We get asked this more than any other question, usually in the same shape: is cold email actually allowed in Europe, or is everyone quietly breaking the law? It's a fair thing to want settled before spending money on outbound.

The honest answer is that it depends which country you're sending into, and that the confident articles you'll find — the ones with a neat table of green ticks and red crosses — mostly contradict each other and, in several cases, contradict the regulators they claim to summarise. We checked. Three of the comparison tables we read place France in the strict column; France's own data protection authority says the opposite.

Before anything else

We run outbound for a living. We are not lawyers, and this is not legal advice — it's what the regulators say and how careful operators behave, current as of July 2026. The UK penalty position in particular changed in February 2026. If you're sending at volume into a market you don't know, pay someone qualified for an hour.

Why there is no single European answer

The rule that decides whether you may send a marketing email doesn't come from GDPR. It comes from the ePrivacy Directive of 2002, as amended in 2009. And the word that matters there is directive.

A regulation applies directly and identically across the EU. A directive is written into each member state's own law, 27 different ways.

GDPR is a regulation, which is why it feels uniform. ePrivacy is a directive, which is why cold email doesn't — and here the divergence isn't accidental. Article 13(5) applies the consent rule only to subscribers who are natural persons, and expressly leaves the protection of business subscribers to each member state. Article 13(3) then lets each country choose opt-in or opt-out for everything the consent rule doesn't cover. The fragmentation is built into the instrument. It isn't a failure to implement it, which is also why no court is going to tidy it away.

This was meant to be fixed. An ePrivacy Regulation was proposed in 2017 to harmonise the rules, and it never got agreement. The Commission listed it for withdrawal in its 2025 work programme in February 2025 — the stated reason being that no agreement was expected from the co-legislators and the proposal had been overtaken by later legislation — approved the withdrawal in July, and formally withdrew it in the Official Journal on 6 October 2025. So the fragmentation isn't a transitional state anyone is about to tidy up. The 2002 Directive stays, and it's worth planning around rather than waiting out.

1 · The two questions everyone merges

Almost every argument about this topic comes from collapsing two separate questions into one. Keeping them apart makes the rest straightforward.

You need to satisfy both, and they aren't independent. Passing the first does nothing for the second — but failing the second contaminates the first. Where national law requires consent for marketing email, the argument that legitimate interest covers the underlying processing tends to fall with it — Italy's regulator rejected exactly that reasoning in a published decision, on the ground that promotional email is governed by the special regime rather than the general one. So in Germany you don't have an impeccable GDPR position alongside an unlawful send; you have an unlawful send and a legal basis that went with it. It runs the other way too: a message to a pure role address that identifies nobody can be an ePrivacy question with no GDPR question attached at all.

What this means for you

When someone tells you outbound is "GDPR compliant", they've answered the easier question. Ask which country's marketing rule they're relying on and what it says.

2 · Legitimate interest: what it buys, and what it doesn't

This is the single most repeated claim in outbound, and it's half right — which is exactly why it spreads. The claim is that GDPR's Recital 47 blesses direct marketing as a legitimate interest, so B2B cold email is fine across Europe.

What Recital 47 actually says is that processing for direct marketing purposes may be regarded as carried out for a legitimate interest. Permissive, not determinative. It's also a recital rather than an operative article — it shapes how the law is read, but it isn't itself a permission. "May be regarded as" is doing a lot of work in that sentence: it makes direct marketing a candidate for legitimate interest, not an automatic one.

Where legitimate interest genuinely helps is the first question — your basis for holding and using the data. To rely on it you need to actually do the three-part test: a real and specific interest, evidence that the processing is necessary for it, and a balance against the recipient's rights that accounts for what they'd reasonably expect. Regulators expect you to have written that down before you started, not after a complaint arrives.

Where it doesn't help at all is the second question — and worse, the second question can take the first down with it. In countries that require consent for marketing email, a flawless assessment changes nothing about the send, and the argument that legitimate interest covers the processing behind it tends to fall at the same time.

Italy's regulator made this unusually clear in a 2023 decision against a company emailing construction professionals: it rejected the legitimate-interest argument as inapplicable to the email channel, and added that offering an unsubscribe link didn't fix the problem, because the sending of the email was itself unlawful.

What this means for you

In the opt-out countries, do the legitimate interests assessment and keep it — you'll need it. Just don't mistake it for permission to send. And in the consent countries it isn't the document you need; consent is.

3 · Where the line actually falls

We're deliberately not publishing a country table. Every competitor has one, they disagree with each other, and the disagreements aren't at the margins — we found the same country listed as both permissive and strict in different tables, and both were presented with total confidence.

So here are the countries where the position is clear from the regulator's or the statute's own words, and nothing beyond that.

Consent required, with no B2B carve-out. Germany is the canonical example, and unusually the rule sits in unfair-competition law rather than data protection: unsolicited advertising by email counts as unreasonable harassment, and unlike the equivalent telephone provision — which accepts presumed consent from business recipients — the email rule makes no such distinction. Italy requires consent, and its regulator rejected the standard outbound argument in a published 2023 decision. Spain's e-commerce law requires prior express consent and draws no B2B distinction at all. A separate Spanish provision on business contact data is frequently cited by outbound vendors as authorising cold email; it does no such thing, because it presumes a legitimate interest in processing professional contact data for dealings with the employer and says nothing about permission to send. Austria requires prior consent for email advertising to every recipient, business customers included.

All four have a narrow existing-customer exception — an address you obtained during a sale, used to market your own similar products, with a free opt-out offered at collection and in every message. It's real and worth using where it applies. It does nothing for cold outreach, because it requires a prior sale to the person you're emailing.

Permitted to business recipients on an opt-out basis. France — genuinely, despite what several comparison articles claim. CNIL's position is consent for individuals, and legitimate interest with a right to object for professionals, on two conditions: the message must relate to the recipient's professional activity, and they must have been informed and able to object. Generic role addresses belonging to a company sit outside the consent rules entirely, because the statutory prohibition is limited to prospecting a natural person. Ireland permits email to non-natural persons on an opt-out basis, with a valid opt-out address in every message — and goes further, carving work addresses of named individuals out of the consent rule too, where the message relates solely to their professional activity. The UK is permissive on a different mechanism again, and gets its own section below.

For everywhere else — including the Netherlands, Poland, the Nordics and the rest — we found sourcing we weren't confident enough to publish. That's not a gap we're going to fill with a guess, because a guess is exactly what got the comparison tables into trouble. Check locally, or work to the strictest standard in your footprint.

What this means for you

If you're sending across Europe from one playbook, the playbook has to satisfy the strictest country in it. The alternative is segmenting your campaigns by jurisdiction, which is more work but usually cheaper than losing a market.

4 · The UK: permissive, with two traps

British rules turn on who holds the contract for the communications service — the subscriber. The consent requirement applies to individual subscribers. A company is a corporate subscriber, so unsolicited marketing email to a business address sits outside it. That makes the UK one of the easier places in Europe to run B2B outbound.

Two things routinely catch people out.

Sole traders and ordinary partnerships are individual subscribers. Scottish partnerships are the exception — they have their own legal personality and count as corporate. The corporate exemption doesn't cover the rest, and in our experience most bought lists contain plenty of one-person consultancies. That part of your list sits under a different rule than the rest, and needs consent or the soft opt-in rather than the corporate exemption.

The exemption is about consent, not about everything else. A named person at a company is still a person, so UK GDPR applies in full to that record — including the right to object to direct marketing, which is absolute. There's no balancing, no legitimate interest argument that survives it. If they say stop, you stop. Separately, the rules on identifying yourself and providing a working opt-out apply to every marketing email regardless of who's receiving it.

One thing that did change: as of 5 February 2026 the maximum penalty under the UK's electronic marketing rules rose from £500,000 to the UK GDPR level — for an undertaking, £17.5 million or 4% of total annual worldwide turnover, whichever is higher. The B2B position wasn't touched. The ceiling for getting the individual-subscriber cases wrong went up roughly thirty-five-fold.

5 · What you owe everywhere, whatever the local rule

These don't depend on consent versus legitimate interest, or on which country you're in. If you do nothing else in this article, do these.

That last point deserves its own paragraph, because it's the obligation outbound teams breach without realising. When you didn't collect the data from the person — bought, scraped, enriched, or reconstructed from a naming pattern — GDPR requires you to give them transparency information, and the deadline is at the latest at the time of your first communication with them. For cold outreach, the first email is that communication. The required content includes who you are, why you're contacting them, your legal basis, their rights including the right to object — and the source of the data.

In practice that's a three or four line block at the foot of the first email, plus a link to a proper privacy notice. Most senders have every part of it except the source disclosure. Adding "we found your details on your company website" costs nothing and is the difference between complying and not.

One genuine relief compared with the United States: there's no ePrivacy or GDPR equivalent of the CAN-SPAM requirement to put a physical postal address in the email. You need a valid route to opt out, not a street address. National e-commerce and imprint rules can still require your address to be identifiable — Germany's are the strictest — so most senders include one anyway. It costs nothing and covers you if a recipient turns out to be American.

What this means for you

Four lines in the footer of your first email — who you are, why them, where you got the address, how to stop — covers most of what's mandatory anywhere in Europe. It is genuinely that cheap.

6 · Enforcement reality — and the thing that actually bites

We'd rather give you the numbers than imply a risk the evidence doesn't support.

Enforcement specifically against B2B cold email is rare. France's regulator received 20,150 complaints across all subjects in 2025, and issued ten sanctions relating to prospecting of any kind, commercial or political. In the UK we went looking for a fine issued for cold email to corporate subscribers and couldn't find one — which is unsurprising, since the consent rule doesn't apply to them.

What French enforcement has concentrated on is data bought from brokers without valid consent — and it has hit both ends of that transaction. Solocal Marketing Services was fined €900,000 in May 2025 and Foriou €310,000 in January 2024, both for prospecting on broker-sourced data. The scraper Kaspr was fined €240,000 in December 2024 for building such a database in the first place. Buying your list doesn't move the risk onto the seller; it spreads it across both of you.

Two exceptions worth knowing. Germany is enforced privately rather than by a regulator: competitors and recipients issue cease-and-desist notices with cost-shifting, and a single email can trigger one. A January 2025 Federal Court of Justice ruling held that an unwanted marketing email doesn't by itself prove damage under GDPR, which killed the routine flat-rate claims of a few hundred euros per email. Injunctions and warning-letter costs are untouched. Cheaper, not safe. And in the UK, low enforcement frequency now sits alongside that thirty-five-fold higher ceiling.

But here's the part that actually governs behaviour, and it isn't a regulator at all.

Gmail and Yahoo enforce most of the same rules, in days rather than years, and they don't send warning letters.

Bulk senders face a spam-complaint ceiling of 0.30%, with Google saying to keep it under 0.10% and never reach 0.30%. It's reported in Postmaster Tools, and it moves fast. Yahoo requires unsubscribes honoured within two days; Google recommends 48 hours. Both want one-click unsubscribe headers and a visible link in the body. Regulatory tolerance is measured in thousands of complaints over months; mailbox-provider tolerance is measured in dozens over days.

Which produces a practical argument that has nothing to do with law. A reply-based opt-out — "just reply STOP" — is legal in most of Europe, and it's the worse operational choice. It's invisible to mailbox providers and needs manual handling. A proper unsubscribe header gives an irritated recipient a low-friction alternative to the spam button at the exact moment they're deciding, and converts a complaint into an unsubscribe. Offer both. The deliverability side of this is covered in cold email deliverability.

One under-discussed wrinkle: open-tracking pixels aren't covered by the marketing rules but are covered by the same rules as cookies — which apply to business recipients too. The B2B exemption everyone relies on gives you nothing there.

7 · What to do on Monday

Ranked by what actually reduces risk per hour spent.

  1. Add the four lines to your first email. Who you are, why them, where you got the address, how to stop. Half a day including the privacy notice.
  2. Check your suppression list survives everything. New data purchases, list re-enrichment, tool migrations, client offboarding. If a contact who objected in January can reappear in March's list, that's the breach most likely to be noticed and evidenced.
  3. Segment by country, or run to the strictest standard in your footprint. If Germany, Italy, Spain or Austria are in scope, they set the bar.
  4. Flag sole traders and ordinary partnerships if you're sending into the UK on the corporate-subscriber basis — they sit outside it, and need consent or the soft opt-in instead.
  5. Write the legitimate interests assessment, dated, before the next campaign — in the countries where legitimate interest is the basis you're relying on. It's an afternoon, and the UK's regulator publishes a template.
  6. Ask your data supplier where the records came from, per field, and get it in writing. "Publicly available" is not a lawful basis, and you're the one responsible for your own sending — see B2B data for outbound.
  7. Turn on one-click unsubscribe headers if you haven't. It's the cheapest deliverability and compliance win in the list.

The takeaway

Cold email is lawful in much of Europe and unlawful in a meaningful part of it, and the boundary follows national transposition rather than anything you'd guess from a map. GDPR decides whether you may hold the data; national law decides whether you may send. Legitimate interest answers the first question well and the second not at all.

What's genuinely mandatory almost everywhere is small: identify yourself, give a working way to stop, honour objections permanently, and tell people where you got their address. Four lines and a suppression table. The rest is knowing which country you're in.

And the honest framing on risk: a regulator probably won't fine you. Google and Yahoo will absolutely throttle you, within days, for the same behaviours. That's usually the more persuasive argument for doing this properly.

Free checklist

The compliance one-pager

The European Cold Email Compliance Checklist — what goes in the footer, what your suppression list must survive, what to ask a data supplier, and which countries set the bar. One page, printable.

No spam — just the occasional outbound insight. Unsubscribe anytime.

FAQ

Is cold email legal in Europe?+
There is no single European answer, because the rule for sending marketing email comes from the ePrivacy Directive, and a directive is written into each member state's own law — plus the UK, which kept its version after Brexit. Some countries permit unsolicited B2B email on an opt-out basis, including France, the UK and Ireland. Others require prior consent with no B2B carve-out, including Germany, Italy, Spain and Austria — though all four have a narrow existing-customer exception that cold outreach can't use. Anyone offering one EU-wide answer is describing their own country or guessing.
Does legitimate interest make B2B cold email legal under GDPR?+
It can make the processing lawful, which is a different question from whether you may send. GDPR governs holding and using the contact data; the permission to send marketing email comes from national ePrivacy law. In countries that require consent for email, a well-documented legitimate interests assessment does not make the send lawful — Italy's regulator said exactly that in 2023, and added that including an unsubscribe link does not cure it.
Do I need consent to email a named person at a company?+
It depends on the country, and on two separate questions that are often merged: who holds the contract for the email service, and whether the address is personal data. In the UK, a named employee at a limited company is still a corporate subscriber, so the consent rule doesn't apply — but UK GDPR applies in full, including an absolute right to object. In France the distinction that matters is different again: role addresses like info@ sit outside the consent principles, named individuals rely on the right to object.
What must a cold email include in Europe?+
Your real identity as sender, a valid address or mechanism for the recipient to ask you to stop, and — where you didn't get the data from the person — the transparency information required by GDPR Article 14, at the latest in your first message. That includes telling them where you got their details, which is the part almost everyone omits. Unlike the US CAN-SPAM Act, there is no European requirement to include a physical postal address.
Share — LinkedInXCopy link