Is it legal to contact companies that visited my website?

What PECR and UK GDPR allow when a company shows up in your visitor feed, and where the line is.

In the UK you can normally email or call a limited company that visited your website without prior consent, because PECR treats companies and LLPs as corporate subscribers. Identify yourself, offer an opt-out, have a lawful basis for the named contact, and never write as though you know who visited.

In short

  • PECR's consent rule for marketing email does not apply to limited companies, LLPs and other corporate subscribers.
  • A named work email is still personal data, so UK GDPR applies: you need a lawful basis, privacy information at first contact and a way to object.
  • Sole traders and some partnerships count as individuals under PECR, so marketing emails to them need consent.
  • Contacts supplied by visitor identification tools are people at the company, not the person who browsed, so never reference their browsing.
  • Since 5 February 2026 PECR fines can reach £17.5 million or 4% of global turnover.
Red leather-bound parliamentary books from 19th century in Bern library, Switzerland.
Photo: Christian Wasserfallen on Pexels

Is it legal to contact companies that visited my website? In the UK the short answer is usually yes: a limited company or LLP can be emailed or called without its prior consent, as long as you say who you are, give a way to opt out, and treat the named person you write to fairly under UK GDPR. What you must never do is write as though you know who browsed your site, because you almost certainly do not.

This is general information about UK rules, not legal advice. If your situation is unusual, or you market at scale, take advice from a solicitor.

Can you legally contact a company that visited your website?

Usually, yes. The Privacy and Electronic Communications Regulations (PECR) set the rules for marketing by email, text and phone, and they draw a line between two kinds of recipient. The ICO describes corporate subscribers as organisations with "separate legal status", including "companies, limited liability partnerships, Scottish partnerships, and some government bodies".1

For those organisations the ICO is direct: "The PECR rule on direct marketing by electronic mail does not apply to corporate subscribers."1 So you do not need prior consent to send a marketing email to a limited company. Two conditions still apply. You must "not disguise or conceal your identity", and you must "give a valid address for business to opt-out or unsubscribe".1

The fact that the company visited your website changes none of this. Visitor identification tells you which organisation's network a visit came from. It does not create a special permission, and it does not remove any obligation. You are simply doing ordinary B2B marketing to a company you now have a reason to think about.

What about the person you email?

This is where most people get caught out. PECR may not require consent to email a company, but the person at the other end is still a person. The ICO notes that when "the email address you are using to communicate with the business identifies an individual", it is personal data and "the UK GDPR applies".1 A named work address such as jane.smith@company.co.uk is personal data. A role address such as sales@ may not be, but you still need to meet PECR's identity and opt-out rules.

Under UK GDPR you need a lawful basis for using a named contact's details. The ICO says "the two lawful bases most likely to apply to sending direct marketing messages are consent and legitimate interests", and its table lists legitimate interests or consent as the options for electronic mail marketing to corporate subscribers.2 In practice most B2B teams rely on legitimate interests, which means you should be able to show a genuine business reason, that emailing this person is necessary for it, and that it is proportionate to their role.

Two further duties follow:

  • Tell them where you got their details. If you obtained the personal data from somewhere other than the person, the ICO says you must give privacy information "if you use the data to communicate with the individual, at the latest, when the first communication takes place".3 A short line and a link to your privacy notice in the first email covers this.
  • Stop when asked. On direct marketing objections the ICO is unambiguous: "This is an absolute right and there are no exemptions or grounds for you to refuse."4

For a fuller view of the data protection side of identifying visitors in the first place, see our guide to visitor identification and UK GDPR.

Who are the contacts a tool gives you?

A visitor identification tool names a company, not a person. When it also offers contacts, those are business contacts at that company drawn from a contact database, not the individual who was reading your pages.

Lead Forensics puts this plainly in its customer compliance FAQ (checked 27 September 2026): "These contacts are not the individuals who visited the customer's website, as Lead Forensics does not identify individual website visitors." It adds that "Customers using this feature are responsible for ensuring their use of the contact data complies with applicable data protection, electronic communications and calling rules."5 That is a fair and accurate description of how the category works, and it applies to every tool in it.

Scout works the same way. It identifies the company behind a visit from its IP address and network data, and it never claims to know who browsed. If you want people to contact, you look them up on request: Forager credits search business contact databases for decision makers at the identified company, and Scout credits reveal a specific person's work email. The pricing page explains how credits work. The key point for compliance is the same whichever tool you use: the person you email is someone you chose because of their role, not someone you watched.

Where is the line?

The law sets the floor. Good practice sits a little above it. These are the lines worth holding:

Do Do not
Contact limited companies and LLPs with a clear sender and an opt-out Email sole traders or partnerships without consent
Pick a contact whose role fits what you sell Imply the recipient personally visited your site
Link to your privacy notice in the first message Quote their browsing back to them ("I saw you on our pricing page")
Check the TPS and CTPS before calling Keep emailing or calling after someone objects
Act on high-confidence matches Treat a weak or ISP-level match as a real company

The sole trader point matters more than it looks. The ICO says "sole traders" and "certain types of partnerships" are "classed as individual subscribers and PECR treats them the same as individuals".1 A July 2025 guide from Hybrid Legal makes the same distinction for cold email: corporate subscribers can be contacted without consent, while sole traders and partnerships need it.6 If a company in your feed turns out to be a sole trader, do not email them without consent.

The confidence point is practical rather than legal. If you act on a weak match you may be writing to a company that never visited at all. Scout gives every identified company a confidence score from 1 to 99 with a one-line reason, and holds ISP, mobile, VPN and data-centre traffic in the low band, so you can see which matches are worth acting on.

A compliant first message

A good first message never mentions the visit. It is written to someone whose job makes your offer relevant, it says who you are, and it makes stopping easy. Something like:

Subject: Stock forecasting for UK distributors

Hello Priya,

I run the sales team at Example Ltd. We help UK distributors cut overstock by forecasting demand from their own order history. As operations director at Northfield Supplies, you may be weighing up something similar before your next buying cycle.

If it would help, I can send a two-page summary of how one wholesaler approached it. If not, just reply "no thanks" and I will not contact you again.

Best, Sam Carter, Example Ltd, 1 High Street, Leeds

We found your details in a business contact database. You can read how we use them in our privacy notice: example.co.uk/privacy

It identifies the sender, explains the source of the data, links to the privacy notice and offers a clear way out. It says nothing about browsing. The visit informed the timing and the choice of company, which is where it belongs. For more on structuring the whole sequence, see how to follow up with a company that visited your website.

Generally yes, with a screening step. The ICO says that before calling businesses you should "screen against both the CTPS and TPS registers, as well as your own 'do not call' list", because "some businesses register with the TPS, and others register with the CTPS".1 If a number is registered, or the business has told you not to call, do not make the marketing call.

What can go wrong?

Three things, in rising order of cost.

Complaints. Recipients can complain to the ICO, and an objection to direct marketing must be honoured. A single complaint rarely leads to action, but a pattern does.

Fines. When the relevant parts of the Data (Use and Access) Act commenced on 5 February 2026, the ICO gained the power to "issue fines of up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR)".7 PECR penalties now sit on the same scale as UK GDPR ones. Our explainer on the Data (Use and Access) Act and B2B marketing covers the other changes.

Reputation. The most likely damage is quieter. A prospect who receives "I noticed you were looking at our pricing" feels watched, and usually says so to colleagues. It is also often wrong: the visit may have come from a colleague, a contractor or someone on shared office wifi. Writing as though you know who browsed turns a reasonable signal into an unforced error.

The honest summary

You may contact the company. Treat the named person as a person: have a lawful basis, tell them where you got their details, and stop when asked. Do not email sole traders or partnerships without consent, screen calls against the TPS and CTPS, and never pretend you know who visited.

If you want to see which companies are already on your site, with a confidence score and reason for each so you know which ones are worth a considered approach, you can start a 14-day free trial of Scout. Identify the company, then contact it properly.

Frequently asked questions

Generally yes. The ICO says you should screen numbers against both the TPS and CTPS registers, and your own do-not-call list, before making marketing calls to businesses. If a number is registered or the business has asked you not to call, do not make the call.

Can I contact the specific person who visited my website?

Only if they identified themselves, for example by filling in a form or booking a demo. Visitor identification names the company behind a visit, not the individual, so any contact you find is someone at that company rather than the person who browsed.

Identifying a company from network data raises separate questions from contacting it, including cookie and storage rules for the tracking script. Our guide to visitor identification and UK GDPR covers that side. This article deals only with contacting the company afterwards.

Can I email a sole trader who visited my website?

Not without consent. The ICO says sole traders and certain partnerships are individual subscribers, and PECR treats them the same as individuals, so unsolicited marketing emails to them need prior consent.

Should I tell a prospect that I know they visited my website?

No. You do not know who visited, only which company's network the visit came from, and quoting browsing back to someone feels intrusive. Let the visit inform which company you approach and when, not what you say.

Sources

  1. ICO: Business-to-business marketing ico.org.uk
  2. ICO: Sending direct marketing: choosing your lawful basis ico.org.uk
  3. ICO: Right to be informed ico.org.uk
  4. ICO: Right to object ico.org.uk
  5. Lead Forensics: Customer compliance FAQ leadforensics.com
  6. Hybrid Legal: Using business emails for B2B cold outreach in the UK hybridlegal.co.uk
  7. ICO: Statement on the commencement of the Data (Use and Access) Act ico.org.uk