GDPR Consent Email Marketing: What Is Legal in 2026

GDPR does not ban cold email. It decides which list you may send to, on what legal basis, and what you must prove later. Here is how GDPR consent email marketing works in practice for B2B outreach in 2026.

Aug 23, 2026 10 min read 2,290 words
GDPR Consent Email Marketing: What Is Legal in 2026

TL;DR — what GDPR consent email marketing really asks of you:

  • GDPR does not ban cold B2B email. It bans the use of personal data with no legal basis. You also have to prove which basis you picked.
  • Consent is one of six legal bases. For most B2B outreach in Europe, legitimate interest is the workable one. But you must write a balancing test, target by job role, and honour opt-outs at once.
  • The ePrivacy Directive and national laws sit on top of GDPR. Germany's UWG, France's CNIL guidance and the UK's PECR each change the answer. Germany is strict. The UK gives corporate subscribers a pass.
  • Your sending list is the proof. Where the data came from, when you got it, and whether it is still correct matter more than your copy.
  • Fines for plain cold email are rare and small. The costly failures are data failures: scraped lists, no notice, no way to delete.

This is an operational guide, not legal advice. If you send at scale into the EU, have a lawyer review your process.

Less than most people think.

GDPR is a data law, not a marketing law. A work email such as firstname.lastname@company.com is personal data. It points to a real person. So you need one of six legal bases from Article 6. Consent is the first. Legitimate interest is the sixth. In law they are equal. Consent is not "more compliant."

The word "marketing" shows up mostly in Article 21. That article gives people an absolute right to object to direct marketing. It also shows up in Recital 47, the line every sales team quotes: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."

Think of GDPR as the building code. ePrivacy is the fire marshal. GDPR says the structure must be sound. You need a basis, a purpose, a time limit and an opt-out. ePrivacy says what you may push into an inbox. Most bad advice about GDPR consent email marketing mashes the two into one made-up rule.

Read two sources once, in full: the official GDPR text and the UK ICO's direct marketing guidance. The ICO page is the clearest plain guide any regulator has put out.

Does GDPR ban cold B2B email?#

No. Three other things kill cold email in Europe.

  1. A list you cannot explain. Say you bought 200,000 records. You cannot say where each one came from. You have failed Articles 5, 13 and 14 before you press send.

  2. A national rule you ignored. Germany treats unwanted business email as unfair competition under the UWG. Prior consent is usually needed, even between firms. That is not a GDPR point at all. It is a competition-law point, and rivals can sue.

  3. No working opt-out. Under Article 21(3) an objection to direct marketing is absolute. No balancing. No grace period. No "we will get to it in 30 days."

Inside those limits, the GDPR consent email marketing rules still leave room to work. A short note to a named person, about something tied to their job, holds up across most of the EU. Spraying 100,000 scraped addresses with a generic pitch does not.

GDPR consent email marketing: a verified B2B list versus a bought contact list
GDPR consent email marketing: a verified B2B list versus a bought contact list

Pick one basis per activity. Stick to it. Switching after someone complains is a red flag to any regulator.

Dimension Consent (Art. 6(1)(a)) Legitimate interest (Art. 6(1)(f))
Best for Newsletters, gated content, webinar follow-up, B2C Cold B2B prospecting to named roles
What you must hold A timestamped, unbundled opt-in record A written Legitimate Interests Assessment (LIA)
Can it be withdrawn? Yes, and withdrawal must be as easy as giving it Not withdrawn — but objection under Art. 21 is absolute
Pre-ticked boxes Never valid N/A
Transparency duty Article 13 notice at collection Article 14 notice within one month, or at first contact
Typical failure mode Consent bundled into T&Cs, no audit trail No LIA on file, irrelevant targeting, no suppression list
Works in Germany for cold email? Yes Generally no — UWG requires prior consent
Works in the UK for corporate subscribers? Yes Yes (PECR exempts corporate subscribers from the opt-in rule)
Effort to maintain Medium: forms, double opt-in, consent logs Medium: LIA reviews, suppression hygiene, data provenance

The short read. If you run content marketing, use consent and build the list well. If you run outbound sales, use legitimate interest. Write the assessment. Keep your targeting tight enough that the assessment is true.

Diagram: GDPR consent email marketing — consent or legitimate interest
Diagram: GDPR consent email marketing — consent or legitimate interest

Article 4(11) says consent must be freely given, specific, informed and clear. It has to come from a real, active choice. Five things decide whether yours holds up.

  1. Unbundled. Marketing consent cannot be the price of a whitepaper, a trial or a set of terms. If the person had no real choice, the consent is void.

  2. Granular. "I agree to receive communications" is too broad. Split email, SMS, phone and sharing with third parties. Split product updates from sales mail if you treat them differently.

  3. Affirmative. An empty box the user ticks. Not a pre-ticked box. Not silence. Not "by continuing you agree."

  4. Recorded. Store who said yes, when, from which form, with what wording, and from which IP. If you cannot show the exact screen a person saw in 2024, you cannot prove consent in 2026.

  5. Revocable. Opting out must be as easy as opting in. Use one-click unsubscribe that reaches every sending tool you own. Not a preference centre buried behind a login.

Double opt-in is not in the text of GDPR. It is still the cheapest proof you can buy, and German courts treat it as the norm. It also lifts list quality. That is why GDPR consent email marketing advice and deliverability advice rarely clash here.

Diagram: What makes consent valid under GDPR
Diagram: What makes consent valid under GDPR

Most GDPR checklists skip this part. It is where the real risk sits. The ePrivacy Directive is a directive, not a regulation. Each member state wrote its own version.

Country Cold B2B email to a work address Notes
Germany Prior consent generally required UWG §7; competitors can sue, not just regulators
France Permitted under a soft B2B rule CNIL: message must relate to the person's job function; opt-out required
United Kingdom Permitted to corporate subscribers PECR exempts limited companies; sole traders and partnerships are treated as individuals
Netherlands Permitted with opt-out Telecommunications Act allows B2B with clear objection route
Ireland Permitted with conditions Opt-out plus identification of sender required
Spain Permitted where a prior relationship or job relevance exists LSSI-CE adds its own information duties
Italy Restrictive in practice Garante has taken a consent-leaning line on unsolicited marketing

Two things follow. First, split your outbound list by country. Apply the strictest rule in each segment. Do not run one global policy and hope. Second, if Germany is a core market, build a consent-led motion there. Events, content, referrals and inbound all work. Legitimate interest does not travel.

The European Data Protection Board collects guidance and national rulings at edpb.europa.eu. Check it before you enter a new market.

Diagram: GDPR consent email marketing rules country by country
Diagram: GDPR consent email marketing rules country by country

What does a compliant B2B outreach workflow look like?#

Here is the order that survives a complaint or an access request.

  1. Define the audience by role, not by volume. "Heads of RevOps at 50–500 employee SaaS firms in France and the Netherlands" works. "Everyone in our database" does not. A narrow list makes the balancing test easy.

  2. Source data you can trace. For any record, you should be able to say where it came from. Public professional sources, your own site, and pattern-based lookup from a company domain are all easy to explain. Bulk buys from unnamed sellers are not. Tomba publishes its data sources for that reason.

  3. Write the Legitimate Interests Assessment first. Three parts: why you contact this segment, why email is a fair way to do it, and why a working professional would not be shocked. Two pages. Date it. Review it once a year.

  4. Verify before sending. Bounces are not just a delivery problem. Dead or role-based addresses bloat your data and mark the list as stale. Run addresses through an email verifier and drop the unknowns.

  5. Add the Article 14 line at first contact. One sentence plus a link. Who you are, where the data came from, what you will do with it, and how to object. It costs you no reply rate. It also removes the top complaint trigger in GDPR consent email marketing.

  6. Suppress at once, and for good. An objection goes into one global suppression list that every tool reads: sequencer, CRM, ad platform. Keep that record forever. It is the one thing you are meant to hold on to.

Escalating from bought lists to compliant, verified prospecting
Escalating from bought lists to compliant, verified prospecting

Diagram: What does a compliant B2B outreach workflow look like
Diagram: What does a compliant B2B outreach workflow look like

What are the penalties, and who actually gets fined?#

The headline number is real: up to €20 million or 4% of global yearly turnover. It is almost never used on a cold-email case. The record shows a clear pattern.

  • Fines on B2B senders for unwanted email land in the four- to six-figure range. They usually follow a complaint nobody answered.

  • The big fines cluster around data sourcing and openness: building profiles with no notice, scraping at scale, ignoring access or deletion requests, and refusing to name a source.

  • Germany adds a second risk. Under the UWG, rivals and trade bodies can send cease-and-desist letters and bill you for them. That is faster and more annoying than a regulator.

The lesson is dull. Your GDPR consent email marketing risk comes from how you built the list, not from the fact that you sent mail. Five people sending 200 well-aimed, well-logged emails a day are far safer than a team blasting 20,000 records of unknown origin.

There is a business cost too, and it arrives first. Bad lists bounce. Bounces hurt sender reputation. A damaged domain loses the inbox placement your whole pipeline rests on. Compliance and deliverability point the same way.

How do you keep your data accurate over time?#

Article 5(1)(d) says personal data must be accurate and, where needed, kept up to date. B2B contact data rots at about 25–30% a year as people move jobs. A list you built in January is badly wrong by December.

Three habits cover it.

  • Re-verify on a schedule. Quarterly for active segments. Before any big send for quiet ones. Treat "unknown" and catch-all results as their own bucket.

  • Enrich rather than re-buy. Updating records you already hold, with a named source, beats stacking a second unexplained database on top. Contact enrichment that returns a source field is worth more than one that returns a bare string.

  • Set a retention limit and keep to it. Pick a period. Twenty-four months with no engagement is a common default. Write it into your privacy notice and delete on time. Regulators read these policies, and they notice when nothing is ever deleted.

Check your vendors too. Under Article 28 your data provider is a processor or a joint controller. Either way you need a DPA. Ask three questions before you sign. Where does the data come from? Do you honour deletion requests passed on from my customers? Can you show the source of a single record on request? A vendor who cannot answer is a risk you are renting. Review sites like G2 help you shortlist. The DPA and the source answer decide it.

Frequently asked questions#

Is a role-based address like info@company.com personal data? Usually not, if it names no one. That makes generic addresses lower risk. They also convert far worse. Do not build your whole plan on them.

Does GDPR apply if my company sits outside the EU? Yes. Article 3(2) covers you if you target people in the EU. A Delaware or Dubai address does not help.

Can I email someone who left the company if the address still works? No, and you would be wasting the send. Re-verify and update the record instead.

Do I need consent to store a prospect's email in my CRM? Not always. Legitimate interest can cover storage for prospecting. You still need the assessment, the notice and a retention limit.

Does an unsubscribe link satisfy the objection right in GDPR consent email marketing? It meets the mechanism. It does not meet the duty to push that objection into every system you use.

Build the list you can actually defend#

The compliance question and the pipeline question share one answer: fewer, better, traceable contacts. A 500-record list with a known source, a clear role fit and a recent check will beat a 50,000-record list. It wins on reply rate, on delivery, and on the day someone files an access request.

Start there. Use the Tomba Email Finder to build lists from company domains and named roles instead of buying blind. Verify before every send. Keep the source attached to each record. The free tier gives you 25 searches a month, and paid plans start at $49/mo — see the full Tomba pricing. Get GDPR consent email marketing right at the list stage, and the rest gets much simpler.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.