Do I Need a Compliance Footer on My Email?

If you run a UK limited company or LLP, yes, but not the one you are thinking of. The law requires four pieces of company information on your business emails. The long confidentiality notice that most businesses copy from one another is unnecessary and does not do what people believe it does.

The head image shows the text "Your email footer is wrong" with an illustration of an envelope representing an email with a red bracket around it

The part everyone copies is the part that does nothing.

Look at a typical email footer, and you will see two blocks of text stuck together. Most business owners assume the first block is the serious legal one, and the second block is admin. It is the other way round.

The confidentiality notice, the bit about viruses, and the line about the author's views carry no legal weight in the UK. You cannot create obligations for someone by sending them text they never agreed to.

The company information block underneath is a statutory requirement. Leaving it off is a criminal offence under the Companies Act 2006, and you can be fined if it is missing!

What does UK law actually require on a business email?

A UK limited company must show its registered name, the part of the UK where it is registered, its registered number, and its registered office address. These rules cover business letters, order forms, and websites. Emails count because the rules apply to correspondence in electronic form as well as in paper form.

The requirement is set out in regulations 24 and 25 of the Names and Trading Disclosures Regulations 2015, made under section 82 of the Companies Act 2006. Regulation 29(c) is the part that catches email: every reference to a document means that document "in hard copy, electronic or any other form."

Regulation 28 makes non-compliance an offence where you have no reasonable excuse. A magistrates' court can fine the company and any officer in default up to level 3 on the standard scale, which is £1,000, plus £100 a day while the breach continues. It is a small sum attached to a criminal conviction, and it takes ten minutes to avoid.

Is an email confidentiality notice legally binding?

No, not as a contract. No agreement exists between you and a stranger who receives your misdirected email, so a paragraph arriving in their inbox creates no duty for them to delete it, ignore it, or call you.

There is a fair counter-argument. UK law recognises an equitable duty of confidence, which turns on whether a reasonable recipient would realise that the information was confidential, and a notice can help tip the balance of that judgement. The wording is not completely inert. It just does far less than people assume.

Specifically on contracts, one UK case is instructive. In Baillie Estates Ltd v Du Pont (UK) Ltd [2009] CSOH 95, Du Pont ran a disclaimer stating that its emails did not form a contract. The Court of Session found a binding contract had been formed anyway. Du Pont never even ran the disclaimer argument at proof, and Lord Hodge noted in passing that it would have failed regardless, because the offer was the attached proposal rather than the email. The law firm CMS drew the same conclusion in its analysis of the judgment: a disclaimer that covers only the email body misses where the terms usually sit.

The virus clause is weaker still. It is a written admission that you might be sending malware, and a blanket exclusion of your own negligence gets tested for reasonableness under the Unfair Contract Terms Act 1977 anyway.

Where did email disclaimers come from?

They spread by copying. One large organisation added a disclaimer in the early days of business email; everyone else assumed it was a requirement, and the text propagated through decades of copy-and-paste. The Economist put the practice down to imitation and habit. A survey by The Register in 2001 found UBS Warburg running a disclaimer of 1,081 words.

Does a long disclaimer cause any real problems?

Yes. Kimbley IT is a managed IT services provider, and we see the same handful of issues across client mailboxes.

Long disclaimers get appended to every message in a thread. A conversation with 40 replies carries 40 copies, which makes it painful to read on a phone and bloats your archive.

Footers injected by a signature service after the message has been signed break the DKIM signature on your outbound mail. That hurts deliverability, and it is a real cause of legitimate mail landing in spam. We covered how to set up SPF, DKIM, and DMARC properly in a separate guide.

The disclaimer also devalues itself. When every message says "confidential," the word carries no weight in the one message where it matters. If you need a message to stay private, Gmail has a confidential mode that restricts what the recipient can do, which is a control rather than a request.

What does each type of UK business need to disclose?

What Each Type of UK Business Must Show on Its Emails
Business type What you must show Where the rule comes from
Limited company Registered name, the part of the UK where you are registered, company number, and registered office address. Regulations 24 and 25 of the Trading Disclosures Regulations 2015.
Limited liability partnership Registered name, the part of the UK where you are registered, LLP number, and registered office address. The same 2015 Regulations, applied to LLPs by SI 2009/1804.
Sole trader (using a business name) Your own name and an address where documents can be served on you. Companies Act 2006, sections 1200 to 1206.
Partnership (using a business name) The names of all partners and an address where documents can be served. Companies Act 2006, sections 1200 to 1206.
Sole trader (trading under your own name) Nothing. No disclosure duty applies to you. Falls outside the business names rules entirely.

Sole traders and partnerships sit under a different law: Part 41 of the Companies Act 2006, sections 1200 to 1206. It only bites when you trade under a name that is not simply your own surname, and it covers letters, orders, invoices, and receipts. Websites are not on that list.

Two things people expect are missing. There is no general requirement to put a VAT number on an email, though you do need one if the email is the invoice itself. UK GDPR does not require a privacy policy link in your footer either. The ICO's guidance on how to provide privacy information is deliberately method-neutral. Marketing email is the exception in which PECR requires a valid opt-out address. On a related note, the ICO data protection fee is a genuine requirement that many businesses mistakenly assume is a scam.

What should you put in your email footer?

  1. Write the compliant block. For a limited company: [Registered Name] | Registered in England & Wales # [Company Number] | Registered Office: [Full Address]

  2. Delete the confidentiality notice. It binds nobody.

  3. Delete the virus disclaimer. It admits a risk and excludes nothing enforceable.

  4. Delete the “views of the author” line. It does not switch off your liability for what a team member sends on your behalf.

  5. Apply it centrally. In Google Workspace, you can enforce this across the domain, using the compliance footer feature in the admin panel.

  6. Check your gateway signs mail after appending the footer, so you do not break DKIM.

Here is the footer Kimbley IT uses:

Kimbley IT Limited | Registered in England & Wales # 07780759 | Registered Office: Kimbley IT Limited, The Moseley Exchange, 149-153 Alcester Road, Birmingham, B13 8JP

That is 27 words; it satisfies every disclosure the Companies Act asks for, and it asks nothing of the person reading it.

Frequently asked questions

If you want a hand tidying up email footers across your team, or you are not sure whether your Google Workspace setup signs mail correctly, the next step is to book a video call with Kimbley IT using the form below. We will take a look and tell you straight what needs changing.

Kimbley IT is an IT support provider, not a firm of solicitors. This article sets out the rules as we understand them at August 2026. For a specific legal question about your correspondence, ask a solicitor.

James Kimbley

<strong>Founder, Entrepreneur & Investor at Kimbley IT Limited</strong>

<br><br>

My team organises your business IT with Google Workspace, AI, Cyber Security & Support in One Package, trusted by 65+ UK businesses. Kimbley IT is a Google Cloud Partner, and Google Workspace is at the heart of everything we do. We recommend it because we've spent nearly 20 years helping UK businesses get the most from it and not because anyone asked us to.

<br><br>

Connect with me:

<a href="https://www.linkedin.com/in/jameskimbley/">LinkedIn</a> •

<a href="https://www.threads.com/@james.kimbley">Threads</a> •

<a href="https://www.kimbley.com/blog?author=50c5e9d6e4b033df8f3030ec">View All Posts</a>

www.kimbley.com
Next
Next

How Do You Open a Zip File in Google Drive?