Guide · Law and ethics
GDPR and B2B cold email
You can cold email a business in Europe. The rules are real, they differ by country, and none of this is legal advice.
Article 6(1)(f) and the balancing testWhat the first email must carryNot legal advice
Two rulebooks, not one
Nearly all the confusion here comes from mixing up two laws that do different jobs.
The GDPR governs personal data. It asks whether you may hold someone’s details and use them for marketing.
The ePrivacy rules govern the message. They ask whether you may send an unsolicited email to that address at all.
You need an answer to both. Passing one does not excuse the other.
- GDPR: may I hold this row and use it for marketing?
- ePrivacy, as written into your country’s own law: may I send this email?
- The second question is where B2B and B2C part company.
The GDPR is a regulation. It reads the same in every EU and EEA country, Norway included.
ePrivacy is a directive. Each country wrote its own version of it, so the answer changes when you cross a border.
This page is not legal advice, and we are not your lawyers. We publish it because the question comes up on every sales call, and because most of what is written about it online is wrong. Take advice for the country you are sending to.
Legitimate interest, and what it asks of you
Article 6(1)(f) of the GDPR is the lawful basis nearly all B2B outreach rests on.
You do not need consent to hold a business contact row. You need a lawful basis, and consent is only one of the six in Article 6(1).
For cold outreach the basis is legitimate interests, at Article 6(1)(f). Recital 47 of the GDPR says direct marketing may count as a legitimate interest.
Note the word may. This is a test you have to pass, not a box you tick.
The three-part test
Regulators break it into three questions. Answer them in writing before the first send.
- Purpose. What is the interest, and is it real? Selling a service a trade plainly uses is a real interest.
- Necessity. Do you need this data to do it? If a smaller, tighter list would work, use the smaller list.
- Balance. Do your interests override their rights? Ask what they would expect. A plumber expects trade mail at a published business address.
That document has a name. Regulators call it a legitimate interests assessment, and its whole value is that you did the thinking first.
It does not have to be long. One page, dated, kept where you can find it in a hurry.
What moves the balance
- For you: a published business address, and an offer that fits their trade.
- For you: modest volume, and a plain way to say no.
- Against you: a home address, or a named person’s private details.
- Against you: an offer with nothing to do with what they do.
- Against you: bulk sending, and data they would never expect you to hold.
Read that list as a design brief. A tight, relevant, low-volume campaign is not just better sales. It is the version that passes the test.
What the first message has to carry
Four things, and not one of them takes more than a line.
You got this data from somewhere other than the person. Article 14 of the GDPR covers exactly that case.
It says you must tell them who you are, why you hold their details, and where those details came from. The deadline is a month, or the first time you contact them, whichever comes first.
For a cold email, that means the first email. There is no later.
- Who you are, with a real name and a real address behind it.
- Why you are writing, in one plain line.
- Where you got their details. Say it. A public listing is a fine answer.
- How to stop it. One sentence, in the body, in the same voice as the rest.
Article 14(5) does list exemptions, including one for disproportionate effort. Do not lean on it for a marketing list. You are writing to the person anyway, so telling them costs you a line.
The right to object is absolute
Article 21(2) gives every person the right to object to direct marketing. There is no balancing test on that one.
Article 21(3) then says you stop. No appeal, no last email, no one more try in six months.
So the opt-out is not a courtesy. It is the thing that holds the whole basis up.
Put the opt-out in the body, not in grey type at the bottom. A plain sentence meets the duty, reads as confident, and gives the reader a cheap way to answer. Every reply is data, and no is data too.
Where B2B and B2C part company
This is the ePrivacy half, and it is the half that changes at every border.
Article 13 of the ePrivacy Directive covers unsolicited email. The default is prior consent, with a soft opt-in for your own customers on similar products.
That default is written around natural persons. Article 13(5) then hands the rest to each country.
It tells member states to protect the interests of subscribers who are not natural persons, and leaves the method open. So the B2B answer is a national answer, every time.
The corporate and individual split
The clearest written example sits in the UK rules, PECR, because the regulator spelled it out.
There, the consent rule for marketing email bites on individual subscribers. Limited companies count as corporate subscribers, and so do limited liability partnerships. The rule does not reach them the same way.
The regulator treats sole traders and some partnerships as individual subscribers instead. So a plumber trading as a person gets consumer-grade cover. The same plumber trading through a company does not.
You still have to identify yourself and give a working address for opt-outs, whoever the subscriber is. And data protection law still applies wherever the row is personal data.
That split matters more in local than anywhere else. A file of trades is full of sole traders, and you cannot tell which is which from a map listing.
Is a business address personal data?
Sometimes yes, sometimes no, and you rarely know which from the row alone.
A named address at a company, like anders@firm.no, points at a person. It is personal data.
A role address like post@firm.no is weaker, and for a large company it may not identify anyone. For a one-van firm it is the owner’s inbox, and the distinction stops helping.
The safe working habit in local is to treat every row as personal data. You lose nothing by doing that, and the campaign you build is better anyway.
The Nordics, and why we will not give you one answer
Norway, Sweden, Denmark and Finland each wrote their own marketing law. They are not the same law.
All four apply the GDPR. Norway is outside the EU but inside the EEA, so the regulation applies there too.
The electronic marketing rules are the part that differs, and they sit in national marketing law rather than in the GDPR.
- Norway: the Marketing Control Act, enforced by the Norwegian Consumer Authority.
- Sweden: the Marketing Act, which carries the electronic marketing rule.
- Denmark: the Marketing Practices Act, where that rule sits in section 10.
- Finland: the Act on Electronic Communications Services.
We are not going to state a national position here that we cannot pin to a primary source. Guides that do are the reason this topic is a mess.
What we will tell you is what to check, and it is the same list in each country.
- Does the electronic marketing rule cover legal persons? Some national laws reach companies as well as people. That single answer changes your whole plan.
- How does the law treat a sole trader? In several countries a one-person firm gets consumer-grade cover. Local files are full of them.
- Is the B2B rule opt-in or opt-out? Opt-out means you may write once and must stop on request. Opt-in means you may not write first at all.
- What must the message itself say? Sender identity and a working opt-out are close to universal. The wording rules are not.
- Who enforces it, and what have they said lately? Consumer regulators and data protection regulators both have a say, and they publish guidance.
The practical answer for most sellers is the cautious one. Write as though the strictest of your four markets applies, and the other three take care of themselves. It costs you a sentence and a slightly smaller list.
Suppression lists, and the paperwork nobody enjoys
Three artefacts. Keep them and most of a complaint answers itself.
- A legitimate interests assessment. One page, written before the first send, with a date on it. This is the document a regulator asks for first.
- A source note on every row. Where it came from and when. You promised to tell people the source, so you have to know it.
- A suppression list you never clear. Every opt-out, forever, across every campaign and every tool you use.
The suppression list trips people up, because deleting somebody sounds like the respectful move. It is the opposite.
Delete the row and your next import writes it straight back in. Then you email a person who told you to stop, which is the one mistake regulators care about.
So keep the least you need to keep them out. The address, the date they asked, and nothing else.
We hold a suppression list per account. Add a domain there and the app keeps it out of every export you pull after that, so the row cannot come back through us.
A ten-minute pre-flight
- Written assessment on file, dated before the send.
- Sender identity in the message, with a real address behind it.
- A line saying where you got their details.
- A plain opt-out sentence in the body of the email.
- A suppression list wired into the sending tool, not kept in a notebook.
- A cap on volume that matches a real sales team, not a machine.
- Advice taken for any market you plan to work at scale.
Questions about GDPR and cold email
Is B2B cold email legal under the GDPR?
Holding and using business contact data for relevant B2B marketing can rest on legitimate interests, at Article 6(1)(f). Recital 47 says direct marketing may count as a legitimate interest.
That is the data protection half. Whether you may send the message is a second question, answered by your country’s own electronic marketing law. This is not legal advice.
Do I need consent to email a business?
Not always, and it depends on the country and on how the business is set up. National rules built on the ePrivacy Directive decide it, and Article 13(5) left the B2B part to member states.
A limited company and a sole trader are often treated differently, and a local file holds plenty of both. Check the rule where you are sending.
What has to be in the first email?
Who you are, why you are writing, where you got the details, and how to stop hearing from you. Article 14 of the GDPR drives the first three.
The deadline under Article 14(3) is a month or your first contact, whichever comes first. For cold email that means message one.
What happens when somebody objects?
You stop. Article 21(2) gives an absolute right to object to direct marketing, and Article 21(3) says the processing for that purpose ends.
There is no balancing test at that point and no second attempt later. Add them to suppression and move on.
Can I keep a record of people who opted out?
Keeping a suppression list is how you honour the objection, so it works with the right to object rather than against it.
Keep the minimum: the address and the date. Deleting the record instead means your next import brings them back, and then you email someone who said no.
Is public data on Google Maps fair game?
Public does not mean unprotected. Data being visible to anyone does not remove it from the scope of data protection law.
It does help the balancing test. A business that published its own phone number expects trade contact at it. That expectation is the argument, and you still owe the opt-out.
Does FindAndClose send the emails?
No. We build the list and hand you the file. You send from your own domain, in your own tool, under your own assessment.
That means the duties in this guide sit with you as the sender. We can give you the source of every row, which is the part most vendors cannot.
Read next
The practical guides that sit either side of this one.
- Find businesses with no website Four methods, honest trade-offs
- Build a local business email list Where the addresses really live
- Cold email local businesses Subject lines, length, a full sequence
- Find web design clients Territory, pricing, a week of work
- Scrape Google Maps without code What Maps exposes, and what it hides
- Every list we publish Trades and countries
- Plumbers in Norway Phone and email flags per row
- Accountants in Norway A trade that drifts off the web
- Electricians in Norway Strong email coverage for a trade
- Electricians in Sweden The Swedish side of the same trade
Build a list you can defend
Every row carries the page we found it on and the date we saw it. That is the evidence your assessment needs.
- 14-day free trial
- 100 leads included
- No credit card