Exporters targeting Germany and the wider EU often assume GDPR makes cold emailing businesses illegal outright. It doesn't — but it does put real conditions on how you do it. This isn't legal advice (talk to a lawyer for your specific situation), but here's the practical shape of the rule and what actually causes exporters to get flagged.
The Short Answer
Business-to-business cold outreach — one company emailing another company's publicly listed work contact about a relevant commercial opportunity — is generally lawful under GDPR's Article 6(1)(f), "legitimate interests" basis, without needing prior consent. This is different from B2C marketing, where consent requirements are much stricter (and where CAN-SPAM/ePrivacy rules layer on additional restrictions).
The reasoning: a procurement manager's work email, used to discuss a product relevant to their job, is a normal part of doing business — not the kind of intrusion GDPR was designed to prevent.
What "Legitimate Interests" Actually Requires
Relying on Article 6(1)(f) isn't a blank check. It generally requires:
- Relevance — the outreach has to be genuinely relevant to the recipient's role (emailing a company's random general inbox about an unrelated product is weaker ground than emailing a named procurement contact about a matching product category).
- A working unsubscribe/opt-out mechanism — every message needs a clear, functioning way to opt out of further contact.
- Honoring opt-outs immediately — once someone unsubscribes, that's final; contacting them again is where most real complaints originate.
- Minimal, purpose-limited data use — you're using their business contact info for the stated commercial purpose, not selling it on or repurposing it for something unrelated.
- A clear identity — recipients need to know who's contacting them and why, with a real way to reply or ask questions.
What Actually Gets Exporters in Trouble
In practice, it's rarely the first cold email that causes a problem — it's what happens after:
- Ignoring unsubscribe requests and continuing to email the same address. This is the single most common source of complaints.
- Buying a bulk "email list" from a third party with no idea whether those contacts are current or how the data was originally collected — this weakens your legitimate-interests basis significantly, since you can't demonstrate the contact and purpose are genuinely connected.
- Scraping personal (not business) email addresses — targeting a named individual's personal Gmail rather than their work email at the company you're pitching is a different, weaker case.
- No real way to stop the emails — a "reply STOP" that nobody actually processes, or no unsubscribe link at all.
What This Means in Practice
If you're finding a specific procurement contact's work email from their own company's website, sending one relevant, clearly-identified message with a working opt-out, and honoring every opt-out — you're operating well within how GDPR's legitimate interests basis is generally applied to B2B outreach. If you're blasting a purchased list with no unsubscribe mechanism and no idea where the addresses came from, that's the pattern that actually generates complaints and enforcement risk.
WhaleIntro is built around the first approach: it finds and verifies live contacts from public sources rather than reselling a static list, and every outreach email sent through the platform includes a compliant unsubscribe mechanism by default.
Start your 14-day free trial →
FAQ
Do I need consent before sending a first cold email to a business contact in the EU?
Generally no, for B2B outreach relying on the legitimate interests basis — but you do need a working opt-out, and you must honor it immediately if the recipient uses it.
Is this different for B2C marketing?
Yes, significantly. Marketing to individual consumers typically requires explicit prior consent (opt-in) under GDPR and related e-privacy rules — the legitimate interests basis for cold outreach applies specifically to B2B communication with a business contact about a relevant commercial matter.
What's the single biggest compliance mistake exporters make?
Continuing to email someone after they've unsubscribed or asked to stop. That's what generates most real complaints — far more than the act of sending a first outreach email itself.
Does this apply to buyers outside the EU too?
GDPR specifically governs data belonging to people in the EU, but the underlying good practice — relevant targeting, clear identity, working opt-out, honoring it — is sound outreach practice everywhere, and increasingly expected by email providers' spam filters regardless of jurisdiction.