Exporters targeting Germany and the wider EU often assume GDPR makes cold emailing businesses illegal outright. It doesn't — but it does put real conditions on how you do it. This isn't legal advice (talk to a lawyer for your specific situation), but here's the practical shape of the rule and what actually causes exporters to get flagged.

The Short Answer

Business-to-business cold outreach — one company emailing another company's publicly listed work contact about a relevant commercial opportunity — is generally lawful under GDPR's Article 6(1)(f), "legitimate interests" basis, without needing prior consent. This is different from B2C marketing, where consent requirements are much stricter (and where CAN-SPAM/ePrivacy rules layer on additional restrictions).

The reasoning: a procurement manager's work email, used to discuss a product relevant to their job, is a normal part of doing business — not the kind of intrusion GDPR was designed to prevent.

What "Legitimate Interests" Actually Requires

Relying on Article 6(1)(f) isn't a blank check. It generally requires:

  1. Relevance — the outreach has to be genuinely relevant to the recipient's role (emailing a company's random general inbox about an unrelated product is weaker ground than emailing a named procurement contact about a matching product category).
  2. A working unsubscribe/opt-out mechanism — every message needs a clear, functioning way to opt out of further contact.
  3. Honoring opt-outs immediately — once someone unsubscribes, that's final; contacting them again is where most real complaints originate.
  4. Minimal, purpose-limited data use — you're using their business contact info for the stated commercial purpose, not selling it on or repurposing it for something unrelated.
  5. A clear identity — recipients need to know who's contacting them and why, with a real way to reply or ask questions.

What Actually Gets Exporters in Trouble

In practice, it's rarely the first cold email that causes a problem — it's what happens after:

What This Means in Practice

If you're finding a specific procurement contact's work email from their own company's website, sending one relevant, clearly-identified message with a working opt-out, and honoring every opt-out — you're operating well within how GDPR's legitimate interests basis is generally applied to B2B outreach. If you're blasting a purchased list with no unsubscribe mechanism and no idea where the addresses came from, that's the pattern that actually generates complaints and enforcement risk.

WhaleIntro is built around the first approach: it finds and verifies live contacts from public sources rather than reselling a static list, and every outreach email sent through the platform includes a compliant unsubscribe mechanism by default.

Start your 14-day free trial →

FAQ

Do I need consent before sending a first cold email to a business contact in the EU?

Generally no, for B2B outreach relying on the legitimate interests basis — but you do need a working opt-out, and you must honor it immediately if the recipient uses it.

Is this different for B2C marketing?

Yes, significantly. Marketing to individual consumers typically requires explicit prior consent (opt-in) under GDPR and related e-privacy rules — the legitimate interests basis for cold outreach applies specifically to B2B communication with a business contact about a relevant commercial matter.

What's the single biggest compliance mistake exporters make?

Continuing to email someone after they've unsubscribed or asked to stop. That's what generates most real complaints — far more than the act of sending a first outreach email itself.

Does this apply to buyers outside the EU too?

GDPR specifically governs data belonging to people in the EU, but the underlying good practice — relevant targeting, clear identity, working opt-out, honoring it — is sound outreach practice everywhere, and increasingly expected by email providers' spam filters regardless of jurisdiction.