All guides
DACH & Compliance 5 min read

B2B Email Compliance in DACH: Cold Emails, GDPR, and UWG — What's Allowed

Complete guide to the legal situation for B2B cold emails in Germany, Austria, and Switzerland: UWG, GDPR, ePrivacy, and practical implementation.

CT
CegTec Team
31 March 2026

B2B cold emails in Germany sit at the intersection of the UWG (unfair competition law), GDPR (data protection), and the ePrivacy Directive. The good news: it’s allowed — if you do it right.

Germany: UWG + GDPR

UWG Section 7 — unfair competition law

The UWG treats advertising by electronic mail without prior express consent as “unreasonable harassment” — Section 7(2) No. 2 UWG, with no B2B exception. The presumed consent that Section 7(2) No. 1 UWG allows for telephone calls to business market participants does not exist for email.

Impermissible without consent — even when:

  • there is a factual connection between your offer and the recipient’s business
  • The email is clearly identifiable as advertising
  • A working opt-out is provided
  • The sender is correctly identifiable (legal notice/Impressum obligation)

Not allowed:

  • Mass emails with no connection whatsoever to the recipient
  • Concealing the promotional nature of the email
  • Emails to private addresses (Gmail, web.de, etc.)
  • Continuing to send after an opt-out

GDPR — data protection

Processing business contact data for cold emails is based on Art. 6(1)(f) GDPR (legitimate interest).

Your obligations:

ObligationWhat you have to do
Legal basisDocument legitimate interest
Balancing of interestsWeigh your interest against the recipient’s rights and document it
Information obligationPrivacy notice in the email (or a link to it)
Right to objectA simple opt-out in every email
Data minimizationCollect only necessary data (name, email, company, role)
Storage limitationDelete data once there’s no longer a reason to process it

Practical implementation for Germany

Email footer (mandatory information):

[Company name] | [Address] | [Commercial register]
You are receiving this email because your company operates
in the [industry] sector and our offer might be relevant to you.
Privacy: [link to privacy policy]
Unsubscribe: [unsubscribe link]

Austria: stricter than Germany

The Austrian TKG 2021 Section 174 is more restrictive:

  • Rule: Email advertising requires prior consent (opt-in)
  • Exception: An existing business relationship + a similar product/service
  • B2B practice: Significantly more restricted than in Germany

Recommendation for Austria:

  • Cold emails to new contacts are risky
  • Better: LinkedIn connection first, then email after contact has been made
  • Or: phone-based first contact, then email as a follow-up

Switzerland: similar to Germany

Switzerland’s nDSG (new data protection act, since 2023) and its UWG are comparable to the German regulation:

  • B2B cold emails: Allowed with a factual connection and an opt-out
  • No GDPR application (except when processing EU citizens’ data)
  • Swiss UWG Art. 3(o): Prohibits mass advertising without a connection, allows targeted B2B outreach

Compliance checklist for the DACH region

Before sending

  • Only business email addresses (no @gmail, @web.de, etc.)
  • Factual connection between offer and recipient’s business can be established
  • Balancing of interests documented (a template is enough)
  • Privacy policy updated (mentions cold outreach)
  • Opt-out process works and has been tested
  • Sender correctly identifiable (company, address)

In every email

  • Company name and address in the footer
  • Unsubscribe link (working)
  • Privacy notice or link to the privacy policy
  • No concealed promotional character

After sending

  • Opt-outs implemented within 24h
  • Opt-out list maintained (suppression list)
  • Bounces removed
  • No renewed contact after an opt-out

Technical implementation with tools

Instantly.ai / Lemlist

Both tools offer:

  • Automatic unsubscribe link
  • Suppression lists (global opt-out list)
  • Custom footer with mandatory information

Setup:

  1. Create a footer template with all mandatory information
  2. Enable the unsubscribe link (this is standard)
  3. Set up a suppression list and check it before every send
  4. Automatically remove bounced emails

Clay + enrichment

GDPR-compliant enrichment:

  • Only enrich business data
  • No private social media profiles
  • Keep a record of processing activities (which data, from where, for what)
  • Delete data after 6 months of no interaction

The most common mistakes

  1. Contacting private email addresses — @gmail.de is a no-go, even if used for business
  2. No opt-out — every cold email must have a working unsubscribe link
  3. Continuing to email after an opt-out — stop immediately, add to the suppression list
  4. No documented balancing of interests — must be documented before the first email goes out
  5. Treating Austria like Germany — Austria is stricter, different rules apply
  6. Using tool data without checking it — Apollo/ZoomInfo data also contains private addresses, filter first

Template: balancing of interests (fill in)

BALANCING OF INTERESTS under Art. 6(1)(f) GDPR

Controller: [Company]
Date: [Date]

1. LEGITIMATE INTEREST
We contact companies in the [industry/segment] sector
to introduce our [service].

2. NECESSITY
Email is the most efficient channel for B2B first contact.
Alternative channels (mail, phone) are less effective
and more expensive.

3. BALANCING OF INTERESTS
- Our interest: acquiring new customers, economic viability
- Recipient's interest: a potentially relevant offer for their business
- Intrusion: low (1 email, business address, simple opt-out)

4. PROTECTION OF DATA SUBJECTS
- Business contact data only
- Transparent sender
- Simple opt-out in every email
- Deletion after 6 months of no interaction

CONCLUSION: The controller's interests prevail,
since the intrusion is low and appropriate protective
measures are in place.

Start your free trial · 4 weeks free on self-registration, no credit card. Prefer to see it running first? Book a demo.

B2B Email ComplianceGDPR Cold EmailCold Email LegalityUWG B2BCold Outreach Legal DACH

Common questions

Are B2B cold emails allowed in Germany?

No, not without prior express consent. Section 7(2) No. 2 UWG treats advertising by electronic mail without prior express consent as an unreasonable nuisance — in B2B too. There is no B2B exception: the law allows presumed consent only for telephone calls to business market participants (Section 7(2) No. 1 UWG), not for email. Data processing is a separate question: researching and storing business contact data from public sources is possible under legitimate interest, Art. 6(1)(f) GDPR — that is the basis for processing, not for sending. Anyone who sends anyway is making a deliberate risk decision: a cease-and-desist warning is possible, the warning costs for a single email realistically run 300 to 500 euros and have to be paid, plus a cease-and-desist undertaking with a contractual penalty for any repeat.

What GDPR rules apply to B2B cold emails?

The GDPR allows processing business contact data on the basis of legitimate interests (Art. 6(1)(f)). Requirements: a business (not private) email address, a factual connection to the offer, a documented balancing of interests, information obligations fulfilled (privacy notice in the footer), and an easily exercisable right to object.

Are there differences between Germany, Austria, and Switzerland?

No — all three countries require consent for email advertising in principle. Germany: Section 7(2) No. 2 UWG requires prior express consent, in B2B too; presumed consent covers telephone only. Austria: Section 174 TKG 2021 likewise requires consent in principle, with a narrow exception for existing business relationships. Switzerland: nDSG and UWG, likewise with a consent requirement and a mandatory opt-out.

What happens if I violate the rules?

A warning notice (Abmahnung) from a competitor (the most common scenario): €1,000-5,000 per violation. A GDPR fine from the data protection authority: up to €20 million or 4% of annual revenue (in practice, rarely this high for B2B cold emails). A cease-and-desist declaration: every further violation triggers a contractual penalty.

How do I make B2B cold emails GDPR-compliant?

5 points: (1) use only business email addresses, (2) establish a factual connection to the recipient's business, (3) include a privacy notice in the footer (who processes the data, legal basis, right to object), (4) include a working unsubscribe link, (5) respect and document opt-outs immediately.

Next step

GTM Goat runs exactly what you just read.

Book an intro call 30 minutes, then 4 weeks free
Rather start on your own? Pricing and free trial →

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.