All guides
DACH & Compliance 6 min read

Is B2B Cold Outreach Allowed? The Legal Position Under UWG & GDPR

Is cold outreach allowed in B2B? The legal position in Germany under the UWG and GDPR — what's allowed, what isn't, and how to prospect in a legally sound way.

CT
CegTec Team
9 April 2026

The short answer

Yes, B2B cold outreach is allowed in Germany — but not without limits. There are clear rules, and ignoring them risks a cease-and-desist warning.

The short answer by channel: email no — impermissible without prior express consent, with no B2B exception (Sec. 7(2) No. 2 UWG). Telephone to businesses yes, where presumed consent exists (Sec. 7(2) No. 1 UWG). Postal mail yes, without consent — the only consent-free channel (Sec. 7(1) sentence 2 UWG). Fax no, same as email. LinkedIn as a rule like messengers, though a staged approach is possible.

The full matrix with every channel, the exact requirements and the statutory citations lives in one place: Which outreach channel needs which consent?. This article only covers what follows from it for cold outreach.

Cold email outreach: Section 7 UWG in detail

What the law says

Section 7(2) No. 2 UWG treats email advertising without prior express consent as an unreasonable nuisance. That is a prohibition, and it applies in B2B too.

There is no B2B exception

The presumed consent frequently cited as a B2B exception sits in Section 7(2) No. 1 UWG — and that provision covers telephone calls to business market participants. For email there is no such relief. The only statutory exception for email is the narrow existing-customer rule in Section 7(3) UWG: the address was obtained in connection with a sale, the advertising concerns your own similar goods or services, and the right to object is pointed out both at collection and in every message. In cold outreach none of those conditions are met.

What the following points actually are

These five points are often presented as the conditions of a permission. They are not — they are duties and risk mitigation. Meeting them makes a warning letter less likely; it does not make the sending permissible:

  1. A factual connection exists: your offer fits the recipient’s line of business
  2. Business address: you write to a business email, not a private address
  3. Relevant function: the recipient is professionally responsible for the topic
  4. Reasonable frequency: no mass mailing to the same contact
  5. Opt-out available: the recipient can unsubscribe at any time

Practical examples: what’s allowed, what isn’t

Allowed (probably):

  • A warehouse management software vendor → the logistics head of an e-commerce company
  • A recruiting tool → the HR head of a growing company (currently posting open roles)
  • CRM consulting → the sales head of a B2B company without a CRM (identifiable from the tech stack)

Not allowed:

  • A catering service → every company in a city (no factual connection)
  • Repeated emails after a clear rejection (“Please don’t contact me again”)
  • Writing to private Gmail/GMX addresses found in a business context
  • Emailing info@ addresses without a specific contact person (disputed, tends to be impermissible)

The same logic, a stricter interpretation

Section 7(2) No. 1 UWG applies to cold calling. This is the only place where the law lets presumed consent suffice — and only towards business market participants, not consumers. For email there is no such relief.

What courts examine:

  • Was there a concrete occasion for the call? (job posting, press release, industry event)
  • Does the offer fit the line of business?
  • Was the right contact person reached?
  • Was the time of day appropriate? (business hours)

How to document it correctly

Keep a short note in the CRM for every call/email:

Contact: Max Müller, VP Sales at Company XYZ
Reason: Company posted 3 SDR openings → pipeline building is a current topic
Offer: Outbound automation for B2B sales
Factual connection: Yes (job postings, B2B sales, matching company size)
Date: 2026-04-09
Result: [Interested / Not interested / Not reached]

Alongside the UWG, GDPR also applies. The two laws complement each other:

AspectUWG (competition law)GDPR (data protection)
GovernsWhether you may advertiseHow you handle data
Legal basisEmail: prior express consent (Sec. 7(2) No. 2). Phone: presumed consent (Sec. 7(2) No. 1)Legitimate interest (Art. 6(1)(f))
Risk on violationWarning letter (€300-500 for a single email, more with a high amount in dispute)Fine (€5,000-50,000 for SMEs)
Enforced byCompetitors, consumer protectionData protection authority

GDPR checklist for B2B cold outreach

  • Legal basis: legitimate interest documented (Art. 6(1)(f) GDPR)
  • Business data only: no private emails, no private mobile numbers
  • Data minimization: only collect the data you need
  • Duty to inform: a privacy notice in the email (a link is enough)
  • Opt-out: an unsubscribe option in every email
  • Deletion: delete data if there’s no interest (or after the retention period)
  • Record of processing: list cold outreach in the record of processing activities

Common gray areas

Writing to info@ addresses?

Disputed. Some lawyers argue that info@ addresses are business addresses meant for inquiries. For email the question is secondary anyway: without prior express consent the sending is impermissible, to info@ just as much as to a personal address. Recommendation: contact a direct point of contact — not because it becomes permissible, but because the reply rate is higher and the friction lower.

LinkedIn messages as advertising?

LinkedIn messages don’t fall directly under Section 7 UWG (no email/phone involved). But: LinkedIn has its own Terms of Service, which prohibit spam messages. And with mass outreach, LinkedIn can suspend your account. Recommendation: LinkedIn outreach yes, but personalized and at a reasonable frequency.

Using data from enrichment tools (Clay, Apollo)?

Having the data itself isn’t the problem — using it for advertising is. As long as you follow the GDPR checklist above (legitimate interest, business data, opt-out), using enrichment data for B2B cold outreach is defensible.

Practical tips: prospecting in a legally sound way

  1. Define your ICP sharply: the better the targeting, the lower the likelihood that someone acts on it — it does not create a ground of permission for email
  2. Personalize: “I see you’re currently hiring SDRs” is much better than “Dear Sir or Madam”
  3. Respect opt-out immediately: “Not interested” → add the contact to a suppression list, never contact again
  4. Document: for every contact: why you’re reaching out, when, the result
  5. Limit frequency: max. 1 email sequence (3-5 emails over 3 weeks), then pause
  6. Legal notice in the email: sender name, company, address — mandatory
  7. Privacy notice: link to your privacy policy in the email signature
Cold OutreachB2B LawUWGGDPRCold EmailCold Calling

Common questions

Is cold email outreach allowed in B2B?

No, not without prior express consent. Section 7(2) No. 2 UWG treats advertising by electronic mail without prior express consent as an unreasonable nuisance — in B2B too. There is no B2B exception: the law allows presumed consent only for telephone calls to business market participants (Section 7(2) No. 1 UWG), not for email. Data processing is a separate question: researching and storing business contact data from public sources is possible under legitimate interest, Art. 6(1)(f) GDPR — that is the basis for processing, not for sending. Anyone who sends anyway is making a deliberate risk decision: a cease-and-desist warning is possible, the warning costs for a single email realistically run 300 to 500 euros and have to be paid, plus a cease-and-desist undertaking with a contractual penalty for any repeat.

Is cold calling allowed in B2B?

Yes, with restrictions. Section 7(2) No. 1 UWG permits B2B cold calling under 'presumed consent.' That means: there must be a factual reason to assume that the person called might be interested in your offer (e.g. because it fits their line of business). Purely indiscriminate cold calls are not permitted, even in B2B.

What are the consequences of unlawful cold outreach?

Violations can trigger: 1) A cease-and-desist warning from competitors or consumer protection associations — cost: €1,000-5,000 per warning. 2) An injunction with a contractual penalty (often €5,000-10,000 per repeat offense). 3) GDPR fines from data protection authorities if data protection violations occur at the same time — theoretically up to €20 million or 4% of revenue, in practice €5,000-50,000 for SMEs.

What should I document if I run cold outreach anyway?

First: documentation does not make email cold outreach permissible — presumed consent applies only to telephone calls (Section 7(2) No. 1 UWG). It does help with the phone channel, with the GDPR duty to give access, and with limiting damage. For every contact, record: 1) the origin of the data — source, timestamp and technical process, which is exactly what Art. 15(1)(g) GDPR asks for. 2) Why you assume a factual connection (industry, job postings, tech stack). 3) Which business address or number you are contacting. 4) Whether and when the contact objected. 5) That an opt-out was provided and actually works.

Next step

GTM Goat runs exactly what you just read.

Book an intro call 30 minutes, then 4 weeks free
Rather start on your own? Pricing and free trial →

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.