Services AI Audit Guides Marketplace Blog Contact
European Union

Cold email and GDPR. Harder, not impossible.

B2B cold email can be lawful in the European Union, but the requirements are substantially heavier than in the United States, New Zealand or Australia — and they vary by member state. Anyone telling you GDPR simply bans cold email is wrong; anyone telling you it is straightforward is also wrong.

This is not legal advice. It is a plain-language summary of publicly available legislation, written to help you ask better questions. Rules change, enforcement practice varies, and your circumstances may differ. If cold outreach is material to your business, have a lawyer in the relevant jurisdiction review what you are doing.

Two regimes apply at once

GDPR

Governs the personal data. A named business address like firstname.lastname@company.com identifies a person and is therefore personal data. You need a lawful basis to process it, and obligations of transparency and rights follow.

ePrivacy

Governs the sending of electronic marketing. Implemented separately by each member state, which is why the rules differ across the bloc even though GDPR is uniform.

Legitimate interest — the usual basis, with conditions

Most compliant B2B outreach in Europe relies on legitimate interest rather than consent. GDPR itself acknowledges that direct marketing may be a legitimate interest. But relying on it is not a formality — it requires you to actually carry out and document a balancing assessment: your interest in marketing against the individual's rights and their reasonable expectations.

It is much easier to defend when the message is relevant to that person's professional role, sent to a business address, at a company plausibly in your market. It is very hard to defend for untargeted bulk sending, and effectively impossible for personal addresses.

The obligation people forget

Transparency. Under GDPR, when you obtain personal data from a source other than the individual, you must inform them — typically at the point of first contact — of who you are, what data you hold, where you got it, your lawful basis, and their rights.

In practice this means a compliant first cold email in Europe includes a short privacy notice or a clear link to one. This is the single most commonly omitted requirement, and its absence is what turns an otherwise reasonable message into a complaint.

National variation is real

ePrivacy is a directive rather than a regulation, so implementation differs. Some member states apply consent requirements to business recipients that others do not; some distinguish sole traders and partnerships from incorporated companies, treating the former closer to individuals. Germany is generally regarded as among the strictest.

The practical consequence: "compliant in Europe" is not a single status. If you target multiple member states, check the rules for each, or take the strictest reading across all of them.

A pragmatic position many small businesses take: keep European outreach narrow, highly relevant, sent only to business addresses at companies with an evident connection to the offer, always with a privacy notice, and with instant permanent suppression on any objection. That is defensible. Bulk untargeted sending into the EU is not.

Common questions

Is cold email banned under GDPR?

No. GDPR does not ban cold email; it requires a lawful basis for processing personal data, and legitimate interest can serve for relevant B2B outreach. What GDPR adds are real obligations — a documented balancing assessment, a privacy notice at first contact, and honouring objections absolutely — that make careless bulk sending unlawful while leaving targeted, transparent outreach available.

Is a company email address personal data?

A named address such as firstname.lastname@company.com identifies an individual and is personal data. A generic role address such as info@company.com generally is not, though the picture is less clean where a sole trader's business address is effectively personal. The safe assumption is that named addresses are personal data.

What do I have to tell people in the first email?

Where you obtained their details, who you are, why you are contacting them, your lawful basis, and how they can object or request erasure. This can be a brief paragraph or a clear link to a privacy notice — but omitting it entirely is the most common compliance failure in European outreach.

Does GDPR apply if my business is outside the EU?

It can. GDPR has extraterritorial reach and applies where you offer goods or services to people in the EU or monitor their behaviour. Sending marketing email to prospects in the EU from New Zealand, Australia or the United States does not place you outside its scope.

Keep reading
Cold email law in the UK Cold email law in the US Finding business emails ethically

Hire a salesperson once.
Keep them forever.

The Cold Outreach Machine finds the companies you sell to, writes a different email for each one, and sends them on its own — paced, inside working hours. US$299.99, paid once, live setup call included.

See the machine Buy once vs subscribe