Outbound Atlas

Atlas/The law/Europe

GDPR and ePrivacy

Two laws stack on every EU cold email: the ePrivacy Directive decides whether you may send at all, the GDPR decides how you may hold and use the contact data.

Lawmedium confidence9 minupdated 2026-10-0519 sources
Jurisdiction
European Union / EEA
Regime
Mixed
Cold B2B email
Member-state choice: opt-in in roughly half the bloc, opt-out to legal persons in the rest; GDPR applies to every named contact
Penalty
GDPR fines up to €20m or 4% of global turnover; national ePrivacy penalties and civil claims vary
Enforced by
National data protection authorities + national ePrivacy/consumer/telecom regulators and courts

Every cold email to a European recipient passes two separate tests. The ePrivacy Directive (2002/58/EC, Art. 13) and its 30-odd national transpositions decide whether you may send an unsolicited marketing email at all. The GDPR decides whether you may collect, store and use the person's name and address to do it. A campaign can pass one and fail the other. Most US-built sequencers treat Europe as one "GDPR" checkbox. It is not one regime. It is roughly 30, and the variation sits in the ePrivacy layer, not in the GDPR.

The big change since 2024 is that the ePrivacy reform is dead. The national rules that were supposed to be harmonised are now permanent. A second change came from the Court of Justice in November 2025: where the ePrivacy rules allow a marketing email, there is no second GDPR legal-basis test. Founders should read that ruling as clearing up how the two laws fit together, not as permission to send more.

Layer 1: ePrivacy decides whether you may send

Article 13(1) of the Directive requires prior consent for marketing by "electronic mail" to natural-person subscribers. Article 13(2) is the soft opt-in for existing customers. Article 13(5) leaves member states to protect "subscribers other than natural persons" (companies) as they see fit. That one clause explains why B2B cold email is legal with an opt-out in France, Ireland, Sweden and Estonia but needs prior consent in Germany, Austria, Italy, Spain and Poland. The full country split is on EU/EEA country matrix.

Three consequences for a sending platform:

  • The recipient's country governs, not the sender's. National rules apply to marketing directed at their market. In April 2026 a German district court found a Belgian software firm liable for three emails to a German business address (AG Düsseldorf, 38 C 135/25, via Otto Schmidt). Hungary's chapter in ICLG says the same thing outright: the rules "apply to marketing directed to Hungary" (ICLG Hungary).
  • "Legal person" is not "work email". Many opt-out countries exempt only the company itself. A named employee's address can still count as a natural person: Norway covers "a natural person's individual email address at work" (ICLG Norway). Finland requires consent for a personal work address unless the offer "is substantially related to the person's work duties" (DLA Piper Finland). Belgium's B2B exception is framed around legal persons, "e.g. to a general email address" (DLA Piper Belgium).
  • Formal requirements apply everywhere. Every regime requires sender identification and a working opt-out. Spain adds a "PUBLI" or "PUBLICIDAD" label in the subject line (DLA Piper Spain).

The ePrivacy Regulation is dead

The Commission's 2025 work programme, published 11 February 2025, announced that it would withdraw the 2017 ePrivacy Regulation proposal for "lack of a consensus" (Hunton; TechCrunch). The formal withdrawal was published in the Official Journal on 6 October 2025 (C/2025/5423), per one secondary source. The Directive and its national laws stay in force with no replacement on the table.

The Digital Omnibus, proposed on 19 November 2025, moves the cookie rules into the GDPR and narrows the definition of personal data, but no source we read touches the Art. 13 rules on unsolicited communications. As of mid-2026 it was still in Parliament–Council negotiation, with application expected no earlier than mid-2027.

So what

Do not wait for Brussels to harmonise B2B email. The patchwork is now the permanent state. A product that encodes it per recipient country is building on stable ground.

Layer 2: GDPR decides how you may use the data

A business email such as jana.schmidt@firma.de is personal data, so the GDPR applies in full even in opt-out countries.

Legal basis: legitimate interest, Art. 6(1)(f). Recital 47 names direct marketing as a possible legitimate interest. In KNLTB (C-621/22, 4 October 2024) the CJEU confirmed that a purely commercial interest can qualify. It also said necessity is read strictly and the outcome turns on what data subjects "reasonably expect" (A&O Shearman). The EDPB's Guidelines 1/2024 on legitimate interest set out the three-step test (legitimate interest, necessity, balancing) (RPC).

Not verified

EDPB Guidelines 1/2024 were adopted for public consultation in October 2024. We could not confirm whether a final version had been adopted by October 2026.

Lex specialis: Inteligo Media (C-654/23, 13 November 2025). The Court held that where Art. 13(2) ePrivacy applies, the GDPR's Art. 6 conditions "are not applicable" (Art. 95 GDPR). No separate consent or legitimate-interest basis is needed for sending the email. It also read "in the context of a sale" broadly, so a free account given in exchange for data can qualify (Grünecker; Reed Smith). This matters most in Germany. German data protection authorities had argued that a breach of the unfair-competition rules automatically breaches the GDPR. DLA Piper now calls it "questionable whether this position can be upheld" (DLA Piper Germany). See Germany.

Caution

Inteligo removes a double test. It does not legalise cold email. Where national law requires consent, you still need consent. Storing, enriching and profiling contacts before the send is still GDPR processing that needs a basis.

Information duty: Art. 14. When data was not collected from the person (scraped, bought, enriched), the controller must tell them who it is, the purposes, the legal basis, the categories of data, the source, the retention period and their rights. This must happen within one month, or at the latest at the first communication if the data is used to contact them (Art. 14(3)(b)). In practice the first cold email can carry the notice. The exemption for "disproportionate effort" (Art. 14(5)(b)) is weak when you are emailing the person anyway. The CNIL fined KASPR partly for informing people four years late and only in English (CNIL, Dec 2024). See Data sourcing law.

Right to object: Art. 21(2)–(3). Objecting to direct marketing is unconditional. No balancing test applies and the processing must stop. Suppression has to persist: it should survive a list re-import, and it should hold across every client workspace that targets the same person.

Access: Art. 15(1)(g). People have the right to learn the source of their data. Answering "publicly available sources" was one of the breaches in the KASPR decision.

Where the CJEU has drawn lines

CaseDateHolding relevant to outbound
KNLTB C-621/224 Oct 2024Commercial interest can be legitimate; strict necessity; reasonable expectations decide (A&O Shearman)
Inteligo Media C-654/2313 Nov 2025ePrivacy Art. 13 is lex specialis; no separate Art. 6 basis for the send; broad "customer" concept (Grünecker)
StWL C-102/20Nov 2021Ads shown in an email inbox count as "electronic mail" under Art. 13
Not verified

The StWL row is from prior knowledge. We did not re-fetch it in this pass.

Enforcement reality

National authorities enforce the GDPR with fines of up to €20m or 4% of global turnover. ePrivacy breaches are enforced by a mix of DPAs, telecom and consumer regulators and, in Germany, competitors and recipients in civil courts. France is the most active fining authority on prospection. It fined Solocal Marketing Services €900,000 in May 2025 over consent bought from data brokers. See France. Individual GDPR damages are harder to get. Germany's Federal Court of Justice (BGH) refused Art. 82 damages for the mere receipt of a spam email in January 2025 (ra-plutte).

Gap in the record

We found no EU-wide statistic on DPA fines specifically for B2B cold email, as opposed to B2C prospection or data brokers. Most published fines involve consumers or data vendors, not senders of B2B sequences.

What this means for an entrant

  • Model the law per recipient, not per account. The unit of compliance is (recipient country × address type × relationship). A sequencer that knows the recipient's country and whether the address is generic or personal can gate sends. US incumbents treat this as the customer's problem. See EU/EEA country matrix and Platform liability: what the sequencer itself risks.
  • Ship Art. 14 as a feature. Auto-insert a localised first-contact notice (source, purpose, legal basis, objection link) into step one of every EU sequence. Log the data source per contact so a "where did you get my data?" request can be answered in one click. This is cheap to build, and its absence was the exact failure behind the KASPR fine.
  • Make objection global and permanent. One Art. 21 objection should suppress the person across campaigns, re-imports and, as a privacy-preserving hashed option, across workspaces. Agencies running many clients need this most. See Lead-gen agencies.
  • Sell evidence, not just sending. Legitimate-interest assessments, consent records with timestamps (Italy and Slovakia require them) and per-campaign audit trails are a product that EU buyers' legal teams will pay for. US tools do not ship them. See the openings.
  • Do not market "GDPR-compliant cold email" as a blanket claim. In Germany, Austria, Italy, Spain and Poland the honest answer is "only with consent". Claims that overreach invite cease-and-desist letters and regulator attention. See Provider rules: Google, Microsoft and the ESPs and Cold email law: the jurisdiction matrix.
19 sources cited on this page · 14 domains
  1. AG Düsseldorf, 38 C 135/25, via Otto Schmidt otto-schmidt.de
  2. ICLG Hungary iclg.com
  3. ICLG Norway iclg.com
  4. DLA Piper Finland dlapiperdataprotection.com
  5. DLA Piper Belgium dlapiperdataprotection.com
  6. DLA Piper Spain dlapiperdataprotection.com
  7. Hunton hunton.com
  8. TechCrunch techcrunch.com
  9. was published in the Official Journal on 6 October 2025 (C/2025/5423), per one secondary source nicfab.eu
  10. 19 November 2025 insideprivacy.com
  11. in Parliament–Council negotiation, with application expected no earlier than mid-2027 ontapgroup.com
  12. A&O Shearman aoshearman.com
  13. RPC rpclegal.com
  14. Grünecker grunecker.de
  15. Reed Smith viewpoints.reedsmith.com
  16. DLA Piper Germany dlapiperdataprotection.com
  17. CNIL, Dec 2024 cnil.fr
  18. €900,000 in May 2025 cnil.fr
  19. ra-plutte ra-plutte.de