B2B Email Marketing: What's Allowed?
Newsletters, cold email, existing customers: what's allowed in B2B without consent — the UWG criteria, mandatory disclosures, and the most common grounds for a cease-and-desist letter.
The 3 types of B2B emails and their legal status
1. Cold emails (1-to-1, no prior relationship)
Legal status: Allowed under certain conditions.
- GDPR Art. 6(1)(f): Legitimate interest
- Requirements: Business address, relevant offer, opt-out available
- Risk: Low with correct implementation
Allowed:
- A personalized email to the VP Sales of a SaaS company, because your outbound tool is relevant to their role
- A follow-up email after no response (1-2 follow-ups)
Not allowed:
- A mass email to 10,000 recipients without personalization
- Email to a private address
- Continuing to email after an explicit opt-out
2. Newsletters (1-to-many, recurring)
Legal status: Opt-in required.
- UWG §7: Advertising by email requires consent
- GDPR Art. 6(1)(a): Consent as the legal basis
- Recommendation: Double opt-in for evidentiary security
Best practice:
- Sign-up form with a clear description (what, how often)
- Confirmation email (double opt-in)
- Every email: unsubscribe link
- Document and retain consent
3. Existing-customer emails (existing business relationship)
Legal status: Largely allowed.
- UWG §7(3): Advertising to existing customers is possible without renewed consent if:
- The email address was collected in the course of a purchase
- The advertising is for similar products/services
- There is no objection on file
- Every email includes an unsubscribe option
Checklist: Legally compliant B2B email marketing
For cold emails
- Business email address
- Personalized and relevant to the role
- Data source documented (LinkedIn, website)
- Legal notice (Impressum) present
- Opt-out option
- Max. 2-3 follow-ups
- Opt-out implemented immediately
For newsletters
- Opt-in obtained (ideally double opt-in)
- Consent documented (timestamp, IP, text)
- Unsubscribe link in every email
- Legal notice in every email
- Privacy policy linked
- Unsubscribes implemented immediately
- List cleaned regularly
For all B2B emails
- Sender clearly identifiable
- Subject line not misleading
- SPF, DKIM, DMARC configured
- Bounces and complaints monitored
- Separate sending domain (not the main domain)
Common mistakes and cease-and-desist risks
1. No legal notice
Every business email needs sender information. A missing unsubscribe link or missing legal notice is the most common reason for a cease-and-desist letter.
2. Missing consent for newsletters
“They bought from us, so we’re allowed to send a newsletter” — only for similar products and with an opt-out option.
3. Ignoring opt-out
Continuing to email after an opt-out is the most expensive mistake. Cost: €2,500-25,000 per violation.
4. Purchased lists
Buying email lists and contacting them: high cease-and-desist risk. The people never gave you consent, and the data source isn’t verifiable.
5. Private email addresses
gmail.com, gmx.de, web.de — even if the recipient uses it for business, it counts as private. Only use company@company.com.
Tools for legally compliant B2B email marketing
| Purpose | Tool | GDPR feature |
|---|---|---|
| Newsletter | Brevo, Mailchimp, HubSpot | Double opt-in, unsubscribe, EU hosting |
| Cold email | Instantly, Lemlist | Opt-out management, blocklist |
| Verification | NeverBounce, ZeroBounce | Email validation before sending |
| Compliance | Usercentrics, Cookiebot | Consent management |
Conclusion
B2B email marketing in the DACH region is consent-based. Newsletters need an opt-in, existing-customer emails an existing business relationship within the narrow limits of Section 7(3) UWG — and cold emails prior express consent, which by definition is absent in cold outreach. Legal notice, opt-out and documentation are duties, but they do not make cold sending permissible.
Common questions
Can I send B2B emails without consent?
It depends on the type. Newsletters: no, opt-in is required. Cold emails to business addresses: no — Section 7(2) No. 2 UWG requires prior express consent, and legitimate interest under Art. 6(1)(f) GDPR covers the processing, not the sending. Transactional emails to customers: yes, within the scope of the business relationship. The key distinction is between advertising and business communication.
Do I need double opt-in for a B2B newsletter?
Legally, single opt-in is sufficient in B2B, but double opt-in is recommended. Reasons: evidentiary security in case of a cease-and-desist letter, a cleaner list, and better deliverability. Most email marketing tools implement double opt-in by default.
What's the difference between cold email and email marketing?
Cold email: direct 1-to-1 outreach to a specific recipient with personalized content. Email marketing: 1-to-many newsletter to a list with general content. Legally both need consent: newsletters an opt-in, cold emails prior express consent under Sec. 7(2) No. 2 UWG. Legitimate interest covers the data processing, not the sending.
What mandatory disclosures must a B2B marketing email include?
Sender name and company, a legal notice (Impressum) or link to it, a privacy notice, an unsubscribe option, and for newsletters: a reference to the consent given. Missing mandatory disclosures are the most common reason for a cease-and-desist letter.