All guides
DACH & Compliance 5 min read

A Lawyer's Letter After Your Cold Email: The Request Before the Cease-and-Desist

A lawyer asks where you got the address, on what legal basis you sent, and for your double-opt-in logs. What that letter really is, which deadline is running, and how a clean answer is built.

LC
Founder, CegTec · 8 September 2026

Not legal advice. This article and the companion guide describe how such a procedure works structurally and how a response letter can be built. They are not legal advice, do not replace case-specific review by a qualified lawyer, and create no attorney-client relationship. Use at your own risk. If you have received an actual letter, instruct a lawyer — before you answer, not afterwards.

The letter it starts with

It does not arrive as a cease-and-desist. It arrives as a polite letter from a law firm writing on behalf of someone you sent a cold email to. The tone is factual. No injunction is demanded, no contractual penalty, no amount in dispute. Three questions are asked:

  1. Source of the data. From which specific source did you obtain the email address?
  2. Legal basis. On what legal basis do you base sending the email?
  3. Proof. If you rely on consent: please provide the complete technical log data so the authenticity of the process can be verified.

Anyone who treats this as a formality and fires back three sentences from the sending inbox has misread the letter. Those three questions are not curiosity. They are a complete evidence-gathering exercise.

Why the three questions are phrased exactly that way

Behind a cold email sit two separate bodies of law, and the request uses one to obtain material for the other.

The GDPR governs the processing. Whether you may store a business email address and use it for direct outreach is a question of legal basis — in B2B outbound usually legitimate interest under Article 6(1)(f) GDPR. Article 15 GDPR gives the data subject the right to information about exactly that processing: purposes, recipients, retention — and, under Article 15(1)(g), the source of the data.

German unfair-competition law governs the sending. Whether the email was allowed to go out is decided by Section 7(2) No. 2 UWG. And there, legitimate interest does not exist as a basis. Advertising by email requires prior express consent. The presumed consent discussed for telephone contact applies under Section 7(2) No. 1 UWG to calls to businesses — not to email.

That makes the mechanics visible. Questions 1 and 2 are GDPR access rights you are obliged to answer. Question 3 targets the unfair-competition element. If you answer that there was no consent and no double-opt-in logs, you have answered truthfully — and simultaneously put in writing what is needed for a competition-law action.

That is not a reason to withhold an answer. It is the reason not to write it in passing.

The deadline you cannot miss

Article 12(3) GDPR: without undue delay, in any case within one month of receipt. For complex requests two further months are possible, but the extension must be communicated and justified within the first month.

The clock starts on receipt, not on the letter’s date. With law firm post, several days can sit between the two — and they count against you if you start counting from the wrong day.

Missing the deadline gives you a second problem alongside the first: a late or absent response is a separate infringement and a separate ground for complaint to the supervisory authority. One question becomes two proceedings.

What a clean answer achieves structurally

A robust response letter does four things, in this order:

  • It reflects the request back. The questions asked are reproduced verbatim and named as what is being answered — with an explicit invitation to correct you if the request has been misunderstood. That bounds the subject matter and forestalls a later claim that the information was incomplete.
  • It confirms the processing. Confirmation that data concerning the data subject was processed. Evasion here costs nothing but credibility.
  • It answers each question separately. The source, specifically. The purpose and legal basis of the processing, as actually relied upon. And where there was no consent: that none was obtained and therefore no log data exists by design.
  • It stays with the processing. Whether the sending was permissible under unfair-competition law is not the subject of an access request. It does not belong in this letter — least of all as a volunteered self-assessment.

Two things that reliably make an answer worse: asserting a consent that never existed, and promising log data that does not exist. Both are verifiable, and the verification happens.

The part that happens before the letter

The hardest question is the first one, and it is decided months earlier. “From which specific source?” can only be answered if the sourcing step recorded it: which source, which search or which dataset, at what time, through which technical process. Anyone pulling addresses from a tool that does not store that provenance per row cannot give a legitimate answer — and then has to write exactly that.

That is the real lever: source documentation is not a compliance nicety but the precondition for being able to answer such a letter at all. In GTM Goat, CegTec’s GTM operating system, provenance sits on the cell where the data point originated — not in a separate log that is lost at the next export. The four-week free trial shows what that looks like in your own data model.

The full guide with the response template

This article explains the procedure. The response template with placeholders, commented section by section, plus a deadline plan, the most common mistakes, and the action plan for the case where this turns into a cease-and-desist, are in the Academy guide:

Data Subject Request After a Cold Email: Response Template and Action Plan

If it is no longer a request but a demand to cease with a contractual penalty: Cease-and-Desist for Cold Outreach — Risk, Costs and the Right Response. The two bodies of law in context: GDPR and Cold Email.

Data Subject RequestGDPRUWGCold EmailCease and Desist

Common questions

What deadline applies to a data subject access request?

Article 12(3) GDPR requires a response without undue delay and in any case within one month of receipt. For complex requests the deadline can be extended by two further months, but the extension must be communicated and justified within the first month. The clock starts on receipt, not on the date printed on the letter.

Do I have to disclose where I got the data?

Article 15(1)(g) GDPR gives the data subject the right to all available information about the source of the data where it was not collected from them directly. For researched or enriched addresses that is the normal case. Anyone who keeps no source documentation cannot give that information — and that is precisely where it becomes a problem.

What if I have no double-opt-in logs?

Then they do not exist, and that is the only permissible answer. Inventing log data or asserting a consent that never happened turns a data protection question into a far bigger problem. If you never relied on consent, no records exist by design — and that can be stated plainly.

Is such a lawyer's letter already a cease-and-desist?

No. A data subject access request asserts GDPR rights and contains no injunction demand and no contractual penalty. But it can be the preliminary stage: your answer documents the basis on which you sent, and that documentation is usable in unfair-competition proceedings.

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.