Everything UK Small Businesses Need to Know to Stay Legal When Marketing to New Customers

Thinking of launching your first marketing campaign? Before you send that email, post that ad, or buy that database, you need to know exactly what the law requires. UK regulations around marketing to new customers are complex, strict, and enforced with real penalties. This guide spells out, in plain English, every legal box you must tick—covering data protection, consent, electronic communications, direct mail, telemarketing, and more. If you want to build your customer base without risking fines or reputational damage, read on.
Marketing to new customers in the UK is governed by a patchwork of laws and regulations. The main pieces of legislation are the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). In addition, there are rules around advertising standards, unfair trading, and contracts with consumers.
It’s not just about avoiding spam complaints. The Information Commissioner’s Office (ICO) can levy fines of up to £17.5 million, or 4% of your annual turnover, for serious breaches of UK GDPR. The ICO also enforces PECR—and they do pursue small businesses, not just big brands. The Advertising Standards Authority (ASA) can ban your ads and publicly name non-compliant businesses. Civil claims from individuals and reputational damage are real risks.
If you’re planning to email, text, call, or even post to new customers, you must know the rules for each channel. The law is especially strict with 'cold' marketing—when you’re reaching people who haven’t bought from you before. Mistakes are common: buying dodgy data lists, importing US marketing tactics, or misunderstanding 'soft opt-in' rules can all land you in trouble.
The Information Commissioner’s Office (ICO) is the main regulator for data protection and electronic marketing in the UK. The Advertising Standards Authority (ASA) oversees advertising content. Trading Standards and Ofcom have additional roles.
Every marketing activity involving personal data—names, emails, phone numbers, addresses—must comply with the UK GDPR and the Data Protection Act 2018. This means you need a 'lawful basis' for collecting and using people’s data. For most marketing, the two lawful bases are 'consent' and 'legitimate interests.' Each has its own requirements and pitfalls.
Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, silence, or 'implied' consent are not valid. You must tell people exactly what you’ll do with their data, who you’ll share it with, and how they can withdraw consent at any time. For many types of electronic marketing, consent is legally required.
Legitimate interests allows you to process data without explicit consent, but only if your interests don’t override the individual’s rights and freedoms. You must conduct a Legitimate Interests Assessment (LIA) and keep a record of your reasoning. For some business-to-business (B2B) marketing, this can be appropriate, but it’s riskier for business-to-consumer (B2C) marketing.
Most off-the-shelf marketing data lists do NOT meet UK GDPR and PECR requirements. If you use them without checking, you risk fines and reputational harm. Always inspect the original consent and collection method.
Email, SMS, and instant messaging marketing to individuals is tightly regulated under PECR. For new customers, you generally need their explicit consent before sending any marketing message. There are very limited exceptions, and the rules differ for sole traders/individuals versus companies.
The 'soft opt-in' rule allows you to market similar products to existing customers, but it does NOT apply to new contacts. For brand new leads, you must have obtained clear consent—such as through a sign-up form with a tick box specifically for marketing communications. Generic consent bundled with terms and conditions is not enough.
Even for B2B marketing, you must be careful. Marketing emails to company addresses (like info@company.com) are permitted without consent, but emails to sole traders and partnerships are treated as 'individuals' and need consent. You must always give recipients a way to opt out in every message.
| Channel | Consent Needed for New Customers? | Key Requirement |
|---|---|---|
| Email to individuals | Yes | Explicit, informed opt-in prior to first contact |
| Email to companies | No (with conditions) | Must identify sender, offer opt-out, be relevant to role |
| SMS to individuals | Yes | Explicit, informed opt-in required |
| Instant messaging (WhatsApp, etc.) | Yes | Consent required for each channel |
In 2023, the ICO issued over £2 million in fines for unlawful marketing texts and emails. Many fines went to small businesses unaware of the rules.
Direct mail (post) and leafleting are less tightly regulated than electronic marketing, but you still have obligations under UK GDPR. You must have a lawful basis for processing addresses and personal data, and you must respect people’s right to object to direct marketing.
If you’re using data from public sources (like the electoral register or Companies House), check whether marketing is a permitted use. For mailing lists, the same data protection principles apply: you must be able to demonstrate the data was collected lawfully and that individuals were informed their data would be used for marketing.
You must also screen your mailings against the Mail Preference Service (MPS). If someone is registered with the MPS, it is unlawful to send them unsolicited direct mail. For leafleting, you can generally distribute to households, but be mindful of 'no junk mail' signs and local council regulations.
Direct mail can be an effective and compliant way to reach new customers, as long as you respect opt-outs and screen against the MPS. It’s often less likely to trigger complaints than cold emails or texts.
Telemarketing (cold calling) is also covered by PECR and UK GDPR. For individuals, you must not call anyone who has registered with the Telephone Preference Service (TPS) or who has told you not to call them. For businesses, you must check the Corporate TPS (CTPS). Even where calling is permitted, you must identify yourself and offer a simple way to opt out of future contact.
You do not need explicit consent to call individuals for marketing purposes unless you’re using automated calling systems (robocalls), which require prior consent. However, you must have a lawful basis, and your interests must not override the individual’s rights. Persistent or aggressive calling is likely to breach both PECR and consumer protection law.
All calls must be made at reasonable times (not early morning or late at night), and you must not disguise your number. You are required to maintain a 'do not call' list within your business and act on opt-out requests immediately. The ICO and Ofcom both enforce these rules, and fines for breaches are common.
| Telemarketing Type | Consent Needed? | Extra Legal Requirement |
|---|---|---|
| Manual call to individual | No (if not on TPS) | Must check TPS, state identity, offer opt-out |
| Automated/recorded call | Yes | Explicit prior consent required |
| Call to business number | No (if not on CTPS) | Must check CTPS, identify caller, offer opt-out |
Fines for calling people on the TPS can reach £500,000 per incident, even for small businesses. Ofcom and the ICO do investigate individual complaints.
Online ads—Google, Facebook, Instagram, LinkedIn, and display networks—are regulated by the UK Code of Non-broadcast Advertising and Direct & Promotional Marketing (CAP Code), enforced by the ASA. Ads must not be misleading, must be clearly identifiable as ads, and must comply with all sector-specific rules (e.g., health claims, financial promotions).
When using cookies or tracking pixels (for retargeting or analytics), you must comply with PECR and UK GDPR. This means obtaining informed consent before setting any non-essential cookies on users’ devices. Your website must have a clear cookie policy and a way for users to manage their preferences. Consent banners must not be pre-ticked or hidden; users must actively choose to accept non-essential cookies.
Social media marketing to new customers is generally permitted, but you must not buy or use scraped data, or target individuals in ways that breach platform rules or privacy laws. If you process personal data for custom audiences, you need a lawful basis and must honour any opt-outs. Misleading or aggressive advertising is likely to fall foul of both the ASA and Trading Standards.
The Advertising Standards Authority can investigate any ad—online or offline—following a single complaint. They can require you to remove or amend non-compliant ads and will publish their rulings online.
Marketing to vulnerable individuals—including children, the elderly, or those with mental or physical impairments—requires extra care. The ICO expects you to assess the risk of harm and to avoid exploiting vulnerabilities. The CAP Code has strict rules around marketing to children: you must not target under-16s for products they cannot legally buy, or use content likely to mislead or pressure them.
If your campaign involves 'special category data'—such as health, ethnicity, sexual orientation, or political opinions—the legal bar is even higher. You must have explicit consent and a clear, documented reason for processing this data. If you are unsure, seek legal advice before proceeding.
Schools, medical practices, and other sensitive settings are subject to additional regulation. Do not undertake marketing to these groups without verifying the rules for your sector. Fines and adverse publicity for breaches involving vulnerable people are often higher.
It’s not enough to simply read the rules—you need to embed compliance into every step of your marketing. Here’s how to make sure your campaign is legal, defensible, and customer-friendly from the start.
| Legal Requirement | Relevant Law | Who Enforces |
|---|---|---|
| Consent for electronic marketing | PECR & UK GDPR | ICO |
| Lawful basis for processing data | UK GDPR | ICO |
| Advertising standards (truthfulness, decency) | CAP Code | ASA |
| Respecting opt-outs (TPS/MPS) | PECR | ICO |
| Cookie consent | PECR & UK GDPR | ICO |
The ICO offers free checklists and self-assessment tools for small businesses covering direct marketing, data protection, and lawful basis. See ico.org.uk for details.
Many small businesses fall foul of the law not through malice, but through misunderstanding or copying overseas practices. The UK is stricter than the US and many EU countries on electronic marketing—so 'growth hacks' you see online may be illegal here.
A classic mistake is assuming you can email anyone whose business card you have, or anyone who has interacted with your website. Without explicit consent (or a valid soft opt-in for existing customers), this is unlawful. Another is failing to screen against TPS/MPS or using bought data lists without checking the original consent.
Failing to include an unsubscribe link, using pre-ticked boxes for consent, or not keeping records of opt-ins are also common errors. These mistakes are easy to avoid with the right processes—and costly to fix after the fact, especially if the ICO gets involved.
UK regulators treat unlawful marketing seriously, even for micro businesses and startups. The ICO can fine up to £17.5 million or 4% of annual turnover for UK GDPR breaches, and up to £500,000 purely under PECR for nuisance calls or emails. The ASA can ban your ads and require public corrective statements. Trading Standards can also bring prosecutions for false or aggressive marketing.
Most ICO enforcement starts with a complaint from a recipient. The ICO will investigate and may require you to change your practices, delete data, or pay a fine. The process is formal: you’ll need to demonstrate your compliance, show records of consent, and explain your data protection policies. If you can’t, you are likely to face sanctions.
You should have a documented complaints process. Respond promptly and professionally to any complaints—removing the individual from your lists and providing details of your data protection officer or contact. The ICO expects you to resolve issues directly if possible. If the ICO investigates, be honest and proactive; attempts to hide or destroy records can dramatically increase penalties.
| Offence | Maximum Penalty | Recent Example (2023) |
|---|---|---|
| Unlawful email marketing | £500,000 (PECR) | Hotel chain fined £80,000 for spamming new contacts |
| Failure to respect suppression lists | £500,000 (PECR) | Telecoms firm fined £90,000 for calling TPS numbers |
| Serious data protection breach | £17.5m or 4% turnover (GDPR) | Estate agent fined £800,000 for failing to secure marketing data |
The ICO received over 120,000 complaints about nuisance marketing in 2023. Even a single complaint can trigger an investigation and a legal requirement to change your practices.
The most successful small businesses treat compliance not as a box-ticking exercise, but as a core part of building trust with new customers. If you’re transparent, respectful, and proactive about people’s rights, you’ll stand out from competitors—and avoid the legal and reputational risks that come with shortcuts.
Train your team (even if it’s just you) on the basics of data protection and marketing law. Use templates from the ICO and review your campaigns regularly. Always ask: 'Would I be happy to receive this communication? Was I given a real choice? Can I opt out easily?' If the answer is no, rethink your approach.
Joining trade associations like the Federation of Small Businesses (FSB) or seeking advice from the ICO’s SME Helpdesk can give you access to templates, checklists, and guidance tailored to your sector. Compliance does require effort, but it protects your business as you grow.

Ready for the next step? Open a business bank account to keep your finances organised.

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.
Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.


Affiliate links. We may earn a commission. Editorial independence maintained.