The people who received the email are likely to have clicked a little check box agreeing to receive these type of emails when signing up to a service in the past.
You could be right, but the the GDPR rules surrounding personal data is now quite specific but quite bureaucratic in it's wording and therefore confusing to many.
Without knowing the OP details it's difficult to tell, but
If his/her email address is
[email protected] or
[email protected] or
[email protected] then there isn't much of a problem as it's not personalised.
If it's personalised ie:
[email protected] or
[email protected] then it
could be a serious issue to the email marketing company that sent it. But like all of these things it's down to circumstances.
Part of what we do is monitor a product called mimesweeper for a few companies - it filters emails before they are passed through to (lets say) an office365 business solution. GDPR has stopped some crap from getting through, so GDPR has made things better. What most people don't see with email in the world is that approx 50-60% of all emails never reach the recipient as they are filtered out before hitting any inbox - that is the scale of the problem in the world. It used to be higher - 10 years ago a business would have been seeing a higher percentage that had to be filtered. If you add is scam/phising/virus, that figure is even higher.
There's plenty of info specifically on the Information Commissions Office (ico.org.uk) that explains the use/none use of personal data which includes email addresses.
IMHO - I don't think the OP problem is anything to do with United - someone is hunting for personal data, for some reason and have faked it up to look as though it's from United.
There is a website that the OP poster can report it to if they want.
Companies are now fined for this, but the ICO can only work when things like this are reported.
UTB