73% lower cost per meeting · live in 7 days · 50+ companies, 5 markets Get your free GTM analysis →
← All plays
gdprcold-email

GDPR Cold Email in Germany: The Exact Compliance Checklist for B2B Outreach

February 27, 2026 · 5 min read · by Ahmet Faruk Yilmaz, Founder of Asphia

GDPR Cold Email in Germany: The Exact Compliance Checklist for B2B Outreach

TL;DR

B2B cold email in Germany is legal under GDPR if you use legitimate interest as your lawful basis, keep messages relevant to the recipient's professional role, include a clear opt-out, and never contact anyone who has opted out. A proper suppression list and documented data sourcing are non-negotiable.

B2B cold email in Germany is legal under GDPR. The short answer: use legitimate interest as your lawful basis, target professional roles not personal inboxes, include a real opt-out, and document everything. The longer answer is a checklist every sender should run before the first sequence goes live.

Germany adds one layer most EU countries do not: the UWG (Unfair Competition Act). Together with GDPR, it means the bar for compliant cold email is slightly higher than in France or the Netherlands, but it is absolutely achievable with the right setup.

The Lawful Basis Question

Under GDPR Article 6(1)(f), you can process a prospect’s data for cold outreach if your legitimate interest outweighs their right to privacy. For B2B email this test is usually satisfied when three conditions are met.

First, the recipient’s role is directly relevant to your offer. Emailing a Head of Sales about outbound tooling passes the test. Emailing the same person about HR software probably does not.

Second, a reasonable person in that role would not be surprised to receive your email. A B2B SaaS founder receiving an email about lead generation is not surprised. A private individual receiving that same email is.

Third, you have conducted and documented a Legitimate Interest Assessment (LIA). This does not need to be a 20-page report. A one-page document covering what data you hold, why you hold it, and why the interest is proportionate is enough to demonstrate accountability if a data protection authority (DPA) ever asks.

Drake meme rejecting getting consent from every prospect, approving writing a one-page Legitimate Interest Assessment You do not need consent. You need a one-page document and a relevant offer.

The Pre-Send Compliance Checklist

Run this before any German sequence launches.

Data sourcing

  • Contacts sourced from professional platforms (LinkedIn, Apollo, Clay) or public business registries only. No personal email addresses (gmail.com, yahoo.de, web.de).
  • You can name the source if a prospect asks. Document it in your CRM or enrichment tool.
  • Data is fresh. Contacts verified within the last 90 days where possible.

Email content

  • Subject line is not misleading. Do not imply a prior relationship that does not exist.
  • First line identifies who you are and why you are reaching out.
  • Offer is relevant to the recipient’s professional role, not their personal life.
  • Sender name and company are your real legal name and entity, not a persona.
  • Physical business address is in the signature (required under UWG for commercial communication).

Opt-out mechanics

  • Every email includes a clear, working unsubscribe mechanism. A reply-based “reply STOP” is acceptable. A one-click link is better.
  • Opt-outs are processed within 72 hours maximum. Automated suppression is strongly preferred.
  • Suppression list is shared across all sending domains and mailboxes for the same company.

Data storage

  • Prospect records are stored in a CRM or database with access controls.
  • You have a written retention policy. Contacts with no commercial relationship after 12 to 24 months are deleted or anonymized.
  • Data processing agreements (DPAs) are signed with every vendor that touches personal data: your email sending platform, CRM, and enrichment tools.

Follow-up limits

  • Sequence length is reasonable. Three to five touchpoints over three to four weeks is standard. Sending 15 emails over 90 days to someone who never replied creates a pattern a German DPA could classify as harassment.
  • Any prospect who replies negatively is immediately suppressed, not just unsubscribed from the current campaign.

Where German Outreach Commonly Goes Wrong

Three failure modes show up repeatedly in Germany-targeted sequences.

Using scraped personal email addresses. German law is strict about the line between professional and private. A personal Gmail is not a B2B contact point even if the person runs a business.

No documented LIA. If you cannot produce a one-page legitimate interest assessment, you are relying on luck rather than compliance. German DPAs (particularly the Hamburg DPA and the Bavarian State Office for Data Protection Supervision) are active in reviewing complaints.

Suppression list silos. If someone opts out from one mailbox and then receives email from a second mailbox belonging to the same company three days later, that is a GDPR violation. The suppression list must be centralized.

How Asphia Runs GDPR-Native Outreach for European Markets

Every sequence Asphia builds for German or EU markets is structured around this checklist by default. Data is sourced from professional platforms via Clay enrichment, verified before sending, and stored in stacks that have signed DPAs. Opt-outs are automated and centralized across all client sending infrastructure.

For companies that want to run their own outbound in Germany, the Done With You outbound model means we build the compliant system in your stack and hand it over. For teams that want full management, the Done For You model keeps Asphia running the sequences while a human approves every send before it goes out.

If you are targeting Germany specifically alongside other European markets, the B2B lead generation agency Europe page covers how we structure multi-market outreach to meet each country’s requirements simultaneously.

The Bottom Line

GDPR cold email in Germany works. The compliance requirements are specific but not unreasonable: legitimate interest documented, professional contacts only, clear opt-out, centralized suppression, and the ability to answer “where did you get my data?” honestly. Build those five elements into your system before the first email sends, and you are operating within the law.

For more on building outreach that avoids spam filters alongside GDPR compliance, see AI cold email that avoids spam.

Free resource

Get the signal tier list in your inbox.

We rank signals from S to D to decide who gets a cold email and who does not. You get the list once. No follow-up emails.

FAQ

Is cold email legal in Germany under GDPR?

Yes, B2B cold email is legal in Germany under GDPR when you rely on legitimate interest (Article 6(1)(f)), keep content relevant to the recipient's professional role, and provide a clear unsubscribe mechanism. Germany also requires compliance with the UWG (Unfair Competition Act), which adds a layer beyond GDPR for commercial emails.

Do I need consent to send cold emails to German businesses?

No explicit consent is required for B2B cold email in Germany if you can demonstrate legitimate interest. This means your offer must be genuinely relevant to the recipient's role, you must not contact personal email addresses, and you must respect any opt-out immediately. Document your reasoning before you send.

What is the UWG and why does it matter for cold email in Germany?

The UWG (Gesetz gegen den unlauteren Wettbewerb) is Germany's unfair competition law. For cold email it means commercial messages must not be deceptive, must identify the sender clearly, and must not be sent to recipients who have not given some form of implied or explicit consent for that type of commercial contact. B2B emails with clear relevance typically satisfy this requirement.

How long can I store German prospect data under GDPR?

GDPR does not set a fixed retention period, but you must store personal data only as long as necessary for the purpose. For cold outreach, most practitioners delete or anonymize records within 12 to 24 months if no reply or commercial relationship develops. Document your retention policy in writing.

What must every cold email to a German prospect include?

Every cold email must include the sender's full legal name and company, a business address, a clear one-click or reply-based unsubscribe option, and no misleading subject line. If you are using data from a third-party source (Apollo, Clay, LinkedIn), you must be able to tell the recipient where you got their contact information if they ask.

What happens if a German prospect asks where I got their data?

Under GDPR Article 13 and 14, you must be able to disclose the source of their personal data. If you sourced a contact from LinkedIn, Apollo, or a similar platform, you must say so clearly when asked. Failing to answer is a GDPR violation and can trigger a complaint to the relevant data protection authority (DPA) in Germany.

Ahmet Faruk Yilmaz, founder of Asphia

Ahmet Faruk Yilmaz

Founder of Asphia. He builds and runs signal-based B2B outbound engines for lean teams, and has booked meetings with teams at companies across five markets. Writes about cold email, Clay, deliverability, and GTM engineering.

Want this run for you?

Get a free GTM analysis. We show you the exact engine we would build.

Get your free GTM analysis →
Keep reading