Is cold email legal in Austria? TKG and the DSGVO, explained
The short answer
Austria's rule on unsolicited advertising email does not live in unfair-competition law, the way it does in Germany. It lives in telecoms law: Section 174(3) of the Telekommunikationsgesetz 2021 (TKG) requires the recipient's prior consent before you can send them electronic mail for direct-advertising purposes, and the text draws no line between a private address and a company one. A narrow existing-customer exception exists, and the GDPR applies on top as a separate question. Unsolicited B2B cold email into Austria carries genuine legal exposure. This page is general information, not legal advice.
Teams that already run German outreach often assume Austria is a smaller copy of the same rulebook. The consent standard lands in the same place, but the statute that gets you there, and the body that enforces it, are different, and that difference changes what a compliance conversation with an Austrian prospect actually sounds like.
Note: this is general information for orientation, not legal advice, and it is not a compliance opinion on your situation. Before you send anything into Austria, get a written view from a qualified Austrian lawyer or data-protection adviser.

On this page
- Why Austria runs on telecoms law, not competition law
- What does TKG Section 174 actually say about email?
- TKG Section 174 at a glance
- Does GDPR legitimate interest cover it?
- Who enforces this, and what does it cost?
- Per-channel risk in Austria, ranked
- What lower-risk Austrian outbound looks like
- Does using an agency move the legal risk?
- How we handle Austria
Why Austria runs on telecoms law, not competition law
Germany's cold-email rule sits inside its unfair-competition statute, the UWG. Austria implemented the same EU ePrivacy Directive requirement in a different place: the Telekommunikationsgesetz 2021, Section 174, a telecoms-privacy law enforced by the telecoms regulator rather than through competitor lawsuits. The practical consent standard lands close to Germany's, but the enforcement path, the penalty structure and the exceptions are worded differently, so a Germany-only compliance memo does not transfer cleanly.
Austria's own unfair-competition statute, the Bundesgesetz gegen den unlauteren Wettbewerb, still matters here: Austrian courts have read persistent unwanted advertising as a breach of it too, which opens a second route to a claim. The GDPR runs alongside both as a third, separate layer for the personal-data side. Our continent-wide notes on GDPR-compliant cold email in Europe cover that third layer in full.
What does TKG Section 174 actually say about email?
Section 174(3) states plainly that sending electronic mail, including SMS, is impermissible without the recipient's prior consent where the sending is for direct-advertising purposes. There is no wording anywhere in the section that limits its protection to consumers, and no exemption for a company's published contact address.
Section 174(4) then sets out the one real exception, and it has four conditions that all have to hold together:
- The address came from an existing sale. The sender obtained the contact information in connection with selling that customer a product or service.
- The message advertises similar products. Not the sender's full catalogue, only offers similar to what the customer already bought.
- A free, clear opt-out was offered twice. Once when the address was collected, and again in every subsequent message, at no cost beyond ordinary transmission.
- The recipient has not already refused, including by registering the address on the RTR's own opt-out registry, the ECG-Liste, which any sender is expected to screen against before mailing.
Section 174(5) adds a separate, absolute bar that no consent can cure: sending electronic mail whose sender identity is disguised or concealed, sending in breach of the E-Commerce-Gesetz's labelling duty under its Section 6(1), or sending with no authentic address the recipient can use to ask you to stop.
TKG Section 174 at a glance
| TKG 2021 Section | What it says | What follows |
|---|---|---|
| 174(3) | Electronic mail, including SMS, sent for direct-advertising purposes is impermissible without the recipient's prior consent. No wording limits it to consumers or exempts a company's published address. | Unsolicited B2B cold email carries genuine exposure |
| 174(4) | The existing-customer exception, with four conditions that all have to hold: the address came from a sale, the message advertises similar products, a free clear opt-out was offered when collected and in every message, and the recipient has not refused, including on the RTR's ECG-Liste. | Narrow; screen against the ECG-Liste first |
| 174(5) | A separate absolute bar no consent can cure: disguised or concealed sender identity, breach of the E-Commerce-Gesetz labelling duty under its Section 6(1), or no authentic address to ask you to stop. | Identify the sender fully in every message |
| 174(1) | Telephone and fax also require prior consent. | Same 100,000 euro ceiling for a breach |
| Enforcement | Complaints go to the Fernmeldebuero, the telecoms authority. | Administrative fine up to 50,000 euro for email breaches |
Treat the fine ceilings as statutory maximums, not a forecast. The rule is not the German one: Germany's sits in Section 7 of the UWG and is enforced mostly through private warning letters, as set out in Is Cold Email Legal in Germany? GDPR and UWG Rules (2026). Switzerland has a third answer in Is Cold Email Legal in Switzerland? UWG and nDSG Explained, and the three side by side are in B2B Lead Generation DACH: Germany, Austria, Switzerland (2026).
Does GDPR legitimate interest cover it?
No, for the same structural reason it does not in Germany. Legitimate interest under Article 6(1)(f) GDPR answers whether you may process the contact's personal data at all. It says nothing about whether you may send that contact an advertising email, which is exactly what TKG Section 174 governs. The two tests run in parallel on the same message, and Austria requires both to pass.
Who enforces this, and what does it cost?
Austria's enforcement path looks less like Germany's warning-letter culture and more like a regulator complaint.
- The Fernmeldebüro. Complaints about a breach of TKG Section 174, including sending unsolicited electronic mail, sending it anonymously, or failing to label it as advertising, go to this office of the Fernmeldebehörde, the national telecoms authority. It can impose an administrative fine of up to 50,000 euro for these breaches; unsolicited marketing calls and faxes carry a separate ceiling of up to 100,000 euro.
- Unfair-competition claims. Austrian courts have treated hartnäckige, typically repeated, unwanted advertising as a breach of the general unfair-competition law, which gives a competitor standing to seek an injunction and damages, independent of the Fernmeldebüro complaint route.
- The data-protection side. The Datenschutzbehörde can separately act on the GDPR processing question, on complaint or on its own initiative.
Treat the fine ceilings as statutory maximums, not a forecast of what any single complaint produces. There is no published record we can cite of typical settlement amounts, so we are not stating one.
Per-channel risk in Austria, ranked
- Email without consent: the constrained channel described above, with no general business exemption.
- Telephone and fax: also require prior consent under TKG Section 174(1), with the same 100,000 euro ceiling for a breach; presumed or implied consent gets less room here than some teams assume.
- LinkedIn and business networks: not directly named in TKG Section 174, which is written around telephony, fax and electronic mail. That is a gap in the statute's wording, not a guarantee a court would treat it the same way indefinitely.
- Postal mail: outside TKG entirely, subject only to ordinary GDPR duties if a named individual's address is used.
- Events, referrals and content: no unsolicited-message problem, and the standard way to build the consented list that later makes Austrian email usable.
What lower-risk Austrian outbound looks like
None of this makes unsolicited email lawful in Austria. It reduces the chance of a complaint reaching the Fernmeldebüro and limits the damage if one does.
- Write in Austrian German. Formal Sie-form, correct register, a real named sender.
- Sequence through a channel TKG does not restrict the same way, commonly a phone call or LinkedIn message, and move to email once the recipient has specifically agreed to it.
- Check the ECG-Liste before any mailing that might rely on the existing-customer exception; it is a real screening step, not a formality.
- Identify the sender fully in every message, with a working reply address, so Section 174(5)'s absolute bars never come into play regardless of consent status.
- Honour every opt-out immediately and permanently, across all sending domains and future campaigns.
- Keep a record of where each contact came from, so the GDPR question and the TKG question can both be answered if asked.
Does using an agency move the legal risk?
Not away from the client. The business whose offer is being promoted is the one that benefits from the advertising, and it stays exposed to a Fernmeldebüro complaint or an unfair-competition claim alongside whoever actually sent the message. An agency that pitches full risk transfer is describing something Austrian law does not readily support.
What a client can reasonably expect instead: named sending domains it owns, full visibility of the copy and list before anything sends, documented data sources, and immediate opt-out handling, the same checklist we set out for Germany in our agency red-flag guide.
How we handle Austria
Ripe Leads runs Austrian campaigns as their own plan rather than a slice of a German send, because the statute, the regulator and the exceptions are not identical. We work from publicly available business data on a legitimate-interest basis, honour opt-outs permanently, screen against the ECG-Liste where the existing-customer exception is in play, and set the channel mix per market with Austria's position on email stated plainly. The final call on risk belongs to the client and their counsel, not to us. Our pricing and engagement terms are public and the first call is a working session.
Frequently asked
Is cold email legal in Austria?
What does TKG Section 174 actually require?
Does GDPR legitimate interest cover Austrian cold email?
What happens if you send cold email into Austria without consent?
Is there a B2B exemption for email marketing in Austria?
How can I prospect into Austrian companies without breaching TKG?
Does using an agency shift the legal risk away from my company?
Does the German cold email rule apply in Austria?
Gilt das auch fuer Oesterreich: ist Kaltakquise per E-Mail erlaubt?
Want the Austrian market handled properly?
We plan the channel mix per market, write in native Austrian German, use publicly available business data and honour every opt-out. You get the accurate picture of the risk, then decide.
Book a strategy call Or get a free target list first