Germany is the strictest large market in Europe for cold email. Section 7(2) No. 2 of the Unfair Competition Act (UWG) bans advertising by electronic mail "without the prior express consent of the addressee". It does not matter whether the addressee is a consumer or a business. For email there is no B2B exception and no "presumed consent". Presumed consent exists only for phone calls to businesses. That is why German companies call and do not email. A recipient can sue over one email, and German courts keep confirming it in 2026.
The risk is mostly not a regulator's fine. It is a steady supply of cease-and-desist letters (Abmahnungen) sent by the businesses you emailed, by competitors and by associations. Each one is cheap on its own and it adds up. The cost rises sharply if you keep sending after the first letter.
The rules
| Channel | B2C | B2B | Source |
|---|---|---|---|
| Prior express consent | Prior express consent | §7(2) Nr. 2 UWG; IHK Köln | |
| Email to existing customers | Soft opt-in, 4 cumulative conditions | Same | §7(3) UWG; DLA Piper DE |
| Phone | Prior express consent | Presumed consent suffices | §7(2) Nr. 1 UWG; BGH I ZR 27/08 (11 Mar 2010) via IHK Köln |
| LinkedIn / Xing message | Contested; scraping discouraged | Contested | bakedwith, 2026 |
The provisions were renumbered in 2022. Email now sits in §7(2) Nr. 2 and phone in Nr. 1. Older blog posts cite email as "Nr. 3". The brief for this page said B2B email allows "express or presumed consent". That is wrong for email. Presumed consent covers phone only.
The soft opt-in in §7(3) applies only when all of these hold: you got the address from the customer in connection with a sale, you advertise your own similar products, the customer has not objected, and you gave a clear opt-out notice both when you collected the address and in every email (DLA Piper DE). Prospects who never bought anything are not covered.
Consent must be specific. It must name who will contact the person, about what products and by which channel. Double opt-in is the German standard for proving it (DLA Piper DE). A published email address is not consent. The LG Baden-Baden (5 O 100/11, 2012) held that an address printed on a letterhead does not count (IHK Köln).
Case law that matters
| Court, date, ref | What happened | Holding |
|---|---|---|
| BGH, 20 May 2009, I ZR 218/07 | Single unsolicited ad email to a business | One email is already unlawful (IHK Köln) |
| KG Berlin, 20 Jun 2023, 5 W 6/23 | Spam to a lawyer, continued after warning | Dispute value €3,000 for the first email, €1,000 per further one (€300 if close in time), €3,000 per email after an Abmahnung (IT-Recht Kanzlei) |
| BGH, 28 Jan 2025, VI ZR 109/23 | Recipient claimed GDPR damages for ad emails | No Art. 82 GDPR damages without a real loss of control over the data. Injunctions and Abmahnung costs remain available (ra-plutte) |
| AG Düsseldorf, 19 Jan 2026, 290c C 153/25 | Recruiter's "business development" emails to a company | Counted as advertising. "Contact us" invitations are not consent. Only an undertaking backed by a contractual penalty removes the repetition risk (IHK Darmstadt) |
| AG Düsseldorf, 30 Apr 2026, 38 C 135/25 | Belgian software company sent 3 emails in Oct 2025, two of them after the warning letter | A one-off email is unlawful interference with the business. Presumed consent, a published address and an unsubscribe link were all rejected as defences. Dispute value €3,500, Abmahnung fees €403.50 net (Otto Schmidt) |
The Belgian case is the one to remember. A foreign sender emailing a German inbox is sued in Germany under German standards. Using a non-German entity or domain does not move you out of German law.
How the Abmahnung economy works
- Who sends them. The business recipient uses tort law: §§823 and 1004 of the Civil Code (BGB), interference with an established business. Competitors and qualified associations such as the Wettbewerbszentrale can use the UWG itself.
- What they demand. A cease-and-desist undertaking (strafbewehrte Unterlassungserklärung) backed by a contractual penalty, plus the lawyer's fees, calculated from the dispute value. The IHK describes contractual penalties of "multi-thousand-euro" amounts and dispute values that regularly exceed €5,000 at the regional courts (IHK Köln). The 2026 Düsseldorf case priced one case at about €480 in fees on a €3,500 value.
- Why it escalates. Once you have signed, every further email to that person can trigger the contractual penalty. If you have not signed, every further email raises the dispute value: €3,000 per email after a warning in the KG Berlin case.
For a campaign of 5,000 German contacts, one Abmahnung costs about €480 in fees. A court case on a €3,500 value adds court and lawyer costs on both sides. The real risk is repeat sending to someone who has already complained, because that is where contractual penalties and per-email values multiply.
The GDPR layer
German data protection authorities have long argued that marketing in breach of §7 UWG also breaches the GDPR, because there is no legitimate interest in unlawful advertising. The CJEU's Inteligo Media ruling (C-654/23, November 2025) treats ePrivacy as lex specialis over GDPR Art. 6. That has cast doubt on the authorities' approach. DLA Piper says it is "questionable whether this position can be upheld" and that it is unresolved whether the blocking effect reaches GDPR sanctions (DLA Piper DE). See GDPR and ePrivacy. Separately, building a contact database (scraping, enrichment, retention) is still GDPR processing that needs a basis and an Art. 14 notice. See Data sourcing law.
We found no 2025–2026 German DPA fine aimed specifically at B2B cold email. In Germany the practical enforcement is civil (Abmahnungen), not administrative.
What German companies actually do
- Phone first. B2B cold calling is lawful with presumed consent, meaning a concrete, objective reason to think the business would welcome the call. A 2026 German guide calls phone the B2B channel that is "grundsätzlich erlaubt" (bakedwith).
- LinkedIn and Xing outreach, manual or automated. This carries platform-terms risk rather than UWG certainty. See HeyReach and Multichannel: LinkedIn, calls, SMS and video.
- Consent-first email: a phone or LinkedIn touch asks for permission, and the email follows once permission is recorded.
- Sending anyway. Plenty of German agencies and startups run cold email and price in the occasional Abmahnung. Many use US tools (Instantly, Apollo.io, Clay) or lemlist. The same 2026 guide lists HubSpot, Pipedrive, Apollo and Clay as the common stack.
No survey data exists on how many German B2B firms send cold email despite §7, or on which sequencers they use. The tool list above is anecdotal (one 2026 blog). Treat it as directional only.
A Germany-based platform: three separate questions
1. Your own marketing. You advertise to German businesses, so §7 UWG binds you. You cannot cold email German prospects for your own product. Recipients include German founders and agencies who know the rules and send Abmahnungen. Cold email into opt-out markets (UK corporate subscribers, France, Ireland, the Nordics, the US) is governed by those markets' rules. See UK: PECR and DUAA 2025, France and United States: CAN-SPAM and state email laws.
2. Your customers' campaigns. The customer is the advertiser and the sender. Liability under the UWG and BGB attaches to whoever sends, or has someone send, the advertising. For campaign data you are usually an Art. 28 processor. Platform-level exposure, such as being named as a contributing party (Störer) after notice of repeated abuse, is untested for cold-email SaaS. See Platform liability: what the sequencer itself risks and Provider rules: Google, Microsoft and the ESPs.
3. Your lead database, if you ship one. You are the controller for the data you collect and resell. Art. 6 basis, Art. 14 notices, retention limits and access answers that name the source are your obligations. Your lead authority is the DPA of the German state where you have your main establishment. KASPR is the cautionary case. See Data sourcing law and Built-in lead database.
Points 2 and 3 are analysis from general principles: the market-location principle, GDPR Arts 3, 28 and 56, and German Störerhaftung doctrine. We found no German judgment on a cold-email SaaS provider's own liability. Get counsel before relying on them.
What this means for an entrant
- Do not build for German cold email as your home market. It is the hardest EU market to serve legally. Being German-based is not a disadvantage when your customers sell into the UK, France, the Nordics or the US. See Non-English markets.
- "DSGVO-konform" as a positioning claim needs a German-specific mode. That means recipient-country detection, a block or hard warning on German recipients without a consent record, a consent ledger with double-opt-in proof, and a global objection list. No incumbent we reviewed markets this. Verify against the feature matrix.
- Build the consent-first funnel. Phone (allowed B2B) and LinkedIn touches, then a recorded "yes, send me details", then email. A sequencer that captures and timestamps that consent turns German outbound from an Abmahnung risk into a defensible process. See Multichannel steps.
- Fix repeat sending first. Most cost comes from emailing someone again after they complained. Cross-campaign, cross-workspace suppression with an "Abmahnung received" flag is a small feature with outsized value.
- Market your own product within the law. Use content, partnerships, opt-in lists, and outbound to non-German opt-out markets. Your first Abmahnung will become a Reddit thread about a "compliant cold email tool" that cold-emailed Germans. See Go-to-market plan.