New Zapier CRM sync is live — push every reply straight into your pipeline. See what's new

September 22, 2026 · LegalBriefsUSA

Is Cold Email Legal Under GDPR? Yes for B2B in Most of Europe, and No in Germany, Austria and Italy

Yes for B2B in most of Europe, and no in at least 3 countries. GDPR permits business prospecting under legitimate interest, Article 6(1)(f). GDPR is also not the law that decides whether you may press send.

That distinction is the whole answer, and almost every page ranking for this question misses it. GDPR governs whether you may hold and use a person’s name, work email and job title. Whether you may send that person an unsolicited marketing message is governed by the ePrivacy Directive as implemented in each member state, and those implementations disagree with each other. Germany, Austria and Italy require prior consent for a marketing email even when the recipient is a company. The UK, France and Ireland do not. This piece sits in our outbound compliance hub and works through both layers. Every statute, decision and figure below is linked and dated at the end.

Does GDPR ban cold email?

No. The regulation does not mention cold email, prospecting or unsolicited marketing anywhere in its 99 articles. It governs the processing of personal data, and a work email address attached to a named human is personal data. So GDPR decides whether you may lawfully hold that record and use it. A second statute decides whether you may send to it.

That second statute is Directive 2002/58/EC of 12 July 2002, the ePrivacy Directive. Article 13(1) requires prior consent for direct marketing by electronic mail in respect of “subscribers.” Article 13(5) then hands the B2B question to national parliaments: Member States must ensure that the legitimate interests of subscribers other than natural persons are sufficiently protected. A directive is not directly binding on you. The national law implementing it is, and 27 parliaments wrote 27 versions.

Two rules in Article 13 are not optional anywhere. Article 13(4) prohibits sending marketing email that disguises or conceals the identity of the sender, and prohibits sending without a valid address the recipient can use to ask you to stop. Those apply in every member state regardless of what the B2B carve-out says locally.

What is legitimate interest, and does B2B prospecting qualify?

Legitimate interest is the lawful basis at Article 6(1)(f): processing is lawful where it is necessary for the legitimate interests of the controller, except where those interests are overridden by the rights and freedoms of the data subject. Recital 47 addresses marketing directly, in one sentence: “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.”

May be regarded. Not is. The word does real work, and it is why a regulator can agree that B2B prospecting is a legitimate interest in principle and still fine you for how you ran it.

France’s CNIL states the test plainly for B2B: prospecting aimed at professionals may be founded on the organisation’s legitimate interest when the subject of the approach relates to the person’s profession, its example being software presented to a company’s IT director. Software to the IT director passes. The same email to the office manager at the same company is a harder argument, because the qualifier is the relevance of the message to that person’s role.

The ICO sets out the three-part test every legitimate interests claim has to survive: a purpose test, a necessity test, and a balancing test against the interests and fundamental rights of the person. The ICO’s position on documenting it is that there is no specific requirement in the UK GDPR to record a legitimate interests assessment, but you must be accountable, and you “should” record the assessment and its outcome. An undocumented LIA is not a breach on its own. It is an absent defence when a regulator asks how you reached your conclusion.

Which countries let you email a business address without consent, and which do not?

Six markets, three answers. The variable is whether national law extended the Article 13 consent rule past natural persons to cover companies, and whether the regulator reads a business inbox as belonging to the company or to the human who reads it.

Country Emailing a B2B address without consent The governing rule
United Kingdom Permitted to corporate subscribers. Sole traders and some partnerships count as individual subscribers and need consent or the soft opt-in. PECR. The ICO states the electronic mail rule “does not apply to corporate subscribers,” while UK GDPR still requires a lawful basis, privacy information and an honoured right to object.
France Permitted where the message relates to the person’s profession. Generic addresses such as contact@ fall outside the individual rules entirely. CNIL guidance on commercial prospecting by electronic mail, page updated 10 June 2026.
Ireland Permitted unless the recipient has told you they do not consent. SI 336/2011 as summarised by DLA Piper: B2B marketing email “can generally be sent unless the recipient has informed the sender that it does not consent.”
Germany Not permitted. No B2B exemption. UWG Section 7(2) no. 2 presumes unacceptable nuisance for “advertising using an automated calling machine, a fax machine or electronic mail without the addressee’s prior express consent.”
Austria Not permitted. The consent rule covers businesses explicitly. Section 174 TKG 2021. The economics ministry states sending is “not permitted neither for the corporate sector nor for the non-commercial sector if the purpose is direct advertising.”
Italy Not permitted. Consent is required and the rule reaches companies. Article 130 of the Italian Privacy Code, which refers to the contracting party’s and user’s consent rather than the data subject’s, covering individuals and companies.
Sources linked and dated at the end of this post, all checked 22 September 2026. Six markets is not the whole EU. Check the destination country before a campaign sends into it, and segment by where the recipient sits rather than where the parent company is headquartered.

All three consent countries keep the same existing-customer exception the directive allows: contact details taken during a sale, used for your own similar products, with a free and clear objection route offered at collection and in every message. That exception has no application to cold outreach. A prospect who has never bought from you is not an existing customer, and stretching the exception to cover them is a deliberate misreading rather than a grey area.

What do you have to tell someone whose email you bought or scraped?

Everything in Article 14, and the deadline is your first message. Where personal data was not obtained from the data subject, Article 14(3) requires the information within a reasonable period and at the latest within one month, or, if the data is used to communicate with that person, at the latest at the time of the first communication. For outbound, those two clocks collapse into one. The first email is the notice.

The information set includes your identity, the purposes and the legal basis, the legitimate interests you are pursuing, the categories of data, the retention period, the rights available including the Article 21 objection, and the source the data came from. In practice a two-line footer plus a link to a privacy notice that actually names your data sources carries it.

The CNIL’s KASPR decision of 5 December 2024 is the clearest published warning on this point, and it landed on a B2B contact data vendor, not a marketer. KASPR ran a browser extension that extracted professional contact details from LinkedIn into a database of about 160 million contacts, sold for commercial prospecting, recruitment and identity verification. The fine was 240,000 euros. The findings: collecting details from profiles whose owners had limited visibility to their own connections exceeded what those people could reasonably expect, so Article 6 failed; retention ran 5 years from each data update; and individuals were not informed until 2022, four years after the extension launched, in English only.

Read that as a provenance test for your own list. If a data vendor cannot tell you per record where it came from and whether that person was ever informed, you are buying their Article 14 exposure along with the emails. Ask for provenance in writing before signing, the same way you would ask who counts as the sender under CAN-SPAM before a US campaign.

What happens when someone objects?

You stop, immediately and permanently, and there is nothing to weigh. Article 21(2) gives the data subject the right to object at any time to processing for direct marketing purposes. Article 21(3) is one sentence: where the data subject objects, “the personal data shall no longer be processed for such purposes.”

This is stronger than the general objection right at Article 21(1), where you can continue if you demonstrate compelling legitimate grounds. For direct marketing there is no balancing exercise and no grounds that override it. The operational requirement follows: suppression has to be global across every sending domain and every inbox in the program, not per sequence and not per mailbox. Most failures here are engineering failures rather than legal ones, and they surface as a second email to a person who already said no, from a different domain you own.

What are the fines, and who actually enforces this?

GDPR’s upper tier is up to 20,000,000 euros or 4% of total worldwide annual turnover, whichever is higher, and it is the tier that covers the articles at issue here: Articles 5, 6, 7 and 9, and Articles 12 to 22. That is the headline. The published reality for outbound data is the KASPR number: 240,000 euros against a company whose entire product was B2B contact data.

What you got wrong Which law Who comes after you
No valid lawful basis for holding the data, no Article 14 notice, objections ignored GDPR Articles 6, 14, 21 The data protection authority, with the Article 83(5) tier available
Sent a marketing email into a consent country without consent National ePrivacy implementation, for example Section 174 TKG in Austria or Article 130 in Italy The national authority designated for that statute, on national penalty scales, not GDPR’s
Sent marketing email into Germany without prior express consent UWG Section 7(2) no. 2 The unfair competition system rather than a privacy regulator, because the UWG is a competition statute
Concealed the sender identity or supplied no working opt-out address ePrivacy Article 13(4), in every member state The national authority, with no B2B exemption available anywhere
The practical point of this table is that the GDPR fine tier and the ePrivacy penalty are separate exposures on separate tracks, and a single campaign can trigger both. Checked 22 September 2026.

What does a defensible GDPR B2B program look like?

Seven controls, and six of them cost nothing but the decision to run them. The seventh is list hygiene, which costs money and is where most programs fail.

None of the above helps if the messages never arrive, and the same infrastructure discipline drives both outcomes. Authentication, domain reputation and suppression hygiene are the shared foundation, covered in the SPF, DKIM and DMARC setup and in why cold emails go to spam.

How LeadButton handles this

European campaigns are segmented by recipient country before anything sends, with Germany, Austria and Italy excluded from cold sequences by default rather than by exception. Every record carries its source. The first message in a European sequence carries the Article 14 disclosure and a one-step objection route, and objections suppress across every domain and inbox in the program, permanently.

Launch is $1,500 a month for managed email outreach, Growth is $3,500 a month for email plus LinkedIn, and Scale is custom. Geography changes the shape of a European program more than the price, which is worth raising on the first call rather than after launch. Pricing is on the LeadButton pricing page. We are not lawyers and this is not legal advice. What we can tell you is which of the controls above we run as standard and which stay with you.

Sources

Leave a Reply

Back home

Discover more from leadbutton.io

Subscribe now to keep reading and get access to the full archive.

Continue reading