Outbound Wiki

National ePrivacy implementation

How EU member states apply ePrivacy marketing rules differently to email, calls, business addresses and corporate subscribers.

Start business cold email by classifying the country and recipient. GDPR applies across the EU, while each country implements electronic marketing rules. The same address can therefore face different sending conditions from one country to another.1 A lawful basis for using personal data does not answer the separate email permission question in most cases.2 Build the country check before the sequence and carry its result through recipient fit, message, and suppression.

Stage What you are trying to learn Example question
Country which national rule applies Which country governs this recipient?
Recipient whether the person and offer fit a business context Is this a business address or an individual address?
Channel whether the route needs consent or fits an exception What permission rule applies to this channel?
Record what you can show for the send Where is the basis and decision recorded?
Suppression what happens after an objection How will this address leave every active send?

Build the country record

Start with the recipient's country and attach that result to the contact. Proceed only after the national rule, address type, and proposed message have recorded answers.

Article 13 of the ePrivacy Directive regulates unsolicited electronic mail marketing and is implemented through national law.3 Check the country matrix before sending abroad.4 The country record should hold the applicable rule, the route you intend to use, the reason that route fits, and the person responsible for checking it.

Reuse the sequence as copy, but keep the permission decision with the recipient and country. Keep separate records for destinations with different implementations, even when the offer and sender stay the same.

Classify the recipient and use

Classify the contact before choosing the sending route. The domain is a starting point. The person's work context and the offer determine whether the outreach belongs in a business pathway.

Direct marketing may include collecting personal data, creating profiles about potential customers and their preferences, and sending personalised communications.567 Treat the full workflow as part of the marketing decision, including how the contact was found and how the message was tailored.

Many countries either do not require consent for business email or apply a lower consent standard to it.8 Use that as a route to investigate. The permission decision remains specific to the country and recipient. A company representative may be contacted without prior consent for business related products or services only in the context of the position they hold.9 Ask whether the offer belongs to the recipient's work before approving the send.

Record the answer in plain language. A reviewer should be able to see why the recipient is relevant, what the message promotes, and which country rule supports the route.

Test the channel route

Check the data protection basis and the electronic marketing rule separately. After classifying the contact, test the channel and record the exact condition that lets the message go out.

The ePrivacy Directive generally requires opt in consent before direct electronic marketing.10 A customer relationship route can allow marketing emails on an opt out basis when the recipient's details were collected in the context of selling a product or service.11 Member states have implemented that exception differently, and those differences can matter especially for business communication.12

Ask these questions in order:

  1. Is this an electronic marketing message?
  2. Does the destination require prior consent for this recipient type?
  3. If you rely on a customer relationship exception, were the details collected during the sale of a product or service?
  4. Does the local implementation permit that exception for this kind of business communication?
  5. Where is the permission, exception, or decision recorded?

Move on when the answers describe a specific route. Calling someone a business prospect does not finish the channel check.

Handle the separate national branch

Treat the United Kingdom as its own branch in the matrix. Finish that branch before applying a rule from another destination.

In the United Kingdom, the UK GDPR applies alongside the Data Protection Act 2018 and PECR, which implement the ePrivacy Directive.13 Business to business marketing still engages PECR and data protection duties.14 Organisations must ensure that direct marketing complies with PECR consent rules.15

For a corporate email address, UK guidance says the law does not require organisations to stop marketing emails, while many organisations stop as good practice after receiving an objection or opt out.16 Record the objection outcome in the suppression process even when the address is corporate. That keeps the operational rule clear for anyone who later reuses the record.

Make objections operational

An objection needs a defined action, not a note for someone to review later. Test the suppression path before the first send and make sure it reaches every campaign using the address.

A data subject has the right to object at any time to processing for direct marketing.17 Once the person objects, the personal data must no longer be processed for that marketing purpose.18 Even when prior opt in consent is unnecessary, the recipient must be given an opportunity to opt out.19

Route an objection to a suppression record, remove the address from active outreach, and preserve enough context to stop the same address being reintroduced by a later list. When the route works, an objection changes the contact's status across the sending process rather than only inside the thread where it arrived.

What not to do

These shortcuts create country and recipient errors. Add each one to the review checklist.

  • Do not treat additional business marketing exceptions as a general permission to send. Check which exception applies to the contact and message.20
  • Do not carry a rule from one destination into another without checking the country matrix first.4
  • Do not use a business label to bypass the role context required for a business related message.9
  • Do not treat legitimate interest as a substitute for the separate consent question raised by the electronic marketing channel.2
  • Do not leave a corporate address active after an objection because the address belongs to a company.16

Use the matrix to approve the country, recipient, channel, and suppression route before the sequence runs. If any record is unresolved, hold the send until the local rule and contact decision are clear.

Sources

  1. 1
    “GDPR is an EU-wide regulation, but the ePrivacy rules that govern electronic marketing are implemented country by country, so cold email legality varies significantly across Europe.”
  2. 2
    “This means, that in most cases, even if you are relying on legitimate interests, the ePrivacy Directive would still require consent.”
  3. 3
    “The ePrivacy Directive's Article 13 regulates unsolicited electronic-mail marketing and is implemented through national law.”
  4. 4
    “Rules vary by country, so check the matrix before sending abroad.”
  5. 5
    “collecting personal data from potential customers,”
  6. 6
    “creating profiles about those potential customers and their preferences,”
  7. 7
    “and then sending personalised communications to them.”
  8. 8
    “Consent: In many countries, consent is either not required to send B2B email or a lower standard of consent is required”
  9. 9
    “In case of B2B communication, company representative can be contacted for direct marketing purposes for business related products or services through electronic mail without their prior consent but only in the context of the position they hold.”
  10. 10
    “Direct electronic marketing is currently regulated under the ePrivacy Directive, which generally requires opt-in consent before engaging in such activity.”
  11. 11
    “However, there is an exception—marketing emails may be sent on an opt-out basis if the recipient’s details were collected “in the context of the sale of a product or a service,”(Directive 2002/58/EC, Article 13(2).).”
  12. 12
    “Please bear in mind that this exception has been implemented differently by the EU member states and some differences may apply, especially in case of B2B communication..”
  13. 13
    “In the UK, the UK GDPR applies alongside the Data Protection Act 2018 (DPA18) and the Privacy and Electronic Communications (EC Directive) Regulations (2003) (PECR), which implement the ePrivacy Directive).”
  14. 14
    “In the United Kingdom, the ICO explains that B2B marketing still engages PECR and data-protection duties.”
  15. 15
    “In particular, you mustensure your direct marketing complies with the Privacy and Electronic Communication Regulations 2003 (PECR) rules on consent.”
  16. 16
    “Whilst the law doesn’t require organisations to stop sending marketing emails to your corporate email address, many organisations will do so as a matter of good practice when they’ve received an objection or opt-out.”
  17. 17
    “where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing”
  18. 18
    “where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.”
  19. 19
    “even if opt-in consent is not required before sending marketing emails, the GDPR requires that the recipient always be provided with an opportunity to opt-out of receiving such emails.”
  20. 20
    “Therefore, there are additional exceptions for B2B direct marketing rules.”