Lead Radary
BlogPricing
Start free

Is Cold Email Legal in Europe? A Country-by-Country Guide for 2026

By Max Swillo·Published 2026-08-07·5 min read

B2B cold email is legal in most of Europe, but the rules come from two separate places that people routinely confuse — and one country, Germany, is far stricter than the rest. GDPR governs whether you may process someone's data. ePrivacy and national law govern whether you may send the message. You need to satisfy both.

This is not legal advice. It's a practical explanation of how to build a process with as little risk as possible. For anything consequential, talk to a lawyer in the relevant country.

The two regimes

GDPR — may you hold the data

GDPR protects personal data of individuals, not companies. The distinction that matters:

  • contact@salon.com — a generic company address, usually not personal data
  • anna.kowalska@salon.com — identifies a person, is personal data
  • Sole traders — company and personal data overlap; treat as personal

For generic addresses the usual lawful basis is legitimate interest (Art. 6(1)(f)). Direct marketing is named in Recital 47 as an example of such an interest. That is not a blank cheque — it requires the recipient's interests not to override yours, which in practice means your message has to be genuinely relevant to their business.

ePrivacy — may you press send

This is separate and stricter. The ePrivacy Directive requires consent for unsolicited commercial email, but leaves member states room on B2B. That's why the answer differs by country.

For a deeper look at the data side — which addresses count as personal data and how to document legitimate interest — see GDPR and cold email.

Country by country

CountryB2B cold emailThe thing that catches people out
GermanyEffectively prohibited without prior consentUWG §7 treats unsolicited advertising as unfair competition. Competitors can send cease-and-desist letters with costs attached. This is a real and active risk, not theory.
United KingdomAllowed to corporate bodiesPECR exempts "corporate subscribers" — limited companies, LLPs, public bodies. Sole traders and partnerships count as individuals and need consent.
FranceAllowed for B2BCNIL permits B2B on legitimate interest if the message relates to the recipient's job. Opt-out must be available from the first message.
PolandAllowed with careRequires a lawful basis and clear identification; generic business addresses with activity-related content is the safe path.
SpainAllowed for B2BLSSI requires clear sender identification and an easy opt-out.
NetherlandsAllowed for B2BTelecommunications Act permits B2B with an opt-out in every message.
ItalyRestrictiveThe Garante has taken a stricter line than most; consent is the safer assumption.

If you take one thing from this table: exclude Germany from cold email campaigns unless you have consent or specific legal advice. Reach German prospects through LinkedIn, events, content or phone instead. The downside risk there is not a fine — it's a competitor's lawyer billing you for the letter.

The checklist that keeps you out of trouble

  1. Write to generic addresses. contact@, office@, info@ — not to guessed personal ones.
  2. Never guess address patterns. firstname.lastname@ derived from a formula is personal data you collected by inference. Don't.
  3. Make every message relevant. This isn't only ethics. Relevance is the argument that you're acting on legitimate interest rather than spamming — it's your legal defence as much as your reply rate.
  4. Identify yourself fully. Company name, registration number, address. No hidden sender, no misleading subject lines.
  5. Offer an easy no. One line: "If this isn't relevant, reply with one word and I won't write again." Honour it immediately.
  6. Keep a permanent suppression list. Not a note — a durable record that survives switching tools.
  7. Be ready to answer "where did you get my data?" Source, purpose, lawful basis, right to object. Have it written before anyone asks.
  8. Collect only what you need. Enough to assess the lead. Don't build profiles of individuals.
  9. Don't resell your list. Data gathered under your own legitimate interest serves you, not a data-broking side business.

What about scraping the data in the first place?

Collecting publicly listed company information — name, phone, website, rating, review count — is generally accepted as processing of business data. Two things change the analysis:

  • If you're collecting named individuals, you're squarely in personal data and need to think much harder.
  • Terms of service of the source platform are a contractual matter, separate from data protection law. Breaking them isn't a GDPR violation, but it isn't nothing either.

The practical position most European tools take, including ours: work on company-level data from public listings, don't build a database of named people, and let the user be the controller for their own outreach.

The stronger the fit between your message and that specific business, the stronger the argument it's direct marketing under legitimate interest rather than bulk spam. It also means you send far fewer messages, which mechanically lowers your exposure.

The incentives point the same way: precise targeting raises replies and lowers risk at the same time. There's no trade-off to manage here.

That's the reasoning behind how Lead Radary works — it detects a concrete reason a business is worth contacting before you write, rather than handing you an undifferentiated list.

Summary

  • GDPR and ePrivacy are two different questions. Answer both.
  • Germany is the outlier — don't cold email there without consent.
  • The UK allows B2B to corporate bodies but not to sole traders.
  • Generic addresses plus activity-relevant content is the safest pattern everywhere.
  • Clear identification, easy opt-out, permanent suppression list. Every time.
  • Relevance protects you better than any footer disclaimer.

Find your first leads today

Lead Radary finds local businesses that need your service — with a reason and a ready message.

Start free