qualified-leads-final contains 2,400 rows. Names, work addresses, job titles, company websites. Nobody in the Friday sales meeting can say whether the people asked to hear from you. The supplier says the data is public and “GDPR compliant”. That answer is being asked to carry far too much.
The first useful move is to slow one part of the process down: not the whole campaign, just the assumption that possessing an address settles permission to use it.
In UK business-to-business marketing, the rules depend on who the subscriber is, whether personal data is involved, the channel, the source and the message. A generic company address, a named employee at a limited company, and a sole trader can lead to different questions. One label on a bought list cannot answer all of them.
Separate four things the spreadsheet has flattened
Start with recipient type. The Information Commissioner’s Office explains in its B2B marketing guidance that PECR treats corporate subscribers differently from individual subscribers, which include sole traders and some partnerships. That distinction affects the electronic-mail rules.
Then separate the other three layers:
- Personal data. A named work email can identify a person even when it belongs to a company domain.
- Message purpose. A service notice, a personal note and a promotional sequence are not the same communication.
- Objections and suppression. A person who has objected should not quietly reappear because a new list was imported.
This is why “B2B does not need consent” is a dangerous summary. It can be true of one PECR question for one corporate subscriber and still leave UK GDPR duties, transparency, lawful basis, identity, opt-out and objection handling in view. It is also no help if the row belongs to a sole trader.
Ask the supplier questions that can survive contact with a row
A data warranty in a sales deck is not enough. Pick ten records and ask:
- Where did this exact address come from?
- When was it collected or last checked?
- Was it supplied directly, observed publicly or obtained from another party?
- What was the person told about this use?
- Is the recipient a corporate or individual subscriber?
- How are objections and withdrawals passed back?
- Can the supplier prove the answer without revealing data it should not reveal?
If the response remains “all data is compliant”, you still do not have an operational basis for the campaign. You have a claim about the dataset.
The ICO’s detailed electronic-mail marketing guidance was updated in April 2026. It covers consent, soft opt-ins, bought-in lists and publicly available details. The B2B page is also marked as under review following legislative change. That makes release review more important, not less. A copied checklist can age while a campaign remains active.
Make the sequence capable of remembering “no”
Suppose a named operations director at a limited company receives a relevant email and asks not to be contacted again. Deleting the row feels respectful, but it can remove the evidence needed to prevent re-import. A suppression record serves a narrower purpose: it remembers enough to avoid repeating the contact.
Now imagine the next list uses a slightly different job title and the same address. The sequence should screen it before sending. This is basic operating memory. Without it, each data import acts as if the relationship has never existed.
The message itself matters too. Honest relevance cannot be manufactured with a first-name token and a line scraped from a press release. State why the observed fact may connect to the offer, mark inference as inference, identify the sender, and make leaving the conversation easy. Legal permission, where it exists, is not the same as earning attention.
Build a release record, not a compliance badge
Before a sequence is activated, keep a compact record of audience, recipient types, data source, assessment, suppression check, sender identity, message purpose, opt-out route, owner and review date. Where consent or a soft opt-in is relied on, preserve the evidence that supports it. Where legitimate interests is considered, do the actual assessment rather than selecting a label in the sending tool.
The Email Sequencing System joins the research, message logic, exceptions and stop conditions once those decisions are made. It cannot make a list lawful. Current guidance, the actual facts and sometimes qualified advice have to do that work.
Before the sequence goes live
Pause one queued campaign and inspect ten rows. Classify the recipient type, locate the data source, check suppression, and write down why this specific message is relevant. If one of those answers is missing, keep the row out until the gap is resolved.
You do not need to turn every email into a legal project. You do need a process that can tell the difference between a reasonable contact and an address you merely happen to possess.
Sources and limits
- ICO: business-to-business marketing — used for subscriber types, UK GDPR, PECR, objections and suppression. The ICO marks this page as under review; it is general guidance, not a lawful-basis decision for a campaign.
- ICO: guidance on direct marketing using electronic mail — used for current consent, soft opt-in, bought-list and public-contact questions. Applying those rules depends on the actual recipient, source, message and facts and may require legal advice.
Sources reviewed 7 September 2026. Recheck ICO guidance and campaign facts before sending.