Outbound Atlas

Atlas/The law/Europe

France

France allows B2B cold email without consent if the message relates to the recipient's job, but the CNIL is Europe's most active fining authority on prospection and data brokers, KASPR included.

Lawhigh confidence7 minupdated 2026-10-059 sources
Jurisdiction
France
Regime
Mixed
Cold B2B email
Allowed without prior consent if the message relates to the recipient's profession, with information and an easy opt-out
Penalty
CNIL fines under GDPR (up to 4% of turnover) and the CPCE; recent prospection fines €80k–€900k plus injunctions with €10k/day penalties
Enforced by
CNIL

France is the most permissive large EU market for B2B cold email on paper and the most heavily enforced in practice. Article L.34-5 of the Postal and Electronic Communications Code (CPCE), as read by the CNIL, requires consent only for consumers. Professionals can be emailed on a legitimate-interest basis if the message concerns their profession. The CNIL then enforces the surrounding GDPR duties hard: valid sourcing, information, retention and access. It has fined the data supply chain, not just senders: KASPR (€240,000), Solocal Marketing Services (€900,000), Caloga (€80,000) and Tagadamedia.

For a sequencer, France is a good market to serve. For a data vendor, it is the most dangerous jurisdiction in Europe.

The B2B rule

The CNIL's prospection guidance (CNIL):

  • B2B: no prior consent when the solicitation relates to the recipient's profession. The CNIL's example is pitching software to a company's IT director.
  • The person must have been informed that their address may be used for prospection and must be able to object easily. Every message must identify the sender and offer a simple opt-out.
  • Generic addresses of legal persons (info@, contact@, commande@) "are not subject to" these rules.
  • B2C needs prior consent through an unticked box, except for existing customers buying similar products.

DLA Piper adds that the information must be given "at the time of collection" of the address (DLA Piper France). That is hard for scraped or bought data. In practice the first email has to carry the GDPR Art. 14 notice. See GDPR and ePrivacy.

Caution

"Relates to the profession" is a real condition. Pitching payroll software to an HR director qualifies. Pitching a personal-finance app to the same person at her work address does not. AI-generated "relevance" at scale is easy to get wrong.

CNIL enforcement relevant to outbound

DateCompanyWhatFineSource
5 Dec 2024KASPR (Chrome extension, LinkedIn contact data)No legal basis for contacts whose LinkedIn visibility was restricted; 5-year retention renewed on every update; no Art. 14 info until 2022, then English only; access requests answered "public sources"€240,000 + injunction (€10k/day)CNIL
4 Mar 2026KASPR: injunction closedKASPR erased its database and stopped all LinkedIn collection; now informs in all EU official languagesNo penalty liquidatedCNIL
15 May 2025Solocal Marketing ServicesBought prospect data from brokers whose forms did not produce valid consent; emailed and texted for advertisers€900,000 + injunctionCNIL
17 Sep 2026Solocal: injunction closedRemedy accepted: automated analysis of partners' collection forms plus human reviewNo penalty liquidatedCNIL
15 May 2025Caloga (data broker emailing for advertisers)Consent, withdrawal, legal basis, retention€80,000CNIL sanctions table
29 Dec 2023Tagadamedia (contest-site data broker)Deceptive consent forms€75,000, reduced to €50,000 by the Conseil d'État on 20 May 2026 (procedural)CNIL
4 Apr 2024Telecom equipment retailerL.34-5 consent, legal basis, Art. 14 information€525,000CNIL sanctions table

Most of these are B2C prospection or data-broker cases. KASPR is the B2B one. It is the closest European precedent to Apollo, Lusha, Cognism and every "find the email from a LinkedIn profile" extension. The CNIL adopted it "in cooperation with all its European counterparts" (CNIL), so it reads as an EU-wide position. See Data sourcing law.

So what

The KASPR outcome is more important than the fine. Faced with an injunction, the company chose to delete its ~160 million-contact database rather than sort the lawful records from the unlawful ones. A lead database whose provenance cannot be shown per record is exposed to exactly this.

The numbers

KASPR: about 160 million contacts, a €240,000 fine, a €10,000-a-day penalty threat, and a full database deletion within 15 months. Solocal: "several million" people affected, €900,000.

Buyers are liable for suppliers

The Solocal decision is the one to pin up for anyone who buys data. Solocal did not collect the data. It bought it from first collectors. The CNIL still held Solocal responsible for the defective consent. When the injunction was closed in September 2026, the CNIL accepted a tooling remedy: automated checks of every partner's collection forms, with human review. It also warned that Solocal remains responsible (CNIL). For B2B the legal basis differs (legitimate interest rather than consent), but the principle carries over: the sender answers for the provenance of the list.

Other French developments

  • The CNIL's June 2025 note on legitimate interest for web scraping says respecting robots.txt and CAPTCHAs is a condition of meeting people's reasonable expectations (CNIL). It was written for AI training data, but the reasoning applies to lead scraping too.
  • The CNIL sanctions table for 2026 (to March) shows breach and security fines and no prospection fines yet (CNIL).
Not verified

A 2025 French law reportedly made telephone canvassing of consumers opt-in from August 2026. We did not verify it in this pass. It would affect B2C phone, not B2B email.

What this means for an entrant

  • France is a good market for a sequencer. B2B email is lawful with an opt-out, and the market is large and has a strong outbound culture (lemlist and La Growth Machine are French). Ship French-language Art. 14 notices and role-relevance checks and the legal story is clean.
  • Do not build a LinkedIn-derived contact database for the EU. KASPR shows where that ends. If you must offer data, use sources whose collection you can document per record (company websites, registers, opt-in networks), keep short retention without auto-renewal, and send notices in the recipient's language. See Built-in lead database and Contact data and enrichment.
  • Build supplier and list checks. The CNIL accepted automated form analysis as a remedy. A product that scores the provenance of an imported list (source, collection method, notice given) answers a question French buyers' DPOs ask. See the openings.
  • Make "relevant to the profession" checkable. Store the recipient's role and the campaign's offer category, and warn when they do not match. It is a small model call with real legal value. See AI personalisation.
  • Answer access requests properly. "Where did you get my data?" must name the actual source. Log it at import. KASPR was fined for answering "public sources".
9 sources cited on this page · 2 domains
  1. CNIL cnil.fr
  2. DLA Piper France dlapiperdataprotection.com
  3. CNIL cnil.fr
  4. CNIL cnil.fr
  5. CNIL cnil.fr
  6. CNIL cnil.fr
  7. CNIL sanctions table cnil.fr
  8. CNIL cnil.fr
  9. CNIL cnil.fr