B2B Email Compliance in DACH: Cold Emails, GDPR, and UWG — What's Allowed
Complete guide to the legal situation for B2B cold emails in Germany, Austria, and Switzerland: UWG, GDPR, ePrivacy, and practical implementation.
The legal situation: complicated, but doable
B2B cold emails in Germany sit at the intersection of the UWG (unfair competition law), GDPR (data protection), and the ePrivacy Directive. The good news: it’s allowed — if you do it right.
Germany: UWG + GDPR
UWG Section 7 — unfair competition law
The UWG generally prohibits “unreasonable harassment” through advertising. For B2B emails, an important exception applies:
Allowed when:
- Presumed interest of the recipient exists (a factual connection between your offer and their business)
- The email is clearly identifiable as advertising
- A working opt-out is provided
- The sender is correctly identifiable (legal notice/Impressum obligation)
Not allowed:
- Mass emails with no connection whatsoever to the recipient
- Concealing the promotional nature of the email
- Emails to private addresses (Gmail, web.de, etc.)
- Continuing to send after an opt-out
GDPR — data protection
Processing business contact data for cold emails is based on Art. 6(1)(f) GDPR (legitimate interest).
Your obligations:
| Obligation | What you have to do |
|---|---|
| Legal basis | Document legitimate interest |
| Balancing of interests | Weigh your interest against the recipient’s rights and document it |
| Information obligation | Privacy notice in the email (or a link to it) |
| Right to object | A simple opt-out in every email |
| Data minimization | Collect only necessary data (name, email, company, role) |
| Storage limitation | Delete data once there’s no longer a reason to process it |
Practical implementation for Germany
Email footer (mandatory information):
[Company name] | [Address] | [Commercial register]
You are receiving this email because your company operates
in the [industry] sector and our offer might be relevant to you.
Privacy: [link to privacy policy]
Unsubscribe: [unsubscribe link]
Austria: stricter than Germany
The Austrian TKG 2021 Section 174 is more restrictive:
- Rule: Email advertising requires prior consent (opt-in)
- Exception: An existing business relationship + a similar product/service
- B2B practice: Significantly more restricted than in Germany
Recommendation for Austria:
- Cold emails to new contacts are risky
- Better: LinkedIn connection first, then email after contact has been made
- Or: phone-based first contact, then email as a follow-up
Switzerland: similar to Germany
Switzerland’s nDSG (new data protection act, since 2023) and its UWG are comparable to the German regulation:
- B2B cold emails: Allowed with a factual connection and an opt-out
- No GDPR application (except when processing EU citizens’ data)
- Swiss UWG Art. 3(o): Prohibits mass advertising without a connection, allows targeted B2B outreach
Compliance checklist for the DACH region
Before sending
- Only business email addresses (no @gmail, @web.de, etc.)
- Factual connection between offer and recipient’s business can be established
- Balancing of interests documented (a template is enough)
- Privacy policy updated (mentions cold outreach)
- Opt-out process works and has been tested
- Sender correctly identifiable (company, address)
In every email
- Company name and address in the footer
- Unsubscribe link (working)
- Privacy notice or link to the privacy policy
- No concealed promotional character
After sending
- Opt-outs implemented within 24h
- Opt-out list maintained (suppression list)
- Bounces removed
- No renewed contact after an opt-out
Technical implementation with tools
Instantly.ai / Lemlist
Both tools offer:
- Automatic unsubscribe link
- Suppression lists (global opt-out list)
- Custom footer with mandatory information
Setup:
- Create a footer template with all mandatory information
- Enable the unsubscribe link (this is standard)
- Set up a suppression list and check it before every send
- Automatically remove bounced emails
Clay + enrichment
GDPR-compliant enrichment:
- Only enrich business data
- No private social media profiles
- Keep a record of processing activities (which data, from where, for what)
- Delete data after 6 months of no interaction
The most common mistakes
- Contacting private email addresses — @gmail.de is a no-go, even if used for business
- No opt-out — every cold email must have a working unsubscribe link
- Continuing to email after an opt-out — stop immediately, add to the suppression list
- No documented balancing of interests — must be documented before the first email goes out
- Treating Austria like Germany — Austria is stricter, different rules apply
- Using tool data without checking it — Apollo/ZoomInfo data also contains private addresses, filter first
Template: balancing of interests (fill in)
BALANCING OF INTERESTS under Art. 6(1)(f) GDPR
Controller: [Company]
Date: [Date]
1. LEGITIMATE INTEREST
We contact companies in the [industry/segment] sector
to introduce our [service].
2. NECESSITY
Email is the most efficient channel for B2B first contact.
Alternative channels (mail, phone) are less effective
and more expensive.
3. BALANCING OF INTERESTS
- Our interest: acquiring new customers, economic viability
- Recipient's interest: a potentially relevant offer for their business
- Intrusion: low (1 email, business address, simple opt-out)
4. PROTECTION OF DATA SUBJECTS
- Business contact data only
- Transparent sender
- Simple opt-out in every email
- Deletion after 6 months of no interaction
CONCLUSION: The controller's interests prevail,
since the intrusion is low and appropriate protective
measures are in place.
Start your free trial · 4 weeks free, no credit card. Prefer to see it running first? Book a demo.
Common questions
Are B2B cold emails allowed in Germany?
Yes, under certain conditions. Section 7(2) No. 3 of the German Unfair Competition Act (UWG) allows promotional emails to business customers when: there's a factual connection between the offer and the recipient's business activity (presumed interest), the email includes a clear opt-out, and the sender is correctly identifiable. Pure mass emails without any connection are not allowed.
What GDPR rules apply to B2B cold emails?
The GDPR allows processing business contact data on the basis of legitimate interests (Art. 6(1)(f)). Requirements: a business (not private) email address, a factual connection to the offer, a documented balancing of interests, information obligations fulfilled (privacy notice in the footer), and an easily exercisable right to object.
Are there differences between Germany, Austria, and Switzerland?
Yes. Germany: UWG Section 7 + GDPR, presumed interest is enough. Austria: stricter, TKG 2021 Section 174 generally requires consent, with an exception for existing business relationships. Switzerland: nDSG (since 2023) + UWG, similar to Germany, presumed interest is sufficient for B2B.
What happens if I violate the rules?
A warning notice (Abmahnung) from a competitor (the most common scenario): €1,000-5,000 per violation. A GDPR fine from the data protection authority: up to €20 million or 4% of annual revenue (in practice, rarely this high for B2B cold emails). A cease-and-desist declaration: every further violation triggers a contractual penalty.
How do I make B2B cold emails GDPR-compliant?
5 points: (1) use only business email addresses, (2) establish a factual connection to the recipient's business, (3) include a privacy notice in the footer (who processes the data, legal basis, right to object), (4) include a working unsubscribe link, (5) respect and document opt-outs immediately.