Compliance

Is cold email GDPR-compliant in Europe? (B2B rules for 2026)

Published 18 June 2026 · 7 min read · By Ripe Leads

The short answer

Yes, B2B cold email is legal in the EU. It runs on the GDPR's legitimate interest basis (Article 6(1)(f)) and does not need the prior opt-in that consumer (B2C) marketing requires, as long as you email a relevant professional contact, identify yourself, and provide a clear, honored opt-out.

On this page
  1. The legal basis: legitimate interest, not consent
  2. What "legitimate interest" actually requires
  3. The ePrivacy layer (and the UK difference)
  4. What GDPR-compliant cold email looks like in practice
  5. Where your data comes from matters
  6. Common GDPR cold email mistakes (and the fixes)
  7. How enforcement varies across Europe
  8. Your GDPR cold-email checklist

"Isn't cold email illegal in Europe?" is the objection that scares teams off outbound. It's a myth, but the nuance matters, and getting it wrong is a real risk. Here's the accurate version.

Note: this is general information, not legal advice. For your specific situation, confirm with a qualified data-protection adviser.

GDPR requires a lawful basis to process personal data. For B2B marketing, that basis is legitimate interest under Article 6(1)(f), you don't need prior consent. As the EU guidance on email marketing puts it, where a company has a justified interest, marketing emails may be sent to potential customers without consent.

The hard line is B2B vs. B2C:

AudienceLawful basisConsent needed?
B2B (professional contacts)Legitimate interest, Art 6(1)(f)No
B2C (consumers)Consent, Art 6(1)(a)Yes (prior opt-in)

What "legitimate interest" actually requires

Legitimate interest isn't a free pass, it's a balancing test. To rely on it for cold email you should be able to show:

The ePrivacy layer (and the UK difference)

GDPR sets the data-processing rules; the ePrivacy Directive governs electronic marketing on top of it. In practice, EU member states apply extra protection to individual subscribers, which is why quality targeting and the relevance test matter so much for compliant outreach.

The UK is a common trip-up: under PECR, unsolicited B2B email to corporate bodies (limited companies, LLPs) is generally permitted, but sole traders and partnerships are treated like individuals and need the stricter consumer approach. If you email the UK, segment accordingly before you build the campaign, as our guide to lead generation in the UK sets out.

What GDPR-compliant cold email looks like in practice

Abstract rules become clearer with a concrete pair of campaigns. Picture a warehouse-automation vendor emailing 300 operations directors at mid-sized logistics firms in the Netherlands. Each message names the sender, explains in one line why a logistics operations lead would care, and closes with a one-click opt-out. That campaign passes the legitimate interest balancing test with room to spare: relevant role, professional address, reasonable expectation, minimal impact.

Now picture the same vendor blasting 40,000 scraped addresses, including info@ inboxes, personal Gmail accounts and roles with no connection to warehousing. No sender identity beyond a bare signature, no opt-out link, follow-ups every two days. Same product, same country, but this version fails every limb of the test. The lesson: GDPR compliance in cold email is mostly a targeting and process question, not a legal-paperwork question.

Where your data comes from matters

Legitimate interest covers the sending; it does not launder a bad list. Under GDPR you should be able to say, for any contact, where the record came from and when. Public business registers, company websites, professional profiles and reputable B2B databases all qualify as legitimate sources, and keeping a source log per contact takes minutes to set up. We cover the main options in where European B2B data comes from.

Two habits keep the data side clean. First, refresh lists regularly: a contact who changed jobs eight months ago is no longer a relevant professional contact, and stale records fail the relevance test. Second, run every new list against your suppression list before the first send, so a past opt-out is never re-contacted under a new campaign name.

Common GDPR cold email mistakes (and the fixes)

How enforcement varies across Europe

GDPR is a regulation, so the core is identical in every member state, but the ePrivacy layer is a directive, and each country transposed it with its own accent. Germany and Austria sit at the strict end: German unfair-competition law gives competitors and associations standing to act against unwanted advertising, so DACH campaigns reward tighter targeting and conservative volume. France and the Netherlands read the B2B exception more generously. The Baltics and most of Central Europe follow the mainstream B2B legitimate interest line. Telephone outreach splits even further, because consent rules and do-not-call registers mean the legality of B2B cold calling changes country by country.

For sellers targeting the German-speaking market, the practical answer is not to avoid outbound, it is to run it with precise role targeting, restrained cadence and clean records. As a Vilnius-based agency running campaigns across the EU in German, English, Lithuanian and Russian, we build every campaign to the strictest interpretation in the target country, which also happens to produce better reply rates.

Your GDPR cold-email checklist

Done right, compliant outreach isn't a constraint, it's a competitive edge. Buyers trust senders who are transparent, and clean practices protect your deliverability at the same time.

Frequently asked

Is B2B cold email legal in the EU under GDPR?
Yes. B2B cold email is lawful under the GDPR's legitimate interest basis (Article 6(1)(f)). It doesn't need the prior opt-in that B2C marketing does, provided you email a relevant professional contact, identify yourself, and offer a clear, honored opt-out.
Does GDPR require consent for cold email?
Not for B2B. GDPR allows cold B2B email under legitimate interest without prior consent. B2C cold email does require consent, and ePrivacy rules give individual subscribers extra protection, so relevance and quality targeting matter.
How do you send GDPR-compliant cold email?
Use a valid legal basis (legitimate interest for B2B), email professional addresses about a genuinely relevant offer, say who you are and why, include an easy opt-out in every message, honor it immediately and permanently, and keep records of your data sources.

Sources

  1. GDPR-info.eu, Email Marketing under the GDPR
  2. Overloop, Is Cold Email Illegal? Legal Guide
  3. Salesforce Europe, Legitimate interest for GDPR cold email B2B rules
  4. GDPR Local, GDPR Cold Email Strategy in 2025

Outbound that's compliant by design

We run B2B campaigns on legitimate interest, use publicly available business data, and honor every opt-out, so you grow pipeline without the legal worry.

Book a strategy call