Cold email in Italy: the address decides the rule, not the industry
A sole trader with a partita IVA individuale gets the same consent protection as a private person. The soft opt-in exists for existing customers, not for a first-touch list.
Italy sits in the same bracket as Germany on the site's own market map: a consent-based email market, not an opt-out one. The mechanism is different, though. Germany's risk is a competitor's lawyer. Italy's risk is the address itself: a named sole trader gets the same protection as a private individual, and the exception senders reach for first is narrower than it looks.
Founders who have already built an opt-out programme in France or the Netherlands sometimes carry that muscle memory into Italy and assume a business address is fair game with an unsubscribe link. It is not. Article 130 of the Codice Privacy asks for consent first, and the regulator that enforces it, the Garante, has been active.
This note is a working summary from a Vilnius consultancy, dated 26 September 2026. It is not legal advice, and if you plan to send at volume into Italy you should have an Italian lawyer read your setup once.
The rule: Article 130 of the Codice Privacy
Legislative Decree 196/2003, the Codice Privacy, was amended by Legislative Decree 101/2018 to align with the GDPR. Article 130 is the provision that governs electronic marketing, including email. Paragraphs 1 and 2 require prior, opt-in consent before you send a promotional message. There is no business-to-business carve-out in the text, and the Garante has not read one into it.
What changes the calculation is who sits behind the address.
| Address type | Consent standard applied |
|---|---|
| Named individual at a company (nome.cognome@azienda.it) | Same as a private person: prior consent required |
| Sole trader or professional, individual VAT number | Treated as a natural person: prior consent required |
| Generic corporate address (info@societa.it) at an SRL or SPA | More flexible in practice, opt-out must still be immediate and clear |
The middle row is the one that catches non-Italian senders. A freelance consultant or an artisan with a partita IVA individuale looks like a business contact on a list, and the Garante's sanctioning practice treats them as a private individual for exactly this reason.
The exception, and why it rarely applies to cold outreach
Article 130(4) contains a soft opt-in, and it is stricter than the version most outbound teams have in mind from other markets. Three conditions have to hold at once: you obtained the address from that same person in the course of an actual, completed sale, not a demo request or a newsletter sign-up; the new message advertises a product or service similar to the one already sold; and you told them at the time that they could object, and repeat that option in every later message.
The practical test: did this person already buy something from you, and are you writing about something like it? If the honest answer is "we found them on a register" or "they downloaded a guide," the soft opt-in does not apply, whatever the CRM field says.
That rules out the exception for a first-touch cold campaign into a new market by definition. It exists to let you re-sell to existing customers without asking twice. A prospecting list built from a register or a downloaded whitepaper sits outside it entirely.
So what actually works in Italy
The consent requirement closes email as a cold first-touch channel. It does not close the market.
LinkedIn. Connection requests and messages sit outside Article 130, which addresses electronic communications by email, fax, MMS and SMS. Italian professionals, especially in Milan and the industrial north, are active on the platform, and a conversational first message builds the relationship that later makes an email welcome rather than cold.
Telephone, with its own register to check. A cold call to a business number is not barred by Article 130 the way a cold email is. It runs instead through the Registro Pubblico delle Opposizioni, a separate opt-out list of phone numbers and postal addresses for telemarketing, extended in 2022 to cover mobile numbers and company switchboards as well as landlines. Check the number against the register before a calling campaign; the channel is open, the number might not be.
Content that earns the address. A benchmark, a market note, a tool. The prospect opts in, you have a provable consent record, and the follow-up email programme runs lawfully from that first exchange.
Trade fairs and associations. Italy's business culture runs on regional trade fairs, sector associations and personal introduction more than most of northern Europe. An address collected at a stand, with a stated marketing purpose at the point of collection, carries its own consent record.
Partners and distributors. For many categories a local partner shortens the trust problem and the language problem in the same move, the same logic the site applies to Germany.
Where senders think they have found a loophole
Three arguments come up, and the Garante has closed all three.
"We will pull addresses from INI-PEC, the national certified email register for companies and professionals." INI-PEC exists so that businesses can exchange documents with public administration. The Garante's position against using it for promotional email traces back to a 2003 decision and has been repeated as recently as 2024. The register's purpose does not extend to marketing.
"We only email the generic info@ address, so it is not personal data." Closer to correct than in Germany, but the opt-out still has to be immediate and clear, and if the reply comes back from a named person at the company, that person's later emails are personal data again.
"Our first email just asks if we can send more information." The Garante does not allow a promotional message to double as the consent request. Asking permission inside a pitch does not convert the pitch into something else.
Italy in a multi-country programme
Group Italy with the other consent-based markets at the segmentation stage, the same way the site treats Germany, Spain, Poland and the Baltics: LinkedIn and phone carry the first touch, checked against the RPO where a call is involved, and email opens once a real exchange has produced consent.
One forward note worth planning around now rather than in October: the Garante has confirmed that an open-tracking pixel inside a marketing email counts as a cookie for consent purposes, with an implementation deadline of 29 October 2026. A programme that already treats Italy as consent-first absorbs this easily. A programme still running Italy as a volume-email market will need to change its tracking setup and its list at the same time.
The cost of getting it right
A programme built on LinkedIn, checked phone numbers and opt-in content costs more per meeting in month one than an email programme into the Netherlands. It also produces a list you can defend if the Garante ever asks, and it does not put a sole trader's cease-and-desist letter, or a regulatory inquiry, in front of you in month three.
Ripe Leads segments outbound by country law
Ripe Leads is KoFi Tech's outbound arm. Italy, Germany and the other consent-based markets run on research, phone and LinkedIn; the opt-out markets run on email. The plan states which channel carries the first touch in each country before anything is sent.
See how Ripe Leads works