Pharma

Cold email rules for pharma suppliers selling across Europe

Done-for-you B2B outbound · Original data

In short

Every cold message to a pharma-industry contact in Europe sits under two layers: GDPR, which binds an EU-established sender, Vilnius or Frankfurt alike, regardless of where the recipient sits, and a national send-rule that decides whether that specific email or call needs prior consent. Germany requires consent for email and presumes it for calls to businesses. Poland and Switzerland lean toward consent with narrow, unsettled B2B readings. Ireland and the UK run a genuine opt-out lane for corporate contacts. Lithuania sits on the EU ePrivacy baseline with no stricter overlay. Two cells in the matrix below carry no confirmed position and are marked to check before sending rather than guessed at.

On this page
  1. Two layers apply to every message, wherever you send from
  2. The matrix: what each country expects, by channel
  3. Germany: consent for email, presumed consent for calls to businesses
  4. Poland: no clean carve-out, and a narrow reading in market practice
  5. Switzerland: opt-in by default, no B2B exception
  6. Ireland: the one market with a real corporate opt-out lane
  7. The UK: PECR splits companies from sole traders
  8. Lithuania: the ePrivacy baseline, without a stricter overlay
  9. Using the matrix without a lawyer on every send

Two layers apply to every message, wherever you send from

Every cold message to a pharma-industry contact in Europe sits under two separate layers of law, and confusing them is where most compliance mistakes happen. The first layer is data protection: whose personal data sits behind the contact, and on what legal basis you may hold and use it. The second layer is the rule governing the send itself: whether the country the recipient sits in requires consent before that specific email or call, or allows it on an opt-out basis.

Sender location changes less than most senders assume. A Vilnius agency and a German-based supplier sending from Frankfurt are both EU-established senders, and under GDPR Article 3(1), an EU-established sender's processing is governed by GDPR regardless of where the recipient sits, in Germany, Lithuania or outside the EU entirely. What changes by recipient country is the second layer: the specific national rule on whether that country's contacts may be emailed or called without prior consent. That is the layer the matrix below covers.

The positions below come from this site's own previously published country pages where one exists, for Germany and Poland specifically, and from a dedicated compliance review for Switzerland and Ireland, where the site had not covered either market before. Where neither source states a position clearly, the honest answer is to say so rather than guess, which is why two cells below read "check before sending" instead of a rule.

The matrix: what each country expects, by channel

Recipient countryCold emailCold phone, business number
GermanyPrior express consent required (UWG s.7)Presumed consent for calls to businesses (UWG s.7(2)(1))
LithuaniaLegitimate-interest basis, no prior opt-in for a relevant professional contact (EU baseline)Opt-out position for live calls to business numbers
PolandConsent required in principle (UŚUDE); narrow, role-specific messages argued as outside scope in market practice, unsettledConsent tied to telecom terminal equipment marketing; general company numbers called in market practice, unsettled
SwitzerlandOpt-in required for templated or automated outreach (UWG Art. 3(1)(o)); no B2B exceptionCheck before sending, the directory opt-out register's coverage of business numbers is not confirmed in primary text
IrelandOpt-out basis for genuine corporate-subscriber addresses (Reg. 13, S.I. 336/2011)Landline: opt-out via the NDD register. Mobile: prior consent unless an existing relationship applies
United KingdomOpt-out basis for corporate bodies (PECR); sole traders and partnerships need consentScreen against TPS and Corporate TPS before calling; automated calls need consent regardless

Every row assumes the underlying GDPR question, whether you have a lawful basis to hold and use that person's contact data, is answered separately and is not resolved by the send-rule alone. A country that allows the send on an opt-out basis still requires a documented lawful basis, usually legitimate interest, for holding the contact's personal data in the first place.

Germany applies Section 7 of the Gesetz gegen den unlauteren Wettbewerb, the UWG, to advertising communication. For email, Section 7 treats an advertising message sent without the recipient's prior express consent as impermissible, and German supervisory authorities have taken the position that a GDPR legitimate-interest basis will usually fail its own balancing test once a message already breaches Section 7, so the two layers reinforce each other rather than offering an alternative route. For live phone calls, Section 7(2)(1) sets a lower bar, presumed consent tied to the called company's own interest, which is why a call to a German business switchboard, on-topic and clearly identified, sits on firmer ground than the equivalent cold email.

Poland: no clean carve-out, and a narrow reading in market practice

Poland's Ustawa o świadczeniu usług drogą elektroniczną, the UŚUDE, ties sending unsolicited commercial information by electronic means to the recipient's prior consent, and the statute does not carve business recipients out the way some other jurisdictions do. Market practice in Poland has settled on a narrower reading for genuinely individual, role-relevant messages, sent to a specific person about their specific professional responsibilities rather than styled as mass advertising, as arguably falling outside "unsolicited commercial information." That reading is interpretation and risk management, not a settled legal position, and the same caution applies to Polish phone rules, where general published company numbers are called in market practice under a similar argument. A narrow, well-targeted list defends itself better than a broad one under either reading.

Switzerland: opt-in by default, no B2B exception

Switzerland sits outside the EU and outside GDPR's territorial default, but an EU-established sender, Vilnius or Frankfurt alike, remains bound by GDPR for the Swiss contact's personal data under Article 3(1) regardless. The Swiss send rule itself, Article 3 paragraph 1 letter o of the Federal Act against Unfair Competition, requires opt-in consent for mass or automated advertising communication, and Swiss unfair-competition law draws no B2B or B2C line the way German or Irish rules do. A narrow existing-customer exception exists, but it does not cover a contact sourced cold from a register or a list. For phone, a directory asterisk mechanism blocks unsolicited advertising calls absent a live business relationship; whether that mechanism covers a business's own published number, as opposed to a personal line, was not confirmed against Swiss primary legal text in the research behind this page. Check before sending on that specific point.

Ireland: the one market with a real corporate opt-out lane

Ireland implements the ePrivacy Directive through Regulation 13 of S.I. No. 336 of 2011, and draws a real line between individual subscribers, opt-in by default, and corporate subscribers, opt-out by default. A genuine business or functional email address, contacted about a message that relates solely to that commercial activity, falls on the opt-out side: no prior consent is required for the send, provided the sender's identity is never disguised and a working opt-out is offered in every message. That opt-out basis covers only the act of sending. The underlying GDPR question, the lawful basis for holding that person's contact data, is a separate one, usually resolved through a documented legitimate-interest assessment alongside it.

Phone follows a different split entirely, landline against mobile rather than personal against business: landline numbers can be screened against the National Directory Database's opt-out register before calling, and mobile numbers need prior consent unless an existing relationship already exists.

The UK: PECR splits companies from sole traders

The UK kept GDPR after leaving the EU and layers the Privacy and Electronic Communications Regulations, PECR, on top of it. For email, PECR treats corporate bodies, limited companies and LLPs, as fair game for unsolicited B2B marketing without prior consent, but sole traders and ordinary partnerships are treated like individual consumers and need the stricter opt-in approach, so a UK list has to be segmented by legal form before it goes anywhere. For phone, the UK runs the most heavily registered system in this matrix: live marketing calls must be screened against the Telephone Preference Service and the Corporate Telephone Preference Service before dialling, automated or recorded calls need prior consent regardless of the number called, and the Information Commissioner's Office has a long enforcement record in this specific area.

Lithuania: the ePrivacy baseline, without a stricter overlay

Lithuania implements the same ePrivacy structure as its Baltic neighbours: consent for automated dialling, SMS and email marketing under the general ePrivacy transposition, sitting alongside GDPR's own legitimate-interest basis, which is the route B2B email to a relevant professional contact runs on in practice, consistent with the EU baseline this site applies generally. Live calls to a business number sit on an opt-out footing, with no separate national overlay comparable to Germany's UWG or Poland's UŚUDE. Lithuania carries no stated exception on this site the way Germany, Poland and the UK do, which is itself informative: the smaller Baltic markets run closer to the EU default than the larger ones, and the practical discipline that matters most here is reputational rather than statutory, because a badly targeted campaign in a market this size is remembered.

Using the matrix without a lawyer on every send

None of this replaces legal advice for a specific campaign, and the pinpoint citations above, sub-paragraph numbers, specific articles, are given at the level the underlying research could actually verify against primary sources; two of them, the Swiss asterisk register's coverage of business numbers and one Irish sub-paragraph reference, could not be confirmed against primary legal text and are flagged as such rather than asserted. The practical discipline that works across every row in the table is the same regardless of the legal detail: identify the sender clearly in every message, honour an opt-out or a refusal immediately and permanently, keep the list narrow and genuinely relevant to the recipient's role, and treat email and phone as separate decisions with separate rules, not one compliance question answered once for both.

Frequently asked

Do the same cold email rules apply whether I send from Lithuania or Germany?
The recipient-country send rule, whether that country needs prior consent, is the same either way. What is identical regardless of sender location is the GDPR layer: an EU-established sender, in Vilnius or Frankfurt, is bound by GDPR for a contact's personal data under Article 3(1) no matter where that contact sits.
Is cold email to Germany harder than cold calling?
Under the positions on this site, yes. Germany's UWG Section 7 requires prior express consent for advertising email, while Section 7(2)(1) sets a lower bar of presumed consent for phone calls to businesses, so a call to a German business switchboard sits on firmer ground than the equivalent cold email.
Can I cold call a Swiss company's published business number?
This page cannot confirm it either way. Switzerland's directory-based opt-out mechanism for unsolicited calls was found described in individual or consumer terms in the sources reviewed, and whether it extends to a company's own published number was not confirmed against Swiss primary legal text. Check before sending.
Which countries in this matrix allow cold email without prior consent?
Ireland and the UK, for genuine corporate-subscriber or corporate-body addresses specifically. Ireland's Regulation 13 puts corporate subscribers on an opt-out basis; the UK's PECR treats limited companies and LLPs the same way, while sole traders and partnerships in the UK need the stricter consent-based approach.
Does Poland have a clear B2B exception for cold email like Ireland or the UK?
No. Poland's UŚUDE ties unsolicited commercial email to prior consent without a general business carve-out. Market practice treats a narrow, individually addressed, role-relevant message as arguably outside that requirement, but that is interpretation and risk management, not settled law.

Want the accounts behind these numbers?

Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.

Book a strategy call