluates or predicts personal aspects, so the answer is about how you built it. ADM provisions refers to articles 22A-22D of the UK GDPR, which apply only to a solely automated decision with a legal or similarly significant effect; ordinary outbound work does not reach that threshold on its own.
| Processing stage | What is actually happening | Profiling? | ADM provisions (articles 22A-22D) in scope? | Possible UK GDPR basis to assess | Evidence and safeguards to retain |
|---|---|---|---|---|---|
| Enrichment | Adding email, phone, title, firmographics to a record | Depends on whether automated processing evaluates or predicts personal aspects — appending factual data is not profiling, inferring seniority or likely interests may be | Very unlikely — no decision with a legal or similarly significant effect | Legitimate interests, assessed for this specific purpose | Source of each field, date acquired, LIA covering acquisition |
| Storage and reuse | Holding the enriched record in a CRM, saved list, or dataset | Not on its own | No | Legitimate interests, assessed against continued necessity | Retention rationale, review date, deletion or archive log |
| Scoring and segmentation | Ranking fit, assigning personas, choosing a sequence | Usually yes — it evaluates or predicts aspects about a person | Not on its own; choosing which sequence someone enters is not normally a significant decision | Legitimate interests, assessed and documented | What inputs feed the score, transparency notice, objection route |
| Personalisation | Generating opening lines from title, company, and public activity | Depends — inserting a stored field is not profiling; inferring interests or behaviour to select an angle may be | Very unlikely | Legitimate interests, assessed for this purpose | Which fields the model may use, and which are off-limits |
| Automated sending | An agent triggering the message without a human in the loop | Not merely because a system triggers it — the question is whether personal aspects are evaluated | Only where a solely automated decision produces a legal or similarly significant effect | Legitimate interests, plus the separate PECR answer from Part A | Human review points, send-gate rules, what the agent may not do alone |
| Suppression and opt-out | Recording an objection and blocking every future contact | No | No | Compliance with the right to object; the objection must be honoured whatever basis applied | Timestamp of request, propagation log across every system that can send |
Read Part B against Part A for every list. A record can clear Part A on channel and still fail Part B because nobody wrote down why the enrichment step was necessary.
Corporate subscribers and the soft opt-in are different things
These get conflated constantly, including in a previous version of this article.
The corporate-subscriber rule is about who the subscriber is. Under PECR, corporate subscribers are bodies with separate legal status: companies, corporation soles, limited liability partnerships, Scottish partnerships, some government bodies. The ICO’s position is that the marketing rules apply equally to corporate and individual subscribers, with one main difference — the electronic mail rule does not apply to corporate subscribers. That is the whole of it.
The products-and-services soft opt-in is a different thing entirely: an existing-customer exception inside the electronic mail rule, subject to its statutory conditions. Broadly, it is available where the person bought or negotiated to buy a similar product or service from you, you gave them a clear opportunity to opt out when you collected their details, and you give them that opportunity in every message since. The ICO states plainly that it does not apply to prospective customers or new contacts, including bought-in lists.
Naming it precisely matters because it is not the only soft opt-in in the frame. Current PECR guidance may also refer to a separate charitable-purposes soft opt-in, which is outside the scope of this commercial B2B article — if you are fundraising or campaigning rather than selling, the rules you need are not the ones described here. The ICO’s PECR guidance is under review following the Data (Use and Access) Act, so confirm the current position for whichever exception you are relying on.
For commercial outreach the practical point is unchanged: the products-and-services soft opt-in is not what makes cold B2B email to a company possible, and it will not rescue a cold list. If someone describes a purchased prospect list as covered by the soft opt-in, that description does not hold.
The email domain is a heuristic, not the test
Sorting a list into “professional” and “personal” domains is a useful operational filter. It is not the legal distinction, and relying on it alone will misclassify records in both directions.
A @ followed by a company-looking domain tells you nothing definitive. A sole trader can run their business from a branded domain and remains an individual subscriber. An ordinary English, Welsh, or Northern Irish partnership — one that is not an LLP — is an individual subscriber with a smart website. Meanwhile a genuine employee address at a corporate body counts as a corporate subscriber precisely because the employer is the subscriber on the account, not the person typing.
What this means in practice is that the classification step needs a corporate-status signal, not a domain regex. Company registration data is the obvious input: a record you can tie to a registered company, LLP, or Scottish partnership is one you can defend as a corporate subscriber; a record you cannot should be handled as an individual subscriber until you can. That check belongs in the data layer, before anything reaches a sequence, which is the same argument made in the prospect data governance framework.
Calls: screen both registers
For phone, the rules are effectively the same for businesses and individuals, and legitimate interests does not override a preference-service registration.
The TPS holds individuals who have opted out of live marketing calls. The CTPS does the same for corporate bodies. Because sole traders and some partnerships register with the TPS while companies and government bodies register with the CTPS, the ICO’s guidance for B2B calling is to screen against both registers, plus your own do-not-call list. Automated calls are stricter again and need consent that specifically covers automated calls.
The mechanics of wiring this into an agent-driven workflow are covered in the TPS screening guide.
Profiling, and where the automated-decision rules actually begin
Two separate questions get run together here, and a previous version of this article ran them together too.
Is it profiling? Profiling is automated processing that evaluates certain personal aspects of someone — analysing or predicting things like their interests, behaviour, reliability, or economic situation. That makes it a question about how your system works, not about which workflow stage you are looking at. Appending a phone number to a record is not profiling. Inferring seniority, likely budget, or probable intent from a job title and a browsing signal may well be. Scoring and segmentation usually are profiling, because ranking someone by fit is evaluating an aspect of them.
Where profiling happens, transparency duties apply — and the right to object to direct marketing, including profiling for direct marketing purposes, is absolute. Once someone objects, you stop.
Do the automated-decision rules apply? That is a narrower question, and the answer is usually no for ordinary outbound. Following the Data (Use and Access) Act 2025, these sit in articles 22A-22D of the UK GDPR rather than the old article 22. The ICO’s guidance describes three conditions that must all be present: a system is making a decision about a person, the decision is a significant decision meaning it has a legal or similarly significant effect, and it is solely automated with no meaningful human involvement.
Ordinary lead scoring and campaign segmentation do not clear that bar on their own. Deciding which of your sequences someone enters is not a decision with a legal or similarly significant effect on them. Nor is every automated output a “decision” — the ICO distinguishes a system making its own evaluative judgement from a system applying a rule a human already set.
A short note on the current position, because it has changed and is still moving:
- Solely automated decisions with legal or similarly significant effects remain a special case requiring safeguards.
- Current UK law allows a wider range of lawful bases for these decisions than the older article 22 framing suggested. The ICO’s draft guidance says all seven article 6 bases are available except the recognised legitimate interests basis, which cannot be used for them.
- Meaningful human involvement, transparency about the significance and envisaged consequences, a route to challenge a decision, and the ability to obtain human intervention all remain central.
- The ICO’s guidance on this is in draft and under consultation, so confirm the current position rather than relying on this summary.
The useful question for an outbound team is therefore not “is an AI doing this?” but “is a decision being made about this person with no meaningful human involvement, and does that decision materially affect them?” Most outbound scoring answers no to the second half. Keep asking it anyway, because the answer changes if agents start gating access to pricing, credit, or eligibility.
Retention: no universal number
An earlier version of this article recommended deleting prospect data after twelve months. That number was not supported by anything, and this article should not have carried it.
Storage limitation does not set a period. It requires that you keep personal data no longer than you need it for the purpose you are processing it for, and that you can justify however long you do keep it. A defensible retention position is built from:
- Purpose — what you are still using the record for, stated specifically enough to test.
- Necessity — whether that purpose genuinely still requires this data, or requires less of it.
- Expectations — what the person would reasonably anticipate, given how you obtained the record.
- Risk — the volume and sensitivity of what you hold, and the harm if it leaked.
- Policy — a written retention schedule, applied automatically, with review dates and a record of what was deleted.
Two organisations can defend very different periods for the same field. What neither can defend is holding everything indefinitely because deletion was never built.
Opt-outs have to outrun the agent
Every message needs a working way to opt out, and the objection has to take effect everywhere before the next send.
This is where agent-driven outreach breaks in a way manual outreach did not. If an agent works from a cached list, or a suppression file that syncs nightly, a person who unsubscribes can receive another message hours later. The original lawful basis does not help you there. Suppression needs to be a hard block at the data layer that every sending path reads through, not a filter bolted onto one sequence tool — the argument set out in governing prospect data before AI agents touch it.
Sources and further reading
Official ICO guidance only. These are the sources this article is based on, and the place to check before making a decision about your own processing. The ICO notes that its direct marketing guidance is under review following the Data (Use and Access) Act, so confirm the current position rather than relying on this page.
- ICO: Business-to-business marketing — corporate versus individual subscribers, and when UK GDPR applies to B2B.
- ICO: Guide to PECR — the structure of the regulations.
- ICO: Electronic mail marketing — regulation 22, and what the soft opt-in is and is not.
- ICO: Telephone marketing — live and automated calls, TPS and CTPS.
- ICO: Direct marketing guidance hub — the full set of detailed direct marketing guidance.
- ICO: Lawful basis for processing — consent — what valid consent requires.
- ICO: Lawful basis for processing — legitimate interests — the three-part test and the LIA.
- ICO: Automated decision-making, including profiling — what counts as profiling, and the scope of the articles 22A-22D provisions. Draft guidance, under consultation following the Data (Use and Access) Act 2025.
- ICO: Storage limitation — why retention periods are justified rather than fixed.
Wrapping up
The law did not change when agents arrived. What changed is how many processing steps sit between acquiring a record and contacting a person, and how quickly a bad classification propagates.
The teams that handle this well do not treat it as a review at the end of the workflow. They resolve subscriber type from company data rather than domain shape, write the LIA before the first send rather than after the first complaint, keep the automated-decision question honest instead of either ignoring it or invoking it for everything, justify their retention periods in writing, and make suppression a hard block that no agent can route around.
None of that is a guarantee of compliance, and this article cannot give you one. It is the difference between a position you can explain and an assumption you cannot.
DataFixr resolves company records against registration data, screens phone numbers, and enforces suppression and retention controls at the data layer - so classification happens before an agent sees the record, not after. Start using DataFixr free ->
