Cease-and-Desist Letters for Cold Calling: Risk, Costs, and the Right Response (B2B)
When is B2B cold calling grounds for a cease-and-desist letter? Who sends them, what does a cease-and-desist letter for unlawful advertising cost — and how do you respond correctly? With a cost table, a 5-step plan, and a prevention checklist.
Cease-and-desist letters for cold calling: the real risk in B2B
Anyone running outbound in the DACH region operates in a regulated environment. The cease-and-desist letter is the most common enforcement instrument in Germany: not a fine from an authority, but a civil-law letter — usually from a competitor or a competition watchdog — demanding a penalty-backed cease-and-desist declaration and payment of the attorney’s fees.
The good news: the risk is manageable. The bad news: ignore it, and you’ll end up paying a multiple of that in the end.
Note: This article is editorial guidance, not legal advice. If you receive an actual cease-and-desist letter, always bring in a lawyer specializing in competition law.
When is cold calling grounds for a cease-and-desist letter?
The governing provision in Germany is Section 7 UWG (unreasonable nuisance). The threshold varies significantly by channel:
| Channel | Cease-and-desist risk | Why |
|---|---|---|
| High | Consent is always missing in cold outreach, and the violation is provable from the inbox | |
| Fax | High (rare in practice) | Legally the same as email, barely used any more |
| Phone | Medium | Presumed consent is available, but has to be substantiated in a dispute |
| Low to medium | No channel-specific UWG provision; the risk sits with platform terms and the GDPR | |
| Letter/mail | Low | Permissible without consent, only objections have to be respected |
Which channel needs which consent is set out in full, with statutory citations, in Which outreach channel needs which consent?. This article is about the cease-and-desist risk that follows from it.
The two most important cases in detail:
Cold email without consent. Contrary to what many assume, German law has no B2B exception for email advertising. The presumed consent that Section 7(2) No. 1 UWG lets suffice for telephone calls to business market participants does not exist for email. Section 7(2) No. 2 UWG requires prior explicit consent — regardless of whether the recipient is a consumer or a managing director. The exception under Section 7(3) UWG only applies to existing customers under narrow conditions. Every classic cold email is therefore formally grounds for a cease-and-desist letter. How outbound teams assess and reduce this risk in practice is covered in detail in the article on the Email Legal Situation.
Phone outreach without a factual connection. B2B calls are permitted when presumed consent exists: the offer must fit the called party’s line of business, and a factual interest must be plausible. Indiscriminate call lists with no recognizable connection, or repeated calls after a rejection, are grounds for a cease-and-desist letter. Details and practical examples can be found in the Cold Calling Legal Guide for DACH.
Who sends cease-and-desist letters?
| Sender | Typical scenario | Motivation |
|---|---|---|
| Competitor | Direct competitor receives your cold email or is called | Competitive advantage, obstruction |
| Competition watchdog | Complaint from a member or recipient | Market conduct oversight |
| Consumer protection agencies | Mostly B2C cases, rare in B2B | Consumer protection |
| Specialized law firms | On behalf of a recipient or competitor | Mandate, sometimes systematic |
| Affected recipients | Civil cease-and-desist claim (Sections 823, 1004 BGB analogous), plus GDPR complaint | Annoyance, principle |
Important: since the 2021 UWG reform, the requirements for standing to send cease-and-desist letters and for abuse of rights have become stricter. The purely commercial “cease-and-desist industry” has been curbed — but the classic competitor cease-and-desist letter for unlawful advertising remains an everyday, legitimate occurrence.
In parallel, a second track runs alongside: the recipient can complain to the responsible data protection authority. Then it’s not about the UWG but about the GDPR — the legal basis for the data processing, information duties under Art. 14, and data subject rights. More on this in the GDPR Guide for Cold Email.
What does a cease-and-desist letter realistically cost?
| Cost item | Typical range | Note |
|---|---|---|
| Cease-and-desist costs (opposing attorney) | €300 – €500 for a single email | Attorney fees under the RVG on the amount in dispute; for a single email courts often assume €3,000 – €5,000. These costs have to be paid. |
| Cease-and-desist costs with a high amount in dispute or bulk sending | €800 – €2,500 | Amount in dispute €5,000 – €15,000 and above |
| Own attorney costs (review + modified declaration) | €500 – €1,500 | Money well spent, see below |
| Contractual penalty for breaching the cease-and-desist declaration | €3,000 – €5,000+ per violation | The real cost driver |
| Preliminary injunction / cease-and-desist lawsuit | €2,000 – €10,000+ | If you ignore the deadline |
| GDPR fine (separate proceeding) | Usually in the four- to five-figure range in a B2B outbound context | Theoretical ceiling: up to €20 million or 4% of annual turnover |
The first cease-and-desist letter is rarely existential. The cease-and-desist declaration is where it gets dangerous: it typically applies for 30 years, and every further violation — for example because the addressed contact is still sitting in a running sequence — triggers the contractual penalty. That’s why every cease-and-desist letter should be followed by a technical stop across all outbound systems: block the contact and domain on the suppression list, review running sequences, inform the team.
The right response: 5 steps
1. Check the deadline — immediately
Response deadlines are short, typically 5 to 14 days. Note the deadline on the day of receipt. Postal delivery counts, not your processing date.
2. Don’t ignore it, don’t sign prematurely
Ignoring it leads to a preliminary injunction with significantly higher costs. Signing without review binds you for 30 years to a declaration that may be far too broad. Both are wrong.
3. Reconstruct the facts internally
Before the lawyer starts working: who was contacted when, through which channel, with what content? Was there consent, a business relationship, a documented factual connection? Export the relevant data from the sequencer and CRM — this documentation determines the line of defense.
4. Bring in a lawyer and issue a modified cease-and-desist declaration
A lawyer specializing in competition law will check whether the letter is justified and typically draft a modified cease-and-desist declaration: scope limited to the specific act of infringement, contractual penalty per the “Hamburg practice” (amount at the creditor’s discretion, subject to court review), no acknowledgment of liability, cost question negotiated separately. This eliminates the risk of repetition just as effectively as the pre-drafted declaration — on considerably better terms.
5. Fix the cause — technically and procedurally
The cease-and-desist declaration is only as good as its implementation. Concretely: blocklist the addressed contact and, ideally, the entire recipient domain across all tools; pause and review the affected campaign; test opt-out processes; catch up on legal-basis documentation.
Prevention: working in a way that’s harder to hit with a cease-and-desist letter
There’s no such thing as 100% safety in cold calling — but the risk can be systematically reduced:
- A clean B2B connection: only contact companies whose line of business plausibly matches the offer. A narrow ICP definition isn’t just sales hygiene, it’s compliance. Fundamentals are covered in the article Is B2B Cold Calling Allowed?
- Document the legal basis: record per campaign which basis the data is processed under (Art. 6(1)(f) GDPR, legitimate interest) — including a balancing test. A template for this is provided in the B2B GDPR Guide.
- Take opt-out seriously: every email with a working unsubscribe path, every “not interested” on the phone, goes straight into the central suppression list, permanently. Most escalations arise not from the first message, but from follow-ups after a rejection.
- Double opt-in wherever consent is the basis: anyone working with consents (newsletters, event leads, content downloads) should collect and log them via double opt-in — that’s the only way consent is provable in a dispute.
- Keep call notes: for phone outreach, document the factual connection per call (why this company, why this contact). That’s your defense if the presumed consent is disputed.
- Limit volume and frequency: mass sending without segmentation raises not only the spam risk but also the cease-and-desist risk. Small, relevant, well-researched lists beat large, generic ones — both legally and in reply rate.
Special case: violations in Austria and Switzerland
The cease-and-desist letter is primarily a German instrument. In Austria, enforcement works differently: violations of the cold-calling and email ban under Section 174 TKG 2021 are pursued by the Fernmeldebüro as an administrative penalty proceeding — with fines of up to €58,000 per violation, without a competitor needing to act. In Switzerland, violations of Art. 3 UWG (for example, calls despite an asterisk entry) can incur fines of up to CHF 20,000. Anyone running outbound across the DACH region should assess the risk profile per country rather than by German standards across the board. Find the full country comparison in the article on Cold Calling in Austria and Switzerland.
Conclusion
A cease-and-desist letter for cold calling is annoying but manageable — if you take the deadline seriously, don’t sign without review, and respond with a modified cease-and-desist declaration. It gets expensive through ignoring it or through violating a declaration already given. The most sustainable strategy is prevention: a narrow B2B connection, documented legal basis, well-maintained suppression lists, and processes that enforce an opt-out technically, immediately.
Outbound without the cease-and-desist nightmare
CegTec builds GDPR-compliant outbound systems for B2B companies in the DACH region: clean ICP segmentation, documented legal bases, central suppression lists, and sequences that enforce compliance technically instead of leaving it to chance. If you want to put your cold calling on a stable legal and operational footing: Start your free trial · 4 weeks free, no credit card. Prefer to see it running first? Book a demo.
Common questions
Can I receive a cease-and-desist letter for a single cold email?
Yes. Under Section 7(2) UWG, even a single promotional email without prior explicit consent is already an unreasonable nuisance — even in B2B. Germany's Federal Court of Justice (BGH) has confirmed this repeatedly. In practice, a cease-and-desist letter is rarely sent over a single email, but legally it's sufficient. The risk rises significantly with volume, lack of relevance, and a missing opt-out.
What does a cease-and-desist letter for unlawful advertising typically cost?
For a single email the cease-and-desist costs (the other side's attorney fees) realistically run €300 to €500 — they are calculated under the German RVG on the amount in dispute, and for a single email courts often assume €3,000 to €5,000. These costs have to be paid. With a high amount in dispute or bulk sending they can reach €800 to €2,500 and more. On top of that come your own attorney costs (€500-1,500) for review. It gets really expensive when you breach the cease-and-desist declaration you've already given: contractual penalties of €3,000-5,000 or more per repeat violation are common. In parallel, a GDPR violation can be pursued by the data protection authority.
Do I have to respond to a cease-and-desist letter?
Yes, absolutely. Ignoring it is the most expensive option: if you let the deadline lapse, the sender can obtain a preliminary injunction or file a cease-and-desist lawsuit — then you also bear the court and litigation costs. Even if the letter appears unjustified, it should be reviewed by a lawyer and answered within the deadline.
Should I just sign the pre-drafted cease-and-desist declaration?
No, not without review. The pre-drafted declaration is regularly too broad: an excessively high fixed contractual penalty, an overly wide scope of the obligation, sometimes an acknowledgment of liability. The common approach is a modified cease-and-desist declaration following the 'Hamburg practice': the contractual penalty amount left to the creditor's discretion, subject to court review, and the scope limited to the specific act of infringement. A lawyer should draft this.
How do I prevent cease-and-desist letters in ongoing outbound campaigns?
Four levers: 1) Phone B2B only with documented presumed consent — a factual connection between the offer and the called party's line of business. 2) Set up email campaigns in a legally clean way — in Germany, even B2B email requires consent as a rule, so manage the risk deliberately and keep lists narrowly segmented. 3) A working opt-out in every message, with a centrally maintained suppression list. 4) Document the legal basis under Art. 6 GDPR per campaign (legitimate interest including a balancing test).