GDPR-Compliant Cold Outreach in the EU: 2026 Guide
TL;DR: B2B cold email in the EU doesn't require opt-in consent under GDPR itself — legitimate interest (Art. 6(1)(f), Recital 47, accessed 2026-08-31) covers it. But national ePrivacy rules differ, and Germany effectively requires consent. What trips teams up: a written Legitimate Interest Assessment before the first send, Article 14 notice, and a per-contact data-origin record.
Every "is cold email legal" article edits the same sentence over and over — soften the CTA, add a disclaimer line — while the actual audit risk sits one layer upstream, in the list. Nobody asks a DPA to review your subject lines. They ask where the contact came from, whether you ran the balancing test before sending, and whether the AI tool that enriched the record invented a data point nobody has a lawful basis to hold. That's the gap this guide fills, with the two documents a regulator will actually ask to see.
Is cold email actually illegal under GDPR — or is that a myth?
It's a myth, and a costly one — teams that believe it either quit outbound entirely or build consent collection they don't need. GDPR governs processing personal data and offers six lawful bases under Article 6 (accessed 2026-08-31), not just consent. Legitimate interest, Article 6(1)(f), is one of them, and Recital 47 (accessed 2026-08-31) names direct marketing explicitly as an interest that may qualify. GDPR itself does not force opt-in for B2B outreach.
What confuses people is a second law that regulates consent for electronic marketing: the ePrivacy Directive (2002/58/EC) (accessed 2026-08-31), whose Article 13 covers unsolicited communications. GDPR answers "may I hold this data for this purpose." ePrivacy answers "may I send this unsolicited message." Conflating the two is the most repeated error in cold email compliance content.
Which law governs your send — GDPR, ePrivacy, or your prospect's national marketing law?
Both apply, to different questions. GDPR governs whether you have a lawful basis to process the contact's data. The ePrivacy Directive (2002/58/EC) (accessed 2026-08-31) governs whether you may send that unsolicited message — and, being a directive, hands the consent rule to each member state to write into national law. "The EU rule" for send permission isn't one answer; it's 27 implementations, and the divergence is the point.
One correction worth stating plainly: the long-promised ePrivacy Regulation is not about to replace this. The 2017 proposal (COM(2017) 10 final, procedure 2017/0003(COD)) is listed for withdrawal in the withdrawals annex of the Commission's 2025 work programme on the stated grounds that no agreement is expected from the co-legislators and the proposal is outdated (accessed 2026-08-31). The 2002 Directive as amended remains the operative instrument. A vendor page still calling the Regulation "expected soon" is running on a line recycled since 2018.
What lawful basis do you use, and how do you actually write the LIA?
Legitimate interest is the standard basis for B2B cold email, and Article 6(1)(f) (accessed 2026-08-31) makes it conditional on interests that are not overridden by the individual's rights — a balancing judgement you should run and document before you rely on it, not after a complaint arrives. That document is the Legitimate Interest Assessment (LIA): three questions, answered in writing, filed somewhere retrievable in ten minutes.
First, purpose: what's the legitimate interest, stated concretely? "Selling our product to relevant B2B contacts" qualifies. Second, necessity: is processing this name, work email, and job title actually needed for that purpose? Third, balancing: does your interest override the individual's expectations, given who they are and what you're doing with their data? A VP of Engineering getting one relevant email about a dev tool, with an easy opt-out, tips toward your interest. Scraping a personal Gmail address and cold-calling someone's mobile does not.
Write the LIA once per campaign type or ICP segment, not per contact. GDPR sets no granularity for this, so the honest framing is a recommendation rather than a rule: per-segment is the level we've seen hold up in practice and the only level that stays maintainable once you're running more than two plays. Date it, keep it with whoever owns compliance, and re-run it whenever your data source, audience, or purpose changes materially.
Where can you legally source EU B2B contacts?
The LIA only holds up if the data underneath it is defensible, and this is where most programs fail — not in the assessment, but in what it's built on. A purchased list with no stated origin, or bulk scraping with no regard for context, makes your necessity and balancing tests fall apart on inspection.
The defensible pattern is B2B data collected in a business context — a company website, a professional profile, a public directory — for a purpose the contact could reasonably anticipate: "a relevant vendor might email me at my work address about a dev tool." Pair that with vendor due diligence: does your enrichment or list provider have its own lawful basis and a DPA with you. If a vendor can't answer "where did this record come from," that gap becomes yours the moment a prospect complains.
Do you have to tell prospects you have their data before you pitch them?
Yes — this is Article 14 (accessed 2026-08-31), and it's the requirement almost every cold email guide skips. When you obtain personal data from a source other than the individual, which describes essentially all B2B prospecting, Article 14 requires giving that person specific information — at the latest when the data is first used to communicate with them: who you are, why you're processing their data, your lawful basis, and how to object.
That doesn't mean a legal paragraph bolted onto your first email. It means the basics are easy to find: your company's identity in the From name and signature, a one-line reason the recipient is hearing from you, a working unsubscribe path, and a privacy policy that actually describes your prospecting practices. Sender identity, purpose, and opt-out at first contact — that's Article 14 notice inside a cold email.
Eight EU markets, and how their national rules actually differ
This is the table worth date-stamping — national implementations shift, and a 2022 guide isn't a source to trust today. It covers 8 of the EU's 27 member states, chosen for size and for how differently they treat B2B email; check your own markets against their national statute or DPA page if they aren't listed here. Every row below links to the national statute or DPA page it rests on; all of them were accessed 2026-08-31. Read the source, not my summary of it, before you rely on a row for a specific market, and re-check it when you next plan that market.
| Country | B2B email stance | Practical note | Primary source |
|---|---|---|---|
| Germany | Consent-leaning even for B2B | Treat like opt-in; legitimate interest alone is a weak defense here | UWG § 7 |
| France | Permits B2B outreach to a professional address where the message relates to the recipient's job function | Relevance to their role is the condition, not a generic blast | CNIL, prospection commerciale par courrier électronique |
| Italy | Consent-leaning | Art. 130 of the Privacy Code sets the consent rule for electronic direct marketing | D.lgs. 196/2003, art. 130 |
| Spain | Consent-leaning | LSSI art. 21 bars unsolicited commercial email absent prior authorisation or a prior customer relationship | Ley 34/2002, art. 21 |
| Netherlands | Opt-out permitted for B2B | Telecommunicatiewet art. 11.7 carries the regime; an easy, working opt-out is the load-bearing safeguard | Telecommunicatiewet art. 11.7 |
| Sweden | Opt-out workable for B2B | The consent rule in § 19 is written for marketing to a natural person, leaving legal-person recipients outside it | Marknadsföringslagen (2008:486) § 19 |
| Denmark | Consent-leaning — do not lump it in with "the Nordics" | § 10's prohibition on unsolicited electronic marketing is not written as consumer-only | Markedsføringsloven § 10 |
| Finland | Opt-out workable for corporate recipients | § 200's consent rule is headed "direct marketing to a natural person"; corporate subscribers are treated separately | Laki 917/2014, § 200 |
Germany is where "legitimate interest covers cold email" fails hardest — UWG § 7 treats unsolicited commercial email as an unreasonable nuisance absent prior express consent, and does not carve out B2B the way an opt-out state does. If Germany is a meaningful chunk of your list, don't extend your French or Swedish playbook there without checking it separately.
Norway is deliberately absent. It isn't an EU member state: GDPR applies there through the EEA agreement, but its marketing rules sit under Norwegian law rather than one of the 27 national ePrivacy implementations this section is about, so it needs its own check rather than a shared "Nordics" row.
The UK is out of the table for the same reason. Post-Brexit it runs UK GDPR alongside PECR, whose rule on unsolicited marketing email attaches to "individual subscribers" — PECR reg. 22 (accessed 2026-08-31) is written in those terms, leaving corporate subscribers outside it, a materially more permissive B2B position than most EU states; see also the ICO's Guide to PECR (accessed 2026-08-31). Don't import EU reasoning into a UK campaign, or the reverse.
What changes when an AI SDR writes and sends the outreach?
Not as much as the fear-based headlines suggest. Article 22's restrictions on automated decision-making (accessed 2026-08-31) apply to decisions that produce legal or similarly significant effects — denying a loan, screening a job application. An AI system drafting a cold email isn't making that kind of decision; it's generating a message, and that doesn't clear the Article 22 bar on its own.
Where AI does raise the stakes is upstream, in what it does to your data, not in what it writes. An enrichment layer that infers new attributes — seniority scoring, buying-intent signals — is creating new personal data, and that needs its own lawful basis; it doesn't inherit one from the original list entry. Large-scale profiling across your prospect base can push you into Article 35 DPIA territory (accessed 2026-08-31), especially if it systematically affects who gets contacted. The fix, and the second artifact worth keeping alongside your LIA, is a provenance record per contact: where the base data came from, what your AI layer added or inferred, and when. That record is your answer when a regulator asks how you know a field is accurate — and it's what lets you delete cleanly when someone objects.
How do you handle objections, opt-outs, and retention?
Every message needs a working way to object, and every objection needs to actually stop future contact — that sounds obvious, but in our experience it's still the most common broken link, usually because opt-outs land in one system while the sending list lives in another. Maintain a single suppression list every campaign checks against, so a contact who opts out of Campaign A isn't re-added when Campaign B pulls a fresh export from the same source.
On retention: keep prospect data only as long as your legitimate interest is live. A non-responder past a defined touch limit (three touches over 30 days, say) rolls off into long-term suppression or deletion. Someone who explicitly opts out goes straight to permanent suppression — keep that entry indefinitely, since deleting it is how you accidentally re-email them.
What does a GDPR-defensible outbound stack look like in practice?
Four things, configured once and revisited when your data sources change: a written LIA per campaign type, Article 14 notice built into your templates by default, a DPA with every enrichment and AI SDR vendor touching prospect data, and a provenance record that survives contact from source through AI enrichment to send. None of this is exotic — it's the same discipline as deliverability hygiene: boring, mostly invisible when it's working, and the first thing checked when something goes wrong. If you're evaluating AI SDR vendors on this basis, ask directly whether they can produce a DPA and where a contact's data originated.
This article is a practitioner's read of the law, not legal advice. It links the primary sources so you can check them; for a decision on your own campaigns, take advice from a qualified lawyer in the relevant jurisdiction.
FAQ
Is B2B cold email legal in the EU without consent?
Yes, under GDPR — legitimate interest (Art. 6(1)(f), Recital 47, accessed 2026-08-31) is a valid lawful basis for B2B direct marketing and doesn't require opt-in consent. Whether you can send a specific unsolicited message without consent is separate, governed by the ePrivacy Directive as implemented per country — Germany leans consent-required, Sweden and Finland scope their consent rules to natural persons.
Does GDPR apply to a US company emailing EU prospects?
Yes. GDPR applies extraterritorially under Article 3(2) (accessed 2026-08-31) when you're processing personal data of individuals in the EU in connection with offering them goods or services, regardless of where your company is based.
Are role-based addresses like info@company.com covered by GDPR?
Personal data is defined in Article 4(1) (accessed 2026-08-31) as information relating to an identified or identifiable natural person, and Recital 26 (accessed 2026-08-31) ties that to whether the person can reasonably be identified. A generic address like info@company.com is typically outside GDPR's scope only when it isn't attributable to a specific individual — a shared inbox at a large company, for instance. That caveat matters: at a one-person company, or wherever the address resolves to an identifiable individual, it's personal data regardless of the local part. A named address like j.smith@company.com is personal data even in a work context, and is covered.
Do I need a DPA with my data enrichment or AI SDR vendor?
Yes, if that vendor processes personal data on your behalf — which covers most enrichment tools, AI SDRs, and list providers. Article 28 (accessed 2026-08-31) requires a written contract governing controller-to-processor processing; get one before data flows.
How long can I keep a prospect's data after they don't reply, or after they opt out?
There's no fixed statutory number — Article 5(1)(e) (accessed 2026-08-31) requires retention no longer than necessary for the purpose. A non-responder should roll off active outreach after a defined touch limit, into deletion or long-term suppression. Someone who opts out goes into permanent suppression, kept indefinitely so you don't accidentally re-contact them.
What are the realistic penalties for non-compliant cold outreach, and who enforces them?
Enforcement sits with each member state's national DPA — Germany's state DPAs, France's CNIL, Italy's Garante. GDPR's upper fine tier is up to €20 million or 4% of total worldwide annual turnover, whichever is higher (Art. 83(5), accessed 2026-08-31). Those headline numbers are the statutory ceiling, not a forecast for a cold-email complaint; we're not aware of published enforcement data broken out for B2B prospecting, so treat any claim about "typical" outcomes — including ours — as an impression rather than a measurement. What is certain is that a documented LIA and provenance record are what you produce when an inquiry lands.
Put your outbound on autopilot
0effort sources your buyers, writes every touch, answers replies over email and phone, and books the meetings. You just show up.
Start free See how it worksOutbound tips, monthly
One email a month with what's actually working in cold outbound. No spam, unsubscribe anytime.