Guide · Updated August 2026

Is cold outreach legal in Europe?

There is no single European answer, and the two-column map most suppliers use — "opt-in countries" and "opt-out countries" — is wrong often enough to matter. There are three regimes. Here is each one, with the statute that governs it.

The short answer

It depends on the country, and there are three groups rather than two. Consent is required outright in Germany and Austria (both expect double opt-in), Italy, Spain, Poland, Greece, the Netherlands, Denmark, Czechia, Bulgaria, Cyprus, Lithuania, Malta and Romania. A second group turns on who you write to rather than which country: Belgium, Finland, Portugal and Norway distinguish a generic company address such as info@ from a named individual, while Sweden and Ireland permit email that genuinely relates to the recipient's professional role. Genuinely opt-out are France, Hungary, Luxembourg, Slovenia, Estonia, Croatia, Latvia and the United Kingdom.

theagency47 · Updated August 2026

Why there is no single European rule

Almost every confident article on this subject makes the same mistake: it reads GDPR and stops. GDPR is a regulation, so it applies identically in every member state, and it does permit processing personal data on a legitimate interest basis in many circumstances. That is where the popular claim "B2B cold email is fine under GDPR because legitimate interest covers it" comes from.

The problem is that GDPR answers a different question. GDPR governs whether you may process someone's data. The ePrivacy Directive governs whether you may send them an unsolicited commercial message. And ePrivacy is a directive, not a regulation — each member state wrote its own national law to implement it, and they diverged substantially.

Article 13(5) of the directive gave member states the option to extend the consent requirement to legal persons, or not to. Some took it, some did not, and several took a middle path that depends on whether the address you are writing to identifies a human being. That single optional clause is the origin of most of the confusion in this field.

You need both: a lawful basis under GDPR and a lawful route under the national ePrivacy implementation. Passing one does not excuse failing the other.

Group one: consent required outright

In these markets an unsolicited commercial email to a business needs prior consent. There is no general B2B exemption to fall back on. Germany and Austria go further and expect double opt-in — a sign-up followed by a confirmation click — which means a purchased or scraped list can never satisfy the standard, whatever the vendor tells you.

CountryGoverning lawNotes
GermanyUWG §7 (Act Against Unfair Competition)Double opt-in. Soft opt-in exists but is read narrowly and rarely relied on.
AustriaTelecommunications ActDouble opt-in. National opt-out list overrides soft opt-in.
ItalyLegislative Decree 196/2003, as amendedConsent required for B2B.
SpainLaw 34/2002 (LSSI)Consent required. Soft opt-in available.
PolandAct on e-Services; Telecommunications LawConsent required. No soft opt-in.
GreeceLaw 3471/2006, art. 11Consent required. Soft opt-in available; no completed transaction needed.
NetherlandsTelecommunications ActConsent required. The spam prohibition was extended to legal persons in 2009.
DenmarkMarketing Practices Act §10Consent required, businesses and consumers alike.
CzechiaAct 480/2004 Coll.Consent required. Soft opt-in available.
BulgariaElectronic Communications ActConsent required. Soft opt-in available.
CyprusLaw 112(I)/2004Consent required.
LithuaniaLaw on Electronic Communications 2004Consent required. Soft opt-in for email only.
MaltaS.L. 586.01Consent required. Soft opt-in available.
RomaniaLaw 506/2004Consent required. Soft opt-in available.
SwitzerlandFederal Act on Unfair Competition, art. 3(1)(o)Consent required. No soft opt-in. Not an EU member.

Two of these deserve a flag because they are so often listed incorrectly elsewhere. The Netherlands extended its spam prohibition to legal persons in 2009 and is routinely described as opt-out anyway. Denmark requires consent under section 10 of the Marketing Practices Act, which applies to businesses and consumers alike. We had both of these wrong on this site until August 2026, which is a reasonable illustration of how easily it happens.

Group two: it depends on the address, not the country

This is the group that a two-column map cannot represent at all, and the reason we stopped using one. Here the question is not where the business is but whether the address you are writing to identifies a person.

Belgium is the clearest case. Writing to info@company.be is exempt from the consent requirement; writing to jan.peeters@company.be is not. The rule sits in the Code of Economic Law rather than in data-protection law, which is one reason it is so often missed.

CountryGoverning lawWhat decides it
BelgiumCode of Economic Law XII.13; Royal Decree 4 April 2003Generic company address (info@, sales@) is exempt from consent. A named individual address is not.
FinlandInformation Society Code 917/2014, §§200, 202Non-individualised address: opt-out. Named individual: opt-in, unless their role is directly related to what you sell and you can evidence that.
PortugalLaw 41/2004Non-individualised address: opt-out, subject to the national opt-out list. Named individual: opt-in.
SwedenMarketing Practices Act (2008:486)Opt-out where the email relates to the recipient’s professional role. Otherwise opt-in.
IrelandS.I. 336/2011 (ePrivacy Regulations)Opt-out where it relates to the recipient’s professional role. Otherwise opt-in.
SlovakiaAct 22/2004; Act 452/2021Opt-out permitted where the business contact details are publicly available.
NorwayMarketing Control Act 2009Non-individualised address: opt-out. Named individual: opt-in. Not an EU member.

For a prospecting system this group is operationally interesting rather than merely restrictive: it means the compliance decision has to be taken per contact, not per market. A single Belgian company can be lawfully reachable at one address and unlawfully reachable at another, on the same day, for the same offer.

Group three: genuinely opt-out

Here personalised business email is permitted without prior consent, provided you have a documented legitimate interest assessment, identify yourself properly, include a postal address, and honour opt-out requests immediately.

CountryGoverning lawNotes
FrancePostal and Electronic Communications Code, art. L34-5Opt-out for B2B. Third-party sharing still requires opt-in.
HungaryAdvertising Act XLVIII/2008 and relatedOpt-out for B2B, including third-party.
EstoniaElectronic Communications ActOpt-out for B2B, including third-party.
LatviaLaw on Information Society Services 2004Opt-out for B2B, including third-party.
LuxembourgLaw of 30 May 2005Opt-out for B2B, including third-party.
CroatiaElectronic Communications Act 76/2022Opt-out for B2B. Third-party sharing requires opt-in.
SloveniaZEKom-2Opt-out for B2B. Third-party sharing requires opt-in.
United KingdomPECR 2003Corporate subscribers are outside the email marketing rules. Not an EU member.

Note how small this list is relative to its reputation, and note what is on it. France is the only large economy in the group. If your European plan assumes broad opt-out availability, it is effectively a plan for France.

One further trap: several of these countries are opt-out for first-party marketing and opt-in for third-party marketing. If you bought the list, or the data came from a partner rather than from your own relationship, France, Croatia and Slovenia change answer.

The soft opt-in: the most useful rule in the whole framework

Most of the consent countries in group one permit marketing on an opt-out basis where four conditions are met together:

  • the contact details were collected in the context of a sale;
  • the sender is the same legal entity that collected them;
  • the marketing relates to similar products or services;
  • an opportunity to object was given at collection and appears in every message.

For an established business this is usually the single most valuable route available, because it converts an existing customer list into a lawful channel in markets where cold email is closed. It is also the reason a consent-capture programme pays for itself: the asset you are building is not a list of addresses but a documented, timestamped record of how each address was obtained.

Two variations to check per market. Some countries require a completed transaction; others accept a commercial relationship such as a quote request or product enquiry — Austria, Greece and the UK sit in the second camp. And in Germany, reliance on the soft opt-in is rare in practice because the courts read it narrowly; double opt-in is the safer route.

Calls are a completely separate question

A market where email is closed is not necessarily a market where you cannot make contact. Telephone rules are analysed separately and frequently land in a different place.

Germany is the instructive example. Under UWG §7 a B2B call may proceed on presumed consent (mutmaßliche Einwilligung) — but the courts read it narrowly. A match of industry sector is not enough. You need specific indications that this business would have an objective interest in this offer. In other words the telephone route in Germany is open, but only to a party that has done the qualification work properly and can show it. That is an unusual situation: the depth of your research is not a quality matter, it is the thing that makes the call lawful.

And AI voice calls are a third category again

This is the distinction most likely to catch out a business in 2026, because the technology arrived faster than the reading of it.

An automated calling system — one that dials and conducts the conversation without a human — is not treated as a phone call. Article 13(3) of the ePrivacy Directive requires prior consent for it. Germany is stricter still: UWG §7(2) no. 3 requires express prior consent for an automated calling machine, with no business-to-business exception at all, and the existing-customer exception of §7(3) covers electronic mail but not calls.

The practical consequence is counter-intuitive and worth stating plainly: a German business you may lawfully call with a person, you may not lawfully call with software. Presumed consent covers the human; it does not extend to the machine.

Separately, since 2 August 2026, Article 50 of the EU AI Act requires that a person be told they are interacting with an AI system unless that is already obvious. That obligation is about transparency, not permission — satisfying it does not make an otherwise unlawful call lawful.

What this means if you are actually building something

Three conclusions follow, and they are the reasons our own system is built the way it is.

The decision belongs to the contact, not the campaign. Because group two exists, a single list can contain lawful and unlawful contacts in the same country. Any system that applies one rule per market will be wrong on a fraction of every send.

The evidence matters as much as the answer. In Germany, both the email route (soft opt-in) and the telephone route (presumed consent) turn on records you either have or do not have when someone complains. A gate that decides correctly but logs nothing protects no one.

Consent is an asset with a build cost. If most of your target markets are in group one, the honest strategy is not to find a clever route around consent but to spend the first year acquiring it — which is slow, unglamorous, and the only thing that makes automated calling available to you later.

How our compliance gate implements this →

Frequently asked questions

Does GDPR allow cold email to businesses?

GDPR is the wrong instrument to be reading. It governs whether you may process personal data, and legitimate interest can sometimes cover that. Whether you may send an unsolicited commercial message is governed by the ePrivacy Directive as implemented in national law — and in many member states that law requires consent regardless of what your GDPR analysis concluded. You need both.

Is a company address like info@ personal data?

Often not, which is a genuine advantage — but it is a separate question from whether you may email it. Belgium, Finland, Portugal and Norway make the distinction explicit in their marketing rules, so a generic address can be lawful to write to in a country where a named individual's address is not.

What about LinkedIn messages?

LinkedIn outreach is generally analysed under GDPR and the platform's own terms rather than under the ePrivacy email rules, which is why it remains available in markets where email is closed. That is not a loophole to lean on heavily — platform terms are enforced faster than statutes — but it is a legitimate route.

Does an unsubscribe link make cold email lawful?

No. In consent markets an unsubscribe link is necessary but not sufficient: the message was already unlawful when it was sent. In opt-out markets it is one of several requirements, alongside a documented legitimate interest assessment, proper sender identification and a postal address.

Who is liable if a supplier sends on our behalf?

In practice the exposure sits with the business being advertised, not with the software vendor. This is the single most important commercial point in the whole subject, and it is why "our tool handles compliance" is not an answer worth accepting without seeing what the tool actually blocks.

Sources and a necessary caveat

This is not legal advice. It is a working map maintained for our own operational use and published because most freely available material on the subject is wrong. National positions change, regulators reinterpret, and several of the entries above involve judgement rather than settled law. Before activating any market we verify the current position for that market and that message type, and for anything consequential you should take your own advice.

Principal sources: Fieldfisher, Email Marketing Across Europe (national-law table); Belgian Code of Economic Law XII.13 and the Royal Decree of 4 April 2003; Greek Law 3471/2006 art. 11; the German Act Against Unfair Competition (UWG) §7; the Danish Marketing Practices Act §10; Directive 2002/58/EC arts. 13(3) and 13(5); Regulation (EU) 2024/1689 (AI Act) art. 50.

Want this applied to your own markets?

Tell us which countries you sell into and what you sell. You will get back a written view of what is lawful in each, which channel we would use where, and what a compliant prospecting system would cost — or an honest note that your markets do not justify one.