GDPR Cold Email B2B: What's Legal and What Isn't in 2026
Cold email to EU businesses is legal under GDPR — but only if you get four things right. Here's the legal basis, the country-by-country rules, and the workflow that keeps you compliant.

TL;DR
- GDPR cold email B2B outreach is legal in the EU. It is not banned, and no regulator has ever said it is. It just needs a lawful basis and a few disclosures most senders skip.
- Your lawful basis is almost always legitimate interest (Article 6(1)(f)), not consent. But you must write a Legitimate Interest Assessment before you send, not after a complaint lands.
- GDPR is only half the rulebook. The ePrivacy Directive and its national versions decide whether you need prior consent. The answer changes by country: Germany and Italy are strict, while the UK, Ireland, and France are permissive for corporate addresses.
- Role accounts (info@, sales@) get lighter treatment than named addresses (firstname.lastname@) in several member states. That split should drive how you build lists.
- Practical compliance = verified data, documented sourcing, a real opt-out, a privacy notice link, and a suppression list you actually honour.
Cold email into Europe is a topic where the loudest advice is the most wrong. You will hear "GDPR killed cold email" from people who never read Recital 47. You will also hear "just use legitimate interest" from people who have never written a Legitimate Interest Assessment. Both answers cost you something. One costs you a market. The other costs you a fine.
This guide covers what actually applies to GDPR cold email B2B outreach in 2026. Which law governs what. How the country rules differ. What a compliant email looks like, line by line. And how to build a prospecting workflow that survives a data subject access request.
Is GDPR cold email B2B outreach legal at all?#
Yes, and the regulation says so directly. Recital 47 of the GDPR states: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." That is the EU legislature naming direct marketing as a legitimate interest use case.
What GDPR does not do is give you a free pass. Legitimate interest is a conditional basis, not an automatic one. You have to pass a three-part test, and you have to show your work:
- Purpose test — Is there a genuine business interest? Selling a product that plausibly helps the recipient's company qualifies. Blasting 40,000 scraped addresses with no regard for role does not.
- Necessity test — Do you need this personal data to achieve that purpose? Emailing a VP of Engineering about a developer tool: necessary. Adding their home address and personal mobile: not necessary, and now you have a problem.
- Balancing test — Do your interests override the person's rights and reasonable expectations? A work address, a role-relevant B2B offer, and a one-click opt-out usually pass. The same message to a personal Gmail does not.
The output of that reasoning is a Legitimate Interest Assessment (LIA). It is a document, and two pages is enough. The ICO's guidance on legitimate interests is the clearest free template available, and UK guidance maps closely enough to EU practice to be useful either way.
Write it once per campaign type, date it, and store it. If a regulator asks and you have nothing, "we thought it was fine" is not a defence.
What's the difference between GDPR and ePrivacy for cold email?#
This is the most common mistake in B2B outreach compliance. GDPR governs whether you may process the personal data. ePrivacy governs whether you may send the message. You need to clear both gates.
| Dimension | GDPR | ePrivacy Directive (2002/58/EC) |
|---|---|---|
| What it regulates | Processing of personal data | Electronic communications, including unsolicited email |
| Scope | EU-wide regulation, directly applicable | Directive — each country writes its own version |
| Your key requirement | Lawful basis + transparency + data subject rights | Consent or a recognised B2B exemption |
| Applies to role accounts? | Only if the address identifies a person | Varies by country; often exempt |
| Typical maximum fine | €20M or 4% of global turnover | Set nationally (e.g. up to £500K in the UK under PECR) |
| Governs opt-out obligation | Yes (right to object, Art. 21) | Yes (every message must carry an unsubscribe) |
Because ePrivacy is a directive, not a regulation, there is no single European answer. Germany implemented it strictly. Under the UWG, unsolicited commercial email generally needs prior consent, even when the recipient is a business.
The UK took the other road. PECR applies the consent rule to "individual subscribers," which the ICO reads as excluding corporate bodies. So cold email to a limited company is allowed, as long as it carries a valid opt-out. Same email, two different legal outcomes.
The long-promised ePrivacy Regulation would have harmonised this. The European Commission formally withdrew it in 2025. So the patchwork is the steady state. Plan for it instead of waiting for a fix.
Which EU countries allow B2B cold email without consent?#
Here's the practical map. Treat it as a planning tool, and confirm with counsel before you launch a country campaign. National case law shifts.
| Country | B2B cold email without prior consent? | Notes |
|---|---|---|
| United Kingdom | Yes, to corporate subscribers | PECR exempts corporate bodies; opt-out still mandatory |
| Ireland | Yes, to corporate bodies | Similar carve-out to the UK |
| France | Yes, if the offer relates to the recipient's job | CNIL explicitly permits B2B outreach on a professional address |
| Netherlands | Yes, for business addresses | Opt-out and sender identification required |
| Spain | Generally yes, role-relevant | LSSI requires clear identification and opt-out |
| Germany | No — prior consent generally required | UWG §7; strictest major market, enforced via competitor suits |
| Italy | No — consent-first in practice | Garante has fined senders relying on legitimate interest alone |
| Belgium | Restricted | Consent expected for named individual addresses |
Two operational takeaways. First, segment your outbound by jurisdiction. A single global sequence that hits Munich and Manchester on identical terms is a liability.
Second, role accounts are your safest entry point in strict markets. An address like procurement@company.de is arguably not personal data at all under GDPR, because it does not identify a natural person. That does not make it exempt from ePrivacy in Germany, but it removes one layer of risk. A domain search that returns both role and named addresses lets you make that call on purpose instead of by accident.
What makes a GDPR cold email B2B message compliant in practice?#
Compliance in the inbox comes down to six things the reader can check in your message. Miss any of them and you look like a spammer, whatever your paperwork says.
- Identify yourself completely. Legal entity name, physical business address, and a working reply-to. Not "The Growth Team." A registered address is required under both ePrivacy implementations and most national e-commerce laws.
- Explain how you got their details. One clause is enough: "I found your details on your company's website." Article 14 says you must tell people when you collected their data indirectly. Doing it inline works far better than burying it in a privacy notice.
- Link to a privacy notice. It must cover what data you hold, your lawful basis, how long you keep it, and how people exercise their rights. A live URL in the footer does the job.
- Make the relevance obvious. Legitimate interest depends on the reader reasonably expecting contact. If your message does not connect to their actual role, your balancing test fails. So does your response rate.
- Offer a genuine opt-out. A one-click link works. So does a plain "reply STOP and I'll remove you." What does not work: an opt-out that needs an account, or one that only stops a single campaign.
- Honour objections instantly and permanently. Article 21 gives an absolute right to object to direct marketing. There is no balancing test at that point. Suppress the address across every sequence, every domain, forever.
The failure that actually generates complaints is almost never the legal basis. It is the fourth follow-up sent to someone who already asked to be removed.
How does data quality affect your GDPR exposure?#
More than most teams realise. GDPR Article 5(1)(d) says personal data must be "accurate and, where necessary, kept up to date." A list that is 30% stale is not just a deliverability problem. It is a documented breach of the accuracy principle sitting in your CRM.
Bad data creates three risks that compound:
- Wrong-person delivery. A guessed permutation can land on a real but incorrect human. That is an unlawful disclosure of your marketing intent to someone who never entered your funnel.
- Bounce-driven reputation damage. High hard-bounce rates wreck your sender reputation. Legitimate mail then lands in spam, and teams reach for workarounds that make compliance worse.
- Retention drift. Records you cannot verify are records you cannot justify keeping. Storage limitation (Article 5(1)(e)) means expired, unverifiable contacts should be deleted, not archived "just in case."
The fix is procedural, not heroic. Verify before you send. Re-verify anything older than 90 days. Log the source and the date for every record.
Running addresses through an email verifier before a sequence goes out protects deliverability and gives you an accuracy audit trail. For domains that accept everything, a catch-all verifier is the difference between a defensible list and a guess.
What are the real penalties for GDPR cold email B2B mistakes?#
The headline number — €20 million or 4% of global annual turnover, whichever is higher — is real. It is also rarely the operative risk for a mid-market outbound team. What actually happens is more mundane and far more frequent:
| Consequence | Likelihood for a typical B2B sender | Trigger |
|---|---|---|
| Recipient complaint to a DPA | Moderate | Ignored opt-out, or no privacy notice |
| Data subject access request (DSAR) | Moderate | Recipient asks "where did you get this?" |
| National DPA warning or reprimand | Low-moderate | Pattern of complaints, no LIA on file |
| Competitor cease-and-desist (Germany) | Real in DE | UWG allows competitors to sue directly |
| Administrative fine | Low, but rising | Systematic scraping, no lawful basis, scale |
| Blocklisting / domain damage | High | Bad data and complaint-driven spam reports |
Note the second row. The DSAR is the underrated one. Any recipient can ask what data you hold, where it came from, and what your lawful basis is. You have one month to answer.
Teams that cannot produce a source field per contact end up scrambling, and the scramble itself usually exposes the gap. This is why sourcing transparency matters day to day. Knowing where your provider gets its data is what lets you answer a DSAR in ten minutes instead of ten days.
Germany deserves a specific flag. Under the UWG, your competitors can send a cease-and-desist over unsolicited commercial email and recover their costs. No regulator has to be involved. It is faster and more common than a DPA fine.
How do GDPR-compliant lead sources compare?#
Not all list-building methods carry the same risk. The method decides whether you can answer "where did this come from?" at all.
| Sourcing method | Traceable source? | GDPR risk | Data accuracy | Best for |
|---|---|---|---|---|
| Verified email finder (e.g. Tomba, from $49/mo) | Yes — per-record source + confidence | Low | High when verified | Targeted, documented outbound |
| Curated B2B database (e.g. BookYourData) | Yes — vendor-documented | Low | High | Volume with a paper trail |
| Manual research from company sites | Yes, if you log it | Low | Variable | Small ABM lists |
| Bulk scraped lists from marketplaces | No | High | Low | Nothing — avoid |
| Purchased lists with no provenance | No | Very high | Low | Nothing — avoid |
| Opt-in inbound signups | Consent on file | Lowest | High | Nurture, not cold |
The dividing line is provenance, not price. A tool that returns an address, the page it was found on, and a confidence score gives you an Article 14 answer built in.
A CSV bought from a marketplace gives you nothing to say when a recipient asks. And "we bought it" is the answer regulators treat least sympathetically. G2's data provider category is a reasonable place to check whether a vendor documents its sources in public.
If you send at volume, run sourcing and verification as one step. A bulk email finder that verifies inline means every record enters your CRM with a status and a timestamp already attached. That is exactly the evidence an accuracy audit needs.
What should your compliant outbound workflow look like?#
Six steps, run in this order, every campaign:
- Write the LIA first. Define the audience, the offer, why it is relevant to that role, and what you are not collecting. Two pages, dated, versioned.
- Segment by jurisdiction. Put DE, IT, and BE on a consent-first or role-account-only track. Everything else can run on legitimate interest with a strong opt-out.
- Source with provenance. Every record gets a source, a discovery date, and a confidence score. No exceptions, and no manual CSV merges that lose the metadata.
- Verify before sending. Drop invalids, flag catch-alls, and re-verify anything older than 90 days.
- Send with all six disclosures. Identity, address, source explanation, privacy link, relevance, opt-out.
- Suppress globally and permanently. One suppression list across all sending domains and all tools. Test it quarterly by opting out of your own sequence.
That last test catches more real problems than any policy document. Most teams find out their suppression list only works per tool, not per company. That is exactly how someone who unsubscribed in March gets a new sequence in July from a different sending domain.
Do GDPR cold email B2B rules apply if you're outside the EU?#
Yes, if you target people in the EU. Article 3(2) extends GDPR to organisations offering goods or services to people in the Union, wherever the sender sits. A US company emailing a prospect in Amsterdam is in scope. The European Commission's own guidance on data protection rules is explicit on this.
That means three things for non-EU senders. First, you may need an EU representative under Article 27 if you process EU personal data regularly and have no establishment in the Union.
Second, your privacy notice must be easy to reach and easy to read. A US-centric CCPA notice does not cover Article 13 and 14 requirements.
Third, your transfer mechanism matters. If EU contact data lands in US-hosted systems, you need Standard Contractual Clauses or Data Privacy Framework cover in place with your processors.
None of this is a reason to skip Europe. It is a reason to set up once, properly, and then send with confidence for years.
The GDPR cold email B2B checklist worth printing#
- Legitimate Interest Assessment written and dated per campaign type
- Country segmentation applied (DE/IT/BE handled separately)
- Every record carries source + date + confidence
- List verified within the last 90 days
- Privacy notice live, covering basis, retention, and rights
- Source disclosure line in the email body
- Full legal entity name and registered address in the footer
- One-click opt-out that works on the first click
- Global suppression list tested this quarter
- DSAR response process documented, owner named
Ten lines. Tick all ten and you are in better shape than most outbound teams sending into Europe right now. The same discipline tends to lift reply rates, because relevance and accuracy are compliance requirements and performance levers.
Where to start#
Compliant European outbound starts with data you can account for. Guessed addresses and anonymous CSVs fail the accuracy principle, fail your DSAR response, and fail the first regulator question that matters.
So start at the source. Run your next list through the email verifier, keep a source and a date on every record, and your GDPR cold email B2B program stays defensible on the day someone asks.
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author