GDPR Email Marketing in 2026: Rules, Consent, and Fines

GDPR does not ban cold email. It bans sloppy cold email. Here is the lawful-basis decision, the country-by-country reality for B2B, and the checklist that keeps your outbound defensible in 2026.

Aug 23, 2026 11 min read 2,466 words
GDPR Email Marketing in 2026: Rules, Consent, and Fines

TL;DR

  • GDPR does not ban B2B cold email. It requires a documented lawful basis, transparency, and a one-click way out. Most teams fail on the second and third, not the first.
  • For B2B outbound, legitimate interest (Article 6(1)(f)) is usually the right lawful basis — but only if you write the assessment down before you send, not after a complaint.
  • The lawful basis is only half the story. The ePrivacy rules are national, so the same campaign can be legal in the Netherlands, borderline in France, and unlawful in Germany or Italy.
  • Data quality is a compliance control, not just a deliverability one. Stale, unverifiable, or over-collected contact data breaks Article 5 before it breaks your bounce rate.
  • Fines top out at €20 million or 4% of global annual turnover, but the realistic risk for most senders is a regulator order to delete the database you spent two years building.

What does GDPR actually say about email marketing?#

Less than you think, and more than you want.

The General Data Protection Regulation never uses the phrase "cold email." It regulates the processing of personal data, and a work email address like firstname.lastname@company.com is personal data because it identifies a person. That single fact pulls your entire outbound motion into scope: sourcing, storing, enriching, sending, and deleting.

Four articles do most of the work in practice:

  1. Article 6 — lawful basis. You need one of six. For marketing, only two are realistic: consent (6(1)(a)) or legitimate interest (6(1)(f)). Recital 47 explicitly says direct marketing may be a legitimate interest. "May" is doing a lot of lifting there.
  2. Article 5 — principles. Data minimisation, accuracy, and storage limitation. If you scraped 40 fields to send a one-line email, you collected too much. If your list is three years stale, it is inaccurate by definition.
  3. Articles 13 and 14 — transparency. Article 14 covers data you did not get from the person directly, which describes almost every prospecting database. You must tell them where you got their data, within one month or at first contact, whichever comes first.
  4. Article 21(2) — right to object. For direct marketing, the objection is absolute. No balancing test, no "let me check with legal." Someone says stop, you stop, and you keep a record proving you stopped.

Then there is the second layer people forget entirely: the ePrivacy Directive (2002/58/EC), transposed differently in every member state. GDPR sets the baseline for the data. ePrivacy sets the rules for the channel. When they conflict, the national ePrivacy rule usually wins on the question "can I send this email at all."

GDPR compliance realization for cold email senders
GDPR compliance realization for cold email senders

Diagram: What does GDPR actually say about email marketing
Diagram: What does GDPR actually say about email marketing

No, and anyone selling you that line is either selling consent-based software or has not read Recital 47.

Consent under GDPR is a high bar: freely given, specific, informed, unambiguous, and provable. A pre-ticked box is not consent. A checkbox bundled with your terms of service is not consent. A business card in a fishbowl at a trade show is, at best, an argument.

For inbound marketing — newsletters, gated content, product updates — consent is the clean path and you should take it. For outbound prospecting, consent is a logical impossibility: you cannot ask someone for permission to email them without emailing them first. That is precisely why the legitimate interest basis exists.

The catch is that legitimate interest is not a free pass. It is a three-part test you must be able to show on demand:

  • Purpose test. Is there a real business interest? Selling accounting software to accountants: yes. Blasting a generic pitch to every address on a domain: harder to defend.
  • Necessity test. Is email the reasonable way to achieve it? Usually yes for B2B. Less so if you also bought their personal mobile number and started texting.
  • Balancing test. Would the recipient reasonably expect this contact in their professional role? A VP of Engineering expects vendor outreach. A nurse at a hospital does not expect a pitch for HR software at her work address.

Write those three paragraphs down. Date them. Store them with the campaign. That document — a Legitimate Interest Assessment, or LIA — is the single highest-leverage compliance artefact in outbound, and it takes twenty minutes. The UK's Information Commissioner's Office publishes an LIA template that most European DPAs will recognise as reasonable practice.

Dimension Consent (Art. 6(1)(a)) Legitimate interest (Art. 6(1)(f))
Best for Newsletters, gated content, product updates, B2C B2B cold outreach, account-based prospecting
What you must prove Timestamp, source, exact wording shown, unbundled action A written LIA covering purpose, necessity, and balancing
Can you switch later? No — swapping bases mid-campaign is itself a breach No — pick before the first send, not after a complaint
Withdrawal Must be as easy as giving it (Art. 7(3)) Absolute right to object (Art. 21(2)), no exceptions
Fails when Consent was bundled, pre-ticked, or bought from a list vendor Targeting is irrelevant to the recipient's job function
Typical B2C verdict Required in most member states Rarely defensible
Typical B2B verdict Nice to have, not always required Defensible with documentation and relevant targeting

The line that trips teams up: a purchased list does not transfer consent. Consent is given to a named controller for a named purpose. When a data broker sells you their list, they cannot hand over the permission a person gave them. You inherit the data, not the lawful basis. If you buy lists, you are on legitimate interest whether you planned to be or not, and you had better have the assessment ready.

Diagram: Consent or legitimate interest: which basis fits your campaign
Diagram: Consent or legitimate interest: which basis fits your campaign

How do national ePrivacy rules change the answer?#

This is where "GDPR email marketing" stops being one question and becomes twenty-seven. The GDPR harmonised data protection. ePrivacy was a directive, not a regulation, so each country wrote its own version.

Country B2B cold email to a work address Practical requirement Risk level
Germany Effectively requires prior consent under §7 UWG Presumed consent is very narrow; competitors can sue directly High
Italy Consent-based interpretation by the Garante Opt-in expected even for B2B High
France Permitted for B2B if relevant to the professional role Notice + opt-out at collection, per CNIL guidance Medium
Netherlands Permitted with opt-out for legal entities Clear unsubscribe, honour objections immediately Low
Spain Permitted for B2B under LSSI with conditions Relevance to the recipient's role, easy opt-out Medium
UK (post-Brexit) PECR allows corporate subscribers Ltd companies and LLPs yes; sole traders and partnerships treated as individuals Low-medium

Two operational consequences follow. First, segment your sending by country, not just by persona. A single European blast applies your loosest standard to your strictest market. Second, treat Germany and Italy as consent-only unless your counsel says otherwise; the cost of carving them out of a campaign is far lower than the cost of a competitor-initiated injunction under German unfair competition law.

The European Data Protection Board publishes the coordinated guidance and enforcement decisions that show how these national rules are actually applied — worth a quarterly skim if outbound is a material channel for you.

Diagram: How do national ePrivacy rules change the answer
Diagram: How do national ePrivacy rules change the answer

What does a compliant cold email actually look like?#

Structurally, it looks like a good cold email. That is the part nobody says out loud: the compliance requirements and the performance requirements point in the same direction.

  • Identify yourself for real. Legal entity name, registered address, and a working reply-to. Not "The Growth Team."
  • Say where you got the data. One sentence: "I found your details on your company's site while researching engineering teams in Berlin." This satisfies Article 14 and, in practice, raises reply rates because it kills the "how did you get this" objection.
  • Make the relevance obvious in the first two lines. Relevance is not a copywriting flourish here; it is the evidence backing your balancing test.
  • Give a one-click opt-out that works. A plain-text unsubscribe link, or an explicit "reply STOP and I'll remove you." Then honour it within days, across every tool you own.
  • Link to your privacy notice. It should name your lawful basis, retention period, and the DPO or contact for rights requests.
  • Keep the data footprint small. Name, work email, company, role, and the signal you're referencing. You do not need their personal phone number to send an email.

Then there is the rule people find least intuitive: you cannot email someone to ask for consent to email them. That request is itself a marketing communication in most member states. If you are on legitimate interest, stay on legitimate interest and make the outreach relevant, rather than trying to launder it into consent with a permission-pass campaign.

Reminder to document your legitimate interest assessment before sending
Reminder to document your legitimate interest assessment before sending

Where does data sourcing fit into all of this?#

Right at the centre, and this is the part most compliance checklists skip.

Article 5(1)(d) requires accuracy. Article 5(1)(c) requires minimisation. Article 5(1)(e) requires you not to keep data longer than necessary. All three are properties of your sourcing pipeline, not your sending tool. If your prospect data comes from an opaque scrape with no provenance, you cannot answer the Article 14 question ("where did you get this?") and you cannot demonstrate accuracy when the regulator asks.

Practical controls that hold up under scrutiny:

  1. Know your provenance. Whatever provider you use, you should be able to state, per record, where the data came from. Tomba publishes its data sources for exactly this reason — being able to point at a documented methodology is materially better than "we bought a CSV in 2023."
  2. Verify before you send. Running addresses through an email verifier removes dead and role-based addresses. That is a deliverability win, but it is also an accuracy control under Article 5 — you are actively maintaining the correctness of your records.
  3. Enrich narrowly. Contact enrichment is fine when it serves the stated purpose. Pulling personal social profiles, home locations, or anything unrelated to the professional relationship is over-collection, and it is what turns a defensible LIA into an indefensible one.
  4. Set a retention clock. Ninety days for unengaged prospects is a common, defensible default. Suppression lists are the exception: you keep those forever, because deleting an opt-out means you might email that person again.
  5. Maintain one central suppression list. Not one per tool. The most common enforcement trigger is re-contacting someone who opted out eighteen months ago because the objection lived in a sequencer you stopped using.
  6. Keep an Article 30 record. A simple table of what data you process, why, on what basis, for how long, and who you share it with. Required for most organisations, and the first thing a regulator asks for.

Pricing matters here too, because compliance costs scale with volume. If you are paying per record for a database you must refresh quarterly to stay accurate, the cheap-looking annual contract is not cheap. Transparent per-search plans — Tomba's free tier covers 25 searches a month, with Starter at $49/mo and Growth at $99/mo, all listed on the Tomba pricing page — make it easier to size a list to what you can actually keep current. Peers such as BookYourData take a pay-as-you-go approach to the same problem, which suits teams that source in bursts rather than continuously.

Diagram: Where does data sourcing fit into all of this
Diagram: Where does data sourcing fit into all of this

What are the real penalties, and who actually gets fined?#

The headline number is Article 83(5): up to €20 million or 4% of worldwide annual turnover, whichever is higher. That tier applies to breaches of the basic principles, lawful basis, and data subject rights — which is exactly the territory outbound email lives in.

The headline number is also not what happens to a 40-person SaaS company. What happens is more mundane and often more damaging:

  • A complaint-driven investigation. One annoyed recipient files with their national DPA. You have roughly 30 days to produce your LIA, your Article 30 record, your privacy notice, and your data provenance. Companies that never wrote those documents spend the month writing them under deadline.
  • An order to delete. Regulators increasingly pair modest fines with a processing ban or deletion order. Losing the database is worse than the fine.
  • Reputational spillover. DPA decisions are published. Prospects search your name.
  • Contractual fallout. Enterprise buyers ask about your DPA and processing records during security review. A live investigation stalls deals.

For sole traders and freelancers in the UK, note the wrinkle: PECR treats sole traders and unincorporated partnerships as individuals, so the corporate-subscriber exemption does not cover them. Segment those records out or get consent.

How should you operationalise this without slowing outbound to a crawl?#

Do these five things once, then stop worrying:

  1. Write one LIA per campaign type, not per campaign. "Outbound to engineering leaders at 50-500 person SaaS companies in the UK, France, Netherlands and Spain" is a reusable scope.
  2. Country-segment your sequences. Exclude consent-only jurisdictions from cold sends by default.
  3. Wire one global suppression list into every sending tool, CRM, and enrichment job. Test it quarterly by attempting to import a suppressed address.
  4. Set a retention job that purges unengaged prospect records on a schedule, and log that it ran.
  5. Publish a privacy notice that names your lawful basis, retention window, and rights contact — then link it from every outbound email footer.

That is a two-day project, and it converts "are we allowed to do outbound in Europe?" from an open question into a documented answer. HubSpot's GDPR resource hub is a reasonable starting point for the policy language if you're drafting from scratch.

None of this makes you legally bulletproof — nothing does, and a regional counsel review before you scale is money well spent. But the gap between teams that get in trouble and teams that don't is almost never sophistication. It is documentation and relevance.

Build a list you can actually defend#

Compliant outbound starts before the first email: with contact data whose provenance you can explain, whose accuracy you can prove, and whose scope you can justify. Use the Tomba Email Finder to source verified professional addresses by domain, name, or company, with documented sourcing behind every record — then keep the list tight, verified, and country-segmented. Start on the free tier at 25 searches a month and scale when your process, not just your pipeline, is ready.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.