Cold calling is not illegal in the UK as a category. A live, unsolicited business-to-business or business-to-consumer marketing call is lawful by default. What makes a specific cold call illegal is who you dial and what you sell: calls to numbers registered with TPS or CTPS, calls to anyone who has told you to stop, automated marketing calls without consent, and almost any cold call about pensions or claims management. Since 5 February 2026 the ICO can fine breaches at UK GDPR levels, up to £17.5 million or 4% of global annual turnover.

That combination surprises people in both directions. Sales leaders assume cold calling is banned outright; it is not. Compliance teams assume a B2B list is safe territory; it is not either. Here is where the lines actually sit.

What counts as a cold call under PECR

The law that governs this is the Privacy and Electronic Communications Regulations 2003, PECR. PECR does not use the phrase "cold call"; it regulates unsolicited calls for direct marketing purposes. That is any live call the recipient did not invite, where any part of the call promotes a product, service, or aim. The test is the content, not the label. A "market update", a "courtesy call", or a "quick introduction" that ends in a pitch is a direct marketing call, and the friendly opening does not change its legal character.

Calls that genuinely are not marketing sit outside the regime: real service calls about an existing order or account, bona fide market research with no selling, and debt collection on an existing agreement. The hybrid call is the trap. If any part of it sells, treat the whole call as marketing.

The main rule: regulation 21

Regulation 21 of PECR sets the general rule for live marketing calls. You must not make an unsolicited marketing call to a number if either of two things is true: the subscriber has previously told you not to call, or the number is registered with the Telephone Preference Service or its corporate sibling. There is no volume threshold, no small-business carve-out, and no grace for a list you bought in good faith. For the wider architecture of PECR, including how it sits next to UK GDPR, see PECR explained.

Outside those two conditions, a live cold call is permitted. That is the "legal by default" part. The practical problem is the scale of the exception: the registers are enormous, and they decide whether most of your list is callable.

Numbers you can never cold call: TPS and CTPS

The Telephone Preference Service holds around 28 million consumer numbers. The Corporate Telephone Preference Service holds around 3 million more, registered by limited companies and other corporate bodies. Registration on either register makes an unsolicited marketing call to that number a breach of regulation 21, and the only exception is that subscriber's specific prior consent to your calls.

Two details catch teams out. First, "it's a business number" is not a defence: CTPS is covered exactly as TPS is, and sole traders and some partnerships count as individual subscribers, so they can sit on the consumer register. Second, the screening obligation is yours; a list seller's assurance that a file was screened does not discharge it. I have covered the TPS-specific rules, the consent exception, and the excuses that fail in is it illegal to call TPS numbers and when consent makes a TPS call lawful.

Sector bans: pensions and claims management

Two sectors are carved out of the "legal by default" position entirely. Regulation 21B, added in 2019, bans cold calls about pensions unless narrow exceptions apply: the caller must be FCA-authorised or a trustee or manager of a pension scheme, and the recipient must either consent or have an existing relationship where a call would be expected. In practice, a pensions cold call to a stranger is illegal regardless of TPS status.

Regulation 21A does the same for claims management services: live calls require the recipient's prior consent, full stop. In both regimes TPS screening stops being the test; you need a recorded opt-in before any call, whether the number is registered or not. If you sell in either space, screening is only the start of your problem.

Everything above concerns live calls. Recorded and automated marketing calls run under regulation 19, which is stricter: you need the subscriber's prior consent to receive automated marketing calls from you specifically. There is no TPS carve-out to argue about because the default is already "no". Most of the ICO's largest call-related penalties have involved automated call campaigns run without any plausible consent.

You must show your number

Marketing callers must present a valid, dialable calling line identification, so the person called can see the number and ring it back or complain about it. Withholding or spoofing CLI on marketing calls is itself a breach, and it is one of the patterns the ICO treats as an aggravating factor because it looks like evading complaints. If your dialler rotates numbers, every one of them needs to trace back to you.

The fines changed in February 2026

For years the ICO's ceiling for a PECR breach was £500,000. That changed when the Data (Use and Access) Act 2025 commenced its enforcement provisions on 5 February 2026: PECR penalties now align with UK GDPR levels, up to £17.5 million or 4% of global annual turnover, whichever is higher. Conduct that predates 5 February 2026 still falls under the old £500,000 cap, but every call your team makes today sits under the new regime.

Company officers can also be fined personally where a breach happened with their consent, connivance or neglect, and dissolving the company does not remove that exposure. Fines are not the only instrument either: enforcement notices order you to stop, and breaching one is a criminal offence. The enforcement record shows what actually triggers penalties: no screening, ignored opt-outs, bought lists with no provenance, and automated calls without consent.

How to cold call legally: a checklist

  1. Screen every number against TPS and CTPS before it is dialled, not only at import. Registrations change daily.
  2. Keep your own do-not-call list and honour it immediately and permanently.
  3. Hold recorded, specific consent before any automated call, any claims management call, or any pensions call.
  4. Present a valid CLI on every call.
  5. Document all of it: screening timestamps, consent records, opt-out dates. The ICO's first question after a complaint is for your evidence.

The first item is the one that fails silently. A list that was clean at import decays as people register with TPS, which is why cadence matters as much as the check itself; see how often should you check TPS. TPSClear exists for exactly this gap: it screens UK TPS and CTPS in real time inside HubSpot, re-screens on every phone-number change, and writes the verdict into the contact record before the call happens. The mechanics are on how it works.

One-line conclusion

Cold calling is legal in the UK only when the number is not TPS or CTPS-registered, the person has not opted out, the sector is not pensions or claims management, and the call is live rather than automated; get any of those wrong and, since February 2026, the ceiling is £17.5 million rather than £500,000.