What GDPR Actually Requires Before You Send a Cold Email
Consent rules differ sharply between B2B and B2C cold email under GDPR.

What GDPR actually requires before you send a cold email is the subject of this analysis.
GDPR does not ban cold email, but it does regulate every step of sending one
GDPR governs every stage of the process that produces a cold email: how the address was found, why the sender believes contact is justified, what the message must disclose, and what happens after someone asks to be left alone. What it does is govern every stage of the process that produces one: how the address was found, why the sender believes contact is justified, what the message must disclose, and what happens after someone asks to be left alone gdprlocal.com instantly.ai. As soon as a message goes out to a named, identifiable person, personal data is in play, and GDPR attaches, governing how the address was found, why the sender believes contact is justified, what the message must disclose, and what happens after someone asks to be left alone. The list may have come from a scrape, a paid database, or a manually built spreadsheet.
Two different laws actually govern this space, and conflating them is where a lot of outreach programs go wrong. GDPR asks whether the sender had a lawful basis to process the recipient's data. The ePrivacy Directive asks a narrower, blunter question: is the sender allowed to send this particular kind of message in the first place. Both apply at once, and a sender has to clear both bars, not just one⟧. Where the two disagree, ePrivacy wins, because it's the more specific instrument governing electronic communications, a legal principle known as lex specialis. Everything that follows in this piece, from legal basis through enforcement, sits downstream of that one distinction.
Different rules for B2B and B2C cold email
The single most consequential decision a sender makes happens before a single word of copy gets written: is this list B2B or B2C gdprlocal.com instantly.ai mailforge.ai? For business contacts, legitimate interest under Article 6(1)(f) is the standard, well-established basis for outreach, and it's the approach most professional cold email relies on. For consumer contacts, the ePrivacy Directive's prior consent requirement takes over in most member states, and legitimate interest doesn't override it. Two people receiving structurally identical emails can be governed by two entirely different legal regimes, depending on nothing more than the kind of address they gave out.
The practical test is almost embarrassingly simple: does the address belong to a named professional role at a company (jane@acmecorp.com), or does it read as personal (a Gmail, Yahoo, or Hotmail account)? A personal address signals a private, consumer context, which pulls the message toward the consent requirement. GDPR itself never draws this line formally. It emerges instead from how individual countries implemented ePrivacy, combined with the balancing test built into legitimate interest, where business addresses carry a lower expectation of privacy than personal ones. So the composition of a list, not the intent behind a campaign, is what decides the legal path available to a sender: a B2B list can proceed through the legitimate interest analysis below, while a list containing personal addresses needs consent, full stop.
How the legitimate interest test works in practice
Legitimate interest gets treated, informally, as the easy button for B2B outreach. It isn't one. It requires a documented, three-part assessment completed before any processing starts, and most senders skip the documentation.
The test itself runs in three stages. Purpose asks whether there's a concrete, present business interest behind the contact: "selling compliance software to financial services firms with 50-plus employees, and reaching their compliance leads" clears that bar; "we want more customers" does not mailforge.ai. Necessity asks whether email is actually required to achieve that purpose, not merely convenient. Balancing weighs the sender's interest against what the recipient would reasonably expect, given their professional role, and against what safeguards, like an opt-out or limited contact frequency, reduce the intrusion.
None of this carries legal weight unless it's written down. GDPR never uses the phrase "Legitimate Interest Assessment," but without a record showing the test was run before the email went out, the legal basis collapses the moment it's challenged. At scale, this gets harder, not easier: a company sending tens of thousands of emails a day cannot plausibly claim it verified legitimate interest for each named individual, so the documentation needs to cover the defined contact category, the shared characteristics that make the group relevant, rather than pretending each name was individually assessed.
What failure actually costs is not abstract. A B2B software company sent cold email to a large list of IT managers spanning France, the UK, and Germany without a single documented LIA on file gdprlocal.com mailshake.com instantly.ai mailforge.ai. A German data protection authority audited the campaign in the third quarter of 2025, found no LIA documentation and no verification of how the list was sourced, and the company settled for €500,000 gdprlocal.com mailshake.com instantly.ai mailforge.ai. Nothing about the campaign's substance was necessarily objectionable. The failure was procedural: no paper trail. The EDPB's October 2024 Guidelines 1/2024 replaced previous Working Party opinions and tightened the standard, requiring that the interest be lawful, clearly articulated, and real (not speculative or hypothetical) instantly.ai. The UK's ICO publishes a free LIA template, and most European DPAs expect an equivalent document.
Sourcing and list quality as a compliance prerequisite
Sourcing isn't a separate compliance category sitting next to legitimate interest. Sourcing is baked directly into whether the balancing test passes. Contacts pulled from public professional sources, LinkedIn profiles, company "team" pages, trade directories, generally support that test, because someone who lists their professional contact details publicly has, in effect, signaled they expect to be reached professionally.
Purchased lists sit on shakier ground. They're not off-limits, but the burden of proof rests entirely with the buyer: confirming that the vendor's own data collection was lawful is a contractual and due-diligence obligation, not a nice-to-have.
Sourcing also determines what has to be disclosed later, in the message itself. Article 14 requires that when data wasn't collected directly from the person being contacted, the sender must proactively tell them where it came from, and that obligation carries straight into the next section.
Required contents of the email before it reaches the inbox
The message itself has to do specific, unglamorous work. In practice this is one plain sentence ("found your contact through your company's website") plus a link to a full privacy policy. It is a small addition, and it frequently separates a defensible email from an indefensible one.
Beyond that, the subject line has to describe what's actually inside the message; a misleading subject line is its own, independent compliance problem, sitting at the intersection of GDPR's transparency rules and anti-spam law more broadly. Relevance isn't just good marketing practice here either, it's load-bearing for the legal argument itself: generic, mass-blast copy sent to a broad, undifferentiated list undercuts the very legitimate interest claim made in the LIA, because it suggests the sender never actually assessed who was being contacted or why. Every message needs a clear, low-friction way to decline further contact, whether that's an unsubscribe link or a plain instruction to reply "no thanks," and both are used in practice (reply-based opt-outs sometimes preferred purely for deliverability reasons). The footer should carry a link to a privacy policy that spells out what's collected, how it was sourced, the legal basis relied on, how long it's kept, and how to exercise data rights.
One newer wrinkle: starting in August 2026, Article 50 of the EU AI Act imposes transparency obligations on providers of generative AI tools, requiring machine-readable marking of AI-generated content gdprlocal.com instantly.ai. Article 50 doesn't explicitly force a sender using AI-drafted copy to add a per-email disclosure statement, though the general guidance leans toward transparency and logging wherever AI involvement could mislead a recipient gdprlocal.com instantly.ai. Practically, none of that removes the underlying burden. Whether the copy was written by a person or generated by a model, the compliance weight still rests on the sender's decisions about legal basis, sourcing, suppression, and how much data got fed into the drafting tool.
Managing opt-outs, deletion requests, and data retention after the send
GDPR technically allows 30 days to process an opt-out request, but that's a ceiling, not a target GDPR Cold Email: Complete Guide (2026). The realistic standard for cold email is stopping before the next scheduled touch to that contact, so suppression needs to be close to automatic, not a weekly manual export GDPR Cold Email: Complete Guide (2026). When someone opts out, every queued follow-up to them has to stop immediately, their address goes onto a suppression list so a future list refresh doesn't re-import them by accident, and if they ask for deletion, their data needs to come out of the CRM, the sending tool, and whatever enrichment platform was used to find them originally.
Slow opt-out handling appears repeatedly in ICO investigations as one of the most common failure points, and it trips up campaigns that were otherwise entirely lawful at the point of sending. A perfectly documented LIA doesn't help much if the suppression list takes two weeks to update.
Follow-up sequences aren't automatically a problem. A second or third email is judged by the same three-part legitimate interest test as the first one, so a well-reasoned follow-up sequence is lawful. But the retention clock started running the moment the first record was created, and that matters. GDPR sets no fixed retention period, but 12 to 24 months is a commonly cited, defensible range for cold prospect data, and one widely used approach is deleting records for anyone who never responded within 30 days of the first message mailforge.ai GDPR Cold Email: Complete Guide (2026). Senders also need a working process, built before any campaign launches, for handling Data Subject Access Requests GDPR Cold Email: Complete Guide (2026). If a European contact asks what data is held on them, the response is due within 30 days, and answering it requires actually knowing which systems that person's data lives in GDPR Cold Email: Complete Guide (2026).
Tracking pixels and email analytics as a separate compliance risk
Open tracking gets treated as a footnote in most cold email guidance, and that's a mistake. Tracking pixels and web beacons are inside GDPR's scope, and data protection authorities across the EU have steadily confirmed that they can't be deployed without the recipient's awareness. The pixel either identifies a specific individual or builds a behavioral profile over time, and the EDPB confirmed in 2023 that consent is required whenever it does instantly.ai.
France's CNIL drew that line with unusual precision in a recommendation issued in draft form in 2025 and finalized in April 2026. Measuring aggregate open rates at the campaign level, or opens broken down by recipient domain, doesn't require consent. Identifying which specific person opened or clicked a given email does. That's a meaningful operational distinction for anyone running analytics dashboards that report individual-level engagement by default.
The scrutiny here isn't theoretical. In March 2026, the EDPB launched its fifth Coordinated Enforcement Framework action, directing 25 national data protection authorities across Europe to simultaneously investigate transparency and information obligations under Articles 12 through 14 gdprlocal.com mailforge.ai instantly.ai. Tracking practices sit directly inside that scope. Any sender whose email platform tracks individual-level opens by default should check whether that tracking can be limited to aggregate or domain-level reporting, or whether it needs consent switched on before it's enabled.
Application of these rules in France, Germany, Spain, and the UK
Every EU member state implemented the ePrivacy Directive on its own terms, so a campaign that's compliant in one country can be a violation in the next. Treating "GDPR compliance" as a single, uniform checklist across borders is one of the more common misreadings of the regulation.
France doesn't require opt-in for B2B outreach, but it does require a working suppression list, and CNIL is an active enforcer gdprlocal.com instantly.ai mailforge.ai. From August 11, 2026, France's Law n° 2025-594 requires explicit prior opt-in for B2C telephone and SMS prospecting, replacing the older Bloctel opt-out register, though that change targets phone and text contact, not cold email; B2C email in France has separately required opt-in consent under existing law for some time, and CNIL's 2026 regulatory action was about tracking pixels, not sending rules gdprlocal.com instantly.ai mailforge.ai. B2B email remains lawful under legitimate interest. The largest email marketing consent fine on record as of 2024, €50 million against Orange, concerned promotional messages placed inside existing customers' inboxes rather than cold outreach to new prospects, so it's a useful data point on enforcement scale, not a direct precedent for cold email specifically gdprlocal.com instantly.ai mailforge.ai.
The Q3 2025 German DPA audit and €500,000 settlement illustrates how seriously German authorities take enforcement, in a country where fines can reach up to €300,000 per case gdprlocal.com mailshake.com instantly.ai GDPR Cold Email: Complete Guide (2026) mailforge.ai.
Spain requires consent as well, with a narrow soft opt-in exception under LSSI Article 21.2 for contacts arising from an existing contractual relationship. Spain's AEPD interprets that exception so tightly that it rarely provides a safe basis to build a program around. The UK's PECR framework is comparatively permissive, carving corporate subscribers out of the consent requirement entirely, though UK GDPR's separate lawful-basis requirement for data processing still applies regardless.
The operational implication is straightforward: segment outreach lists by country before sending, and apply the strictest rule that touches any given segment, since Germany calls for a fundamentally different approach than France or the UK do. For jurisdictions not covered here, checking local DPA guidance before launch matters, since restrictions vary further still: Denmark imposes restrictions tighter than the EU baseline, and Canada's CASL framework imposes restrictions comparable to the EU baseline, though stricter than the US CAN-SPAM standard.
The enforcement environment senders are operating in right now
GDPR's upper tier, covering unlawful data processing and failure to honor data subject rights, including opt-out failures, caps at €20 million or 4% of global annual revenue, whichever is greater instantly.ai. The lower tier, for procedural violations and inadequate security, caps at €10 million or 2% instantly.ai. Cold email failures tied to a missing legal basis or an unhonored opt-out request are in the upper tier, which is the one that actually threatens a company's financials.
This is not a distant risk. The CEF 2026 action launched in June 2026 has 25 national data protection authorities simultaneously investigating email marketing compliance, which is coordinated, cross-border scrutiny rather than one country's regulator acting alone gdprlocal.com instantly.ai. Regulators, in deciding penalties, weigh how severe and prolonged the violation was, how many people it touched, whether it was deliberate or careless, and what the company did to fix it: documented LIAs, working suppression lists, and fast opt-out handling all count as mitigation. Fines aren't the only cost, either. A public enforcement action carries reputational damage that compounds the financial penalty, and that's especially true in B2B, where the prospects being targeted are frequently the exact people most attuned to how their own data gets handled.
Every requirement covered here, LIA documentation, clean and verifiable sourcing, transparent message content, automated suppression, country-specific targeting, is precisely the list a regulator checks when deciding how much leniency to extend. Getting them right limits exposure before an investigation ever starts. Getting them wrong doesn't just risk a fine; it strips away every argument a company would otherwise have to make in its own defense. GDPR fines operate on a two-tier structure.
