73% lower cost per meeting · live in 7 days · 50+ companies, 5 markets Get your free GTM analysis →
← All plays
gdprcold-email

GDPR Opt-In vs Opt-Out for B2B Cold Email: What the Law Actually Requires

March 12, 2026 · 5 min read · by Ahmet Faruk Yilmaz, Founder of Asphia

GDPR Opt-In vs Opt-Out for B2B Cold Email: What the Law Actually Requires

TL;DR

GDPR does not require opt-in consent for B2B cold email. You can email business contacts under legitimate interest, provided the message is relevant to their role, you identify yourself clearly, and every email includes a simple way to opt out. Opt-out must be honoured immediately.

Many founders and sales teams assume GDPR means you need permission before every cold email. That assumption is wrong, and it costs them real pipeline.

The short answer: GDPR does not require opt-in consent for B2B cold email to professional contacts. You can reach out under legitimate interest, provided you follow a clear set of rules. Here is what those rules actually say.

The Lawful Basis That Covers B2B Cold Email

GDPR Article 6 lists six lawful bases for processing personal data. For cold outreach, the relevant one is legitimate interest (Article 6(1)(f)).

Legitimate interest allows you to process someone’s professional contact details and send them an email if:

  1. You have a genuine business reason (prospecting, partnership, a relevant offer).
  2. The contact’s role makes the outreach relevant to them professionally.
  3. Your interest is not overridden by the contact’s privacy rights.

The third point is where most teams go wrong. Legitimate interest is not a blank cheque. Sending irrelevant bulk email to thousands of random contacts fails the balancing test. Sending a targeted, relevant email to a Head of Sales at a company that matches your ideal customer profile passes it.

Consent (opt-in) is a separate lawful basis. It is stricter, requires an affirmative action from the contact, and must be as easy to withdraw as to give. For B2B outreach, most European DPAs (data protection authorities) and the GDPR text itself support legitimate interest as the appropriate basis. Consent is rarely necessary and often impractical for cold outbound.

Insanity Wolf meme: B2B cold email does not need opt-in consent, legitimate interest covers it Opt-in is not the law for B2B. Legitimate interest is.

What a Compliant Cold Email Must Include

Whether you use legitimate interest or any other basis, every email you send must contain:

  • Your real identity. Company name, website, and a way to reach you. No vague sender names or obscured domains.
  • A clear reason for contact. One sentence is enough. “I noticed you recently expanded into the German market” is better than a generic pitch opener because it signals the email is relevant to them specifically.
  • An opt-out mechanism. This can be a simple line at the bottom: “Not relevant? Reply with ‘unsubscribe’ and I will remove you.” A formal unsubscribe link works too. The format matters less than the fact that it is easy to use and you actually honour it.
  • Prompt suppression. Once someone opts out, you must stop. Not after one more follow-up. Immediately. Log the opt-out and ensure no future sequences can reach that address.

Agencies building GDPR-compliant cold email infrastructure treat suppression lists as a first-class system, not an afterthought.

The ePrivacy Directive Adds One More Layer

GDPR governs data processing. The ePrivacy Directive (sometimes called the Cookie Law, though it covers much more) governs electronic communications specifically.

Under ePrivacy, most EU member states require prior consent for unsolicited commercial email to individuals, including sole traders. However, emails sent to corporate addresses (role-based or named contacts at registered companies) are generally treated as B2B communications and fall outside the individual-consent requirement.

The practical rule is simple: if the email address belongs to a person acting in a professional capacity at a company, legitimate interest under GDPR applies. If it is a personal consumer address, you need opt-in.

This is why signal-based outreach that targets verified business contacts at relevant companies is both more effective and more legally defensible than broad list blasting.

What Opt-Out Actually Means in Practice

Opt-out does not mean silence equals consent to continue. It means:

  • You have the right to send the first email (and a reasonable follow-up sequence) without prior permission.
  • If the recipient says stop, you stop. No exceptions, no “just one more.”
  • You cannot re-add an opted-out contact to a new campaign six months later and treat the opt-out as expired.

A suppression list that persists across campaigns and tools is not optional, it is a compliance requirement.

At Asphia, every sequence we build or run includes a suppression layer that spans tools. When a contact opts out of one campaign, they are excluded from all future sends for that client. This is part of what it means to run done-for-you cold email that is actually GDPR-native rather than bolted-on compliant.

The Legitimate Interest Assessment (LIA)

If you are building an outbound function for a European market, you should document your legitimate interest assessment. This is a short internal record that covers:

  • What data you hold (name, email, job title, company).
  • Why you hold it (prospecting relevant contacts for your offer).
  • How you collected it (Apollo, LinkedIn, Clay enrichment from public sources).
  • Why you believe the contact’s interests do not override yours (the email is relevant to their role, it is not intrusive, it is easy to opt out).

You do not file this with a regulator. You keep it in case of a complaint or audit. The ICO in the UK and the EDPB at EU level have both published guidance confirming that legitimate interest can apply to B2B marketing where the balancing test is met.

If you are running outbound into Germany, the Netherlands, or other markets with active DPAs, a documented LIA is practical protection, not just theory.

Bottom Line

GDPR is not a ban on B2B cold email. It is a framework that rewards relevant, targeted outreach and penalises bulk, untargeted sending. Opt-in consent is not required for professional contacts. Opt-out rights must be respected immediately. Every email must identify you and give a clear way to stop.

Teams building outbound for European markets with this framework in place run cleaner, more effective campaigns than those treating compliance as an obstacle. The law and good outbound practice point in the same direction: relevance, transparency, and respect for the contact’s time.

Free resource

Get the signal tier list in your inbox.

We rank signals from S to D to decide who gets a cold email and who does not. You get the list once. No follow-up emails.

FAQ

Does GDPR require opt-in consent before sending B2B cold email?

No. GDPR allows B2B cold email under the legitimate interest lawful basis (Article 6(1)(f)) without prior consent, as long as the email is relevant to the recipient's professional role, you are transparent about who you are, and you provide a clear opt-out in every message.

What is the difference between opt-in and opt-out under GDPR?

Opt-in means the recipient actively consented before you contact them. Opt-out means you can contact them first but must stop immediately if they ask. For B2B cold email, opt-out (legitimate interest) is the standard lawful basis used across Europe, including under UK GDPR.

What must every GDPR-compliant cold email include?

Every cold email must include your real company name and contact details, a clear explanation of why you are reaching out (relevance to their role), and a simple way to opt out, such as a reply instruction or unsubscribe link. Suppressing opt-outs promptly is a hard requirement.

Can I email a personal Gmail or consumer email address under legitimate interest?

No. Legitimate interest for cold outreach applies to professional contacts at business domains. Consumer email addresses (Gmail, Hotmail, Yahoo) require explicit opt-in consent under GDPR and, in most EU countries, under local ePrivacy laws as well.

How long can I keep a contact's data if they never reply?

GDPR does not set a fixed retention period, but you must not keep personal data longer than necessary for your stated purpose. Most compliance guidance suggests reviewing non-engaged contacts after 12 to 18 months and deleting or suppressing those who have not interacted.

Does GDPR apply to cold email sent from outside the EU?

Yes. GDPR applies whenever you target data subjects located in the European Economic Area, regardless of where your company is based. If you are emailing contacts at EU companies, GDPR governs how you handle their data even if you operate from the US, UK, or Turkey.

Ahmet Faruk Yilmaz, founder of Asphia

Ahmet Faruk Yilmaz

Founder of Asphia. He builds and runs signal-based B2B outbound engines for lean teams, and has booked meetings with teams at companies across five markets. Writes about cold email, Clay, deliverability, and GTM engineering.

Want this run for you?

Get a free GTM analysis. We show you the exact engine we would build.

Get your free GTM analysis →
Keep reading