GDPR and Cold Email: Is B2B Outreach Legal in the EU? (2026) | AI Email Tools
Legal Guide · European Union

GDPR and Cold Email: Is B2B Outreach Legal in the EU?

Updated July 2026 11 min read By Scott Holmes

GDPR governs how personal data is processed across the European Economic Area, and a business email address tied to a named person counts as personal data even in a B2B context. That single fact is why "is cold email legal under GDPR" doesn't have a one-word answer — it depends on which legal basis you're relying on and how carefully you've applied it.

Does GDPR Ban Cold Email?

No. GDPR doesn't prohibit B2B cold email outright — it requires that any processing of personal data, including sending a cold email to a named contact, rest on one of six lawful bases defined in Article 6. For B2B prospecting, the basis nearly every EU business relies on is legitimate interest, not consent.

Legitimate Interest as the Legal Basis

Article 6(1)(f) allows processing personal data when it serves a legitimate interest of the business, isn't overridden by the individual's rights and freedoms, and is necessary for that purpose. B2B sales outreach is widely accepted across most EU member states as a legitimate interest, provided the message is relevant to the recipient's professional role and you can point to a real reason you're relevant to them — a shared industry, a role that matches your product, a specific trigger event.

The Legitimate Interest Assessment

Relying on legitimate interest isn't a one-line justification — it's a documented balancing test with three parts: identify the specific interest you're pursuing, confirm the processing is necessary to achieve it, and weigh that interest against the individual's rights and reasonable expectations. A recipient whose role and company genuinely match your offering weighs differently than someone on a broad, unfiltered list scraped without regard for relevance.

Why this matters in practice: A legitimate interest assessment doesn't need to be a legal filing, but having one on record — even a short internal document explaining why a given list or campaign qualifies — is what separates a defensible position from a guess if a complaint ever comes in.

What GDPR Requires in Every Email

The Right to Object

Under Article 21, individuals have an unconditional right to object to direct marketing at any time. Once someone objects, you have to stop processing their data for that purpose — permanently, not just pausing the current sequence. This is a stronger and more immediate right than a typical unsubscribe request under CAN-SPAM's 10-business-day window; GDPR expects the objection to be actioned without undue delay.

Where Member States Diverge: Germany

GDPR sets the EU-wide floor, but the ePrivacy Directive that governs unsolicited electronic communications specifically is implemented differently country by country. Most member states layer a workable legitimate-interest allowance on top of GDPR for B2B email. Germany doesn't — its UWG law requires prior express consent for commercial email even between businesses, which functionally removes the legitimate-interest option that works almost everywhere else in the EU. See our dedicated guide to German compliance before running any campaign into German contacts.

Penalties

GDPR fines can reach €20 million or 4% of a company's total global annual turnover, whichever is higher. That ceiling applies to serious infringements broadly, not specifically to cold email violations, but a pattern of unlawful marketing processing — especially after a data subject has objected and continued to be contacted — is squarely within scope.

Practical GDPR Compliance for Cold Email

A defensible GDPR position for B2B cold email means: relying on legitimate interest with a documented rationale, targeting recipients whose role genuinely matches your offering, identifying yourself clearly, linking to a privacy notice, and honoring objections immediately and permanently. If you're sourcing contact data through scraping or list purchases, our guide to data privacy and B2B prospecting covers where that sourcing itself can create GDPR exposure independent of the email content.

GDPR compliance checklist for cold email

  • Legitimate interest rationale documented for the campaign or list
  • Recipient's role genuinely relevant to the outreach
  • Privacy notice accessible and linked
  • Clear sender identification in every message
  • Immediate, permanent opt-out honored on objection
  • Data sourced and retained under a documented minimization policy
  • German contacts handled under UWG's stricter consent rule, not general EU legitimate interest

FAQ

Is B2B cold email legal under GDPR?

Yes, in most of the EU, when it relies on the legitimate interest legal basis under Article 6(1)(f) — the recipient's role has to genuinely match your outreach, and you need a documented rationale for why the processing is justified. Germany is the major exception; see our German compliance guide.

What is legitimate interest under GDPR?

A legal basis for processing personal data that doesn't require consent, provided the processing serves a real business interest, is necessary for that purpose, and doesn't override the individual's rights and reasonable expectations. It's the basis most EU businesses rely on for B2B cold email.

What's the difference between GDPR's right to object and an unsubscribe link?

GDPR's right to object under Article 21 is broader and more immediate than a typical marketing unsubscribe — once exercised, you must stop processing that person's data for direct marketing entirely and without undue delay, not just remove them from one list.

What are the maximum GDPR fines?

Up to €20 million or 4% of a company's total global annual turnover, whichever is higher. This ceiling applies to GDPR infringements generally, and unlawful marketing processing after an objection is within its scope.

Related guides

→ Cold Email Compliance in Germany: Stricter Than the Rest of the EU? → Is Cold Email Legal? A Country-by-Country Quick Reference → Implied Consent vs Express Consent: What It Means for B2B Email

Written by

Scott Holmes

AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has advised B2B senders on GDPR-compliant outbound structures for EU-facing campaigns.

Ready to run compliant outreach?

Answer four quick questions and get a tool recommendation for your setup.