Outbound Atlas

Atlas/The law/Europe

EU/EEA country matrix

Country-by-country status of B2B cold email across the 27 EU states, Norway, Iceland, Liechtenstein and Switzerland: about 13 require consent, about 11 allow opt-out to companies, and 5 are unclear.

Lawmedium confidence10 minupdated 2026-10-0532 sources
Jurisdiction
EU-27 + Norway, Iceland, Liechtenstein + Switzerland
Regime
Mixed
Cold B2B email
Consent needed in ~13 countries (incl. DE, AT, IT, ES, PL); opt-out to companies in ~11 (incl. FR, IE, SE, NL-narrow); ~5 unclear
Penalty
GDPR ceiling (€20m / 4%) everywhere; national ePrivacy penalties and civil claims vary
Enforced by
National DPAs, telecom and consumer regulators, and courts

Article 13(5) of the ePrivacy Directive lets each country decide how to protect companies from unsolicited email. Twenty years on, the result is a patchwork. Roughly 13 of 31 countries require prior consent even for B2B cold email, including Germany, Italy, Spain and Poland. About 11 allow email to legal persons with an opt-out, though several of those protect named employees as individuals. For about 5 countries we could not pin down the treatment of legal persons from primary or tier-one secondary sources.

The GDPR applies on top everywhere: a legal basis (in practice legitimate interest), an Art. 14 notice, and an unconditional right to object. See GDPR and ePrivacy. The recipient's country decides. See Germany for a Belgian sender sued in Düsseldorf.

How to read the matrix

  • B2B to companies: can you cold email a business contact without prior consent?
    • Opt-out: yes, with identification and an opt-out.
    • Opt-in: no, consent is needed (the soft opt-in for existing customers aside).
    • Generic only: yes, but only to the company's impersonal addresses (info@). Named people need consent.
  • Named employee / sole trader: how a personal work address or a one-person business is treated.
  • Conf.: our confidence in the row. H = statute or tier-one source states the B2B position explicitly. M = inferred from the statute's wording ("subscriber", "anyone") or the sources conflict. L = no reliable source found.

Primary secondary sources: DLA Piper Data Protection Laws of the World, electronic marketing chapters (fetched 5 Oct 2026, URL pattern dlapiperdataprotection.com/index.html?t=electronic-marketing&c=XX), and ICLG Data Protection 2025–26 chapters, question 10.2.

The matrix

CountryB2B to companiesNamed employee / sole traderLegal basisNotesSourceConf.
AustriaOpt-inConsentTKG 2021 §174Soft opt-in also requires checking the RTR/WKO Robinson listsDLA ATH
BelgiumGeneric onlyConsentCode of Economic Law, Book XIIException for "legal persons (e.g. to a general email address)"; DPA recommendation 1-2025 in consultationDLA BEM
BulgariaUnclearConsent (natural persons)Electronic Communications ActOpt-in mandatory for natural persons; legal persons not addressedDLA BGL
CroatiaUnclearUnclearElectronic Communications ActDLA chapter lists no rules beyond GDPRDLA HRL
CyprusOpt-outConsentLaw 112(I)/2004 s.106Consent rule applies to natural-person subscribers; legal persons covered by a 2005 OrderDLA CYM
CzechiaOpt-inConsentAct 480/2004 (CSIS)No B2B carve-out stated; message must be tagged as commercialDLA CZM
DenmarkOpt-inConsentMarketing Practices ActTrader "must not approach anyone" by email without prior consentDLA DKM
EstoniaOpt-outConsent (natural persons)Electronic Communications Act"If the addressee is a legal person, the opt-out system is applicable"DLA EEH
FinlandOpt-outConsent unless offer "substantially related" to job dutiesAct on Electronic Communication ServicesGeneric addresses fine; personal work address only if role-relevantDLA FIH
FranceOpt-outAllowed if related to professionCPCE L.34-5 + CNILGeneric addresses outside the rules; CNIL fines actively. See FranceCNILH
GermanyOpt-inConsentUWG §7(2) Nr. 2One email is actionable; enforced via Abmahnung. See GermanyDLA DEH
GreeceOpt-inConsentLaw 3471/2006 art. 11"Prior express consent"; position on legal persons not spelled outDLA GRM
HungaryGeneric onlyConsent (any natural person, B2B or not)Act XLVIII/2008Opt-in "triggered by the recipient being a natural person"; legal persons as such outsideICLG HUM
IrelandOpt-outAllowed if address used mainly for business and message relates solely to itS.I. 336/2011Customer soft opt-in limited to 12 months from saleDLA IEH
ItalyOpt-inConsentPrivacy Code s.130Consent must be recorded with date and personDLA ITH
LatviaUnclearUnclearLaw on Information Society ServicesDLA chapter lists no derogationsDLA LVL
LithuaniaOpt-inConsentElectronic Communications Law art. 81Restrictions "apply to ... both B2C and B2B"ICLG LTH
LuxembourgUnclearUnclearLaw of 30 May 2005DLA: "no specific provisions"DLA LUL
MaltaOpt-inConsentS.L. 586.01Applies "irrespective of whether ... natural person or a legal person"; consent "in writing"DLA MTH
NetherlandsNarrow opt-outConsentTelecommunicatiewet art. 11.7B2B exemption only for "designated" business contact details, "applied very strictly"ICLG NLM
PolandOpt-inConsentElectronic Communications Law art. 398Covers subscribers and end-users, explicitly B2BICLG PLH
PortugalOpt-outConsent (natural persons)Law 41/2004 (amended)Legal persons can register on a non-subscribers listDLA PTH
RomaniaOpt-inConsentLaw 506/2004"Expressly consented in advance" by subscriber or userDLA ROM
SlovakiaOpt-inConsentAct 452/2021Keep consent proof 4 years after withdrawal; confirm withdrawal within 30 daysDLA SKH
SloveniaOpt-in (likely)ConsentZEKom-2, ZEPT"Consent of an individual is required"; legal persons not spelled outDLA SIL
SpainOpt-inConsentLSSI 34/2002Consent required "also where the recipient is a legal entity"; "PUBLI" in subject; fines usually €30k–150kDLA ESH
SwedenOpt-outConsent (natural persons, incl. sole traders)Marketing Act s.19ICLG: consent rule "only applicable in business-to-consumer"; GDPR still covers employeesICLG SEM
Iceland (EEA)Opt-in (likely)ConsentElectronic Communications Act 70/2022"Subscriber" prior informed consent; legal persons not separatedDLA ISM
Liechtenstein (EEA)UnclearUnclearKommunikationsgesetz (unverified)No source retrievedn/aL
Norway (EEA)Generic onlyConsent, incl. "individual email address at work"Marketing Control Act s.15Natural-person rule reaches named work addressesICLG NOH
SwitzerlandOpt-inConsentUnfair Competition Act (UCA)Applies to "mass advertising", B2C and B2B alikeDLA CHH
UK (reference)Opt-outSole traders: consentPECR reg 22See UK: PECR and DUAA 2025ICOH
Not verified

Rows marked L, plus the legal-person position in Bulgaria, Greece, Romania, Czechia, Slovenia and Iceland, are inferred from statute wording, not from an explicit source statement. In Liechtenstein, the DLA Piper URL returned another country's chapter. Have local counsel confirm before hard-coding these rows into product logic.

Switzerland nuance

The UCA targets "mass advertising". Whether a single, individually written prospecting email falls outside it is debated. We did not verify a source on that point.

The pattern

TierCountriesWhat a sequencer should do
Opt-out to companiesFrance, Ireland, Sweden, Estonia, Finland, Portugal, Cyprus (+ UK)Allow; insert Art. 14 notice + opt-out; check role relevance (FR, FI, IE)
Generic / narrow onlyBelgium, Norway, Hungary, NetherlandsAllow for info@-type addresses; flag named addresses as consent-required
Consent requiredGermany, Austria, Italy, Spain, Poland, Denmark, Malta, Slovakia, Lithuania, Czechia, Romania, Greece, Switzerland (+ likely Iceland, Slovenia)Block or hard-warn unless a consent record exists
UnclearCroatia, Latvia, Luxembourg, Liechtenstein, Bulgaria (legal persons)Treat as consent-required by default
The numbers

By GDP the consent-required tier includes Germany, Italy, Spain, Poland, Austria, Denmark and Switzerland. Those are most of the continent's large B2B economies outside France, the UK and the Nordics.

Contradictions and gaps in the record

  • Sweden. DLA Piper says the Marketing Act rules apply "to natural persons as well as to legal entities". ICLG says the consent requirement is B2C only (DLA SE vs ICLG SE). We read the DLA line as referring to the identification and valid-address duty, and treat Sweden as opt-out for legal persons.
  • Netherlands. It is usually described as "opt-out for legal persons". ICLG describes a much narrower B2B exemption for "designated" contact details. We use the stricter reading.
  • Denmark. DLA's paraphrase mixes "anyone" with "natural person". We treat Denmark as opt-in for all, consistent with the statute's "anyone".
Gap in the record

No single authoritative, current table of the Art. 13(5) choices exists. The Commission has not published one since the ePrivacy Regulation was abandoned. This matrix is assembled from two law-firm guides. Vendor blog tables (sequencers, data vendors) disagree with each other and with these guides, and we did not use them.

What this means for an entrant

  • Turn this table into code. A recipient-country × address-type rule engine that allows, warns or blocks per contact is the most concrete "EU-native" feature an entrant can ship. US sequencers leave it to the customer. See Platform liability: what the sequencer itself risks and the openings.
  • Detect generic versus personal addresses. Four countries (BE, NO, HU, NL) turn on it, and it costs one classifier. Pair it with country detection from TLD, company HQ and enrichment data.
  • Default the unclear rows to strict. It costs a few lost sends in small markets and protects the product's credibility with EU legal buyers.
  • Sell the opt-out markets first. France, Ireland, the Nordics, Portugal and the UK give a legal B2B cold-email market of meaningful size with English or French as the working language. See Non-English markets and Go-to-market plan.
  • Keep the table maintained. Laws change: Belgium's DPA guidance is in consultation, the Netherlands has announced telemarketing changes, and the UK's DUAA guidance is "under review". A versioned, sourced ruleset is an asset that competitors would have to rebuild.
32 sources cited on this page · 4 domains
  1. DLA AT dlapiperdataprotection.com
  2. DLA BE dlapiperdataprotection.com
  3. DLA BG dlapiperdataprotection.com
  4. DLA HR dlapiperdataprotection.com
  5. DLA CY dlapiperdataprotection.com
  6. DLA CZ dlapiperdataprotection.com
  7. DLA DK dlapiperdataprotection.com
  8. DLA EE dlapiperdataprotection.com
  9. DLA FI dlapiperdataprotection.com
  10. CNIL cnil.fr
  11. DLA DE dlapiperdataprotection.com
  12. DLA GR dlapiperdataprotection.com
  13. ICLG HU iclg.com
  14. DLA IE dlapiperdataprotection.com
  15. DLA IT dlapiperdataprotection.com
  16. DLA LV dlapiperdataprotection.com
  17. ICLG LT iclg.com
  18. DLA LU dlapiperdataprotection.com
  19. DLA MT dlapiperdataprotection.com
  20. ICLG NL iclg.com
  21. ICLG PL iclg.com
  22. DLA PT dlapiperdataprotection.com
  23. DLA RO dlapiperdataprotection.com
  24. DLA SK dlapiperdataprotection.com
  25. DLA SI dlapiperdataprotection.com
  26. DLA ES dlapiperdataprotection.com
  27. ICLG SE iclg.com
  28. DLA IS dlapiperdataprotection.com
  29. ICLG NO iclg.com
  30. DLA CH dlapiperdataprotection.com
  31. ICO ico.org.uk
  32. DLA SE dlapiperdataprotection.com