AxiGrowth

Cold Email Playbookfor engineering firms

How a UK engineering, manufacturing or electronics firm writes to companies it has never spoken to. The playbook covers the law, the sending set-up, who to write to and what to write about, gives twelve templates, and sets out the routine that keeps it working. Sections 1 and 2 are free to read below.

2026 edition. About thirty-five printed pages, delivered as a private link and PDF.

Sections 3 to 10 are in the full playbook, £95.

Everything in the library

1. The rules in plain English

Two pieces of law govern email to people at other businesses in the UK. The Privacy and Electronic Communications Regulations (PECR) say when you may send marketing by email at all. The UK GDPR says on what basis you may hold and use a named person's details to do it. You need to be on the right side of both. For business-to-business email the rules are more permissive than for email to consumers, because the tightest consent rule applies only to individual subscribers.

PECR: corporate subscribers and individual subscribers

PECR draws a line between two kinds of recipient. An individual subscriber is a person, a sole trader or an unincorporated partnership. A corporate subscriber is a limited company, a limited liability partnership, a public body or a similar organisation. The consent rule in regulation 22 protects individual subscribers. You may not send them unsolicited marketing email without their prior consent, apart from the narrow "soft opt-in" for existing customers.

Corporate subscribers are treated differently. You may send marketing email to a named person at a limited company without their prior consent, provided that you do not conceal who you are and you give them a valid address to which they can send an opt-out request. PECR asks nothing more than that for corporate recipients. The ICO's guidance adds that you should still honour opt-outs promptly, and that an individual's work address at a company is personal data for UK GDPR purposes, which is where the second piece of law comes in.

Two things follow for an engineering firm.

  • You can write to the project engineer at a limited company about a matter relevant to their job. You cannot write to a sole trader, a partnership of individuals, or anyone at a personal address such as a Gmail or Outlook.com mailbox, without consent.
  • Companies House tells you whether a business is a company or an LLP. Public bodies such as councils, NHS trusts and universities are corporate subscribers too, although they are not on Companies House. A trading name with no registered entity behind it, and no public body, is an individual; leave it alone.

UK GDPR: legitimate interest

Holding a person's name, job title and work email address, and using them to send a message, is processing personal data. You need a lawful basis. For business-to-business marketing the usual basis is legitimate interests under Article 6(1)(f). Recital 47 of the GDPR says in terms that direct marketing may be a legitimate interest.

Legitimate interest is a judgement, and the ICO expects you to have made it and written it down, in what it calls a legitimate interest assessment. The assessment has three parts. The first asks what you are trying to achieve and whether that is a legitimate aim, the second whether the processing is necessary for it, and the third whether your interest is outweighed by the interests, rights and expectations of the person. Section 2 is a worked example you can adapt.

The person you write to has rights that you must be able to meet. They can ask who you are and why you have their details, which your privacy notice answers; they can object to direct marketing at any time, which is the opt-out; and they can have their details erased on request. An objection to direct marketing is absolute. Once someone objects you stop, and you keep a record of the objection so that you do not write to them again.

What changed in February 2026

The Data (Use and Access) Act 2025 amended PECR. The most important change for marketing is the penalty regime. From 5 February 2026 the ICO can fine a firm that breaks PECR up to £17.5 million or 4% of worldwide annual turnover, whichever is higher, which is the same ceiling as the UK GDPR. The previous ceiling was £500,000. The substantive rules on who you may email, and on what terms, are the same as before. The ICO has said that it will publish updated direct marketing guidance under the new Act.

The change matters because the largest PECR fines the ICO has issued over the years have been for bought lists, missing opt-outs, high volume and messages to people who had no relationship with the sender. The routine set out here rules out each of those.

What the ICO expects to see

  • A written legitimate interest assessment, dated, reviewed when the activity changes.
  • A privacy notice that covers direct marketing and says where you obtain contact details.
  • A record of where each address came from. Addresses printed on the recipient organisation's own website, or given to you by the person or their colleague, are defensible. Addresses bought in a list, or guessed from a naming pattern, are hard to defend.
  • A working opt-out in every message, and a suppression list that is checked before every send.
  • Reasonable volume and frequency. There is no number in the law. A named engineer receiving one relevant message and two follow-ups is reasonable; the same person receiving something every week is not.

2. A legitimate interest assessment, filled in

The example below is written for a fictional Midlands gearbox manufacturer with sixty staff, making industrial gearboxes and geared motors for plant engineers and OEM design teams. Replace the specifics with your own and keep the structure. Date it, have a director sign it, and keep it with your other data protection records.

Part one: the purpose test

QuestionAnswer
What we are doingSending short, individually written emails to named engineers and buyers at UK limited companies and public bodies whose role makes industrial gearboxes relevant to their work. Each email is prompted by something the organisation has made public, such as a capital investment announcement, a planning consent, a hiring pattern, a tender, or a quotation we gave that was not taken up.
Why we are doing itTo win enquiries for gearboxes, geared motors and repairs from organisations that are specifying or replacing drive equipment. That is a normal commercial purpose and direct marketing is recognised as a legitimate interest.
Who benefitsWe benefit through enquiries and orders. The recipient benefits from hearing about a relevant option, with lead times and technical details, at the point when they are choosing.
What would happen if we did notWe would depend on inbound enquiries and distributors, and organisations that would have bought from us would not know we exist.

Part two: the necessity test

QuestionAnswer
Is the processing necessary?Yes. There is no way to tell a project engineer about a relevant product without contacting that engineer. Generic advertising does not reach the person specifying the equipment.
Is it proportionate?We hold only a name, a job title, an employer, a corporate email address and the public signal that prompted the message. We do not hold personal addresses, home details, or anything from social media beyond a job title.
Is there a less intrusive way?We considered telephone and post. Email is less intrusive than a telephone call to a person at work, and it is easier for the recipient to ignore or decline.

Part three: the balancing test

PointAnswer
Who we write toNamed people at limited companies, LLPs and public bodies, in their professional capacity, at their work address. Sole traders, partnerships and personal addresses are excluded.
Where the details come fromAddresses printed on the organisation's own website, or supplied by the organisation to us (for example on a quotation request). We do not buy lists and we do not guess addresses from a name pattern.
Reasonable expectationsAn engineer at a firm that has publicly announced a new line, or applied for planning consent for a production building, can reasonably expect relevant suppliers to get in touch. Each email says what prompted it.
Volume and frequencyNo more than sixty emails a day from our sending domain. One message and at most two follow-ups, a week apart. No organisation is written to again within ninety days of the last message.
Opt-outEvery message carries a one-click unsubscribe header and a plain link. Opt-outs take effect immediately and are kept permanently on a suppression list. A reply asking us not to write again is treated the same way.
Bounces and complaintsA hard bounce or a spam complaint suppresses the address permanently. If complaints exceed the mailbox providers' published threshold, sending stops and a director reviews the list and the messages.
Existing customersOur customer list is loaded as a suppression list before any sending, so that no existing customer receives a cold message.
Human reviewEvery message is read and approved by a named person before it is sent.
RetentionContact records and sent messages are deleted twelve months after the last contact, except suppression entries, which are kept so that opt-outs continue to be honoured.
ConclusionThe interest is legitimate, the processing is necessary and limited, and the safeguards mean that the recipient's interests are not overridden. We will review this assessment annually and whenever the audience, the volume or the sources change.

Signed and dated by a director. Reviewed: date. Next review: date.

£95one-off, ex VAT

The full playbook adds the sending set-up with a four-week warm-up schedule, the people to write to in each of five sectors, the eight signals worth writing about, twelve templates each under a hundred words with notes on what to change, the two-step follow-up sequence, the routine for replies and opt-outs, how to measure it, and a checklist for the first send. Delivered as a private link and PDF within a minute of payment.

Buy the playbook, £95

Sources for the free sections: Privacy and Electronic Communications (EC Directive) Regulations 2003, regulations 22 and 23, as amended by the Data (Use and Access) Act 2025 (commencement 5 February 2026); ICO direct marketing and legitimate interests guidance; UK GDPR Article 6(1)(f), Article 21 and Recital 47. General guidance for UK businesses, not legal advice.

Outbound runsthis playbook for you

Outbound, from £1,100 a month

The set-up is £2,000 and the sending subdomain warms up for four weeks before the first approved emails go out. The monthly price includes the signal reading, contact verification, opt-out handling and the PECR and UK GDPR checks, and it stops at any month end.

How it arrives
Private link and PDF within a minute of payment.