Ask ten sales leaders whether cold email is legal under GDPR, and you will get at least three different answers, usually somewhere between “it is completely banned” and “it is fine as long as you add an unsubscribe link.” Neither answer is accurate, and the gap between them is exactly where most B2B teams either get overly cautious and stop outbound entirely, or get careless and expose themselves to real risk.
GDPR does not ban cold email. It sets conditions under which sending one is lawful, and those conditions are specific enough to follow deliberately, rather than guessing at.
This is not legal advice, and GDPR enforcement involves country specific nuance that changes over time. Treat this as a practical starting point, and involve a lawyer or data protection advisor for anything client facing or high risk.
The Legal Basis Most B2B Teams Actually Use
Every use of personal data under GDPR needs a lawful basis. For B2B cold email, that basis is almost always legitimate interest under Article 6(1)(f), not consent. Requiring consent before a first cold email would make cold outreach impossible by definition, which is not what the regulation intends. GDPR’s own recitals acknowledge direct marketing as a legitimate interest in principle.
Legitimate interest is not a blanket permission, though. To rely on it properly, you need to work through what is generally called a Legitimate Interest Assessment, or LIA, covering three questions:
Purpose test
Is there a genuine business reason for this specific outreach, not just a general desire to grow the business? A relevant, specific reason for contacting this particular company and role holds up. A generic justification that could apply to literally anyone does not.
Necessity test
Is sending this message actually necessary to achieve that purpose, or is there a less intrusive way to reach the same goal? For most B2B prospecting, direct outreach genuinely is necessary, since there is rarely a workable alternative for initiating contact with a new potential customer.
Balancing test
Does the recipient’s right to privacy outweigh your business interest in this specific case? This is where relevance matters most. A message sent to someone in a role clearly connected to what you are offering, at a reasonable frequency, is easier to justify than a broad, irrelevant blast sent to every contact you could find at a company.

Running through this assessment, and documenting that you did it, is the actual compliance work. Most of the risk in this area comes from skipping the assessment entirely, not from getting a borderline judgment call wrong.
What This Looks Like in Practice
Target relevance, not just reachability
Contact people whose role is genuinely connected to what you are offering. A message about enterprise data infrastructure sent to a marketing coordinator is harder to justify under legitimate interest than the same message sent to a data or engineering lead, even if both addresses were sourced identically. This is the same discipline behind building any clean, targeted B2B prospect list: relevance has to be built in at the sourcing stage, not patched on afterward.
Use professional contact information tied to the person’s role
A work email address, used to discuss something relevant to that person’s job, sits more comfortably under legitimate interest than a personal address or a role clearly unrelated to your offer.
Disclose where the data came from
If you did not collect the contact’s information directly from them, GDPR expects you to be able to tell them where it came from if asked, and in some cases proactively. Being able to say clearly that an address came from a company website, a professional directory, or a specific data provider matters more than most teams realize — which is one more reason bad prospect data is a compliance problem, not just a deliverability one.
Make opting out immediate and genuinely easy
A working, one click way to stop receiving messages, honored promptly and permanently, is not optional. Suppression needs to actually work across every tool in your stack, not just the one campaign where someone clicked unsubscribe.
Keep a record
Being able to show that you completed an LIA, that your data sourcing is documented, and that suppression requests are tracked and honored is what separates a defensible compliance position from an assumption that everything is probably fine.
Watch sending volume and frequency per contact
Sending occasional, relevant messages sits differently under the balancing test than sending a high volume of unrelated pitches to the same person across multiple campaigns run by different parts of the business. Volume discipline matters for the same reason it matters for protecting your sending domain — a heavy, unfocused send pattern raises both compliance risk and spam risk at the same time.
What to Avoid
Buying or scraping bulk consumer style lists without a clear source
Lists with unclear origins, or ones that mix personal and professional contacts indiscriminately, make both the necessity test and the data source disclosure requirement much harder to satisfy.
Generic, high volume blasts with no role relevance
A message sent to every contact at a company regardless of title weakens the purpose and balancing tests significantly, since it signals volume over genuine relevance. It is also exactly the pattern that tends to trigger inbox provider spam filtering, so the same discipline protects you on both fronts.
Ignoring or delaying opt out requests
This is one of the more common and most avoidable violations, and it tends to draw complaints even when the original outreach itself was reasonably compliant.
Untracked tracking pixels
Open tracking collects data about the recipient, which means it needs to be disclosed rather than run silently in the background without any mention of it.
Treating one country’s rules as the EU standard
This is the mistake that catches the most experienced outbound teams, and it deserves its own section.

Why “EU Compliant” Is Not One Standard
GDPR sets a baseline across the EU, but the ePrivacy rules that govern electronic communication specifically are implemented differently by individual member states, and enforcement culture varies meaningfully by country. A campaign built to a single, uniform “EU compliant” standard is often either too cautious for some markets or too loose for others.
Germany is consistently the strictest market for outbound in practice. Unfair competition rules there set a high bar for what counts as a reasonably presumed interest, and both cold email and cold calling require a strong, demonstrable case for relevance. Teams that succeed with outbound in the DACH region tend to treat legitimate interest as a floor, not a target, leaning heavily on genuine, specific personalization rather than templated sequences.
France, by contrast, takes a more permissive practical stance for B2B specifically. The French data protection authority has been explicit that prior consent is not required for B2B outreach connected to the recipient’s professional role, which gives more room for standard cold email practices than the German approach allows.

The practical implication for any agency or team running outbound across multiple EU countries: build your baseline process to the stricter end of this range, and treat looser markets as room to move faster, rather than building to the most permissive market and hoping it holds up everywhere else. This is the same logic behind entering a new market with cold outreach generally — the compliance bar is just one more variable that shifts by geography and needs to be planned for before the first send, not discovered after one.
FAQ
Yes, with conditions. GDPR does not require consent for B2B cold email in most cases; it relies on the legitimate interest basis under Article 6(1)(f). What it requires is that you can show a genuine purpose, that outreach is necessary, and that the recipient’s privacy interests do not outweigh your business interest — the three-part Legitimate Interest Assessment described above.
Generally no, for B2B outreach connected to someone’s professional role. Consent is the standard for direct-to-consumer marketing under ePrivacy rules, but B2B cold email typically relies on legitimate interest instead. The exception is markets with stricter national interpretations, where the practical bar for what counts as a defensible interest is higher.
No. GDPR itself is EU-wide, but the ePrivacy rules governing electronic communications are implemented at the national level, and enforcement culture varies by country. Germany applies a notably stricter standard in practice than markets like France, which has given explicit guidance that is more permissive for B2B outreach.
Skipping the Legitimate Interest Assessment entirely rather than running it and documenting the result. Most compliance risk comes from having no defensible answer to why a specific contact was targeted, not from a borderline judgment call made in good faith.
The Actual Takeaway
GDPR compliance for cold email is not about adding a footer disclaimer and calling it done, and it is not about avoiding outbound entirely out of caution either. It is about being able to answer three questions clearly for any campaign you run: why this specific contact, why is this necessary, and does this respect their rights enough to justify the outreach. Teams that can answer those questions with specifics, and that have the documentation to back it up, are in a genuinely defensible position. Teams that cannot are exposed regardless of how many unsubscribe links they have added.
If your current process cannot produce clear answers to those three questions for a campaign you are running right now, that gap is worth closing before volume, not after a complaint forces the issue. If you would rather have your outbound process built compliantly from the start, get in touch and we can walk through how we structure EU campaigns for exactly this.
This article provides general information and does not constitute legal advice. For guidance specific to your campaigns and data processing activities, consult a qualified data protection professional or lawyer.