GDPR Cold Email in 2026: What Is Actually Legal to Send
Cold email to EU prospects is legal under GDPR — but only if you get four things right. Here is the legitimate-interest checklist, the country rules that override it, and the fines that prove it matters.

TL;DR
- GDPR cold email is legal in the EU. It was never banned. It is regulated.
- Your lawful basis is almost always legitimate interest (Article 6(1)(f)), not consent. Legitimate interest needs a written balancing test. A gut feeling will not do.
- ePrivacy overrides GDPR on the sending side. Germany and Italy require prior consent for B2B email in practice. France, the Netherlands, and Ireland allow role-based B2B outreach without it.
- Four things decide whether you comply: lawful sourcing, transparency, opt-out, and retention. Most programs fail on sourcing and retention.
- Fines are real. They rarely target the email itself. They target the data pipeline behind it. Scraped personal Gmail addresses are the biggest risk.
Is GDPR cold email legal in the EU?#
Yes, with conditions. The regulation never uses the phrase "cold email." That surprises people. GDPR governs processing of personal data. A work address like firstname.lastname@company.com is personal data, because it points to a real person. Finding it, storing it, enriching it, and mailing it are separate acts. Each one needs a lawful basis.
Article 6 lists six lawful bases. For B2B outbound, only two matter:
- Consent (6(1)(a)) — the prospect agreed first. That is almost never true in cold outreach. If you had consent, the email would not be cold.
- Legitimate interest (6(1)(f)) — you have a real business reason, the email is needed for it, and it does not override the person's rights.
Recital 47 of the GDPR text says it plainly: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." That one sentence is the legal base for every compliant GDPR cold email program in Europe.
So the answer is simple. Cold email is legal, but only if you can show the balancing test on demand.
What is the legitimate interest balancing test?#
Write this three-part check down before you send. It is called an LIA (Legitimate Interests Assessment). Regulators expect to see it. "We assumed it was fine" is not a defence.
- Purpose test — Is there a real business interest you can name? "Selling our procurement software to procurement managers" works. "Building a list to resell" does not.
- Necessity test — Is email a fair way to reach that goal? Could you reach the person without using their data? In B2B, contacting a named role-holder is usually fair.
- Balancing test — Would the reader expect this message? A VP of Sales who gets a pitch about sales tools at work: expected. A nurse who gets crypto offers at a personal Gmail: not expected. You lose that one.
The balancing test turns relevance into a legal asset. Tight targeting is compliance. If a message is clearly irrelevant to the reader's job, that is evidence you failed the expectations test.
| LIA component | What you must document | Common failure |
|---|---|---|
| Purpose | Specific product, specific buyer role, specific business outcome | Vague "lead generation" |
| Necessity | Why email, why this person, why now | Blanket sends to every contact at a domain |
| Balancing | Relevance evidence, data source, risk to individual | No record of where the address came from |
| Safeguards | Opt-out mechanism, retention limit, suppression list | Unsubscribes not honored across tools |
| Review date | When the LIA gets re-checked (annually is standard) | Written once in 2022, never revisited |
Keep the LIA alive. Re-run it when you change your ideal customer, swap data vendors, or open a new country.
Is GDPR the only law that applies?#
No. This is the part most guides get wrong. GDPR governs the data. The ePrivacy Directive governs the message. They stack.
ePrivacy (2002/58/EC) is a directive, not a regulation. Each member state wrote it into its own national law. The result is a patchwork. You can handle data perfectly and still break German law by pressing send.
| Country | B2B cold email without prior consent | Practical note |
|---|---|---|
| Germany (UWG §7) | No — opt-in required in practice | Strictest in the EU; competitor lawsuits are common, not just regulator action |
| Italy | No — consent-based regime | Garante has issued marketing fines repeatedly |
| France (CNIL) | Yes, for business addresses | Message must relate to the recipient's professional role |
| Netherlands | Yes, for legal entities | Opt-out must be in every message |
| Ireland | Yes, for business contacts | Corporate subscribers treated differently from individuals |
| Spain | Yes, with conditions | Must relate to recipient's professional activity |
| UK (post-Brexit, PECR) | Yes for corporate bodies | Sole traders and partnerships treated as individuals — opt-in |
Two things follow. First, split your outbound list by country before you send, not after. Second, if Germany is a big market for you, run an inbound or LinkedIn motion there instead. LinkedIn outreach sits outside the ePrivacy email rules. GDPR still applies to any data you keep about the person.
The UK's ICO guidance on direct marketing is the clearest free reference on the corporate-subscriber rule. Several EU regulators reason the same way.
What makes a GDPR cold email compliant in practice?#
Strip the theory away. Compliance comes down to five things you do. Get them right and you survive an audit.
- Lawful sourcing. Say where every address came from, and show it was obtained fairly. Public corporate addresses, pattern-derived role addresses, and licensed B2B data all pass. Scraped personal addresses and bought consumer lists do not.
- Transparency at first contact. Article 14 says you must tell people you hold their data when they did not hand it to you. One line does most of the work: "I found your details on your company website." Add a privacy policy link.
- A working opt-out in every message. Not a preference center behind a login. Use one-click unsubscribe, or plain words: "reply STOP and I'll remove you." Then honor it in every tool and CRM you own.
- Defined retention. Put a clock on cold prospect records. Twelve to 24 months is a defensible norm. Delete or re-verify at expiry. "We keep everything forever" fails Article 5(1)(e).
- DSAR readiness. If someone asks what you hold on them, you have one month to answer. That is impossible when your data sits in five untracked spreadsheets.
The retention rule is also a data-quality rule. B2B contact data decays by roughly 25–30% a year through job changes alone. A list you built in 2024 and never touched is both non-compliant and mostly bounces.
Running periodic email verification across your database serves both goals at once. It purges dead records, and it creates an audit trail that shows active data hygiene.
How do you build a compliant prospect list?#
Sourcing is where most GDPR cold email programs quietly break the law. The compliance question lands months before the send.
What passes:
- Role-based corporate addresses —
sales@,press@,info@. Lowest risk everywhere. Several national laws do not even treat these as personal data. - Named business addresses at a corporate domain, found from public sources or derived from a company's known email pattern. This is the bread and butter of B2B outbound. It holds up under legitimate interest almost everywhere outside Germany and Italy.
- Licensed B2B databases where the vendor documents its sources and its own lawful basis. Ask for that in writing. If a vendor cannot produce it, that is your answer.
What fails:
- Personal addresses (
@gmail.com,@outlook.com) that belong to individuals. There is no corporate-subscriber shelter here, and the balancing test gets much harder. - Scraped social profile data, harvested at volume with no regard for source terms.
- Lists bought from brokers with no provenance trail. When a regulator asks "where did this come from," "we bought it" is not a source.
This is the real difference between an email-finder tool and a scraped list. A tool like Tomba's email finder works from company domains and known naming patterns, and it publishes where its data comes from. That is exactly the provenance record an LIA needs. A CSV from an anonymous seller gives you volume and nothing else.
For teams working at scale, the domain search approach is safer by design. You pull verified addresses for a company you deliberately chose. Every record then traces back to a targeting decision you can explain.
What do the fines actually look like?#
The GDPR ceiling is €20 million or 4% of global yearly turnover, whichever is higher. That number gets quoted constantly, and on its own it misleads. The top tier is reserved for severe, systemic breaches.
What matters more is what gets fined in marketing:
- Data pipeline breaches, not message content. Enforcement clusters around unlawful list building, missing lawful-basis records, and ignored deletion requests. It rarely lands on one annoying email.
- Ignored opt-outs. Several regulators have fined companies that kept mailing after a removal request. This is the cheapest violation to avoid, and one of the most enforced.
- No transparency. Failing the Article 14 notice shows up again and again in decisions.
For small and mid-sized senders, the real risk looks like this. Someone complains to a national DPA. You get an information request and one month to answer. Then comes an enforcement notice or a modest fine. In Germany, add competitor cease-and-desist letters, which arrive faster than any regulator.
The CNIL's enforcement register is worth a yearly skim. It is public, searchable, and shows the real pattern rather than the headline maximum.
GDPR vs CAN-SPAM vs CASL: how do the regimes compare?#
If you sell across regions, you run three rulebooks at once. Build to the strictest one and you are covered everywhere.
| Dimension | GDPR + ePrivacy (EU) | CAN-SPAM (US) | CASL (Canada) |
|---|---|---|---|
| Default model | Opt-in for data use; country-dependent for B2B email | Opt-out | Opt-in (express or implied) |
| B2B carve-out | Varies by member state | No distinction | Limited — implied consent via published business address |
| Lawful basis required | Yes — documented | No | Yes — consent, must be provable |
| Opt-out deadline | Without undue delay | 10 business days | Immediate-ish; 10 days max |
| Transparency notice | Required (Art. 13/14) | Physical address required | Sender ID required |
| Max penalty | €20M / 4% turnover | ~$53k per email | CAD $10M per violation |
| Retention limits | Yes — purpose-limited | None | None specified |
CASL is arguably stricter than GDPR for cold email. Canada has no legitimate-interest equivalent. A published business address can create implied consent. That only holds when the message fits the reader's role, and when the address carried no "no unsolicited email" notice.
The practical build: one standard, applied everywhere. Document your basis. Name your source in the first message. Honor opt-outs at once. Cap retention at 24 months. That clears GDPR, passes CAN-SPAM easily, and gets you most of the way to CASL.
What does a compliant cold email look like?#
Here is a first-touch message that meets Article 14, ePrivacy, and basic deliverability hygiene:
Subject: Question about [specific process] at [Company]
Hi [Name],
I saw on [Company]'s careers page that you're hiring three SDRs this quarter. We help teams in that position cut ramp time — [one-line specific claim].
Worth a 15-minute look, or should I close the loop?
[Name], [Title], [Company]
[Physical business address]
I found your contact details via your company website. Our privacy policy explains how we handle data: [link]. Reply "remove" and I'll delete your details immediately.
The footer does three legal jobs in three lines: source disclosure, transparency link, and opt-out. It costs you nothing in replies. It is the difference between a defensible program and an indefensible one.
One caveat on the send itself. Compliance and deliverability are separate problems. A lawful email still lands in spam when your authentication is broken. Check your SPF record before you worry about the regulator.
What should you do this week?#
A short, ordered checklist:
- Audit your list by source. Delete any record you cannot trace. Not archive — delete.
- Split by country. Move German and Italian contacts to another channel until you have consent.
- Write the LIA. One page: purpose, necessity, balance, safeguards, review date. Store it where legal can find it.
- Add the three-line footer to every cold sequence template.
- Wire opt-outs to one suppression list that every tool reads. Manual removal across four tools will fail sooner or later.
- Set a retention job. Anything untouched for 24 months gets purged or re-verified.
None of this slows a well-targeted GDPR cold email program. It slows spray-and-pray, which is the point. The rules make irrelevant mass mailing expensive and relevant outreach cheap.
Where does tooling fit?#
The heaviest burden is data provenance — proving where each address came from. That is a tooling choice, not a policy choice.
Build EU lists from a source that finds addresses from company domains and public patterns, and that documents its method. Tomba's Email Finder does that. You give it the company and the person. It returns the verified business address with a confidence score and source signals.
That is a record you can point at during an audit. It starts free at 25 searches per month, and paid plans start at $49/mo; full Tomba pricing is public. Pair it with the verifier to keep retention windows clean. Your legitimate-interest file then stops being a liability and becomes a document you are happy to hand over.
This article is general information, not legal advice. Consult qualified counsel in each jurisdiction where you send.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author