All guides
DACH & Compliance 5 min read

Cold Email Allowed? GDPR Rules for B2B in 2026

Can you send B2B cold emails under GDPR? Legal basis, mandatory disclosures, and warning-letter risk explained — with a practical checklist for 2026.

CT
CegTec Team
29 April 2026

Is this allowed? Short answer: yes, under conditions — not unconditionally. B2B cold email in Germany is legally complex, but not a black box. There are two legal layers that both have to be satisfied at the same time, plus a practical reality that many practitioners aren’t clear on.

This article is the sober version: what actually applies, what courts have ruled, and which setups work in practice. For phone-based cold calling, see Cold Calling Legal Rules DACH; for cold email specifically, see B2B Cold Email Legal Situation; and for the broader GDPR picture, see B2B GDPR Guide.

Cold email touches two laws at once. Both have to check out, or the email is unlawful.

LayerLawWhat it governs
Data processingGDPR (Art. 6)Are you allowed to store and process the email address?
Advertising contactUWG (Section 7)Are you allowed to send the recipient a promotional email?

Common mistake: “I have legitimate interest under GDPR, so I’m allowed to send.” Wrong — legitimate interest only justifies the data processing. The email itself has to be checked against the UWG, and that’s the stricter standard.

What Section 7 UWG Says

Advertising by electronic mail is, in principle, only permissible with the recipient’s prior explicit consent. Exceptions:

  • An existing business relationship
  • Products/services similar to those previously purchased
  • A clear opt-out option

How to build consent through ads and your own content instead of sending without it: Build consent instead of risking cold email.

For pure B2B cold outreach there is no UWG exception. Legitimate interest under Art. 6(1)(f) GDPR carries the data processing, not the sending — Section 7(2) No. 2 UWG knows no legitimate-interest ground. A clear connection to the recipient’s professional role reduces the practical likelihood of someone acting on it; it does not make the sending permissible.

What Courts Have Ruled

German case law on B2B cold email is inconsistent. Tendencies 2024-2026:

Case patternTendency
Highly relevant to the role (e.g., a CFO gets an email about a treasury tool)still impermissible, but the lowest practical risk
Generically broad (e.g., “marketing solution” sent to HR)impermissible
With tracking pixel, no consentimpermissible
Multiple follow-ups without a replycritical
No clear sender identityimpermissible
Personalized with a clear business connectiontends to be permissible

Important point: even an email that “tends to be permissible” can still draw a cease-and-desist letter — the question then is whether the court follows that interpretation or not. Anyone seriously running cold email lives with residual risk.

A Practical Setup That Works

Mandatory elements in every cold email

  1. Clear sender — name, company, role. No pseudonyms, no “Sales Team” as sender.
  2. Working reply address — no noreply@, no generic address with nobody behind it.
  3. Connection to the recipient’s role — the email must be recognizably relevant to their professional role.
  4. Opt-out — a simple line in the footer: “If you don’t want any further emails, just reply with STOP — I’ll respect that.”
  5. Privacy notice — a short sentence with a link to the privacy policy.
  6. Imprint — mandatory in every business email.
  7. No tracking pixel — disable open tracking and click tracking without consent.

Tool configuration for compliance

If you use Instantly, Lemlist, Smartlead, or similar tools:

SettingWhat to do
Open trackingDisable for DACH recipients
Click trackingDisable, or use only on clear CTAs after opt-in
Unsubscribe linkEnable, worded in German
Reply detectionKeep enabled — further emails to recipients who replied are impermissible
Sender domainYour own domain, no free provider

ICP definition as a compliance tool

The more precise your targeting, the stronger the legitimate-interest argument. An email to “all CMOs in DACH” is weaker than an email to “CMOs at SaaS companies with Series A through C funding rolling out marketing automation.”

What Happens When Something Goes Wrong

Three escalation levels:

  1. Recipient marks it as spam — the email provider blacklists the domain, sender score drops. The most common and most expensive case in practice.
  2. Recipient files a complaint — this may end up with the data protection authority or a competition association.
  3. Cease-and-desist by a competitor or consumer protection body — costs €500-2,500, a cease-and-desist declaration, and contractual penalties on repeat offenses.

Fines from supervisory authorities are rarer on first offenses than the first two cases, but theoretically possible.

Short Checklist

  • Highly relevant targeting, clear connection to the recipient’s role
  • Clear sender with name and role
  • Reply address works and is monitored
  • Tracking pixel disabled
  • Opt-out in the footer, worded in German
  • Privacy notice with a link
  • Imprint linked
  • Reply detection enabled (no further emails after a reply)
  • Maximum 3-4 follow-ups, then stop
  • Your own sender domain, no free provider

Conclusion

GDPR and cold email are not mutually exclusive. But anyone systematically running cold email in Germany in 2026 has to satisfy the UWG and GDPR at the same time, disable tracking, target precisely, and live with residual risk. That’s doable — but not as trivial as many US tools suggest.

GDPRCold EmailB2B ComplianceCold OutreachUWG

Common questions

Can a B2B company still send cold emails in 2026?

Short answer: no, not without prior express consent. Section 7(2) No. 2 UWG treats advertising by electronic mail without such consent as an unreasonable nuisance, in B2B too. There is no B2B exception: presumed consent exists only for telephone calls under Section 7(2) No. 1 UWG. A concrete business connection to the recipient's role lowers the practical risk but does not make the sending permissible. The legal situation isn't clear-cut — German courts rule inconsistently. Pragmatic practice: highly relevant, clearly identifiable, with opt-out, no tracking pixel without consent.

Is cold email to B2B contacts allowed in Germany?

No, not without prior express consent (Section 7(2) No. 2 UWG) — not even with legitimate interest, a clear connection to the recipient's role, an opt-out and tracking-free sending. Those four points are duties that lower the practical risk; they do not create a permission.

What does 'legitimate interest' (Art. 6(1)(f) GDPR) actually say?

Legitimate interest is the legal basis for data processing — not for sending the email. GDPR governs storing and processing the email address. The actual sending is governed by the UWG (competition law). In other words: even if GDPR processing is justified under Art. 6(1)(f), the email itself can still be impermissible under the UWG. Both levels have to check out.

What mandatory disclosures does a B2B cold email need?

Mandatory elements: 1) A clear sender identity (name, company, role) — no pseudonyms. 2) A working reply address (no noreply@). 3) An imprint (Impressum) or a link to one. 4) A note on data processing linking to the privacy policy. 5) A simple, clearly worded opt-out option. 6) A connection to the recipient's role that establishes the legitimate interest. 7) No tracking pixel without consent.

Am I allowed to use tracking pixels in B2B cold emails?

No, not without consent. The ECJ's cookie ruling (Planet49, 2019) and the German Data Protection Conference (DSK) make clear: tracking pixels that transmit open and click behavior to third parties (Instantly, Lemlist, HubSpot) are not permissible without the recipient's active consent. In practice: disable tracking in cold email tools, or only use it after a reply, later in the sales process.

What happens if I violate the UWG/GDPR?

Three scenarios: 1) The recipient complains to the data protection authority — fines up to €20 million or 4% of annual revenue. In practice, first offenses usually draw lower amounts (€5,000-50,000). 2) A competitor issues a cease-and-desist letter (Abmahnung) — costs realistically €300-500 for a single email, which have to be paid, plus a cease-and-desist undertaking with a contractual penalty. 3) The more common case: the recipient marks it as spam, email providers blacklist the domain. Reputational damage is often more expensive than the fine.

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.