Skip to content

I Love SalesFree, every week.

JumpLead
Outbound Alternatives

Is Cold Calling Legal in the UK? The B2B Rules

Joe Stone
Joe Stone
6 min read
A cream clay desk telephone whose coiled cord runs across the table to a small open padlock in red

The short answer

Yes. Live B2B cold calls are legal in the UK under PECR if you screen numbers against the TPS and CTPS (unless the person has specifically consented), never call anyone who has asked you not to, say who is calling and show your number. Automated marketing calls need specific consent, and the ICO can fine up to £17.5 million.

When founders ask me about adding the phone to their outbound, the first question is nearly always the same: is cold calling even legal any more? It is. Live business-to-business calls are legal in the UK, but the rules are specific, the regulator enforces them, and the fines went up this year.

I have spent 15 years in B2B sales and I still make calls myself, so this is the version I wish someone had handed me. It sets out what the Information Commissioner's Office (ICO) says you must do before and during a live marketing call, where sole traders fit in, what changes for automated calls, and a checklist you can run before your next list goes anywhere near a phone. It is a plain summary of the ICO's guidance, not legal advice.

Yes. Unsolicited live marketing calls, including calls to businesses, are allowed under PECR as long as you follow its rules. The ICO's guidance on live calls says you can make unsolicited live direct marketing calls to numbers that aren't on the Telephone Preference Service (TPS) or the Corporate Telephone Preference Service (CTPS). The rules are the same whether you are calling a person or a company. What changes is which register you check.

Two things catch people out. The rules apply to marketing calls, which includes promoting your own services to a business, not just consumer sales. And the ICO says its guidance is under review after the Data (Use and Access) Act, so check the current version before you build a process around it.

The rules for live B2B marketing calls

The ICO's guide to telephone marketing sets out what you must not do and what you must always do. In plain terms:

  • Do not call anyone who has told you they don't want your calls.
  • Do not call a number registered with the TPS or CTPS, unless that person has specifically consented to your calls.
  • Always say who is calling. Give the name of your organisation, not just your first name.
  • Always show your number, or a valid alternative contact number. Withholding it is not allowed.
  • If asked, give contact details or a Freephone number for your organisation.

The ICO also recommends keeping your own do-not-call list of anyone who says they don't want your marketing calls, and screening against it as well as the registers. In practice that list is the one that protects your reputation, because it holds the people who told you no.

TPS and CTPS: what to screen and when

There are two registers. The TPS covers individuals, which includes sole traders and some partnerships. The CTPS covers companies and other corporate bodies. The ICO says you must check numbers against both before you make the calls.

28 days

How long a number must sit on the TPS or CTPS before the registration takes effect. Screen your list again at least every 28 days, or it goes out of date.

Source: ICO, What are the rules on live direct marketing calls?

One screening provider, TPS Services, puts it bluntly: you are legally required to screen cold-call data against the TPS when targeting consumers, or the CTPS when targeting businesses, every 28 days. A list you screened in the spring is not a screened list today.

Consent is the one way past a registration. The ICO's business-to-business guidance says you cannot call numbers registered with the CTPS or TPS unless the business has consented. Consent here means they specifically agreed to calls from you, not that their number appears on a website.

Sole traders and partnerships count as individuals

This is the most common mistake I see in B2B lists. The ICO says sole traders and other types of partnerships are classed as individual subscribers, and PECR treats them the same as individuals. So a plumber trading under their own name, a freelance consultant or a small partnership is screened against the TPS, not the CTPS, and the rules for personal data apply in full.

Limited companies and limited liability partnerships are corporate subscribers. If your list mixes both, which most small-business lists do, screen against both registers.

Automated calls and the sectors with stricter rules

Everything above is about live calls, where a person speaks to a person. Automated marketing calls, where a recorded message plays, are a different category. The ICO says you must not make an automated marketing call unless the person has specifically consented to receive that type of call from you.

Two sectors also sit under tighter rules for live calls. For claims management and pensions calls, the ICO says you must have the person's specific consent, so screening against the registers is not enough. If you sell into either, take advice before you call anyone.

Where UK GDPR comes in

PECR decides whether you can make the call. UK GDPR covers the personal data behind it: the named person, their direct line and anything you note about them. The ICO says that if PECR does not require consent, in many cases legitimate interests will be the appropriate lawful basis for processing a business contact's details.

Legitimate interests is not a free pass. Keep the data you hold to what you need for the call, record where it came from, and act on objections the same day. Someone who says "don't call me again" goes on the do-not-call list and stays there.

What happens if you get it wrong?

The ICO enforces PECR, and the penalties rose this year. In its update marking the Data (Use and Access) Act's full commencement on 19 June 2026, the ICO says the Act gives it the power to issue fines of up to £17.5 million or 4% of global turnover under PECR. That brings PECR enforcement into line with UK GDPR.

£17.5m or 4%

The maximum fine the ICO can now issue under PECR: up to £17.5 million or 4% of global turnover, following the Data (Use and Access) Act.

Source: ICO, One year on: marking the 12-month commencement of the Data (Use and Access) Act (June 2026)

Fines are not the only cost. A prospect who gets an unscreened call from a number they can't see does not become a client, and they tell people. Doing it properly is cheaper than the clean-up.

If an agency calls for you

Outsourcing the calls does not outsource the responsibility. The ICO's live-calls guidance says that if you ask someone to make calls for you, you are likely to be the instigator, and you can both be responsible for complying. It advises checking the provider and putting a written contract in place that sets out who does what.

Before you sign, ask three things: how and how often they screen against the TPS and CTPS, how they hold and honour do-not-call requests, and what number shows on the prospect's phone. We cover the other contract terms to check in our guide to outsourced sales teams for UK SMEs.

A pre-call checklist

Run this before every calling block, not once a year:

  • Every number screened against the TPS and CTPS in the last 28 days.
  • Sole traders and partnerships flagged, and screened against the TPS.
  • Your own do-not-call list loaded, and screened against as well.
  • Caller ID on, showing a number people can call back.
  • An opener that says your name and your company's name.
  • A same-day process for adding anyone who says no to the do-not-call list.
  • No recorded or automated marketing calls without specific consent.
  • If a provider calls for you: their screening checked and a written contract in place.

When we add calling to a client's outbound, every list is screened before the first call, and anyone who says no goes straight onto the do-not-call list. If you want to see how the phone fits alongside email and LinkedIn, here is how we run outbound. And because the guidance is under review after the Data (Use and Access) Act, check the ICO's current version before you rely on any of this.

Sources

  1. ICO, Telephone marketing (guide to PECR: do not call people who object or numbers on the TPS or CTPS unless they have specifically consented; say who is calling; display your number; automated calls need specific consent; keep a do-not-call list).
  2. ICO, What are the rules on live direct marketing calls? (screen against the TPS and CTPS before calling; registrations take effect after 28 days; caller ID and contact details; claims management and pensions need consent; instigator and caller can share responsibility; guidance under review after the Data (Use and Access) Act).
  3. ICO, Business-to-business marketing (no calls to TPS or CTPS numbers unless the business has consented; sole traders and other partnerships are individual subscribers; legitimate interests for business contacts).
  4. ICO, One year on: marking the 12-month commencement of the Data (Use and Access) Act, June 2026 (fines of up to £17.5 million or 4% of global turnover under PECR).
  5. TPS Services, CTPS register (screen cold-call data against the TPS for consumers or the CTPS for businesses every 28 days).

Frequently asked questions

Is B2B cold calling legal in the UK?

Yes. According to the ICO, PECR allows live B2B marketing calls if you screen numbers against the TPS and CTPS, don't call anyone who has asked you not to, say who is calling and show your number.

Do I need to screen business numbers against the CTPS?

Yes. The ICO says you must check numbers against the TPS and CTPS before live marketing calls, unless the person has specifically consented to your calls. A registration takes effect after 28 days, so screen at least every 28 days.

Are sole traders on the TPS or the CTPS?

The TPS. The ICO classes sole traders and other types of partnerships as individual subscribers, and PECR treats them the same as individuals.

What are the fines for breaking the UK cold calling rules?

Following the Data (Use and Access) Act, the ICO says it can issue fines of up to £17.5 million or 4% of global turnover under PECR.

Joe Stone

Joe Stone

Co-Founder, JumpLead

Co-Founder of JumpLead. 15+ years selling B2B from SME to enterprise. Focus: GTM strategy, messaging, and lean, repeatable systems.

The call

Let's findyour next client.

Not sure why your pipeline has stalled? Book a free 30-minute call. You'll get a clear read on where the leaks are and the two or three moves that will get meetings booked again. No pitch, no obligation.

Free · 30 minutes · No pitch