The short answer
Cold calling is legal in the UK. There is no blanket ban on unsolicited phone calls.
What is illegal is making unsolicited direct marketing calls to people who are registered with the Telephone Preference Service (TPS) or Corporate Telephone Preference Service (CTPS), unless you have their specific prior consent to call.
That single distinction -- between cold calls in general and direct marketing calls to TPS-registered numbers -- is where most businesses get confused and where most enforcement action originates.
What counts as a "cold call" under UK law
The term "cold call" does not appear in UK legislation. It is a colloquial term that covers any unsolicited phone call -- one that the recipient has not requested or expected. But not all cold calls are treated the same way by the law.
UK regulations distinguish between several types of unsolicited call, and each has different rules:
Direct marketing calls
These are calls made to promote a product, service, or organisation to a specific individual. Direct marketing is defined in the Data Protection Act 2018 as "the communication (by whatever means) of advertising or marketing material which is directed to particular individuals." This is the category that PECR regulates most heavily.
Automated marketing calls
These are calls made using an automated dialling system that plays a pre-recorded message. The rules here are stricter than for live calls: you must have specific prior consent from the recipient before making any automated marketing call, regardless of whether they are on the TPS.
Market research calls
Genuine market research calls -- surveys and data-gathering exercises with no promotional element -- are not classified as direct marketing under PECR. They are therefore not subject to the TPS screening requirement. However, if a research call includes any promotional content, or if the data collected is used for future marketing, the call is treated as direct marketing and the full PECR rules apply. The ICO has taken enforcement action against companies that disguised marketing calls as market research.
Service and transactional calls
Calls about an existing contract, appointment, delivery, or account query are not direct marketing. A garage calling to confirm a service booking, or a bank calling about a suspicious transaction on your account, is not making a marketing call and PECR's marketing rules do not apply.
Charity and fundraising calls
Live charity fundraising calls follow the same PECR rules as commercial marketing calls. You must screen against TPS before calling. However, the Data (Use and Access) Act 2025 introduced a new soft opt-in exemption for charities sending electronic messages (emails and texts) from 5 February 2026. This soft opt-in does not extend to phone calls.
The critical point is this: when people ask "are cold calls illegal?", what the law actually cares about is whether your call is unsolicited direct marketing to someone who has opted out. Everything else flows from that.
What PECR says about marketing calls
The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) is the primary legislation governing marketing calls in the UK. The relevant provision is Regulation 21, which deals with "calls for direct marketing purposes."
Regulation 21 establishes two core prohibitions:
1. You must not call someone who has told you to stop. If a subscriber has previously notified the caller that they do not want to receive marketing calls on that line, you must not call them. This applies regardless of TPS registration.
2. You must not call TPS-registered numbers. If a number is listed on the TPS register (maintained under Regulation 26 of PECR), you must not make unsolicited direct marketing calls to it.
There is one exception to both rules: specific prior consent. If the individual has specifically notified you that they consent to receiving your marketing calls, you may call them even if they are TPS-registered.
What Regulation 21 does not say
Regulation 21 does not prohibit cold calling in general. It does not ban unsolicited business calls. It does not require consent for all marketing calls. It specifically targets unsolicited direct marketing calls to numbers where the subscriber has opted out, either directly or via the TPS register.
This means that making a live marketing call to a number that is not on the TPS, where the individual has not previously asked you to stop, is lawful under PECR. You do not need prior consent for that call. You do, however, need a lawful basis for processing the person's personal data under UK GDPR, which is a separate but related obligation.
TPS and CTPS: your legal obligations
The Telephone Preference Service and its corporate equivalent, the CTPS, are central to the regulatory framework. Here is what you must do.
Check before you call
Before making any direct marketing call, you must screen the number against the TPS register and, if you are calling businesses, the CTPS register. This is a legal requirement, not a recommendation. The ICO's guidance is explicit: "If you want to make live marketing calls, you must check phone numbers against these registers before you make the calls."
Re-check regularly
TPS registrations take up to 28 days to become active. Regulation 21 includes a statutory defence for calling a number that has been on the register for fewer than 28 days. This means that if your last TPS check is older than 28 days, you lose that defence. The ICO recommends re-screening your call lists at least every 28 days. For a detailed breakdown of this requirement, see our article on the 28-day TPS re-check rule.
Maintain records
You need to be able to demonstrate that you checked a number before calling it, and when that check occurred. If the ICO investigates, "we always check TPS" is not sufficient. You need timestamped audit trails.
Both registers matter
Checking TPS alone is not enough if you also call business numbers. The CTPS covers sole traders, partnerships, and corporate subscribers. A single API call through TPSCheck checks both registers simultaneously.
Consent, legitimate interest, and the existing customer question
The relationship between consent, legitimate interest, and TPS registration is one of the most misunderstood areas of UK marketing law. Here is how it actually works.
When you do not need consent
For live (non-automated) direct marketing calls, PECR does not require prior consent as a general rule. You can make unsolicited live marketing calls to numbers that are not on the TPS or CTPS, provided the individual has not previously asked you to stop. This is a significant difference from the rules on marketing emails and texts, which do generally require consent or the soft opt-in exemption.
However, you still need a lawful basis under UK GDPR to process the person's personal data. For most outbound marketing calls, businesses rely on legitimate interests as that lawful basis. This requires a balancing test: your interest in marketing must not be overridden by the individual's rights and interests.
When you must have consent
Consent is required in three scenarios:
-
Calling TPS-registered numbers. If a number appears on the TPS register, you must have that individual's specific prior consent to make a marketing call. General consent ("we may share your details with third parties") is not sufficient. The consent must specifically name your organisation and must specifically cover marketing calls.
-
Automated marketing calls. Any pre-recorded or automated marketing call requires specific prior consent from the recipient, regardless of TPS registration. General marketing consent is not sufficient; the consent must specifically cover automated calls.
-
Claims management and pensions marketing. PECR contains additional restrictions for these sectors. Marketing calls about claims management services require specific prior consent in all cases. Pension scheme marketing calls are permitted only in narrowly defined circumstances, typically requiring either consent or an existing authorised client relationship.
The existing customer question
This is where many businesses make a costly mistake. Having an existing customer relationship does not automatically give you the right to make marketing calls to a TPS-registered number.
Under PECR Regulation 22, there is a "soft opt-in" exemption that allows marketing emails and texts to existing customers who bought (or negotiated to buy) a similar product, provided they were given an opt-out opportunity. This soft opt-in is widely used and well understood in email marketing.
But there is no equivalent soft opt-in for phone calls under Regulation 21. The soft opt-in applies to "electronic mail" -- defined as emails, texts, and other electronic messages. It does not apply to live telephone calls. If your customer registered with the TPS and did not specifically consent to your marketing calls, you must not call them.
This distinction catches businesses out regularly. "But they are our customer" is not a defence if the customer is TPS-registered and has not given specific consent to your calls.
What is actually illegal
To summarise the legal position clearly, here is what crosses the line:
Illegal under PECR: - Making unsolicited direct marketing calls to TPS-registered numbers without the subscriber's specific prior consent - Making unsolicited direct marketing calls to CTPS-registered numbers without consent - Making any automated marketing call without specific prior consent - Making claims management marketing calls without specific prior consent - Making pension scheme marketing calls outside the permitted circumstances - Failing to identify yourself or display a calling number when making marketing calls - Continuing to call someone who has asked you to stop
Not illegal under PECR (but still regulated): - Making live marketing calls to numbers not on the TPS, where the individual has not asked you to stop - Making live marketing calls to TPS-registered numbers where you hold valid specific consent - Making genuine market research calls (with no promotional element) - Making service, transactional, or account management calls
Important: even where a call is lawful under PECR, you must still comply with UK GDPR when processing personal data. This means having a lawful basis (typically legitimate interests for marketing), providing privacy information, and respecting data subject rights.
ICO enforcement: what happens when businesses get it wrong
The Information Commissioner's Office is the regulator responsible for enforcing PECR. It has a consistent track record of fining businesses that call TPS-registered numbers without consent.
Since the Data (Use and Access) Act 2025 came into force on 5 February 2026, the maximum penalty for PECR breaches has increased from £500,000 to £17.5 million or 4% of annual global turnover, whichever is higher. This brings PECR fines into line with UK GDPR penalties.
Recent enforcement cases illustrate the scale of consequences:
- Green Spark Energy and Home Improvement Marketing were fined a combined £550,000 for instigating nearly 12 million automated marketing calls using pre-recorded messages and avatar software.
- Outsource Strategies and Dr Telemarketing received a combined £340,000 in penalties for making 1.43 million calls to TPS-registered numbers, including deliberate targeting of elderly individuals.
- AFK Letters Co was fined £90,000 for making 95,277 calls to TPS-registered numbers without demonstrable consent. The company's third-party consent statements did not name it as a caller, and it could not produce evidence even within its own data retention window.
Every one of these fines was issued under the old £500,000 maximum. Under the new regime, the same conduct could attract penalties many times larger. For a comprehensive analysis of ICO enforcement cases and the fine calculation methodology, see our article on TPS fines and ICO enforcement.
The Data (Use and Access) Act 2025 also expanded the definition of "call" under PECR to include attempted calls -- meaning dialling a TPS-registered number is a breach even if nobody answers. For auto-dialler and predictive dialler operations, this is a significant change. Read our full analysis in How the Data Use and Access Act 2025 Changes TPS Compliance.
How to stay compliant: practical steps
If your business makes outbound calls, here is a compliance framework that keeps you on the right side of PECR.
1. Determine whether your calls are direct marketing
Be honest about the purpose of your calls. If you are promoting a product, service, or brand to specific individuals, you are conducting direct marketing. Service calls, appointment confirmations, and account queries are not marketing. But a "customer satisfaction survey" that ends with a sales pitch is.
2. Screen every number against TPS and CTPS
Before making any direct marketing call, check the number against both registers. This is a legal obligation, not optional best practice. With TPSCheck, you can verify numbers individually or in batches of up to 100 via a single API call. Every check includes TPS status, CTPS status, and phone intelligence data. See our API documentation for integration details.
3. Re-screen at least every 28 days
People register with TPS continuously. A number that was clear last month may be registered today. Re-check your active call lists within 28 days of the previous check. Setting an internal deadline of 25 days provides a safety buffer. Our product guide explains how TPSCheck's compliance tracking dashboard automates this process.
4. If relying on consent, make it bulletproof
If you intend to call TPS-registered numbers on the basis of consent, that consent must be:
- Specific: it must name your organisation
- Informed: it must make clear that you will make marketing calls
- Unambiguous: the individual must take a positive action to consent (no pre-ticked boxes)
- Recorded: you must be able to produce evidence of consent if challenged
- Current: consent can expire or be withdrawn at any time
Generic consent statements like "we may share your data with selected partners" do not override TPS registration.
5. Maintain your own suppression list
In addition to checking TPS, you must maintain an internal list of people who have asked you directly not to call them. This is a separate PECR obligation. Even if someone is not on the TPS, if they have told you to stop calling, you must stop.
6. Keep audit trails
Log every TPS check with a timestamp, the number checked, and the result. Log every call made, including the outcome. If the ICO investigates, your records are your defence. TPSCheck logs every query automatically on Pro plans and above, with exportable audit trails for compliance reporting.
7. Train your team
Everyone involved in outbound calling -- agents, managers, and any third-party diallers acting on your behalf -- must understand the PECR rules. You are responsible for calls made in your name, even if outsourced. "Our dialler provider handles compliance" is not a defence the ICO accepts.
8. Display your number and identify yourself
PECR requires that you display a calling number (or an alternative contact number) and promptly identify yourself and the organisation you are calling on behalf of. If asked, you must provide a contact address or freephone number.
Summary
Cold calling is not illegal in the UK. But unsolicited direct marketing calls to TPS-registered numbers without specific consent are. That distinction is not academic -- it is the difference between lawful business activity and conduct that can attract fines of up to £17.5 million.
The key points to remember:
- PECR Regulation 21 governs unsolicited direct marketing calls
- You must screen all numbers against TPS and CTPS before making marketing calls
- You do not need consent for live marketing calls to numbers not on the TPS (but you need a lawful basis under UK GDPR)
- Consent is required to call TPS-registered numbers, for automated calls, and for claims management or pensions marketing
- The soft opt-in exemption for existing customers applies to emails and texts, not phone calls
- Genuine market research calls are not direct marketing, but any promotional element changes the classification
- The Data (Use and Access) Act 2025 raised maximum PECR fines to £17.5 million and extended the definition of "call" to include attempted calls
- The ICO actively enforces PECR and publishes all enforcement actions publicly
Compliance is not expensive. Screening your call list against TPS costs pennies per number. A fine costs thousands at minimum, and potentially millions under the new regime. The maths has never been clearer.
Start checking numbers for free -- 50 checks per month, no credit card required. Or explore our API documentation to integrate TPS screening into your existing calling workflows.
This article is for general information purposes and does not constitute legal advice. For specific guidance on your obligations under PECR and UK GDPR, consult a qualified legal professional. TPSCheck is an independent commercial service operated by Visian Systems Limited. It is not affiliated with, endorsed by, or operated by the Information Commissioner's Office (ICO), TPS Limited, or the Data & Marketing Association (DMA).