France is the most permissive large EU market for B2B cold email on paper and the most heavily enforced in practice. Article L.34-5 of the Postal and Electronic Communications Code (CPCE), as read by the CNIL, requires consent only for consumers. Professionals can be emailed on a legitimate-interest basis if the message concerns their profession. The CNIL then enforces the surrounding GDPR duties hard: valid sourcing, information, retention and access. It has fined the data supply chain, not just senders: KASPR (€240,000), Solocal Marketing Services (€900,000), Caloga (€80,000) and Tagadamedia.
For a sequencer, France is a good market to serve. For a data vendor, it is the most dangerous jurisdiction in Europe.
The B2B rule
The CNIL's prospection guidance (CNIL):
- B2B: no prior consent when the solicitation relates to the recipient's profession. The CNIL's example is pitching software to a company's IT director.
- The person must have been informed that their address may be used for prospection and must be able to object easily. Every message must identify the sender and offer a simple opt-out.
- Generic addresses of legal persons (
info@,contact@,commande@) "are not subject to" these rules. - B2C needs prior consent through an unticked box, except for existing customers buying similar products.
DLA Piper adds that the information must be given "at the time of collection" of the address (DLA Piper France). That is hard for scraped or bought data. In practice the first email has to carry the GDPR Art. 14 notice. See GDPR and ePrivacy.
"Relates to the profession" is a real condition. Pitching payroll software to an HR director qualifies. Pitching a personal-finance app to the same person at her work address does not. AI-generated "relevance" at scale is easy to get wrong.
CNIL enforcement relevant to outbound
| Date | Company | What | Fine | Source |
|---|---|---|---|---|
| 5 Dec 2024 | KASPR (Chrome extension, LinkedIn contact data) | No legal basis for contacts whose LinkedIn visibility was restricted; 5-year retention renewed on every update; no Art. 14 info until 2022, then English only; access requests answered "public sources" | €240,000 + injunction (€10k/day) | CNIL |
| 4 Mar 2026 | KASPR: injunction closed | KASPR erased its database and stopped all LinkedIn collection; now informs in all EU official languages | No penalty liquidated | CNIL |
| 15 May 2025 | Solocal Marketing Services | Bought prospect data from brokers whose forms did not produce valid consent; emailed and texted for advertisers | €900,000 + injunction | CNIL |
| 17 Sep 2026 | Solocal: injunction closed | Remedy accepted: automated analysis of partners' collection forms plus human review | No penalty liquidated | CNIL |
| 15 May 2025 | Caloga (data broker emailing for advertisers) | Consent, withdrawal, legal basis, retention | €80,000 | CNIL sanctions table |
| 29 Dec 2023 | Tagadamedia (contest-site data broker) | Deceptive consent forms | €75,000, reduced to €50,000 by the Conseil d'État on 20 May 2026 (procedural) | CNIL |
| 4 Apr 2024 | Telecom equipment retailer | L.34-5 consent, legal basis, Art. 14 information | €525,000 | CNIL sanctions table |
Most of these are B2C prospection or data-broker cases. KASPR is the B2B one. It is the closest European precedent to Apollo, Lusha, Cognism and every "find the email from a LinkedIn profile" extension. The CNIL adopted it "in cooperation with all its European counterparts" (CNIL), so it reads as an EU-wide position. See Data sourcing law.
The KASPR outcome is more important than the fine. Faced with an injunction, the company chose to delete its ~160 million-contact database rather than sort the lawful records from the unlawful ones. A lead database whose provenance cannot be shown per record is exposed to exactly this.
KASPR: about 160 million contacts, a €240,000 fine, a €10,000-a-day penalty threat, and a full database deletion within 15 months. Solocal: "several million" people affected, €900,000.
Buyers are liable for suppliers
The Solocal decision is the one to pin up for anyone who buys data. Solocal did not collect the data. It bought it from first collectors. The CNIL still held Solocal responsible for the defective consent. When the injunction was closed in September 2026, the CNIL accepted a tooling remedy: automated checks of every partner's collection forms, with human review. It also warned that Solocal remains responsible (CNIL). For B2B the legal basis differs (legitimate interest rather than consent), but the principle carries over: the sender answers for the provenance of the list.
Other French developments
- The CNIL's June 2025 note on legitimate interest for web scraping says respecting robots.txt and CAPTCHAs is a condition of meeting people's reasonable expectations (CNIL). It was written for AI training data, but the reasoning applies to lead scraping too.
- The CNIL sanctions table for 2026 (to March) shows breach and security fines and no prospection fines yet (CNIL).
A 2025 French law reportedly made telephone canvassing of consumers opt-in from August 2026. We did not verify it in this pass. It would affect B2C phone, not B2B email.
What this means for an entrant
- France is a good market for a sequencer. B2B email is lawful with an opt-out, and the market is large and has a strong outbound culture (lemlist and La Growth Machine are French). Ship French-language Art. 14 notices and role-relevance checks and the legal story is clean.
- Do not build a LinkedIn-derived contact database for the EU. KASPR shows where that ends. If you must offer data, use sources whose collection you can document per record (company websites, registers, opt-in networks), keep short retention without auto-renewal, and send notices in the recipient's language. See Built-in lead database and Contact data and enrichment.
- Build supplier and list checks. The CNIL accepted automated form analysis as a remedy. A product that scores the provenance of an imported list (source, collection method, notice given) answers a question French buyers' DPOs ask. See the openings.
- Make "relevant to the profession" checkable. Store the recipient's role and the campaign's offer category, and warn when they do not match. It is a small model call with real legal value. See AI personalisation.
- Answer access requests properly. "Where did you get my data?" must name the actual source. Log it at import. KASPR was fined for answering "public sources".