B2B cold email has no universal yes or no across European Union countries. The answer changes with the country, recipient type, data source and message.1 Separate permission to send from permission to use personal data. A legitimate interests basis for handling a contact record can still leave a consent requirement for the marketing email in place.2 Answer both questions before the campaign is ready.
The answer across countries
There is no universal yes or no for B2B email compliance.3 The result depends on the country, recipient type, data source and message.1 National implementation also affects the result across the EU and EEA.4
For direct electronic marketing, the ePrivacy Directive generally requires opt in consent before you send.5 In some B2B situations, a company representative may be contacted by email without prior consent for business related products or services when the message fits the position they hold.6 Treat this as a local exception to verify, not a rule for every business address.
Run the decision
Use this order for every campaign. Stop at the first unanswered question because the missing detail can change whether the message may be sent.
| Stage | What you are trying to learn | Example question |
|---|---|---|
| Classify | Which country, recipient type, data source and message are involved | Which local rule applies to this contact? |
| Check sending permission | Whether the message needs prior consent or fits a local exception | May this message be sent to this recipient? |
| Check data use | What permits you to process the contact's personal data | What lawful basis covers this record? |
| Build the request | What the person is agreeing to receive and how they can refuse later | Does the prompt explain the business, content and opt out? |
| Keep the record | What proves the choice or supports the exception | Where is the wording and affirmative action recorded? |
Classify the contact
Clarify the legal context before writing copy. A campaign segment is useful only when its country and recipient assumptions are clear.
Write down the country, recipient type, data source and message for each segment.1 Do not put every European address under one rule. Split the campaign when the country or recipient category changes, then check the relevant national implementation.4
Pay special attention to unusual sources and new markets. For a new market, a large program or an unusual data source, have qualified counsel review the exact facts.7 Move on when you can explain why this recipient falls under the rule you selected.
Check sending permission
This step answers one question: can this marketing email be sent to this recipient under the local electronic marketing rule? Keep that answer separate from your CRM status or the quality of the lead.
The general rule for direct electronic marketing is opt in consent under the ePrivacy Directive.5 The possible B2B route depends on the recipient's role and the relevance of the product or service to that role.6 Ask whether the contact received the message because of a business function and whether the offer relates to that function.
If the answer is unclear, pause the send and check the national rule. A broad business audience label cannot resolve a country specific exception.
Check data use
Under GDPR, specific and unambiguous consent from the data subject, such as opting into a marketing email list, can provide a basis for processing personal data.8 Strict rules govern what counts as consent from a data subject.9 For certain marketing activities, consent is the only appropriate lawful basis.10
Record the basis you are relying on and connect it to the contact source. If the basis does not match the source or the message, stop before outreach begins.
Build the consent request
When consent is required, make the request easy to understand and easy to act on. The person should choose the marketing permission themselves.
An example prompt asks an existing customer whether they want marketing messages about similar products and offers separate boxes for each contact method.11 Have the prospect take the affirmative action to opt in. Do not have a sales or service team member enter that choice for them.12
For a messaging opt in, name the business, explain the expected content and frequency, and state how the person can opt out.13 If consent is your lawful basis, explain how long you will keep the data, since retention information supports a genuinely informed choice.14
Move on only when the person has selected the relevant permission and the request makes its scope clear. A vague acceptance leaves you with a record that is difficult to interpret later.
Keep the record
A consent decision needs a trail that another person can understand without reconstructing the campaign. Store the request and the response together.
Adding people to a subscriber list asserts that you have permission to email them.15 Keep the wording shown, the contact method selected, the source of the contact, the time of the action and any later withdrawal in the same record. Keep the opt out path visible in the campaign process.
If you cannot show what the person agreed to, pause the sequence. Obtain a fresh choice or get a review of the specific facts before sending.
What not to do
During campaign review:
- Do not answer from the B2B label alone. The result depends on country, recipient type, data source and message.1
- Do not treat legitimate interests as a substitute for consent where the electronic marketing rule still requires consent.2
- Do not carry one national rule across every EU or EEA segment. National implementation affects the result.4
- Do not rely on a fully generic opt in before checking GDPR requirements.16
- Do not have a sales or service team member take the affirmative action for the prospect.12
- Do not treat CAN SPAM compliance as proof of GDPR compliance.17