Digital Patron Logo
Back to all solutions
Lead GenerationB2B (cross-vertical)· United Kingdom

Cold email agency for UK B2B: outbound that respects PECR and UK GDPR and still books meetings.

Digital Patron runs done-for-you B2B cold email for the UK market, built to work within PECR and UK GDPR. We target corporate subscribers only, document the legitimate-interests basis, include the privacy notice and opt-out every time, and send from dedicated, warmed-up domains so your main domain is safe. Plans start at $800 a month, with first sends usually in week three.

Why this combo

Why UK cold email is allowed, and why most of it is still done wrong

A lot of UK founders believe GDPR made cold email illegal. It didn't. Under the Privacy and Electronic Communications Regulations (PECR), the consent rule for email marketing applies to individual subscribers: consumers, sole traders and some partnerships. Emailing corporate subscribers, meaning limited companies, LLPs and public bodies, does not need prior consent, although you must say who you are and give a valid address to opt out. UK GDPR still applies, because a named work address like jane.smith@company.co.uk is personal data. So you need a lawful basis, which for B2B outreach is usually legitimate interests backed by a written assessment, a privacy notice at first contact, and an absolute right for the person to object. The Data (Use and Access) Act 2025 is raising the maximum PECR fines to UK GDPR levels as its provisions come into force, so the cost of sloppy outreach is going up. Where most UK campaigns fail is not the law itself but the execution: lists that mix in sole traders, no record of the legitimate-interests assessment, and opt-outs that are honoured in one tool and ignored in another. We run it properly.

International authority

GDPR-regime outbound we have actually run.

We don't have a published UK case study yet. The closest proof is Paris MedTech, a compliance-aware outbound programme aimed at hospital procurement and clinical directors across France and Europe under EU GDPR, which shares its core principles with UK GDPR.

19
Qualified meetings in 45 days, Paris MedTech
€250K+
Pipeline in 90 days, same client
EN + FR
Languages run in that programme

Countries served

United KingdomFranceUnited StatesCanadaUnited Arab Emirates

Featured work: Paris MedTech (France + EU) · ToothLens.ai (USA + Europe) · GT Tech Solutions (North America)

What you get

Capabilities of this lead generation stack.

Corporate-subscriber targeting

Prospects are filtered to limited companies, LLPs and other corporate bodies, using registration data such as Companies House where available. Sole traders and partnerships that count as individual subscribers under PECR are excluded by default.

Documented legitimate-interests basis

We draft the legitimate-interests assessment for your campaign with you: the purpose, why outreach is necessary, and how the recipient's interests are balanced. It is kept on file in case the ICO or a prospect asks.

Transparency and objection handling

Every first email identifies your company, explains where the contact details came from in plain terms, links to your privacy notice and offers a one-step opt-out. Objections are suppressed across every mailbox and tool, permanently.

Data minimisation and retention

We collect only what the campaign needs (name, role, company, work email, relevant signal) and agree retention periods, so non-responders are not held indefinitely.

Dedicated sending domains and warm-up

Look-alike sending domains with SPF, DKIM and DMARC aligned, warmed before launch and capped per mailbox. UK companies lean heavily on Microsoft 365, so we test placement there as well as Google.

Copy written for UK buyers

UK decision-makers tend to respond to understated, specific emails. We write in British English, avoid hard-sell US phrasing, and lead with a relevant observation rather than a pitch.

Reply handling and CRM sync

Replies are categorised and routed, subject access and erasure requests are flagged to you immediately, and booked meetings land in your CRM with the full thread attached.

How we deliver

A predictable path from kickoff to live.

  1. 01

    Week 1: ICP, offer and compliance set-up

    We define target accounts and roles, confirm the corporate-subscriber filter, write the legitimate-interests assessment and agree the privacy notice wording and retention period with you.

  2. 02

    Weeks 1–2: domains, mailboxes and warm-up

    Sending domains registered and authenticated, Microsoft 365 or Workspace mailboxes created, tracking set up and warm-up started. Your primary domain is never used.

  3. 03

    Weeks 2–3: list build, verification and copy

    UK lists built and verified, individual subscribers removed, your customers and previous opt-outs suppressed, and the first sequences written in British English for your approval.

  4. 04

    Weeks 3–4: first sends in UK business hours

    A small first cohort goes out in UK working hours, adjusted for GMT and BST. We review bounces, replies and objections by segment and tune before increasing volume.

  5. 05

    Month 2 onward: scale and keep the paper trail current

    Volume rises to plan, new segments are added, the legitimate-interests record is updated for each one, and you get a weekly report on replies, meetings, opt-outs and deliverability.

Outcomes we target on this work

19
Qualified meetings in 45 days, Paris MedTech (EU, GDPR regime)
€250K+
Pipeline added in 90 days, same client
<2%
Bounce-rate ceiling we hold every list to
Week 3
Typical first send after warm-up

The stack we use.

Apollo.ioClayLinkedIn Sales NavigatorCompanies House dataMillionVerifierSmartleadInstantlyMicrosoft 365Google WorkspaceHubSpotPipedriveCalendly
Real numbers

What this typically costs in India.

Starter

$800/mo (2-month minimum)

UK founder or small team testing outbound in one segment. Around 2,000 verified corporate-subscriber leads a month, one sequence, dedicated sending domain, legitimate-interests documentation.

Growth

$1,500–$2,200/mo

Funded UK startup or agency. Around 5,000 verified leads a month, three persona sequences, multiple sending domains, full reply and objection handling, weekly tuning.

Scale

$2,800+/mo

Established sales team covering the UK and Europe. 10,000+ leads a month, per-country compliance notes for EU markets, larger mailbox pool and custom CRM integration.

Questions, answered.

Is B2B cold email legal in the UK?

Yes, when it is aimed at corporate subscribers and handled properly. PECR's consent requirement for email marketing covers individual subscribers (consumers, sole traders and some partnerships), not limited companies, LLPs or public bodies. You must still identify yourself and give a valid opt-out address in every email. UK GDPR also applies to named work addresses, so you need a lawful basis, usually legitimate interests, plus transparency and an absolute right to object.

Do we need consent under UK GDPR to email a named person at a company?

Not necessarily. Consent is one lawful basis; legitimate interests is the one most B2B outreach relies on. It requires a documented assessment showing the outreach is relevant to the person's role, necessary for your purpose and balanced against their interests. If they object, you must stop, and we suppress them everywhere.

Why exclude sole traders and partnerships?

Under PECR, sole traders and some partnerships are treated as individual subscribers, so emailing them requires prior consent. Because their addresses look like any other business address, the safest approach is to filter by company type and leave them out of cold campaigns unless they have opted in.

What do we need to tell prospects in the first email?

Who you are, why you are contacting them, roughly where their details came from, a link to your privacy notice and a simple way to opt out. UK GDPR requires that privacy information at the latest when you first communicate with someone whose data you did not collect from them directly. We build this into the first email and the signature without making it read like a legal notice.

What does the Data (Use and Access) Act 2025 change?

Among other things, it brings the maximum fines for PECR breaches up to UK GDPR levels and clarifies that direct marketing can be a legitimate interest. Its provisions are coming into force in stages, so check the current position, but the direction is clear: compliant B2B outreach stays possible and careless outreach gets more expensive.

Can you run the UK and EU from the same programme?

Yes, as separate segments. EU countries implement the ePrivacy rules differently. Germany, for example, is much stricter about B2B cold email than the UK. We keep per-country lists and compliance notes rather than applying UK rules to Europe. Our Paris MedTech engagement ran across France and other European markets.

How is this different from your Cold Email Outreach at Scale offer?

Same engine, same price bands. Cold Email Outreach at Scale (/solutions/cold-email-outreach-at-scale) describes the general offer. This page covers what the UK adds: PECR's corporate-subscriber rule, UK GDPR documentation, Microsoft 365-heavy inboxes and British-English copy.

Which tools do you use, and do they have UK data?

Usually Apollo or Clay for data and Smartlead or Instantly for sending. UK coverage is good but thinner than the US, so we verify more and enrich from several sources. For tool choices, see Apollo vs Smartlead (/compare/apollo-vs-smartlead), Smartlead pricing (/compare/smartlead-pricing) and Apollo alternatives (/compare/apollo-alternatives).

Ready to ship a cold email agency for uk b2b (gdpr-compliant)?

Book a free 30-minute call. We'll come back with a fixed-scope proposal within 24 hours.