Cold email and the GDPR: what a B2B sender in Europe can actually do
The GDPR is not the rule that stops your campaign. The ePrivacy Directive is, and it was written into 27 national laws that disagree with each other. Germany and France sit at opposite ends.
Written for operators planning campaigns, not as legal advice. The national rules below move, and the fines are large enough that one hour with a lawyer in your target market pays for itself. Positions described here are as at September 2026.
Ask ten European B2B teams whether cold email is legal and you get ten answers, most of them about the GDPR. The GDPR is the smaller half of the problem. The rule that decides whether you may send an unsolicited commercial email lives in the 2002 ePrivacy Directive, which each member state wrote into its own law, and those national laws disagree with each other. Germany and France, two markets you might reasonably enter in the same quarter, sit at opposite ends of the range.
The Commission dropped the proposed ePrivacy Regulation that was supposed to harmonise this, so the Directive and its 27 transpositions remain what you have to work with. Plan per country.
What the GDPR actually asks of you
A work address of the form firstname.lastname@company.com identifies a person, so it is personal data and the GDPR applies. That does not mean you need consent. Consent is one of six lawful bases, and for B2B prospecting the relevant one is legitimate interest under Article 6(1)(f). Recital 47 says in plain words that processing for direct marketing purposes may be carried out for a legitimate interest.
Relying on it comes with obligations that most senders skip.
- Write the balancing test down. A legitimate interest assessment records your purpose, why the processing is necessary for it, and why your interest is not overridden by the person's rights. One page, dated, kept on file. A supervisory authority that asks and receives nothing treats the basis as unclaimed.
- Tell people where you got their data. Article 14 applies whenever you did not collect the data from the person. The notice is due within a month, or at the first communication if that comes sooner. A line in the email footer pointing to a privacy page that names your sources satisfies it.
- Honour objections immediately. Article 21(2) gives an absolute right to object to direct marketing. No balancing, no exceptions. In practice that means a working unsubscribe and a suppression list that survives your next tool migration.
- Keep the targeting defensible. The narrower and more relevant your list, the easier the balancing test. Emailing a procurement lead about a category they buy is a different proposition from emailing 30,000 addresses scraped from a conference site.
The rule that varies: ePrivacy, country by country
Article 13(1) of the Directive requires prior consent for unsolicited marketing email to natural persons. Article 13(5) leaves the protection of legal persons to member states, and that single sentence produced the divergence. Broadly, states fall into two camps.
| Market | Position | Practical effect |
|---|---|---|
| Germany | Prior express consent, business included (UWG §7) | Cold email is unlawful without consent. Competitors can send a warning letter and claim costs. |
| Italy, Spain | Consent-based, with a narrow existing-customer exception | Treat cold email as closed. Use other channels. |
| Poland | Consent under the Electronic Communications Law in force since November 2024 | Tightened from the previous regime. Assume consent is required. |
| Lithuania, Latvia, Estonia | Consent for subscribers, soft opt-in for existing customers | Prospecting into a cold list is not available. Warm bases are. |
| France | Opt-out for professional addresses, per CNIL guidance | Permitted when the message relates to the person's job and the opt-out works. |
| Netherlands, Ireland | Opt-out for corporate subscribers | Cold B2B email is workable with correct identification and a live unsubscribe. |
| United Kingdom | Outside the EU. PECR: opt-out for corporate subscribers | Workable, and sole traders and partnerships count as individuals. |
Two consequences follow for anyone running one campaign across Europe. First, the segment you send to has to be built by country, because a single list that includes German recipients carries German exposure for every one of them. Second, the country with the strictest rule is not the country to start in, whatever its market size. Plenty of teams have launched in Germany on principle and spent the first quarter answering an Abmahnung instead of booking meetings.
What a defensible European campaign looks like
The compliant version costs a little more to set up and looks almost identical to the reckless version from the recipient's side. That is the point.
- Segment the list by country before anything else, and route consent-required markets to LinkedIn, phone, events or paid channels instead of email.
- Send from a real, identifiable business. Legal name, company number and postal address in the footer. Anonymous senders lose the legitimate interest argument on sight.
- Target on a business reason you can state. The relevance that makes the email work commercially is the same relevance that makes the balancing test pass.
- Give one honest exit. A plain unsubscribe line beats a tracked button. Log every opt-out centrally, and check new lists against that log before each send.
- Publish the sources. A short privacy page naming your data sources covers Article 14 and answers the question a suspicious prospect will ask.
- Keep the file. The assessment, the source records, the suppression log. If a complaint arrives eighteen months later, this is the whole of your defence.
The commercial argument for doing it properly
Compliance work has a reputation as a tax on growth. In outbound it behaves more like a filter that improves the numbers. Every requirement above pushes you toward a smaller list, a clearer reason for contact, and a sender the recipient can verify. Those are the same three things that lift reply rates.
The teams that get into trouble in Europe are rarely the ones sending 300 well-aimed emails a week. They are the ones sending 30,000 badly aimed ones, which is also the pattern that produces no meetings.
Outbound built for European rules from day one
Ripe Leads is KoFi Tech's outbound arm, run from an EU entity for clients selling into Europe. Country segmentation, identified senders, suppression handling and per-market channel choice are part of the build, not a retrofit after the first complaint.
Visit Ripe Leads