B2B Email Compliance in DACH: Cold Emails, GDPR, and UWG — What's Allowed
Complete guide to the legal situation for B2B cold emails in Germany, Austria, and Switzerland: UWG, GDPR, ePrivacy, and practical implementation.
The legal situation: complicated, but doable
B2B cold emails in Germany sit at the intersection of the UWG (unfair competition law), GDPR (data protection), and the ePrivacy Directive. The good news: it’s allowed — if you do it right.
Germany: UWG + GDPR
UWG Section 7 — unfair competition law
The UWG treats advertising by electronic mail without prior express consent as “unreasonable harassment” — Section 7(2) No. 2 UWG, with no B2B exception. The presumed consent that Section 7(2) No. 1 UWG allows for telephone calls to business market participants does not exist for email.
Impermissible without consent — even when:
- there is a factual connection between your offer and the recipient’s business
- The email is clearly identifiable as advertising
- A working opt-out is provided
- The sender is correctly identifiable (legal notice/Impressum obligation)
Not allowed:
- Mass emails with no connection whatsoever to the recipient
- Concealing the promotional nature of the email
- Emails to private addresses (Gmail, web.de, etc.)
- Continuing to send after an opt-out
GDPR — data protection
Processing business contact data for cold emails is based on Art. 6(1)(f) GDPR (legitimate interest).
Your obligations:
| Obligation | What you have to do |
|---|---|
| Legal basis | Document legitimate interest |
| Balancing of interests | Weigh your interest against the recipient’s rights and document it |
| Information obligation | Privacy notice in the email (or a link to it) |
| Right to object | A simple opt-out in every email |
| Data minimization | Collect only necessary data (name, email, company, role) |
| Storage limitation | Delete data once there’s no longer a reason to process it |
Practical implementation for Germany
Email footer (mandatory information):
[Company name] | [Address] | [Commercial register]
You are receiving this email because your company operates
in the [industry] sector and our offer might be relevant to you.
Privacy: [link to privacy policy]
Unsubscribe: [unsubscribe link]
Austria: stricter than Germany
The Austrian TKG 2021 Section 174 is more restrictive:
- Rule: Email advertising requires prior consent (opt-in)
- Exception: An existing business relationship + a similar product/service
- B2B practice: Significantly more restricted than in Germany
Recommendation for Austria:
- Cold emails to new contacts are risky
- Better: LinkedIn connection first, then email after contact has been made
- Or: phone-based first contact, then email as a follow-up
Switzerland: similar to Germany
Switzerland’s nDSG (new data protection act, since 2023) and its UWG are comparable to the German regulation:
- B2B cold emails: Allowed with a factual connection and an opt-out
- No GDPR application (except when processing EU citizens’ data)
- Swiss UWG Art. 3(o): Prohibits mass advertising without a connection, allows targeted B2B outreach
Compliance checklist for the DACH region
Before sending
- Only business email addresses (no @gmail, @web.de, etc.)
- Factual connection between offer and recipient’s business can be established
- Balancing of interests documented (a template is enough)
- Privacy policy updated (mentions cold outreach)
- Opt-out process works and has been tested
- Sender correctly identifiable (company, address)
In every email
- Company name and address in the footer
- Unsubscribe link (working)
- Privacy notice or link to the privacy policy
- No concealed promotional character
After sending
- Opt-outs implemented within 24h
- Opt-out list maintained (suppression list)
- Bounces removed
- No renewed contact after an opt-out
Technical implementation with tools
Instantly.ai / Lemlist
Both tools offer:
- Automatic unsubscribe link
- Suppression lists (global opt-out list)
- Custom footer with mandatory information
Setup:
- Create a footer template with all mandatory information
- Enable the unsubscribe link (this is standard)
- Set up a suppression list and check it before every send
- Automatically remove bounced emails
Clay + enrichment
GDPR-compliant enrichment:
- Only enrich business data
- No private social media profiles
- Keep a record of processing activities (which data, from where, for what)
- Delete data after 6 months of no interaction
The most common mistakes
- Contacting private email addresses — @gmail.de is a no-go, even if used for business
- No opt-out — every cold email must have a working unsubscribe link
- Continuing to email after an opt-out — stop immediately, add to the suppression list
- No documented balancing of interests — must be documented before the first email goes out
- Treating Austria like Germany — Austria is stricter, different rules apply
- Using tool data without checking it — Apollo/ZoomInfo data also contains private addresses, filter first
Template: balancing of interests (fill in)
BALANCING OF INTERESTS under Art. 6(1)(f) GDPR
Controller: [Company]
Date: [Date]
1. LEGITIMATE INTEREST
We contact companies in the [industry/segment] sector
to introduce our [service].
2. NECESSITY
Email is the most efficient channel for B2B first contact.
Alternative channels (mail, phone) are less effective
and more expensive.
3. BALANCING OF INTERESTS
- Our interest: acquiring new customers, economic viability
- Recipient's interest: a potentially relevant offer for their business
- Intrusion: low (1 email, business address, simple opt-out)
4. PROTECTION OF DATA SUBJECTS
- Business contact data only
- Transparent sender
- Simple opt-out in every email
- Deletion after 6 months of no interaction
CONCLUSION: The controller's interests prevail,
since the intrusion is low and appropriate protective
measures are in place.
Start your free trial · 4 weeks free on self-registration, no credit card. Prefer to see it running first? Book a demo.
Common questions
Are B2B cold emails allowed in Germany?
No, not without prior express consent. Section 7(2) No. 2 UWG treats advertising by electronic mail without prior express consent as an unreasonable nuisance — in B2B too. There is no B2B exception: the law allows presumed consent only for telephone calls to business market participants (Section 7(2) No. 1 UWG), not for email. Data processing is a separate question: researching and storing business contact data from public sources is possible under legitimate interest, Art. 6(1)(f) GDPR — that is the basis for processing, not for sending. Anyone who sends anyway is making a deliberate risk decision: a cease-and-desist warning is possible, the warning costs for a single email realistically run 300 to 500 euros and have to be paid, plus a cease-and-desist undertaking with a contractual penalty for any repeat.
What GDPR rules apply to B2B cold emails?
The GDPR allows processing business contact data on the basis of legitimate interests (Art. 6(1)(f)). Requirements: a business (not private) email address, a factual connection to the offer, a documented balancing of interests, information obligations fulfilled (privacy notice in the footer), and an easily exercisable right to object.
Are there differences between Germany, Austria, and Switzerland?
No — all three countries require consent for email advertising in principle. Germany: Section 7(2) No. 2 UWG requires prior express consent, in B2B too; presumed consent covers telephone only. Austria: Section 174 TKG 2021 likewise requires consent in principle, with a narrow exception for existing business relationships. Switzerland: nDSG and UWG, likewise with a consent requirement and a mandatory opt-out.
What happens if I violate the rules?
A warning notice (Abmahnung) from a competitor (the most common scenario): €1,000-5,000 per violation. A GDPR fine from the data protection authority: up to €20 million or 4% of annual revenue (in practice, rarely this high for B2B cold emails). A cease-and-desist declaration: every further violation triggers a contractual penalty.
How do I make B2B cold emails GDPR-compliant?
5 points: (1) use only business email addresses, (2) establish a factual connection to the recipient's business, (3) include a privacy notice in the footer (who processes the data, legal basis, right to object), (4) include a working unsubscribe link, (5) respect and document opt-outs immediately.