September 22, 2026 · LegalBriefsUSA
Is Cold Email Legal Under GDPR? Yes for B2B in Most of Europe, and No in Germany, Austria and Italy
Yes for B2B in most of Europe, and no in at least 3 countries. GDPR permits business prospecting under legitimate interest, Article 6(1)(f). GDPR is also not the law that decides whether you may press send.
That distinction is the whole answer, and almost every page ranking for this question misses it. GDPR governs whether you may hold and use a person’s name, work email and job title. Whether you may send that person an unsolicited marketing message is governed by the ePrivacy Directive as implemented in each member state, and those implementations disagree with each other. Germany, Austria and Italy require prior consent for a marketing email even when the recipient is a company. The UK, France and Ireland do not. This piece sits in our outbound compliance hub and works through both layers. Every statute, decision and figure below is linked and dated at the end.
Does GDPR ban cold email?
No. The regulation does not mention cold email, prospecting or unsolicited marketing anywhere in its 99 articles. It governs the processing of personal data, and a work email address attached to a named human is personal data. So GDPR decides whether you may lawfully hold that record and use it. A second statute decides whether you may send to it.
That second statute is Directive 2002/58/EC of 12 July 2002, the ePrivacy Directive. Article 13(1) requires prior consent for direct marketing by electronic mail in respect of “subscribers.” Article 13(5) then hands the B2B question to national parliaments: Member States must ensure that the legitimate interests of subscribers other than natural persons are sufficiently protected. A directive is not directly binding on you. The national law implementing it is, and 27 parliaments wrote 27 versions.
Two rules in Article 13 are not optional anywhere. Article 13(4) prohibits sending marketing email that disguises or conceals the identity of the sender, and prohibits sending without a valid address the recipient can use to ask you to stop. Those apply in every member state regardless of what the B2B carve-out says locally.
What is legitimate interest, and does B2B prospecting qualify?
Legitimate interest is the lawful basis at Article 6(1)(f): processing is lawful where it is necessary for the legitimate interests of the controller, except where those interests are overridden by the rights and freedoms of the data subject. Recital 47 addresses marketing directly, in one sentence: “The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.”
May be regarded. Not is. The word does real work, and it is why a regulator can agree that B2B prospecting is a legitimate interest in principle and still fine you for how you ran it.
France’s CNIL states the test plainly for B2B: prospecting aimed at professionals may be founded on the organisation’s legitimate interest when the subject of the approach relates to the person’s profession, its example being software presented to a company’s IT director. Software to the IT director passes. The same email to the office manager at the same company is a harder argument, because the qualifier is the relevance of the message to that person’s role.
The ICO sets out the three-part test every legitimate interests claim has to survive: a purpose test, a necessity test, and a balancing test against the interests and fundamental rights of the person. The ICO’s position on documenting it is that there is no specific requirement in the UK GDPR to record a legitimate interests assessment, but you must be accountable, and you “should” record the assessment and its outcome. An undocumented LIA is not a breach on its own. It is an absent defence when a regulator asks how you reached your conclusion.
Which countries let you email a business address without consent, and which do not?
Six markets, three answers. The variable is whether national law extended the Article 13 consent rule past natural persons to cover companies, and whether the regulator reads a business inbox as belonging to the company or to the human who reads it.
| Country | Emailing a B2B address without consent | The governing rule |
|---|---|---|
| United Kingdom | Permitted to corporate subscribers. Sole traders and some partnerships count as individual subscribers and need consent or the soft opt-in. | PECR. The ICO states the electronic mail rule “does not apply to corporate subscribers,” while UK GDPR still requires a lawful basis, privacy information and an honoured right to object. |
| France | Permitted where the message relates to the person’s profession. Generic addresses such as contact@ fall outside the individual rules entirely. | CNIL guidance on commercial prospecting by electronic mail, page updated 10 June 2026. |
| Ireland | Permitted unless the recipient has told you they do not consent. | SI 336/2011 as summarised by DLA Piper: B2B marketing email “can generally be sent unless the recipient has informed the sender that it does not consent.” |
| Germany | Not permitted. No B2B exemption. | UWG Section 7(2) no. 2 presumes unacceptable nuisance for “advertising using an automated calling machine, a fax machine or electronic mail without the addressee’s prior express consent.” |
| Austria | Not permitted. The consent rule covers businesses explicitly. | Section 174 TKG 2021. The economics ministry states sending is “not permitted neither for the corporate sector nor for the non-commercial sector if the purpose is direct advertising.” |
| Italy | Not permitted. Consent is required and the rule reaches companies. | Article 130 of the Italian Privacy Code, which refers to the contracting party’s and user’s consent rather than the data subject’s, covering individuals and companies. |
All three consent countries keep the same existing-customer exception the directive allows: contact details taken during a sale, used for your own similar products, with a free and clear objection route offered at collection and in every message. That exception has no application to cold outreach. A prospect who has never bought from you is not an existing customer, and stretching the exception to cover them is a deliberate misreading rather than a grey area.
What do you have to tell someone whose email you bought or scraped?
Everything in Article 14, and the deadline is your first message. Where personal data was not obtained from the data subject, Article 14(3) requires the information within a reasonable period and at the latest within one month, or, if the data is used to communicate with that person, at the latest at the time of the first communication. For outbound, those two clocks collapse into one. The first email is the notice.
The information set includes your identity, the purposes and the legal basis, the legitimate interests you are pursuing, the categories of data, the retention period, the rights available including the Article 21 objection, and the source the data came from. In practice a two-line footer plus a link to a privacy notice that actually names your data sources carries it.
The CNIL’s KASPR decision of 5 December 2024 is the clearest published warning on this point, and it landed on a B2B contact data vendor, not a marketer. KASPR ran a browser extension that extracted professional contact details from LinkedIn into a database of about 160 million contacts, sold for commercial prospecting, recruitment and identity verification. The fine was 240,000 euros. The findings: collecting details from profiles whose owners had limited visibility to their own connections exceeded what those people could reasonably expect, so Article 6 failed; retention ran 5 years from each data update; and individuals were not informed until 2022, four years after the extension launched, in English only.
Read that as a provenance test for your own list. If a data vendor cannot tell you per record where it came from and whether that person was ever informed, you are buying their Article 14 exposure along with the emails. Ask for provenance in writing before signing, the same way you would ask who counts as the sender under CAN-SPAM before a US campaign.
What happens when someone objects?
You stop, immediately and permanently, and there is nothing to weigh. Article 21(2) gives the data subject the right to object at any time to processing for direct marketing purposes. Article 21(3) is one sentence: where the data subject objects, “the personal data shall no longer be processed for such purposes.”
This is stronger than the general objection right at Article 21(1), where you can continue if you demonstrate compelling legitimate grounds. For direct marketing there is no balancing exercise and no grounds that override it. The operational requirement follows: suppression has to be global across every sending domain and every inbox in the program, not per sequence and not per mailbox. Most failures here are engineering failures rather than legal ones, and they surface as a second email to a person who already said no, from a different domain you own.
What are the fines, and who actually enforces this?
GDPR’s upper tier is up to 20,000,000 euros or 4% of total worldwide annual turnover, whichever is higher, and it is the tier that covers the articles at issue here: Articles 5, 6, 7 and 9, and Articles 12 to 22. That is the headline. The published reality for outbound data is the KASPR number: 240,000 euros against a company whose entire product was B2B contact data.
| What you got wrong | Which law | Who comes after you |
|---|---|---|
| No valid lawful basis for holding the data, no Article 14 notice, objections ignored | GDPR Articles 6, 14, 21 | The data protection authority, with the Article 83(5) tier available |
| Sent a marketing email into a consent country without consent | National ePrivacy implementation, for example Section 174 TKG in Austria or Article 130 in Italy | The national authority designated for that statute, on national penalty scales, not GDPR’s |
| Sent marketing email into Germany without prior express consent | UWG Section 7(2) no. 2 | The unfair competition system rather than a privacy regulator, because the UWG is a competition statute |
| Concealed the sender identity or supplied no working opt-out address | ePrivacy Article 13(4), in every member state | The national authority, with no B2B exemption available anywhere |
What does a defensible GDPR B2B program look like?
Seven controls, and six of them cost nothing but the decision to run them. The seventh is list hygiene, which costs money and is where most programs fail.
- Segment by recipient country before the first send. Not by company headquarters. A German employee of a French group is in the consent country.
- Exclude Germany, Austria and Italy from cold sequences unless you hold consent or have taken local advice. Those three are not aggressive interpretations of a grey rule. They are the written rule.
- Business addresses and named roles only. The legitimate interest argument runs on relevance of the offer to that person’s job, which is exactly the CNIL test.
- Write the legitimate interests assessment before launch, not after the complaint. Purpose, necessity, balancing, dated, one page per campaign type.
- Put the Article 14 notice in the first email. Who you are, where the data came from, a link to a privacy notice that names your sources, and how to object.
- One-step objection, honoured globally and permanently, across every domain and inbox. Test it by sending yourself an objection from an address on a different sequence.
- Keep provenance per record. Source, date acquired, and whether the source informed the person. Vendors who cannot supply this are the risk you are actually buying.
None of the above helps if the messages never arrive, and the same infrastructure discipline drives both outcomes. Authentication, domain reputation and suppression hygiene are the shared foundation, covered in the SPF, DKIM and DMARC setup and in why cold emails go to spam.
How LeadButton handles this
European campaigns are segmented by recipient country before anything sends, with Germany, Austria and Italy excluded from cold sequences by default rather than by exception. Every record carries its source. The first message in a European sequence carries the Article 14 disclosure and a one-step objection route, and objections suppress across every domain and inbox in the program, permanently.
Launch is $1,500 a month for managed email outreach, Growth is $3,500 a month for email plus LinkedIn, and Scale is custom. Geography changes the shape of a European program more than the price, which is worth raising on the first call rather than after launch. Pricing is on the LeadButton pricing page. We are not lawyers and this is not legal advice. What we can tell you is which of the controls above we run as standard and which stay with you.
Sources
- Directive 2002/58/EC of 12 July 2002 (ePrivacy Directive), Article 13, EUR-Lex, checked 22 September 2026. Source for the Article 13(1) consent rule, the Article 13(2) existing-customer exception, the Article 13(4) prohibition on concealed identity and missing opt-out address, and the Article 13(5) obligation toward subscribers other than natural persons.
- GDPR Recital 47, checked 22 September 2026. Source for the sentence that direct marketing “may be regarded as carried out for a legitimate interest.”
- GDPR Article 14, checked 22 September 2026. Source for the information required when data is not obtained from the data subject and for the one month or first communication deadline at Article 14(3).
- GDPR Article 21, checked 22 September 2026. Source for the unqualified right to object to direct marketing at 21(2) and the obligation to stop at 21(3).
- GDPR Article 83, checked 22 September 2026. Source for the 20,000,000 euro or 4% upper tier and the list of articles it covers.
- CNIL, La prospection commerciale par courrier electronique, SMS-MMS et automate d’appel, page updated 10 June 2026, checked 22 September 2026. Source for the French position that B2B prospecting may rest on legitimate interest where the approach relates to the person’s profession, and for the treatment of generic addresses.
- ICO, Business to business marketing, checked 22 September 2026. Source for the corporate subscriber exemption under PECR, the treatment of sole traders and partnerships as individual subscribers, and the UK GDPR obligations that still apply.
- ICO, How do we apply legitimate interests in practice, checked 22 September 2026. Source for the three-part purpose, necessity and balancing test and the ICO’s position on recording a legitimate interests assessment.
- Act against Unfair Competition (UWG), official English translation, Section 7, as amended by the Act of 6 May 2024, checked 22 September 2026. Source for the German prior express consent requirement for email advertising and the existing-customer exception at Section 7(3).
- Austrian Federal Ministry, Unsolicited messages (SPAM), checked 22 September 2026. Source for Section 174 TKG 2021 applying to the corporate sector and for the existing-customer exception.
- DLA Piper, Data Protection Laws of the World, Italy, electronic marketing, last modified 16 January 2025, checked 22 September 2026. Source for Article 130 of the Italian Privacy Code requiring consent and referring to the contracting party and user rather than the data subject.
- DLA Piper, Data Protection Laws of the World, Ireland, electronic marketing, last modified 17 January 2025, checked 22 September 2026. Source for Irish B2B marketing email being permitted unless the recipient has objected.
- CNIL, Data scraping: KASPR fined 240,000 euros, decision of 5 December 2024, checked 22 September 2026. Source for the fine amount, the database of about 160 million contacts, the Article 6 finding on reasonable expectations, the 5 year retention finding, and the delayed English-only information to individuals.
Leave a Reply