• One verified data layer, not a stitched one: Explorium pulls from 150M+ company profiles and 800M+ people profiles across 50+ sources, so a single API call returns the firmographic context needed to document a legitimate interest basis instead of patching records from unverified scrapers.
    • Built for scale with guardrails: enrich up to 1,000 contacts per call at 100 QPS sustained, so you can validate and refresh an entire EU send list in one governed pass instead of ad hoc exports.
    • Affordable by design: a free Explorium account with no sales call and a unified credit pool removes the incentive to skip EU markets entirely or over-commit to an unvetted bulk list purchase.
    • Germany is the outlier, not the EU default: most of the EU runs on GDPR’s legitimate interest basis (Article 6(1)(f)), but Germany’s Section 7 UWG requires prior express consent for commercial email, with no general B2B carve-out.
    • 97.8%+ company match accuracy is the metric that actually matters for compliance: a stale or mismatched contact record is the single hardest thing to defend if a cease-and-desist letter arrives.
    • Start free: enrich your first 100 EU contacts with Explorium before you send a single email, then scale once the process holds up.

    Sending GDPR-compliant cold email in Europe comes down to one question most teams never answer precisely: which legal basis covers this contact, in this country. GDPR’s legitimate interest basis (Article 6(1)(f), Recital 47) permits most B2B cold email across the EU, but Germany runs a stricter, separate standard under Section 7 of its unfair competition law (UWG) that requires prior express consent, with no B2B exception.

    A 2026 Reddit AMA on cold-emailing Germany drew 50 comments describing the same gap: teams knew “GDPR” existed but not the enforceable test, so they froze EU outbound or sent anyway and risked a cease-and-desist letter (Abmahnung). Getting this right starts with what is data enrichment and a verified source for every contact.

    Is Cold Email Legal Under GDPR for B2B Outreach in Europe?

    Yes, B2B cold email is legal in most EU countries under GDPR’s legitimate interest basis, but Germany is a documented exception that requires prior express consent. Article 6(1)(f) permits processing a work email when a business has a legitimate interest not overridden by the individual’s rights, and Recital 47 names direct marketing as one.

    ❌ Why Treating “GDPR” as One Law Fails

    • GDPR sets the EU-wide floor, but member states layer their own marketing rules on top.
    • Germany’s Section 7 UWG is a separate statute, and it is the law German courts cite in disputes.
    • Conflating the two causes two failures: skipping the EU entirely, or sending unsolicited German email with no consent on file.
    Diagram comparing GDPR legitimate interest basis across the EU against Germany's stricter Section 7 UWG consent requirement for GDPR-compliant cold email

    ✅ What Real Compliance Requires

    • A documented legal basis for every contact record, recorded before the first send.
    • A verified source for each email, so you can show where it came from if challenged.
    • Country-specific handling: legitimate interest for most of the EU, prior consent for Germany.

    What Is the Legal Basis for Cold Email: Legitimate Interest or Consent?

    Legitimate interest under Article 6(1)(f) is the basis most EU cold email relies on, but it requires a documented three-part test, not a business justification. A valid LIA shows the interest is real, necessary, and not overridden by the contact’s rights.

    ✅ What a Valid LIA Test Requires

    • The contact’s role must be relevant to what you are selling, not a generic inbox.
    • The message must be plausibly expected given the contact’s public role.
    • An easy, honored opt-out has to exist in every message.

    ❌ Where Legitimate Interest Claims Break Down

    Commenters on the Reddit AMA pushed back on treating legitimate interest as a blanket shield; it only holds up when documented and defensible. That step is where most ad hoc B2B data providers stacks fall apart: a scraped list has no provenance.

    Why Is Germany’s Section 7 UWG Stricter Than GDPR Itself?

    Section 7 UWG treats unsolicited commercial email as “unreasonable harassment” (unzumutbare Belästigung) unless the recipient gave prior express consent, with no general B2B exception. This competition-law standard is separate from and stricter than GDPR’s legitimate interest basis, and it is what German courts apply in cold email disputes.

    ⚠️ What Counts as Consent in Germany

    • Express, opt-in consent (ausdrückliches Einverständnis) given before the first commercial email, not implied from a public listing.
    • A publicly listed company email address does not constitute implied consent, per German case law.
    • An existing customer relationship with a narrow, related offer is the one recognized exception.

    🔑 The Practical Takeaway

    Treat Germany as its own compliance track: the rest of the EU runs on documented legitimate interest, while German sends need prior opt-in or an existing-customer exception.

    What Did the BGH Actually Rule on B2B Email Advertising?

    Germany’s Federal Court of Justice (BGH) ruled in 2009 that publishing a business email address does not imply consent to receive marketing. Two rulings anchor this standard:

    📊 The Two Rulings That Anchor German Enforcement

    • BGH I ZR 218/07 (“E-Mail-Werbung II”), May 20, 2009: unsolicited commercial email sent without prior consent is an actionable interference, even in a B2B context.
    • BGH I ZR 201/07 (“E-Mail-Werbung III”), December 10, 2009: a published business contact address does not create implied consent for marketing email.

    🔑 Why This Still Matters in 2026

    Most pages on this topic cite “a 2009 Federal Court ruling” loosely without naming the case numbers. Both still anchor German enforcement in 2026: a public email does not make cold email to it defensible without documented consent.

    A scraped or purchased EU list has no documented source, so there is nothing to show if a contact disputes how their email was obtained. A verified match rate on file before the first send is what makes the process defensible.

    How Much Does a German Cease-and-Desist Letter Actually Cost?

    A German Abmahnung for unsolicited cold email typically demands EUR 400 to 3,000 or more, depending on whether it stays pre-litigation or escalates. Treat any single online figure as a floor, not a ceiling.

    📊 Abmahnung Cost by Stage

    StageTypical Cost RangeWhat Triggers It
    Pre-litigation AbmahnungEUR 400 – 1,000A single unsolicited commercial email with no consent on file
    Repeat or escalated demandEUR 1,000 – 3,000+A pattern of sends, or a higher “amount in dispute” (Streitwert)
    Court proceedingLegal fees plus Streitwert awardThe recipient declines to settle and files

    💡 Why the Fear Leads to Overcorrection

    That fear pushes some teams to avoid EU outbound entirely, the overcorrection the Reddit AMA called out. The fix is a documented, provenance-checked process, not avoidance.

    How Do Other EU Markets Differ From Germany?

    France, the Netherlands, and the Nordics generally allow B2B cold email under GDPR’s legitimate interest basis, making Germany the stricter outlier. Treating every EU country as Germany-strict leads teams to under-use a basis available almost everywhere else.

    📊 EU Market Comparison

    MarketGoverning StandardB2B Cold Email BasisKey Risk
    GermanySection 7 UWG + GDPRPrior express consent requiredAbmahnung, EUR 400-3,000+
    FranceGDPR + CNIL guidanceLegitimate interest, B2B exception recognizedCNIL complaint if targeting is irrelevant to the role
    NetherlandsGDPRLegitimate interest, documented LIA expectedAutoriteit Persoonsgegevens inquiry on repeat complaints
    NordicsGDPRLegitimate interest, generally permissive for B2BLow enforcement volume, but still requires an opt-out

    🔑 The Takeaway for EU-Wide Campaigns

    Build one default workflow for legitimate interest, then route German contacts into a separate consent-gated track.

    What Must a Legitimate Interest Assessment Document Before You Launch?

    A defensible legitimate interest assessment documents the purpose, the necessity, and the balancing test against the contact’s rights, before the first send. Skipping this step is the gap the Reddit AMA’s commenters described most often.

    ✅ Purpose and Necessity

    • The specific business purpose for contacting this person, not a generic “sales outreach” line.
    • Why this contact’s role makes the message relevant to their job function.

    🛡️ Provenance and Ongoing Compliance

    • The source and verification method for the contact’s email and employer.
    • The opt-out mechanism included in the message and the process for honoring it.
    • A refresh schedule so stale records do not outlive their documented basis.
    Already stitching contact data from more than one unverified source before you send into the EU? Start a free trial: 100 credits, no subscription required →

    How Do You Verify Contact Data Provenance at Scale With Explorium?

    Explorium gives GTM teams one verified data layer instead of a stitched one, scale to validate a full EU list in a single pass, and an affordable entry point that removes the incentive to skip EU markets. This answers the Reddit AMA’s open question: how to verify provenance before sending at scale.

    Architecture diagram showing Explorium API enriching and verifying an EU contact list before a GDPR-compliant cold email send

    🏗️ One Verified Data Layer

    • 150M+ company profiles and 800M+ people profiles sourced from 50+ data providers, returned in one call instead of five disconnected exports.
    • Each response carries the firmographic context an LIA needs: role, company size, sector.
    • 97.8%+ company match accuracy cuts the risk of emailing a stale or mismatched contact.

    🚀 Scale With Guardrails

    • Up to 1,000 entities enriched per call at 100 QPS sustained, enough to validate an entire EU list in one pass.
    • 99.999% uptime supports a recurring refresh cadence before every send wave, not once at list purchase.
    • Sample-before-export gating returns representative records and a cost estimate before credits are spent.

    💰 Affordable by Design

    • A free account with no sales call lets a team start with a small, verifiable EU batch.
    • Credits flow into a single unified pool across every endpoint, with no per-endpoint allocation.
    • Starting small and provenance-checked costs less than one Abmahnung demand.
    pip install explorium
    
    import requests
    
    response = requests.post(
        "https://api.explorium.ai/v1/prospects/enrich",
        headers={"Authorization": "Bearer YOUR_API_KEY"},
        json={
            "email": "[email protected]",
            "fields": ["company_name", "job_title", "company_size", "country"]
        }
    )
    record = response.json()
    print(record["match_confidence"], record["source_count"])
    

    Bulk-verify an existing list, then log the LIA fields from the response so documentation exists before the first send:

    import requests
    
    contacts = [{"email": e} for e in email_list[:1000]]
    response = requests.post(
        "https://api.explorium.ai/v1/prospects/bulk_enrich",
        headers={"Authorization": "Bearer YOUR_API_KEY"},
        json={"records": contacts, "fields": ["job_title", "company_size", "country"]}
    )
    results = response.json()["records"]
    defensible = [r for r in results if r["match_confidence"] >= 0.9]
    lia_log = [{
        "email": r["email"], "job_title": r["job_title"], "match_confidence": r["match_confidence"],
        "basis": "legitimate_interest" if r["country"] != "DE" else "requires_consent"
    } for r in defensible]
    

    See Explorium’s side-by-side B2B data provider comparison for provenance and match accuracy across providers.

    What’s the Compliant Cold-Email Workflow, Step by Step?

    A compliant EU cold-email workflow runs legitimate interest assessment, source verification, opt-out logging, and a refresh cadence as one repeatable process, not a one-time list purchase. The sending infrastructure teams already run (lemlist, HeyReach, Zapmail, EmailBison) handles delivery but was never built to verify legal basis.

    🚀 The Five-Step Process

    • Step 1: Document the LIA. Write the purpose, necessity, and balancing test before pulling any contacts.
    • Step 2: Verify provenance at the source. Match-check every contact through one documented API call.
    • Step 3: Route by country. Flag German contacts as requiring consent; route the rest through legitimate interest.
    • Step 4: Send with a working opt-out. Suppress the contact immediately on use.
    • Step 5: Refresh on a schedule. Re-verify role and company data before each send wave.
    de_requires_consent = [r for r in lia_log if r["basis"] == "requires_consent"]
    eu_default_basis = [r for r in lia_log if r["basis"] == "legitimate_interest"]
    print(f"DE (consent required): {len(de_requires_consent)}, EU default: {len(eu_default_basis)}")
    

    🔑 The Decision Framework

    Teams getting EU outbound wrong are not breaking GDPR on purpose, they are skipping documentation and provenance checks. Explorium’s 150M+ company and 800M+ people profiles across 50+ sources give you the LIA context, its 1,000-entities-per-call scale checks a full list in one pass, and its free, unified-credit-pool pricing costs less than one Abmahnung. Explorium is the data layer that makes legitimate interest defensible instead of theoretical.

    Verify your EU contact list before your next send wave. Get started with Explorium →

    Related Posts

    FAQs