Is cold calling legal in the UK?
Yes — and the conditions are narrower than most people calling for a living realise. The duty that catches businesses out is not consent; it is screening, and it applies to business-to-business calls just as it does to consumers. Every quote below was read on legislation.gov.uk or on the ICO’s own guidance on 28 August 2026.
This is not legal advice
This page quotes primary sources and says plainly where one is silent or under review. It is not legal advice and it cannot tell you whether your own campaign is lawful — that depends on your list, your data source and your consent position. Take your own advice before you scale.
The short answer
Cold calling is lawful in the UK. The Privacy and Electronic Communications Regulations 2003 (PECR) do not ban it — they attach conditions to it. In the ICO’s own summary of the live-call rules:
“In general, you must not make marketing calls to any number listed on the Telephone Preference Service (TPS) or Corporate TPS (CTPS), unless that person has specifically consented to your calls. You can call a number if it is not listed on the TPS or CTPS and you are not marketing claims management services. So you need to screen call lists against the TPS and CTPS. You can only make marketing calls in relation to pension schemes if you meet a strict criteria. You must allow your number to be displayed.”
Read on the ICO website on 28 August 2026: ICO guide to PECR — telephone marketing.
The rule in the legislation itself
Regulation 21(1) of PECR 2003, read on legislation.gov.uk, states:
“A person shall neither use, nor instigate the use of, a public electronic communications service for the purposes of making unsolicited calls for direct marketing purposes where—(a) the called line is that of a subscriber who has previously notified the caller that such calls should not for the time being be made on that line; or (b) the number allocated to a subscriber in respect of the called line is one listed in the register kept under regulation 26.”
Two separate obligations sit in that one sentence, and campaigns tend to satisfy the second while failing the first. (a) is your own suppression list — anyone who has ever told you to stop. (b) is the statutory register, which is what the TPS and CTPS are. Screening one does not discharge the other.
Regulation 21(A1) adds the caller-ID duty, and it applies to all direct marketing calls, solicited or not:
“A person shall neither use, nor instigate the use of, a public electronic communications service for the purposes of making calls (whether solicited or unsolicited) for direct marketing purposes except where that person—(a) does not prevent presentation of the identity of the calling line on the called line; or (b) presents the identity of a line on which he can be contacted.”
Source: PECR 2003, regulation 21, read 28 August 2026.
B2B is not exempt — and this is the expensive misunderstanding
The belief that TPS is a consumer problem and business numbers are fair game is the single most common error in this area. The ICO’s guidance answers it directly, under the heading “When can we make marketing calls to businesses?”:
“The rules are the same as for calls to individuals. … You should remember that some businesses (sole traders and some partnerships) register with the TPS, and others (companies, some partnerships and government bodies) register with the CTPS. For business-to-business (B2B) calls, you will therefore need to screen against both the TPS and the CTPS registers, as well as your own ‘do not call’ list.”
The reason sits in how PECR defines who you are calling. Its rules refer to “subscribers” — the customer named on the bill for the line. The ICO’s business-to-business guidance explains the split:
“Businesses are classed as ‘corporate subscribers’ under PECR if they are a corporate body with separate legal status (eg companies, limited liability partnerships, Scottish partnerships, and some government bodies). However sole traders and other types of partnerships are classed as ‘individual subscribers’ and PECR treats them the same as individuals.”
So a list of restaurants, bars, hotels and venues will contain both kinds in the same spreadsheet, with nothing on the row to tell you which is which. That is precisely why the guidance says to screen against both registers rather than choosing one.
One further point worth knowing if you also email: the ICO states that “the main difference is that the rule on marketing by electronic mail (eg email or text message) doesn’t apply to corporate subscribers”. Email and calling are governed differently. A B2B email permission is not a calling permission.
Source read 28 August 2026: ICO business-to-business marketing.
How often must you re-screen? The 28-day rule
PECR gives you a grace period on newly registered numbers, and it is the reason screening is a recurring job rather than a one-off. Regulation 21(3):
“A person shall not be held to have contravened paragraph (1)(b) where the number allocated to the called line has been listed on the register for less than 28 days preceding that on which the call is made.”
Read plainly: a number that joined the register in the last 28 days does not put you in breach. A number that joined 29 days ago does. If your list was screened more than 28 days ago, you have no protection for anything registered since, so the practical reading is to re-screen at least every 28 days — and more often if the list is large or long-lived.
Regulation 21(4) and 21(5) cover the other direction: a registered subscriber can tell you specifically that they do not object to your calls, in which case you may call despite the listing — but they may withdraw that at any time, and once withdrawn you must stop.
What you must say on the call
Regulation 24 of PECR sets the identification requirement. For a call to which regulation 21 applies, the caller must provide the name of the person, and — if the recipient of the call so requests — either an address or a telephone number reachable free of charge. The ICO puts the same duty in operational terms:
“You must always say who is calling, allow your number (or an alternative contact number) to be displayed to the person receiving the call, and provide a contact address or freephone number if asked.”
Note the asymmetry that regulation 24(1) draws: for automated calls under regulation 19 the contact details must be given with the message, whereas for live calls they are given on request. The name, however, is not optional either way.
Source: PECR 2003, regulation 24, read 28 August 2026.
What it costs to get it wrong
The ICO’s own description of its PECR enforcement powers:
“ICO has several ways of taking action to change the behaviour of anyone who breaches PECR. They include criminal prosecution, non-criminal enforcement and audit. The Information Commissioner can also serve a monetary penalty notice imposing a fine of up to £500,000 which can be issued against the organisation or its directors.”
The phrase to read twice is “or its directors”. The ICO’s overview of PECR notes that director liability for serious breaches of the marketing rules was introduced by amendments in 2018. For an owner-run business this is not a corporate risk that stops at the company.
The same page also states the ICO will “take enforcement action against organisations that persistently ignore their obligations, starting with those that generate the most complaints” — which is a reasonable description of how the risk actually materialises. It is complaint-led.
Source: ICO — what are PECR, read 28 August 2026.
Two things that are outright banned, whatever your list says
PECR was amended to prohibit cold calling in two specific sectors regardless of screening. From the ICO’s live-call rules, you must not make unsolicited live calls:
“for the purpose of claims management services, unless the person has specifically consented to your calls; or in relation to pension schemes unless you are a trustee or manager of a pension scheme or a firm authorised by the Financial Conduct Authority, and the person you are calling has specifically consented to your calls or your relationship with the individual meets a strict criteria.”
If you sell into either sector, screening is not the question you need answered and this page is not enough. Take advice.
Something to watch: the guidance is under review
At the top of the ICO’s telephone marketing guidance, read on 28 August 2026, sits this notice:
“Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change.”
We are recording that as it stands rather than predicting what changes. If you are writing a compliance process around this page, note the date it was checked and check the source again before you rely on it in six months. The underlying regulations are amended periodically — the ICO states its guide covers the version of PECR that came into effect on 29 March 2019.
The practical checklist
- Screen every list against the TPS and the CTPS — both, for B2B as well as B2C.
- Keep and screen your own do-not-call list. It is a separate legal duty from the register.
- Re-screen at least every 28 days; the grace period in regulation 21(3) runs out.
- Present your caller ID, or a number on which you can be reached.
- Say who is calling on every call, and be able to give an address or freephone number on request.
- Record objections the moment they are made, and honour a withdrawn permission immediately.
- Do not cold call about claims management or pension schemes without meeting the specific conditions.
- Establish separately whether your dialling setup engages regulation 19 — the AI disclosure page covers that question.
Where this touches an AI caller
None of the duties above change because the caller is software. The list still has to be screened, the number still has to be presented, and someone still has to say who is calling. What does change is how easy the record is to produce afterwards: an ICO enquiry is complaint-led, and the useful answer to “what did you say to this person” is a transcript rather than a recollection.
FoxEra Calls logs every call word for word and keeps the outcome against the contact, so the record exists before you need it. See how that works in the outbound calling CRM. Screening against the TPS and CTPS registers is your responsibility and is not performed for you — we say that plainly rather than letting you assume otherwise.
If you are still deciding what kind of tool you need, the comparison of AI calling, power diallers and answering services sets out the categories, and what a connected minute costs covers the money.
Frequently asked questions
Is cold calling legal in the UK?
Yes, subject to conditions in PECR 2003. You must not make unsolicited live marketing calls to anyone who has told you not to call, or to a number on the register kept under regulation 26 (the TPS and CTPS), unless they have specifically consented. You must also present your caller ID and say who is calling.
Do the TPS rules apply to B2B cold calling?
Yes. ICO guidance states the rules are the same as for calls to individuals. Sole traders and some partnerships register with the TPS; companies, some partnerships and government bodies register with the CTPS. A B2B list must be screened against both, plus your own do-not-call list.
What is the 28-day rule?
Regulation 21(3) says you are not held to have contravened regulation 21(1)(b) where the called number has been on the register for less than 28 days before the call. In practice it means re-screening at least every 28 days.
What is the penalty for breaking the rules?
Per ICO guidance, a monetary penalty notice of up to £500,000, issuable against the organisation or its directors, alongside criminal prosecution, non-criminal enforcement and audit.
Do you have to show your number when cold calling?
Yes. Regulation 21(A1) requires you either not to prevent presentation of the calling line identity, or to present the identity of a line on which you can be contacted. It applies to solicited and unsolicited marketing calls alike.
Does an existing customer relationship let you call a TPS-registered number?
Not on its own. ICO guidance states you must not make unsolicited live calls to a TPS- or CTPS-registered number unless the person has specifically consented to your calls — “even if they are an existing customer” — with a narrow pension-scheme exception subject to strict criteria.