Home / Notes / Cold Email and GDPR

Cold Email and GDPR

Possible in Europe, but not the American way.

GTME.cc analysisPublished July 20267 min read
Section 01

The short answer

B2B cold email is possible under GDPR, but not the way it works in the US. You cannot rely on blanket consent the way American volume playbooks assume. The workable path in the EU rests on legitimate interest, tight relevance, easy opt-out and often leading with LinkedIn where the rules are friendlier. This is general information, not legal advice, and a data protection lawyer should confirm your specifics.
Section 02

Why Europe is not the US

US cold email operates under CAN-SPAM, which permits unsolicited commercial email as long as it identifies itself and offers an opt-out. Many European markets are stricter. Under GDPR and the ePrivacy rules, contacting a person requires a lawful basis, and business email addresses that identify an individual are personal data. Copying a US volume playbook into the EU is how teams end up on the wrong side of both the law and the spam filters.

Section 03

Legitimate interest, done carefully

For B2B outreach the usual lawful basis is legitimate interest rather than consent. That is not a free pass. It requires that your interest is balanced against the recipient's rights, that the message is genuinely relevant to their professional role, and that opting out is trivial. A documented legitimate interest assessment, written once, is what makes this defensible. Relevance is the whole game: a targeted message to someone whose job your product clearly serves is defensible, a blast to a scraped list is not.

Section 04

What compliant EU outbound looks like in practice

  • A lawful basis identified and documented before sending
  • Targeting tight enough that relevance to the role is obvious
  • Clear sender identity and a real, one-click opt-out in every message
  • Opt-outs honoured immediately and suppressed permanently
  • LinkedIn considered as the opening channel, where outreach is expected
  • Data sources that are themselves compliant, not scraped consumer lists

None of this reduces performance. Tighter targeting and genuine relevance are exactly what makes signal based outbound work anyway. Compliance and effectiveness point the same direction in Europe.

Section 05

Why LinkedIn often leads in the EU

Because cold email to individuals is legally heavier in much of Europe, LinkedIn frequently becomes the opening channel rather than the backup. It is a professional context where outreach is expected, acceptance is opt-in by design, and a real profile carries the trust an email domain cannot. The full approach is in the LinkedIn playbook. Email still plays a role, it just supports rather than leads.

Section 06

Questions people also ask

Is cold email legal in the EU under GDPR?

B2B cold email can be lawful, usually on a legitimate interest basis, when the message is relevant to the person's role and opting out is easy. Consumer email is stricter. Confirm your case with a data protection lawyer.

What is the lawful basis for B2B cold email in Europe?

Typically legitimate interest rather than consent, supported by a documented assessment, tight targeting and a clear opt-out. Relevance to the recipient's role is central.

Should EU outbound lead with email or LinkedIn?

In most EU and DACH markets LinkedIn often leads because the rules are friendlier and acceptance is opt-in, with email in support. In the US the order usually flips.

This article is general information about outbound practice in Europe and not legal advice. Consult a qualified data protection lawyer for your specific situation.

Keep reading

Selling into Europe?

The diagnosis designs an EU-appropriate motion, channel mix and data sourcing that respects the rules and still performs.

Book a call