Cold Email in France: CNIL Rules, GDPR Overlap, and Compliant Outreach Templates
March 7, 2026 · 5 min read · by Ahmet Faruk Yilmaz, Founder of Asphia
TL;DR
B2B cold email in France is permitted under CNIL guidelines without prior consent, provided the message is relevant to the recipient's professional role, you disclose your identity, and include a clear opt-out. GDPR legitimate interest applies. Personal email addresses (Gmail, Hotmail) require prior opt-in.
Cold email in France sits at the intersection of two overlapping frameworks: CNIL, the French data protection authority, and the EU-wide GDPR. The short answer is that B2B cold email is legal in France without prior consent, but only if you follow specific conditions. Miss them, and you move from compliant prospecting into territory that CNIL actively monitors.
What CNIL Actually Says About B2B Cold Email
The French legal framework for electronic prospecting is built on Article L34-5 of the Postal and Electronic Communications Code (CPCE), which transposes the EU ePrivacy Directive. CNIL interprets this to mean:
- No prior consent required for B2B when the message targets a professional in their professional capacity and the offer is relevant to their function.
- Prior consent is required when you contact someone at a personal email address (Gmail, Hotmail, Yahoo) even if they sometimes use it for work.
- Every message must include your sender identity, your company’s address, and a clear opt-out mechanism that you act on promptly (typically within one month, in line with GDPR timelines).
The critical word is “relevant.” A cold email selling CRM software to a sales director at a software company passes relevance. A cold email selling that same CRM to the head of HR at a law firm does not. CNIL expects a documented rationale you could defend if asked.
No consent form. Just a relevant offer, a clear opt-out, and a one-page LIA you could produce if CNIL asked.
GDPR on Top: Legitimate Interest and Data Handling
GDPR does not replace CNIL’s consent exemption; it layers on top of it. Your data processing still needs a lawful basis. For B2B cold email, that basis is almost always legitimate interest under Article 6(1)(f).
To rely on it, you need a lightweight Legitimate Interest Assessment (LIA) that answers three questions:
- What is your legitimate purpose? (Example: identifying companies that could benefit from your outreach service.)
- Is that purpose necessary? (Example: direct email is proportionate because the recipient is a decision-maker in your exact ICP.)
- Does your interest override the individual’s rights? (Low impact when it is one targeted email to a professional address with an opt-out, not a mass consumer blast.)
You do not need to publish a full LIA publicly, but you should document it internally. If CNIL investigates, you will need to produce it.
Additional obligations under GDPR that affect cold email operations in France:
- Data minimisation: store only the fields you need for outreach (name, company, role, email). Do not build profiles beyond what the campaign requires.
- Retention limits: contacts who opt out must be suppressed immediately and purged from your prospect list after a defined retention window (commonly six to twelve months of inactivity, documented in your privacy policy).
- Data source transparency: if asked, you must be able to tell a prospect where you obtained their data. Using a tool like Apollo or Clay is fine provided those tools comply with GDPR and you state the data source category in your privacy policy.
For a deeper look at running GDPR-native outbound across multiple EU markets, see our guide on GDPR compliant cold email agency practices.
A Compliant French B2B Cold Email: What It Looks Like
A compliant cold email to a French B2B prospect needs five elements:
1. Honest subject line. No misleading headers, no faked “Re:” threads. CNIL can cite deceptive subjects independently of your opt-out compliance.
2. Sender identity in the email body or footer. Company name, legal form (SAS, SARL, etc.), and a contact address. A signature block with your name and company website satisfies this in practice.
3. Relevance signal. One or two sentences that connect your offer to their specific role or a signal you observed (a job posting, a funding announcement, a product launch). This is not just good copy, it is part of your legitimate interest justification.
4. Clear opt-out. A one-line statement with a reply-to-opt-out instruction or an unsubscribe link. “Reply STOP to be removed from future emails” works. You must honour it within a reasonable period.
5. No data from personal addresses. If your list contains anyone at @gmail.com, @yahoo.fr, or similar consumer domains, remove them before sending or obtain documented prior consent.
For team-level execution at scale, see how signal-based targeting integrates with compliance in our B2B lead generation agency Europe overview.
The Practical Workflow: How Compliant Teams Structure French Outreach
The compliance burden in practice is lighter than it sounds, because most of it is infrastructure you build once:
- Suppression list: a single file or table that blocks opted-out contacts across all campaigns. Update it the same day someone opts out.
- LIA template: a one-page document per campaign type (not per contact). Approved internally, stored with version history.
- Data source log: which tool sourced the contact, on what date, and what fields were pulled. A simple spreadsheet column works for smaller teams.
- Privacy policy: publicly accessible, covering data categories used in prospecting, retention periods, and the right to access or delete data.
If you are running outbound across multiple European markets, France sits on the more permissive end compared to Germany (where the debate about GDPR and cold email is sharper) but still requires more documentation than the United States. French prospects also respond well to personalised, concise outreach that demonstrates you understood something specific about their context before reaching out.
Asphia’s outbound campaigns are built GDPR-native from day one: every claim in a cold email is fact-checked against a live source, legitimate interest assessments are part of campaign setup, and suppression lists are maintained automatically. Whether you want us to build and hand over the system or run it for you, the compliance layer is embedded from the start. See done-for-you cold email or done-with-you outbound to understand which model fits your team.
For official CNIL guidance on electronic prospecting, the CNIL website (cnil.fr) publishes updated sheets on the consent and legitimate interest rules for professional prospecting in French and English.
Get the signal tier list in your inbox.
We rank signals from S to D to decide who gets a cold email and who does not. You get the list once. No follow-up emails.
Request received. The list lands in your inbox within 24 hours.
One more step: send the prepared request to [email protected]
FAQ
Is cold email legal in France for B2B?
Yes. CNIL allows unsolicited commercial email to professional contacts without prior consent when the message relates to their job function and you include an opt-out. Personal email addresses are excluded and require prior opt-in.
What is the CNIL rule for B2B cold email in France?
CNIL guidance permits B2B cold prospecting by email if three conditions are met: the recipient is a legal entity or professional acting in that capacity, the offer is relevant to their role, and every email includes a clear, working unsubscribe mechanism.
Does GDPR apply to cold email in France?
Yes. GDPR governs data handling (storage, processing, deletion). You need a lawful basis, most commonly legitimate interest, documented in a brief legitimate interest assessment before you send. Suppression lists must be maintained on opt-out.
Can I cold email a French prospect using their company address?
Yes, a corporate email address ([email protected]) is treated as professional data. You may contact them without prior consent if the outreach is relevant to their work and includes opt-out. A generic personal address even if used for work still falls under stricter rules.
What must a compliant French B2B cold email include?
Sender identity (company name and registered address), a clear subject line, a description of what you offer that is relevant to the recipient's role, and a one-click or reply-based opt-out. No pre-ticked consent boxes. No deceptive headers.
What happens if I ignore CNIL cold email rules in France?
CNIL can issue warnings, injunctions, and administrative fines. Under GDPR, fines can reach 4% of global annual turnover. In practice, most enforcement starts with a formal notice and opportunity to comply, but repeat violations or bulk spam attract larger penalties.
Ahmet Faruk Yilmaz
Founder of Asphia. He builds and runs signal-based B2B outbound engines for lean teams, and has booked meetings with teams at companies across five markets. Writes about cold email, Clay, deliverability, and GTM engineering.
Want this run for you?
Get a free GTM analysis. We show you the exact engine we would build.
Get your free GTM analysis →