B2B Cold Email: Legal Situation, GDPR, and What's Really Allowed
Is B2B cold email legal? GDPR, UWG, warning-letter risk, and data protection — the complete legal picture for Germany, Austria, and Switzerland.
The Legal Situation: What Does the Law Say?
Two laws govern B2B cold email in Germany:
1. GDPR — General Data Protection Regulation
The GDPR governs whether you’re allowed to process the contact data. For B2B cold emails, Art. 6(1)(f) — legitimate interest applies.
Requirements:
- You have a legitimate business interest in making contact
- The recipient’s interest in non-processing does not outweigh it
- The recipient can object to the processing (opt-out)
In practice, that means:
- ✅ Use a business email address (firstname@company.com)
- ✅ The offer must be relevant to the recipient’s role
- ✅ Opt-out link or notice in every email
- ✅ Privacy notice in the email signature
- ❌ Private email addresses (Gmail, GMX, etc.)
- ❌ Irrelevant mass emails to generic distribution lists
2. UWG — Act Against Unfair Competition
Section 7 UWG governs when advertising constitutes “unreasonable harassment.”
For B2B emails, this applies:
- Telephone cold calling: allowed given “presumed consent” (Section 7(2) No. 2 UWG)
- Email cold outreach: more strictly regulated — consent is required in principle, BUT: legitimate interest under GDPR is increasingly recognized by courts as sufficient
- Decisive factor: the email must have a recognizable factual connection to the recipient’s business activity
The Gray Zone
The legal situation isn’t black and white. German courts rule differently. The tendency:
- Individual, personalized B2B emails with a clear connection to the recipient → generally permissible
- Mass emails without personalization to thousands of recipients → legally risky
- Follow-up after opt-out → clearly illegal
Warning Letters: When Do They Threaten?
High Warning-Letter Risk
- Email to a private address without consent
- Continuing to email after an explicit objection
- No legal notice (Impressum) in the email
- Identical mass email to thousands of recipients
- Irrelevant offer (e.g., a marketing tool pitched to an accountant)
- Purchased email lists without proof of origin
Low Warning-Letter Risk
- Personalized email to a business address
- Clear connection to the recipient’s role/industry
- Opt-out is respected immediately
- Complete legal notice and privacy notice
- Traceable data source (LinkedIn, website, commercial register)
What Does a Warning Letter Cost?
- Typical warning-letter costs: €500-2,000
- With a cease-and-desist declaration including a contractual penalty: €2,500-5,000 per violation
- For a repeat violation after a cease-and-desist declaration: €5,000-25,000
Best Practices for Legally Sound B2B Cold Emails
1. Document Data Sources
For every contact, you should be able to prove where the data came from:
- LinkedIn profile (save the URL)
- Company website (legal notice, team page)
- Commercial register
- Industry directories
2. Ensure Relevance
Every email must have a recognizable connection:
- Recipient’s industry ↔ your solution
- Recipient’s role ↔ your offer
- Current company event ↔ your value proposition
3. Mandatory Technical Information
Every cold email needs:
- Full sender name and company
- Legal notice or a link to it
- Privacy notice or a link to the privacy policy
- Opt-out option (“Not interested? Just reply and we’ll remove you immediately.”)
4. Opt-Out Management
- Implement opt-outs immediately (within 48 hours max)
- Maintain a central blocklist
- Respect it across all channels and campaigns
- Keep documentation
Legal Situation in Austria and Switzerland
Austria
Similar to Germany. The Telecommunications Act (TKG) and GDPR apply. B2B cold emails are permissible given legitimate interest. Austrian courts tend to be somewhat stricter than German ones.
Switzerland
The new Data Protection Act (nDSG, since September 2023) is modeled on the GDPR but is more lenient on some points. B2B cold emails are generally allowed, as long as an opt-out is offered. The Swiss UWG prohibits mass advertising without consent.
Checklist: Is My B2B Cold Email Legal?
- Business email address of the recipient
- Data source documented and traceable
- Offer is relevant to the recipient’s role/industry
- Email is individually personalized (no identical mass mailing)
- Complete legal notice included
- Privacy notice present
- Opt-out option clearly visible
- Opt-out process works and is honored
- No private email address
- Not contacted again after opt-out
If you can check all these boxes, you’re operating in legally safe territory.
Conclusion
B2B cold email is legal in Germany, Austria, and Switzerland — if you do it right. The combination of legitimate interest (GDPR), factual relevance (UWG), and clean execution (legal notice, opt-out, documentation) makes the difference between a permissible business approach and harassment that invites a warning letter.
Common questions
Is cold email allowed in B2B?
Yes, under certain conditions. Under GDPR Art. 6(1)(f) (legitimate interest) and Section 7 UWG, B2B cold email is permissible if the offer is factually relevant to the recipient, a business email address is used, and a simple opt-out is offered.
Can you receive a warning letter (Abmahnung) for B2B cold outreach?
Yes, but the risk is low with correct implementation. Warning letters threaten when: the offer lacks relevance, private email addresses are used, there's no legal notice (Impressum), mass identical emails are sent without personalization, or contact continues after an explicit opt-out.
What data am I allowed to use for B2B cold outreach?
Publicly accessible business contact data (website, LinkedIn, commercial register) may be used under legitimate interest. Private email addresses, purchased lists without consent, and data from data leaks are not permitted.
Do I need consent for B2B cold emails?
No, not necessarily. In B2B, legitimate interest under GDPR Art. 6(1)(f) is sufficient — provided the offer is relevant to the recipient in their business role. Explicit consent (opt-in) is only mandatory in B2C.
How many cold emails am I allowed to send per day?
There is no legal limit. Technically, 30-50 emails per sender per day are recommended, to avoid endangering domain reputation. More important than volume: every email must be individually relevant.