Blog

Is B2B Cold Email Legal in the EU? GDPR, ePrivacy, and What Changes by Country

Quick answer

Yes, broadly, but "the EU" isn't one jurisdiction for this question. GDPR's Recital 47 lets direct marketing count as a legitimate interest, which is the legal basis most B2B cold email runs on for holding a contact's name and email address. That's necessary, but it isn't the whole answer: a separate law, the ePrivacy Directive, decides whether you're allowed to actually send the unsolicited email, and Article 13(5) leaves it to each member state to decide how much protection a business inbox gets. France and Belgium treat a generic professional address on an opt-out basis. Germany treats every inbox, business or personal, on an opt-in basis. Get the GDPR basis right and still break the local send rule, and the GDPR basis doesn't save you.

The short answer

I'm Hlib Storchak. I build and run outbound systems for B2B founders and sales teams, mostly cold email and LinkedIn, and I've booked 2000+ meetings for B2B clients doing it. Whether cold email is legal in the EU is the question I get asked by almost every founder about to send into Europe for the first time, usually right after they've read three different blog posts that each gave a slightly different answer.

Here's why the posts disagree: they're usually describing one country's rule and generalizing it to "the EU." The honest answer has two layers. GDPR sets an EU-wide floor for whether you can process a contact's data at all, and direct marketing can count as a legitimate interest under that floor. A second, separate law, the ePrivacy Directive, governs the actual sending of an unsolicited commercial message, and it explicitly hands member states the choice of how strict to be with business recipients. That second layer is where "legal in the EU" stops being one answer and starts depending on which country's inbox you're emailing.

Two separate questions: can you hold it, can you send it

The mistake I see in almost every "is cold email legal" thread is treating GDPR as the only rule that matters. GDPR answers one question: do you have a lawful basis to process someone's name, job title, and email address. The ePrivacy Directive (2002/58/EC) answers a different one: are you allowed to put an unsolicited commercial message in that inbox at all. The European Data Protection Board's own Guidelines 1/2024 on legitimate interest are explicit that for direct marketing, the ePrivacy Directive is the lex specialis, the more specific law that controls. If sending the message isn't permitted under a country's own implementation of ePrivacy Article 13, a legitimate-interest argument under GDPR doesn't rescue it. You need both questions answered, not just the first one.

What GDPR legitimate interest actually covers

Recital 47 of GDPR says processing personal data for direct marketing purposes "may be regarded as carried out for a legitimate interest." That's a real, usable legal basis under Article 6(1)(f), and it's what lets a B2B outbound program hold a prospect's business email address in a CRM without asking permission first. But "may be regarded as" is doing real work in that sentence. It isn't automatic. A proper legitimate interest assessment weighs your interest in sending the message against the recipient's interest in not getting it, and that balance tends to tip in your favor when the contact is relevant to their actual job and the message is easy to opt out of, and tips against you when the targeting is generic or the list was built in a way the person couldn't reasonably expect. Ireland's own Data Protection Commission guidance quotes this same Recital 47 language almost verbatim, which I go through in more detail, alongside where that reasoning stops applying, in what actually differs about appointment setting rules in Ireland.

Where this data came from matters. The legitimate interest balancing test leans partly on how the contact's details were collected in the first place. A list scraped from a source the person never expected to be mined for sales outreach is a weaker legitimate interest claim than one built from a public professional directory or an opt-in source. I've written more on the compliance side of web scraping for sales lists if that's the layer you're building on.

The EU-wide floor: the soft opt-in exception

Underneath the country-by-country variation sits one genuinely EU-wide rule: the soft opt-in exception in ePrivacy Article 13(2). It lets a business that already has a customer relationship keep emailing that customer about similar products without collecting fresh consent, as long as four conditions all hold:

  • The address was collected directly from the customer, in the context of an actual sale.
  • The email promotes the sender's own similar products or services, not an unrelated catalog.
  • The customer had a clear, free chance to opt out when the address was collected, and didn't.
  • Every message since has included a working, easy way to opt out.

That's the one piece of this that doesn't depend on which country you're sending into. It also doesn't help a true cold send to someone who's never bought anything from you, which is the case most outbound teams are actually asking about.

Here's the specific clause that creates the country-by-country split. ePrivacy Directive Article 13(5) states that the strict consent rules in Article 13 apply in full to subscribers who are natural persons, and then separately requires member states to "ensure... that the legitimate interests of subscribers other than natural persons," meaning businesses, "with regard to unsolicited communications are sufficiently protected." It doesn't say how. Each EU country gets to decide what "sufficiently protected" means for a business inbox, and that single clause is the reason Germany, France, and Belgium all answer "is cold email legal here" differently, despite implementing the same directive.

How five EU countries actually treat it

I'm covering five countries here, not twenty-seven, because these are the ones clients actually ask me about and where I could verify the rule against a primary source rather than an aggregator restating someone else's summary.

CountryDefault rule for a cold B2B emailWhat actually makes it defensible
FranceOpt-out is enough for a generic professional addressAddress like contact@ or a role-based inbox, message tied to the recipient's professional function, working opt-out
BelgiumOpt-out is enough for a legal person at an impersonal addressAddress like info@company.be rather than firstname.lastname@, clear opt-out in every message
NetherlandsCloser to opt-in in practice than the other twoMost named-contact addresses count as personal data under GDPR regardless of B2B framing, and the recipient has an unconditional right to object
GermanyOpt-in required, business or personal, no exceptionPrior express consent under UWG §7(2) No. 2, no general B2B carve-out for email
IrelandNo email-specific carve-out in the way France has, but calling runs opt-out for bothSee the full breakdown in the Ireland appointment setting rules, which covers the call side of this in detail

France: the clearest permissive case

France's Article L34-5 of the Code des postes et des communications électroniques, administered by the CNIL, draws a line most other countries don't: it distinguishes a generic professional address, contact@, info@, commercial@, from a personal one, firstname.lastname@company.fr. For the generic address, you can send without prior consent as long as the message is relevant to the recipient's professional function, the sender and commercial purpose are clear, and there's a working right to object in every message. For a personalized address, the CNIL's own position treats it as GDPR personal data and expects the same legitimate-interest reasoning as anywhere else, which pushes it closer to the soft opt-in logic above. France is the country where a genuinely cold, non-customer B2B send to a role-based inbox is on the firmest legal footing in the EU, which is also why most "is cold email legal" guides quietly use a French example to make the EU-wide case sound more settled than it actually is.

Belgium: similar idea, narrower reading

Belgium runs a comparable logic to France's: no prior consent is required to email a legal person at an impersonal address, as long as a clear, working opt-out is in every message. The practical gap between Belgium and France is narrower than most posts suggest, both lean on the same Article 13(5) discretion and land on an opt-out regime for the address, not the person. The difference that actually matters operationally is the same one France has: the moment the address looks like a named individual rather than a department, you're back to relying on GDPR legitimate interest rather than a clean statutory opt-out.

The Netherlands: less permissive than most posts assume

This is the one correction worth making, because a lot of the generic "EU cold email rules" content lumps the Netherlands in with France and Belgium as a third permissive market, and that's a weaker claim than it looks. Dutch electronic marketing sits partly under Article 11.7 of the Telecommunicatiewet and partly under GDPR directly, and the Dutch reading leans harder on the GDPR side: most named business email addresses still count as personal data, the recipient keeps an unconditional right to object to direct marketing at any time, and there isn't a clean statutory carve-out for an impersonal address the way French and Belgian law spell one out. In practice that means a Dutch cold send needs a genuinely solid legitimate interest case, not a confident assumption that "B2B rules are relaxed here," because the law doesn't hand you the same clean exception France's does.

Germany: the strict outlier

Germany sits at the opposite end from France. Its unfair-competition law, UWG Section 7(2) No. 2, requires prior express consent for email advertising by default, for business inboxes exactly as much as personal ones, with only a narrow existing-customer exception attached. I've gone deep on exactly what that requires, the four conditions, the enforcement mechanism, and why I run German outreach LinkedIn-first because of it, in is cold email legal in Germany, so I won't repeat the detail here. The short version for this article: if your EU send list includes German addresses, don't assume the France or Belgium answer travels. It doesn't.

What this means if you're sending across more than one country

Operationally, the safest approach isn't to find the one most permissive EU rule and apply it everywhere, it's to build your process around the strictest country you're sending into and treat the more permissive ones as upside. That means a working, one-click opt-out in every message regardless of destination, sender identification that's accurate everywhere, and a list that's segmented well enough that you can actually tell which addresses are German versus French versus Dutch when a complaint or a DPA inquiry comes in. If you're sending into a market where you don't operate in English day to day, the opt-out notice and sender line deserve the same localization care as the message itself, which I've covered separately in when native-language cold email localization is actually worth it. This is also the part where decent sending infrastructure earns its keep rather than being a nice-to-have: what I run for clients, Salesforge for sequencing, defaults to a working unsubscribe link and consistent sender identification on every send, which removes one of the more common compliance gaps I see, a template that had a working opt-out link on day one and quietly lost it after three rounds of copy edits.

The mistakes I see most often

The mistake I see most often when I take over an account that's already sending EU-wide is a single list and a single opt-out line built for whichever country the founder happened to read about first, usually the UK or the Netherlands, then pointed at every other EU market without anyone checking whether the rule actually traveled. The second most common one is the opposite: a team hears "Germany requires opt-in" and assumes the whole EU does, and skips genuinely winnable markets like France and Belgium out of excess caution. Both mistakes come from treating "the EU" as one jurisdiction. If you're deciding which European market to prioritize for outbound at all before you get into the legal weeds of any one of them, that's a sequencing question I've written about separately in when a startup should actually start outbound.

Key takeaways

  • GDPR's Recital 47 lets direct marketing count as a legitimate interest for holding a contact's data, but it doesn't answer whether you can send the email, that's a separate question under the ePrivacy Directive.
  • The EDPB's own 2024 guidelines confirm ePrivacy is the more specific law for direct marketing: if a country's ePrivacy rule doesn't permit the send, legitimate interest under GDPR doesn't override it.
  • ePrivacy Article 13(5) leaves it to each EU country to decide how much protection a business inbox gets, which is the actual source of the country-by-country split.
  • France and Belgium allow an opt-out approach for generic, role-based professional addresses; the Netherlands leans closer to needing a genuine legitimate interest case; Germany requires opt-in with no general B2B exception.
  • The one EU-wide rule that doesn't depend on country is the soft opt-in exception, and it only covers emailing an existing customer about similar products, not a true cold send.
  • Build your process around the strictest country on your list, not the most permissive one, and localize the opt-out notice along with the message itself.

FAQ

Is cold email legal under GDPR for B2B?

GDPR itself doesn't ban it. Recital 47 lets direct marketing count as a legitimate interest, which is the legal basis most B2B cold email relies on for processing a contact's business email address. That covers holding and using the data, it doesn't by itself answer whether sending the unsolicited message is allowed, that's governed by the separate ePrivacy Directive and its national implementations.

Does "B2B" mean cold email is automatically fine across the whole EU?

No. ePrivacy Article 13(5) leaves it to each member state to decide how much protection a business inbox gets, and states made different choices. France and Belgium allow an opt-out approach for generic professional addresses. Germany requires opt-in regardless of whether the recipient is a business. There's no single EU-wide B2B exception for email the way there's a shared floor under GDPR.

What's the safest approach if I'm sending into several EU countries at once?

Build your process around the strictest country on your list rather than the most permissive one: a working one-click opt-out in every message, accurate sender identification, and a list segmented well enough to know which addresses sit under which country's rule. Treat permissive markets like France as upside, not the baseline you design for.

Does the soft opt-in exception let me email a cold EU prospect?

No. The soft opt-in in ePrivacy Article 13(2) only covers emailing an existing customer about similar products, and only when all four conditions hold: the address came directly from the customer during a sale, the product is similar, they had a clear chance to opt out when you collected it, and every message since has included a working opt-out. A genuinely cold contact who's never bought from you isn't covered by it in any EU country.

If I'm GDPR-compliant, am I automatically compliant with each country's email rules too?

No, and this is the gap that catches most teams. GDPR compliance and ePrivacy compliance are two different checklists. You can have a fully documented legitimate interest assessment for processing the data and still be sending an email that breaks a specific country's consent rule, Germany's UWG Section 7 being the clearest example. Check both, not just the one most guides focus on.

Sending cold email into the EU and want the compliance layer actually handled?

There are three ways I work with B2B teams on this: done-for-you outbound, where I build and run the cold email and LinkedIn engine with the country-by-country rules built into the send process, not bolted on after a complaint; fractional Head of GTM, where I plug in as your GTM lead and make these calls as markets get added; or building the outbound function inside your own team, so the judgment on what's defensible in which country stays in-house.

Book a call