Is cold email legal in Germany? GDPR and the UWG, explained
The short answer
Germany is the strictest large market in Europe for advertising email. GDPR can supply a processing basis through legitimate interest, but a second law sits on top of it: Section 7 of the UWG treats advertising email sent without the recipient's prior express consent as an unreasonable nuisance, with no general carve-out for business recipients. Unsolicited B2B cold email to German companies therefore carries genuine legal exposure, mostly civil rather than regulatory, and no honest operator can call it safely lawful. This page is general information, not legal advice.
Every team that sells into DACH eventually asks the same question, usually after someone forwards them a horror story about a warning letter. The answer is more specific than "yes" or "no", and the specifics decide how you should run outbound in Germany at all.
Note: this is general information for orientation, not legal advice, and it is not a compliance opinion on your situation. German advertising and data protection law turns on facts and on case law that moves. Before you send anything into Germany, get a written view from a qualified German lawyer or data protection adviser.

Why Germany is different from the rest of Europe
Most European markets let B2B senders work from a single question: do you have a valid GDPR basis for processing the contact data. In Germany you have to answer two questions, and the second one is harder.
The first layer is the GDPR. Article 6(1)(f) allows processing where you have a legitimate interest that is not overridden by the rights of the person concerned, and Recital 47 acknowledges direct marketing as a possible legitimate interest. That is the layer we cover across the continent in our guide to GDPR-compliant cold email in Europe.
The second layer is national competition law. The Gesetz gegen den unlauteren Wettbewerb, the UWG, governs unfair commercial practices. Section 7 of the UWG is the German implementation of the ePrivacy Directive's rules on unsolicited communications, and it is where cold email in Germany runs into trouble.
What does UWG Section 7 actually say about email?
Section 7 declares commercial communications that unreasonably harass a market participant to be impermissible, and it then lists cases that always count as unreasonable harassment. Advertising sent by electronic mail without the addressee's prior express consent is on that list.
Two features of that wording matter more than anything else you will read on the subject.
- The consent standard is express and prior. Not implied, not inferred from a published address on a company website, not assumed because the offer is obviously relevant. German practice generally expects a documented, informed, specific opt-in, typically captured with a confirmed double opt-in so the sender can prove it later.
- There is no general B2B exemption. For telephone advertising, Section 7 distinguishes consumers, who need express consent, from other market participants, where at least presumed consent can suffice. For electronic mail that distinction is absent. A purchasing manager's work address receives the same protection as a private one.
The narrow exception is the existing-customer rule in the same section. Where you obtained an address in connection with selling goods or services to that customer, you may advertise your own similar goods or services to it, provided the customer has not objected and is told clearly at collection and in every message that they can object at any time at no cost beyond transmission rates. That is a real and usable exception, but it is an exception for customers, not for prospects.
Does GDPR legitimate interest override the UWG?
No, and the sequence is what people get wrong. Legitimate interest answers whether you may hold and use the personal data. The UWG answers whether the advertising act itself is permitted. Clearing the first does not clear the second, and the second is the stricter one in Germany.
German supervisory authorities have gone further and joined the two together. Their published guidance on direct marketing takes the position that where an email breaches Section 7 of the UWG, the balancing test under Article 6(1)(f) will normally fail as well, because a recipient cannot reasonably expect a message that competition law prohibits. Under that reading, a Section 7 problem becomes a GDPR problem too.
Who enforces this, and what does it cost?
In Germany the first knock on the door usually comes from a private party rather than a regulator, which surprises teams used to thinking about data protection fines.
- The Abmahnung. A formal warning letter from the recipient, a competitor or a competition association, demanding that you sign a cease-and-desist undertaking and reimburse the legal costs of sending it. This is the common outcome and it is fast.
- The undertaking that follows you. Signing a cease-and-desist undertaking normally binds you to a contractual penalty for any repeat. One stray follow-up to that address years later can trigger it, which is why suppression discipline matters so much afterwards.
- Civil injunction claims. German courts have long treated unsolicited advertising email as an interference with the recipient's protected sphere, including a company's established business operation, and have granted injunctions over a single message.
- The data protection side. A supervisory authority can act separately under the GDPR, on complaint or on its own initiative, with the usual range of orders and fines.
On the money: the UWG's administrative fine provision is aimed at unlawful telephone advertising to consumers rather than at email, so the direct email exposure is mainly civil cost and injunction risk rather than a headline regulatory penalty. Reported Abmahnung costs vary widely with the value in dispute and the counsel involved, from a few hundred euros to several thousand, before any contractual penalty. Treat any quoted figure as an illustration, not a forecast.
So why do companies still send cold email in Germany?
Because plenty do, and the honest reason is risk appetite rather than a legal loophole. The gap between what the statute says and what happens in practice is real: most unsolicited business emails do not produce a warning letter, and many German sales teams run outbound quietly.
That is an argument about probability, not about lawfulness, and it should be stated that way in front of a client. The exposure is a low-frequency, non-trivial-cost event. Volume increases the number of draws you take, irrelevance increases the chance any single recipient reacts badly, and legal-adjacent recipients are the classic source of an Abmahnung. If a supplier tells you German cold email is fine because everyone does it, that is a red flag about how they will handle everything else.
Per-channel risk in Germany, ranked
Once you accept that email is the constrained channel, the planning question becomes which channels carry which exposure.
- Email without consent: the highest exposure of the digital channels, for the reasons above.
- Telephone: more workable for B2B than for consumers, because Section 7 allows at least presumed consent for calls to other market participants. Presumed consent is not a free pass. It has to rest on concrete indications that the specific business would be interested in this specific offer, and a generic list-dialling campaign will not carry it.
- LinkedIn and business networks: commonly treated as lower risk, and not settled. German courts have shown willingness to apply the same nuisance reasoning to advertising messages on social and business platforms. Lower risk, not exempt.
- Postal mail: the least restricted channel for advertising to businesses, subject to data protection duties and the recipient's right to object. Slow and expensive per contact, but it exists.
- Events, referrals and content: no unsolicited-message problem, and the natural way to build the consented list that makes email usable later.
Why many operators run LinkedIn-first in Germany
Put those rankings together and the DACH playbook writes itself. LinkedIn is where German buyers already accept professional approaches, the platform's own rules do the volume limiting for you, and a connection plus a short relevant message avoids the specific act that Section 7 names.
The sequence most experienced teams use looks like this: identify a tight account list, approach the named decision maker on LinkedIn in German, earn a conversation, and only then move to email with the recipient's agreement. Consent captured that way is documented and specific, which is what makes it worth having. Content, webinars and events feed the same list from the other direction.
This is slower than blasting a bought list, and it produces better meetings, which is roughly the trade every strict market forces on you. Our market notes on B2B lead generation in Germany and the wider DACH region cover the commercial side of that trade.
What lower-risk German outbound looks like in practice
None of the following makes cold email lawful in Germany, and nobody should present it as a compliance shield. It reduces the chance of a complaint and limits the damage if one arrives.
- Write in German. Formal German, correct Sie-form, and a real person's name. English-language mass mail reads as a foreign blast and gets treated like one.
- Keep volumes small and targeting tight. A hundred researched accounts beat ten thousand scraped rows on every axis, including this one.
- Make the relevance obvious in the first two lines. If a recipient can see instantly why they specifically were contacted, the message reads as business correspondence rather than spam.
- Identify yourself fully. Company, legal entity, address, sender name, working reply address. Anonymity turns an annoyed recipient into a complainant.
- Honour every opt-out immediately and permanently, across all sending domains and all future campaigns, with a suppression list that survives tool changes.
- Use publicly available business data and keep a record of where each contact came from, so you can answer the question when it is asked.
- Stop the moment someone objects, and skip the apology follow-up. The apology is another message.
Does using an agency move the legal risk?
Not away from you. Under German unfair competition law the business that benefits from the advertising is generally answerable for acts carried out by the people and firms it engages, so the client whose offer is being promoted stays in the frame alongside the sender. Any agency that pitches "we take the compliance risk" is describing something German law does not readily allow.
What you can reasonably expect from a provider is different: named sending domains you own, full visibility of the copy and the list before anything goes out, documented data sources, immediate opt-out handling, and a written channel recommendation per market. Ask to see all of it before signing, the same way you would with any other red-flag checklist.
How we handle Germany
Ripe Leads runs native German campaigns from Vilnius, and we treat Germany as its own plan rather than one slice of a DACH-wide send. We work from publicly available business data on a legitimate interest basis, honour opt-outs permanently, and set the channel mix per market with the German position on email stated plainly rather than buried. Where a client wants to reach German companies, we set out the options and the exposure attached to each. The final call on risk belongs to the client and their counsel, not to us. Our pricing and engagement terms are public and the first call is a working session.
Frequently asked
Is cold email legal in Germany?
Does GDPR legitimate interest cover cold email in Germany?
What happens if you send cold email in Germany without consent?
Is LinkedIn outreach safer than cold email in Germany?
Want the German market handled properly?
We plan the channel mix per market, write in native German, use publicly available business data and honour every opt-out. You get the accurate picture of the risk, then decide.
Book a strategy call