Is Cold Email Legal in Europe? GDPR and B2B Outreach, Country by Country

Europe

Conceptual purple and white illustration for Is Cold Email Legal in Europe? GDPR and B2B Outreach, Country by Country

B2B cold email is legal in some European countries and effectively banned in others. GDPR allows outreach under legitimate interest, but national ePrivacy rules decide who you may email. Sweden, Finland and the UK allow emails to company addresses; Denmark, Germany and Austria require prior consent; Norway, the Netherlands and Belgium depend on the address.

Last reviewed in October 2026. This article summarises published guidance from regulators, national legislation and law firms. It is not legal advice: take advice from a lawyer in each market before you send.

Is cold email legal in Europe? Many articles answer yes, cite the GDPR and legitimate interest, and move on. That answer is incomplete, and in some of Europe’s most valuable B2B markets it is wrong.

The reason is that two separate sets of rules apply to every cold email. The GDPR governs whether you may process someone’s personal data. National ePrivacy rules, which implement the EU’s ePrivacy Directive differently in each country, govern whether you may send them electronic marketing at all. A campaign can pass the first test and fail the second.

This guide covers nine markets: the four Nordic countries, Germany, Austria, the Netherlands, Belgium and the United Kingdom, with a note on Switzerland. For each, it answers the three questions that decide an outbound plan. Can you email a named person at a company? Can you email a generic address such as info@? Can you call?

The two laws behind every cold email

The GDPR decides whether you may use the data. A business email address that identifies a person, such as firstname.lastname@company.com, is personal data. Under the GDPR you need a lawful basis to process it, and for B2B outreach that is usually legitimate interest under Article 6(1)(f). Recital 47 recognises that direct marketing may be a legitimate interest, but it is not automatic. You have to pass the three part test that the European Data Protection Board sets out in its guidelines on legitimate interest: a genuine interest, necessity, and a balance against the person’s rights and reasonable expectations.

ePrivacy rules decide whether you may send the email. Article 13 of the ePrivacy Directive requires prior consent for email marketing to individuals, with a narrow exception for existing customers, and leaves each member state to decide how far to protect businesses. That is where the countries split. Some protect only private individuals and sole traders. Some protect named employees at companies. Some protect every recipient, including generic company inboxes.

Norway applies the same framework through the EEA, and the United Kingdom kept its own version after leaving the EU. Switzerland has separate rules altogether.

An envelope beside separate data and sending-permission checks.

Is cold email legal in Europe? The rules by country

The table summarises the position for a sender emailing or calling a business contact without prior consent. “Named address” means an address that identifies a person, such as anna.berg@company.se. “Generic address” means a role address such as info@ or sales@.

Country

Named address, no consent

Generic address, no consent

Calling businesses

Main rule

Denmark

No

No

Allowed unless they have objected

Marketing Practices Act, section 10

Germany

No

No

Only with at least presumed consent

Act Against Unfair Competition (UWG), section 7

Austria

No

No

Only with prior consent

Telecommunications Act 2021, section 174

Norway

No

Yes

Allowed; oral calls are exempt from consent

Marketing Control Act, section 15

Netherlands

Only via an address published for such messages

Only if published for such messages

Legal entities yes; sole traders need consent

Telecommunications Act, article 11.7

Belgium

No

Yes, if impersonal and the offer suits a business

Separate rules; check locally

Code of Economic Law XII.13 and Royal Decree of 4 April 2003

Finland

Only if your offer relates essentially to their job, verified

Yes, unless the organisation has refused

Allowed

Act on Electronic Communications Services, section 202

Sweden

Generally yes at companies, if relevant to the role; no for sole traders

Yes

Allowed unless they have objected

Marketing Act, sections 19 to 21

United Kingdom

Yes for companies and LLPs; no for sole traders and some partnerships

Yes

Allowed; screen against the CTPS

PECR

The sections below explain each market, starting with the strictest. Where the law says consent, it means consent obtained before the first message, and in Denmark and Norway the regulators state explicitly that an email asking for consent is itself marketing.

Denmark: the strictest market in the Nordics

Denmark’s Marketing Practices Act bans electronic marketing to anyone who has not agreed to it in advance. The Danish Consumer Ombudsman is explicit that the ban covers businesses and public bodies as well as consumers, and that it makes no difference whether you write to a generic inbox such as info@ or to a named director.

Four details catch foreign senders:

  • Asking for consent by email is itself a breach. The first contact cannot be the request for permission; consent has to be collected by other means, such as a form on your website.

  • Social media is covered. Private messages and notifications with marketing content fall under the same ban. Posts in the news feed do not.

  • Branding counts as marketing. An email that only aims to raise awareness of a company is still marketing in the Ombudsman’s view.

  • Fines are real. According to the business association Dansk Erhverv, fines start at 20,000 kroner for up to 30 emails and rise with volume, and the Ombudsman has taken up complaints from businesses as well as consumers.

What remains open: calling businesses that have not objected, meeting them at events, sending neutral market research that promotes nothing, and publishing content that brings Danish buyers to you. Denmark is a market where outbound is led by phone, events and content, with email following once someone has agreed to hear from you.

Germany: consent for email, presumed consent for calls

Section 7 of Germany’s Act Against Unfair Competition, the UWG, treats advertising by email without the recipient’s prior express consent as an unacceptable nuisance, and it draws no distinction between consumers and businesses. Business to business cold email is therefore not a lawful way to make a first approach in Germany.

The phone is different. Advertising calls to businesses need only presumed consent, meaning an objective reason to assume the company would welcome the call. German courts read that narrowly: matching your target list is not enough on its own. The reason should be concrete, specific to that company, and recorded before you call.

Enforcement in Germany often comes from competitors and trade associations rather than a regulator, through formal warning letters, known as Abmahnungen, that demand the practice stops and that the sender pays the legal costs. It is an expensive way to learn the rule. Our guide to B2B sales in Germany covers the channel mix that works instead.

Austria: consent for email and for calls

Austria is stricter still. According to the Austrian Economic Chamber, WKO, section 174 of the Telecommunications Act 2021 requires the recipient’s prior consent, revocable at any time, for advertising calls, faxes and electronic mail, and the rule applies to social media messages as well. Breaches can be fined up to 50,000 euros for electronic mail and up to 100,000 euros for calls and faxes by the telecommunications authority. Emails from Austrian companies must also carry the company details required by commercial law. Plan Austrian outreach around events, partners, content and consent rather than cold channels.

Norway, the Netherlands and Belgium: the address decides

Norway. The Norwegian Consumer Authority’s guidance on section 15 of the Marketing Control Act is precise. The consent requirement protects every natural person, including at their individual work address: an email to ola.nordmann@company.no needs prior consent even when the offer is aimed at the company, and even when the address is listed as a company contact in a business register. Generic addresses that do not belong to a specific person, such as post@company.no, may be emailed. Oral phone calls are exempt from the consent requirement. Two further points matter for anyone buying data: an email asking for consent is itself marketing, and a buyer of a contact database cannot rely on the seller’s guarantee that consent exists, but must verify it.

Netherlands. Article 11.7 of the Telecommunications Act allows email to businesses without consent only when you use an address the business has designated and published for receiving that kind of message, and only for the purpose it attached. The Dutch Data Protection Authority says the same on its page on digital direct marketing: businesses also have to consent unless an exception applies. A generic info@ address on a contact page is not automatically such an address, and a note beside it saying that sales approaches are not welcome removes the exception entirely. Every message must show your real identity and a valid address for opt outs, and the Authority for Consumers and Markets, ACM, can fine up to 900,000 euros or 1 percent of turnover. Calling legal entities is allowed; calling sole traders and partnerships requires consent, and the telemarketing rules tightened again on 1 July 2026.

Belgium. Article XII.13 of the Code of Economic Law starts from a ban on email advertising without prior consent. The Royal Decree of 4 April 2003 creates an exception for legal entities contacted at impersonal addresses such as info@ or sales@, provided the offer is intended for businesses. Addresses built from a person’s name, such as firstname.lastname@company.be, are treated as addresses of natural persons whatever they are used for, so they need consent.

Finland, Sweden and the United Kingdom: open, with conditions

Finland. Under section 202 of the Act on Electronic Communications Services, direct marketing to organisations is allowed unless the organisation has refused it, and every message must offer a free and easy way to opt out. Named addresses are different. Finnish law firm Dittmar & Indrenius summarises the position: an address in the form firstname.lastname@company.fi is a natural person’s address and in principle needs consent, unless the recipient works in a role that your offer essentially relates to. You must verify that role rather than assume it. Generic organisational addresses, such as a purchasing inbox, need no consent. The Data Protection Ombudsman supervises the rules.

Sweden. The Marketing Act requires prior consent for email marketing to natural persons, and the preparatory works for the rule, Government Bill 2003/04:43, confirm that sole traders count as natural persons. Legal entities can be emailed without consent, and the Swedish Data and Marketing Association’s ethical rules for B2B email add that messages to employees should be clearly relevant to their professional role. Every marketing email, including those sent to businesses, must carry a valid address where the recipient can ask you to stop.

United Kingdom. The Privacy and Electronic Communications Regulations, PECR, require consent for email marketing to individual subscribers, a category that includes sole traders and some partnerships. Limited companies, LLPs and other corporate subscribers can be emailed without consent, provided you identify yourself and offer an opt out, as the Society for Computers and Law summarises from the ICO’s guidance. UK GDPR still applies to the personal data involved, and marketing calls to businesses must be screened against the Corporate Telephone Preference Service. The ICO’s direct marketing guidance is the reference point.

Switzerland. Switzerland is outside the EU and regulates unsolicited mass advertising by electronic means under its own Unfair Competition Act. Treat it as a separate market and take Swiss advice before sending.

Who enforces the rules, and what a breach costs

Market

Enforcer

What a breach can cost

Denmark

Consumer Ombudsman and the police

Fines from 20,000 DKK, rising with volume

Germany

Competitors and associations, through the courts

Injunctions, legal costs and contractual penalties for repeat breaches

Austria

Telecommunications authority

Fines up to 50,000 EUR for email and 100,000 EUR for calls

Norway

Consumer Authority

Prohibition orders, coercive fines and infringement fines

Netherlands

ACM

Fines up to 900,000 EUR or 1 percent of turnover

All EU and EEA markets

Data protection authorities, under the GDPR

Up to 20 million EUR or 4 percent of worldwide annual turnover

Is LinkedIn outreach covered by the same rules?

Often, yes. The rules are written for electronic mail in a broad sense, and several regulators apply them to messages on platforms. Denmark’s Consumer Ombudsman treats private marketing messages on social media as covered by the ban. Austria’s WKO says the consent rule applies to social media. Norway’s Consumer Authority applies the same considerations to marketing on social media, and Dutch commentary reads platform messages in the same way as email. Content published in the feed, which people choose to read, is not a message sent to them; connection requests without a sales message sit in a greyer area. On top of the law, LinkedIn’s own User Agreement prohibits bots and other unauthorised automation for adding contacts or sending messages.

What the GDPR requires in every B2B cold email

Where email outreach is lawful, the GDPR still sets the terms. In practice that means six things.

  1. Document a legitimate interest assessment for each campaign: why you are contacting this group, why it is necessary, and why it does not override the recipients’ interests and reasonable expectations.

  2. Tell people where you got their data. Under Article 14, when personal data comes from another source, you must tell the person, at the latest when you first communicate with them. In outbound, that means the first email: a short line naming the source plus a link to your privacy notice.

  3. Flag the right to object in the first message. Article 21(4) requires the right to object to direct marketing to be brought to the recipient’s attention clearly and separately, at the latest at the first communication.

  4. Honour objections immediately and permanently. An objection to direct marketing is absolute. Stop at once, across every tool and mailbox.

  5. Keep a suppression list, not a deletion habit. Deleting an address lets it return with the next import. Keep the minimum needed to make sure you never contact that person again.

  6. Know your data sources and processors. Record where each contact came from, and have a data processing agreement with every tool that handles the data.

A compliance checklist before any European campaign

  • Split the list by the country you are sending into. Danish rules, for example, apply to messages sent into Denmark from abroad, and a German office of a Swedish company is a German recipient.

  • Separate named addresses from generic ones, because several countries treat them differently.

  • Remove sole traders where the country treats them as individuals: Sweden and the UK for email, and the Netherlands for calls.

  • Check each target market in this guide, then confirm with local counsel.

  • Put the source and your identity in the first email, and an opt out line in every email.

  • Set up suppression across every tool before the first send.

  • Record the legitimate interest assessment and the origin of the list.

What this means for your channel mix

Market group

Countries

Lead channel for first contact

Email friendly

Sweden, Finland, United Kingdom

Email to relevant roles, with LinkedIn and phone alongside

Address dependent

Norway, Netherlands, Belgium

Phone to companies first; generic addresses in Norway and Belgium, published addresses in the Netherlands; named emails only with consent

Consent first

Denmark, Germany, Austria

Phone where lawful, events, partners and content; email after agreement

The practical consequence is that one European campaign is really three campaign designs. Running the same email sequence into Stockholm, Copenhagen and Munich treats three different legal systems as one, and it is an easy mistake to make when the tools make sending to every market equally simple. Our guide to entering the Nordic market applies these rules market by market.

The honest position. Most outbound advice treats Europe as one market with one rule. It is closer to ten markets with ten rules, and the differences are largest in some of the countries with the highest contract values. The companies that do well here do not look for loopholes. They build a channel mix per country and keep email for the markets and addresses where it is clearly allowed.

Want outbound that is planned market by market? See what our clients say, or book a call.

Communication channels considered against market-specific gates.

Frequently asked questions

Is B2B cold email legal under GDPR?

GDPR alone does not prohibit it. Legitimate interest can be a lawful basis for B2B direct marketing, provided you document it, disclose your data source and honour objections. Whether you may send the email is decided separately by each country’s ePrivacy rules, which range from open in Sweden to consent only in Germany.

Is cold email legal in Denmark?

Not without prior consent. Denmark’s Marketing Practices Act bans electronic marketing to anyone who has not agreed to receive it, and the Consumer Ombudsman confirms this covers businesses, generic addresses such as info@ and named employees alike. Calling businesses that have not objected and content led approaches remain open.

Is B2B cold email legal in Germany?

No. Section 7 of the German UWG requires prior express consent for advertising by email, with no exception for business recipients. Advertising calls to businesses are allowed with presumed consent, meaning a concrete reason to believe that specific company would welcome the call, which German courts interpret narrowly.

Can I cold email a generic company address like info@?

In Sweden, Finland, Norway and the UK, generally yes. Belgium allows impersonal addresses when the offer suits a business. In the Netherlands, only if the company published the address for such messages. In Denmark, Germany and Austria, no: the consent requirement covers generic addresses too.

Do I need to tell prospects where I got their email address?

Yes. When you collect personal data from a source other than the person, Article 14 of the GDPR requires you to tell them the source, at the latest in your first communication. In outbound that means stating it in the first email, alongside a clear and separate way to object.

Do the same rules apply to LinkedIn messages?

Often, yes. Denmark treats private marketing messages on social media like email, Austria applies its consent rule to social media, and Norway’s regulator applies the same considerations. Content in the feed is not a message sent to someone. LinkedIn’s own terms also prohibit automated messaging and automated contact adding.

Apply To Partner

With Leadsify.

Schedule a meeting with any of our Regional Directors and let’s chat about scaling your business in 2026.

This is NOT for you if your business:

Is not making at least €100,000/year.

Does not have any case studies.

Is still searching for product-market fit.

This is FOR YOU if you want to:

Scale fast and get new clients predictably.

Save 15+ hours a week from prospecting.

Get 7–35 qualified sales meetings a month.

Expand to new markets.

Trusted by 50+ B2B companies