Is cold email legal in Europe? It depends on the country. In most EU countries in this guide, cold email to a named business contact needs the recipient's prior consent. France, the United Kingdom and Turkey allow cold B2B email under conditions, and the Netherlands only in narrow cases.
Below: the framework, a summary table and one section per jurisdiction, each linked to the official texts as checked on 27 September 2026.
This is an overview, not legal advice; check your own case with counsel.
How the rules fit together: ePrivacy, GDPR and national law
In the EU, three layers apply: national law decides whether B2B email needs consent and who enforces, and two EU rules sit above it:
- The ePrivacy Directive. Article 13 of Directive 2002/58/EC requires prior consent only for subscribers who are natural persons; for companies, each Member State chooses opt-in or opt-out. For every recipient, the sender may not be disguised and each message needs a valid opt-out address.
- The GDPR. A named address such as jan.novak@firma.cz is personal data. Recital 47 of the GDPR says direct marketing may be a legitimate interest, but per the EDPB Guidelines 1/2024 (version 1.0, for consultation) there is none where national law bars the email. People can object at any time (Article 21), you must say so by your first message, and Article 14 requires naming the source of data not collected from them.
Cold email rules by country: summary table
| Country | Cold B2B email without prior consent? | Key exception or limit | Regulator | Source |
|---|---|---|---|---|
| Czech Republic | No, for any address | Own customers | ÚOOÚ | Act 480/2004 Coll. |
| Germany | No | Own customers | Courts (civil claims) | UWG § 7 |
| Austria | No | Customers not on the ECG list | Fernmeldebüro | TKG 2021 § 174 |
| Poland | No | None | President of UKE | PKE art. 398 |
| Spain | No | Customers with a prior contract | AEPD | LSSI art. 21 |
| France | Yes, to professionals (CNIL) | The offer must fit their job | CNIL, DGCCRF | CPCE art. L34-5 |
| Netherlands | Only in narrow cases | Published offer address; non-EEA recipient; own customers | ACM | Telecommunicatiewet art. 11.7 |
| Italy | No | Own customers | Garante | Codice privacy art. 130 |
| United Kingdom | Yes, to companies and LLPs | Sole traders: consent or soft opt-in | ICO | PECR regulation 22 |
| Turkey | Yes, to merchants and tradesmen | Prior İYS registration and check | Ministry of Trade | Law No. 6563 |
Is cold email legal in the Czech Republic?
No. Under § 7(2) of Act No. 480/2004 Coll. (zákon č. 480/2004 Sb.), commercial email needs the prior consent of the user, natural or legal person alike. The regulator ÚOOÚ's FAQ adds that addresses found online cannot be used, bought databases are in practice not usable, and an email asking for consent is itself a commercial communication.
- Named or generic address: no difference; both need consent.
- Existing customers: § 7(3) allows email on your own similar products or services to customers whose address you got in a sale, with a free, simple opt-out at collection and in every message. Only contract partners count as customers.
- Every email must: be marked as commercial, identify the sender in the message itself and give a valid opt-out address (§ 7(4)).
- Fines: up to CZK 10,000,000 for a company sending in bulk or repeatedly without consent (§ 11).
Bottom line: outside the customer exception, Czech B2B email needs consent, and you cannot ask for it by email.
Is cold emailing legal in Germany?
No, not even B2B. Under UWG § 7, advertising email without the addressee's prior express consent is always an unreasonable nuisance; presumed consent covers only business phone calls. Per the regulators' DSK guidance, a channel barred by § 7 UWG leaves no GDPR legitimate interest either.
- Named or generic address: no difference.
- Existing customers: § 7(3) allows email about your own similar goods or services to customers who gave you their address in a sale and have not objected, if you tell them at collection and in every email that they can object at any time, at no cost beyond basic transmission rates.
- Every email must: reveal the sender, give a valid address for stop requests and, under § 6 DDG, not disguise the sender or commercial nature in header or subject line.
- Enforcement and fines: no authority enforces § 7 UWG for email; competitors, associations and chambers such as the IHK can sue for injunctions (§ 8 UWG, with warning letters under § 13 UWG). Deliberately disguising sender or commercial nature in header or subject line can be fined up to EUR 300,000 (§ 33 DDG).
Bottom line: in Germany, advertising email needs express consent, B2B included, unless the customer exception applies.
Cold email law in Austria
Austria is opt-in for every recipient, companies included: § 174(3) TKG 2021 bans direct marketing email without the recipient's prior consent, and the regulator RTR says advertising email needs consent given in advance.
- Named or generic address: no difference; companies can also join the free ECG list kept by RTR to refuse commercial email.
- Existing customers: § 174(4) allows marketing of your own similar products or services to customers whose details you got in a sale or service, if they could refuse free of charge at collection and with every message and have not refused, in particular via the ECG list.
- Every email must: not disguise the sender, be recognisable as commercial, show who commissioned it (§ 6 E-Commerce-Gesetz) and give an authentic address for stop requests (§ 174(5)).
- Fines: up to EUR 50,000, imposed by the Fernmeldebüro (§ 188 TKG 2021).
Bottom line: consent first in Austria; only customers who never refused and are not on the ECG list are exempt.
Is cold email legal in Poland?
No. Since 10 November 2024, Art. 398 of the Electronic Communications Law (Prawo komunikacji elektronicznej, PKE) bans sending commercial information to any subscriber or end user without prior consent; the old rule covered only natural persons. An official ministry answer of 14 October 2025 confirms that companies and sole traders are covered, relays the data protection office UODO's view that cold calling and cold mailing are now blocked, and rules out contact made to obtain consent.
- Named or generic address: no difference.
- Existing customers: no soft opt-in; Art. 398 has no customer exception.
- Every email must: be marked as commercial and identify the sender with its electronic addresses (Art. 9 of the Act on providing services by electronic means); consent must meet GDPR standards (Art. 400 PKE).
- Fines: up to 3% of the previous year's revenue or PLN 1,000,000, whichever is higher, from the President of UKE (Art. 446(5)); it is also a petty offence (Art. 448) and unfair competition (Art. 398(4)).
Bottom line: in Poland, every B2B email needs prior consent, customers included.
Cold email law in Spain (LSSI)
Spain is opt-in for every recipient. LSSI art. 21 (Ley 34/2002) bans advertising email that the recipient did not previously request or expressly authorise, and a recipient can be a natural or legal person. The data protection authority's report 2018-0164 says GDPR legitimate interest cannot replace this consent, and tacit consent is not enough.
- Named or generic address: no difference. Published addresses are not free to use either, per an Audiencia Nacional judgment the AEPD cites.
- Existing customers: art. 21.2 allows offers of your own products or services similar to what the customer contracted, with lawfully obtained details and a simple, free objection at collection and in every message.
- Every email must: be identifiable as commercial, identify the sender (art. 20) and include a valid email or other electronic address for objecting (arts. 21 and 22).
- Fines: EUR 30,001 to 150,000 from the AEPD for mass sending, or insistent or systematic sending to one recipient, in breach of art. 21; up to EUR 30,000 otherwise.
Bottom line: consent first in Spain, except similar offers to contract customers.
Is B2B cold email legal in France?
Yes, to professionals, under conditions. The consent rule in article L34-5 of the CPCE protects natural persons, and the CNIL reads it this way: private individuals must consent in advance, professionals must be able to object, with legitimate interest as the basis when the offer relates to their job. This opt-out is the CNIL's reading, not the law's wording.
- Named or generic address: a named professional address works on an opt-out basis if the offer fits the person's job and they were informed. Generic addresses such as info@ concern legal persons and, per the CNIL, fall outside these consent and objection principles.
- Existing customers: L34-5's soft opt-in (sale or service, similar products, free opt-out at collection and in every email) matters mostly for consumers.
- Every email, generic addresses included, must: give valid contact details for stop requests, not conceal the sender and use a subject line related to the offer.
- Fines: as described by the Conseil constitutionnel, up to EUR 10 million or 2% of worldwide annual turnover from the CNIL (EUR 20 million or 4% in some cases) and up to EUR 375,000 for a legal person from the DGCCRF. Its decision 2026-1210 QPC of 25 June 2026 declared these overlapping powers unconstitutional from 31 October 2027 and, until then, bars a second authority from pursuing the same facts.
Bottom line: relevant cold email to French professionals is allowed on an opt-out basis.
Cold email to businesses in the Netherlands
Opt-in applies to businesses too: article 11.7 of the Telecommunicatiewet requires provable consent. For businesses, consent is not needed for an address the company published for receiving unsolicited offers, used for that purpose, or for a recipient outside the EEA, where that country's rules apply. The Autoriteit Persoonsgegevens confirms both.
- Named or generic address: both need consent. A general info@ published for contact does not automatically qualify; the AP's example is an address like salesoffers@.
- Existing customers: art. 11.7(4) allows marketing of your own similar products or services to customers whose details you got in a sale, if you can prove it and offered a clear, free, easy objection at collection and in every message.
- Every email must: state the sender's real identity and a valid postal address or number for stop requests (art. 11.7(7)); the ACM expects consent to be provable up to five years after sending.
- Fines: up to EUR 900,000 or 1% of turnover, whichever is higher, from the ACM (art. 15.4 Telecommunicatiewet). Its predecessor OPTA fined Companeo EUR 100,000 in 2012 for spam mainly to businesses.
Bottom line: Dutch B2B email needs provable consent except in the narrow cases above.
Is cold email legal in Italy?
No. Art. 130 of the Codice privacy (D.Lgs. 196/2003) allows promotional email only with the consent of the contraente o utente, and a contraente (contracting party) includes legal persons. The Garante's 2013 spam guidelines, older than the GDPR but still its reference, add that addresses easy to find online may not be used without consent.
- Named or generic address: both need consent; the Garante also treats a name.surname@company address as the employee's personal data.
- Existing customers: art. 130(4) allows email about your own similar products or services to someone who gave you the address in a sale, if they were informed, did not refuse and can object easily and free of charge at collection and in every message.
- Every email must: not disguise the sender and give a suitable contact for exercising GDPR rights (art. 130(5)).
- Fines: up to EUR 20 million or 4% of worldwide annual turnover, the GDPR's top level (art. 166), imposed by the Garante.
Bottom line: consent first in Italy, companies included; only own customers are exempt.
UK PECR rules for B2B cold email
Yes, to companies. PECR regulation 22 limits the consent rule to individual subscribers, and the ICO says you can send B2B marketing emails to any corporate body, such as a company or LLP, without PECR consent. Sole traders and some partnerships are individual subscribers and need consent or the soft opt-in; if unsure, treat the address as an individual's, the ICO says.
- Named or generic address: both can be emailed at a company, but a named address such as initials.lastname@company.com is personal data under UK GDPR, where the ICO sees legitimate interests as often appropriate and the right to object as absolute; a generic info@ involves no personal data.
- Existing customers: regulation 22(3) covers your own similar products and services for contacts obtained during a sale or negotiations for a sale, with a simple, free refusal option at collection and in every message.
- Every email must: not disguise your identity and give a valid opt-out address (regulation 23), for companies too.
- Fines: since 5 February 2026, up to GBP 17,500,000 or 4% of worldwide turnover, whichever is higher (Data Protection Act 2018, s.157, applied to PECR). The ICO's guidance is under review.
Bottom line: UK companies can be cold emailed without consent if you identify yourself and honour opt-outs.
Is B2B cold email legal in Turkey?
Yes, to merchants and tradesmen. Law No. 6563 (6563 sayılı Kanun) requires prior approval for commercial electronic messages but exempts tradesmen and merchants (esnaf ve tacir) in Article 6(2). Under the implementing regulation, you first register their addresses in İYS (İleti Yönetim Sistemi) and check that they have not rejected messages. Everyone else needs prior approval, which the Ministry of Trade says may not be requested by commercial message.
- Named or generic address: info@ is clearly the merchant's address; whether a named employee's address counts is not settled in the texts we checked, and it is also personal data under Law No. 6698 (KVKK).
- Existing customers: no general soft opt-in; without approval, only messages on change, use or maintenance of goods or services supplied, if the recipient gave contact details to be contacted.
- Every email must: identify the sender (for a Turkish merchant, MERSİS number and trade name), give a contact detail, label the subject (for example promotion) if the nature is unclear and offer free rejection through the same channel; rejections must be honoured and reported to İYS within three business days.
- Fines in 2026, from the Ministry of Trade: TRY 2,859 to 14,309 for sending without approval, up to tenfold when sent to more than one person at once; TRY 2,859 to 28,620 for identification and TRY 5,723 to 42,930 for rejection breaches (Resmî Gazete).
Bottom line: Turkish merchants and tradesmen can be cold emailed without approval, but only after an İYS check.
How to do B2B outbound legally in Europe in 2026
Outbound still works; plan the channels before the copy.
- Pick markets with the rules in mind. Cold email can reach UK companies, relevant French professionals and İYS-checked Turkish merchants; elsewhere other channels lead, and our Czech Republic outsourcing guide compares partners in one strict market.
- Use the soft opt-in only for real customers: a sale or contract, similar products, an opt-out from the start.
- Check phone and LinkedIn rules separately. Germany allows B2B calls with at least presumed consent, while UODO reads the Polish law as blocking cold calls too. Where allowed, signal-based selling helps you time the contact.
- Build inbound demand. Under Czech guidance, a provable reply to a specific inquiry is not a commercial communication; see where good IT sales leads come from.
- Identify yourself, offer an opt-out, keep records. Keep one suppression list across tools, note each contact's source and store proof of consent; clean lists also help deliverability.
- Be careful with bought lists. The European Commission says their contacts must be informed by the first communication and can object, and ePrivacy rules still apply.
Our lead generation service covers email, LinkedIn and phone; see pricing.
Frequently asked questions
Is cold email legal under GDPR?
The GDPR does not ban it, but it is not the only law. Recital 47 allows direct marketing as a possible legitimate interest, yet national ePrivacy rules decide whether the email may be sent. Where they require consent, the EDPB says no legitimate interest remains, and named contacts can always object.
Can I cold email generic addresses like info@?
In some countries. The CNIL puts generic addresses outside the French consent and objection principles, a UK company's info@ needs no consent and involves no personal data, and a Turkish merchant's info@ needs no approval after the İYS check. Czech, German, Austrian, Polish, Spanish and Italian law require consent, and Dutch law does unless the address was published for offers.
Can my first email ask for permission?
Not in several countries. The Czech ÚOOÚ treats an emailed consent request as a commercial communication, the Polish ministry rules out contact made to obtain consent, and Turkey's Ministry of Trade says approval may not be requested by commercial message. Collect consent where the law allows, for example on your website.
What happens if I break the rules?
Fines reach CZK 10,000,000 in the Czech Republic, EUR 150,000 in Spain for mass sending, 3% of revenue or PLN 1,000,000 in Poland, and GDPR levels in Italy and the UK. In Germany, the main risk is an injunction claim from a competitor or an association.
Build your outbound around each country's rules
The law decides the channels. Our lead generation team runs outbound for IT and SaaS companies in English, Czech and Turkish, our full sales cycle service takes deals to close, and every plan on our pricing page guarantees qualified meetings.
Sources and further reading: ePrivacy Directive, EUR-Lex; GDPR, EUR-Lex; EDPB Guidelines 1/2024; European Commission Q&A; Act 480/2004 Coll., e-Sbírka; ÚOOÚ FAQ; UWG § 7; UWG § 8; DDG § 6; DDG § 33; DSK guidance; TKG 2021 § 174; TKG 2021 § 188; RTR, unwanted emails; PKE, ISAP; Sejm, interpellation 12182; LSSI, BOE; AEPD report 2018-0164; CPCE art. L34-5, Légifrance; CNIL, email prospecting; Decision 2026-1210 QPC; Telecommunicatiewet art. 11.7; AP, direct marketing; ACM, spam rules; ACM, 2012 OPTA fine; Codice privacy art. 130; Codice privacy art. 166; Garante, spam guidelines; PECR regulation 22; PECR regulation 23; Data Protection Act 2018, s.157; ICO, B2B marketing; Law No. 6563, Mevzuat; Commercial electronic messages regulation; Ministry of Trade; Resmî Gazete, 2026 fines.
