All guides
DACH & Compliance 5 min read

GDPR and Cold Email: What's Allowed in Germany in 2026 — and What Isn't

B2B cold email and GDPR is a minefield. When is cold outreach by email allowed, what does 'legitimate interest' actually say, and which obligations apply in practice? A practical guide with checklist.

CT
CegTec Team
29 April 2026

B2B cold email in Germany is legally complex. There’s no simple “yes, allowed” or “no, forbidden” answer. Instead there are two legal layers that both have to be satisfied at the same time, plus a practical reality that many practitioners aren’t clear on.

This article is the sober version: what actually applies, what courts have ruled, and which setups work in practice.

Cold email touches two laws at once. Both have to check out, or the email is unlawful.

LayerLawWhat it governs
Data processingGDPR (Art. 6)Are you allowed to store and process the email address?
Advertising contactUWG (Section 7)Are you allowed to send the recipient a promotional email?

Common mistake: “I have legitimate interest under GDPR, so I’m allowed to send.” Wrong — legitimate interest only justifies the data processing. The email itself has to be checked against the UWG, and that’s the stricter standard.

What Section 7 UWG Says

Advertising by electronic mail is, in principle, only permissible with the recipient’s prior explicit consent. Exceptions:

  • An existing business relationship
  • Products/services similar to those previously purchased
  • A clear opt-out option

For pure B2B cold outreach there is no explicit UWG exception. What carries this in practice is a judicial interpretation: if the sender’s legitimate interest outweighs the recipient’s interest in being left alone — and the email has a clear connection to the recipient’s professional role — cold email can be permissible.

What Courts Have Ruled

German case law on B2B cold email is inconsistent. Tendencies 2024-2026:

Case patternTendency
Highly relevant to the role (e.g., a CFO gets an email about a treasury tool)tends to be permissible
Generically broad (e.g., “marketing solution” sent to HR)impermissible
With tracking pixel, no consentimpermissible
Multiple follow-ups without a replycritical
No clear sender identityimpermissible
Personalized with a clear business connectiontends to be permissible

Important point: even an email that “tends to be permissible” can still draw a cease-and-desist letter — the question then is whether the court follows that interpretation or not. Anyone seriously running cold email lives with residual risk.

A Practical Setup That Works

Mandatory elements in every cold email

  1. Clear sender — name, company, role. No pseudonyms, no “Sales Team” as sender.
  2. Working reply address — no noreply@, no generic address with nobody behind it.
  3. Connection to the recipient’s role — the email must be recognizably relevant to their professional role.
  4. Opt-out — a simple line in the footer: “If you don’t want any further emails, just reply with STOP — I’ll respect that.”
  5. Privacy notice — a short sentence with a link to the privacy policy.
  6. Imprint — mandatory in every business email.
  7. No tracking pixel — disable open tracking and click tracking without consent.

Tool configuration for compliance

If you use Instantly, Lemlist, Smartlead, or similar tools:

SettingWhat to do
Open trackingDisable for DACH recipients
Click trackingDisable, or use only on clear CTAs after opt-in
Unsubscribe linkEnable, worded in German
Reply detectionKeep enabled — further emails to recipients who replied are impermissible
Sender domainYour own domain, no free provider

ICP definition as a compliance tool

The more precise your targeting, the stronger the legitimate-interest argument. An email to “all CMOs in DACH” is weaker than an email to “CMOs at SaaS companies with Series A through C funding rolling out marketing automation.”

What Happens When Something Goes Wrong

Three escalation levels:

  1. Recipient marks it as spam — the email provider blacklists the domain, sender score drops. The most common and most expensive case in practice.
  2. Recipient files a complaint — this may end up with the data protection authority or a competition association.
  3. Cease-and-desist by a competitor or consumer protection body — costs €500-2,500, a cease-and-desist declaration, and contractual penalties on repeat offenses.

Fines from supervisory authorities are rarer on first offenses than the first two cases, but theoretically possible.

Short Checklist

  • Highly relevant targeting, clear connection to the recipient’s role
  • Clear sender with name and role
  • Reply address works and is monitored
  • Tracking pixel disabled
  • Opt-out in the footer, worded in German
  • Privacy notice with a link
  • Imprint linked
  • Reply detection enabled (no further emails after a reply)
  • Maximum 3-4 follow-ups, then stop
  • Your own sender domain, no free provider

Conclusion

GDPR and cold email are not mutually exclusive. But anyone systematically running cold email in Germany in 2026 has to satisfy the UWG and GDPR at the same time, disable tracking, target precisely, and live with residual risk. That’s doable — but not as trivial as many US tools suggest.

GDPRCold EmailB2B ComplianceCold OutreachUWG

Common questions

Is cold email to B2B contacts allowed in Germany?

In principle, B2B cold email in Germany is only allowed with consent — that's what Section 7 of the UWG (Act Against Unfair Competition) says. But there are exceptions: if there's a concrete business connection to the recipient's role and a demonstrable legitimate interest, cold email can be permissible. The legal situation isn't clear-cut — German courts rule inconsistently. Pragmatic practice: highly relevant, clearly identifiable, with opt-out, no tracking pixel without consent.

What does 'legitimate interest' (Art. 6(1)(f) GDPR) actually say?

Legitimate interest is the legal basis for data processing — not for sending the email. GDPR governs storing and processing the email address. The actual sending is governed by the UWG (competition law). In other words: even if GDPR processing is justified under Art. 6(1)(f), the email itself can still be impermissible under the UWG. Both levels have to check out.

What mandatory disclosures does a B2B cold email need?

Mandatory elements: 1) A clear sender identity (name, company, role) — no pseudonyms. 2) A working reply address (no noreply@). 3) An imprint (Impressum) or a link to one. 4) A note on data processing linking to the privacy policy. 5) A simple, clearly worded opt-out option. 6) A connection to the recipient's role that establishes the legitimate interest. 7) No tracking pixel without consent.

Am I allowed to use tracking pixels in B2B cold emails?

No, not without consent. The ECJ's cookie ruling (Planet49, 2019) and the German Data Protection Conference (DSK) make clear: tracking pixels that transmit open and click behavior to third parties (Instantly, Lemlist, HubSpot) are not permissible without the recipient's active consent. In practice: disable tracking in cold email tools, or only use it after a reply, later in the sales process.

What happens if I violate the UWG/GDPR?

Three scenarios: 1) The recipient complains to the data protection authority — fines up to €20 million or 4% of annual revenue. In practice, first offenses usually draw lower amounts (€5,000-50,000). 2) A competitor issues a cease-and-desist letter (Abmahnung) — typical costs €500-2,500, plus a declaration to cease and desist. 3) The more common case: the recipient marks it as spam, email providers blacklist the domain. Reputational damage is often more expensive than the fine.

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.