Is cold email GDPR compliant?
In short
Cold email to business contacts can be lawful under GDPR using legitimate interest, but national rules differ and some countries require prior consent regardless.
On this page
The short answer
GDPR itself does not ban B2B cold email. It requires a lawful basis, and for business-to-business outreach that basis is usually legitimate interest, documented in a balancing assessment you carry out and keep.
The complication is that GDPR is not the only law involved. National marketing rules sit on top of it and they are not consistent.
Where national law changes the answer
Germany applies UWG section 7 alongside GDPR and reads it strictly, with penalties reaching into six figures. Poland adds USUDE. Austria has its own telecoms act provision. Switzerland sits outside the EU under revDSG.
A posture that is defensible in the Netherlands may not survive in Germany, which is why a single European approach usually is not one.
What compliance looks like in practice
A documented lawful basis. Business contacts rather than personal addresses. A clear identification of who you are. An easy and immediate way to object, honoured permanently rather than for one campaign. And retention limits you actually apply.
Article 14 also requires telling people where you got their data, which most cold senders omit entirely.
The honest caveat
This is not legal advice, and the differences between member states are the part that catches people out. Have counsel review your approach once for the markets you actually sell into. It is a small cost against the exposure.
Frequently asked
Is cold email legal under GDPR?
Which European countries are strictest on cold email?
What do I have to tell recipients?
Want the accounts behind these numbers?
Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.
Book a strategy call