You're sitting on a list of 500 potential clients. Your copy is solid. Your offer makes sense. Then someone on your team asks: "Wait, are we allowed to email these people?"
And suddenly, you're in the weeds. GDPR, PECR, consent requirements, opt-in vs opt-out - it's a mess. You don't want to get sued or fined. But you also can't afford to sit around doing nothing.
Here's the truth: cold email in Europe isn't illegal. It's just heavily regulated. And the rules changed again in 2025-2026. If you're sending cold emails to anyone in Europe, you need to understand what actually applies to your situation.
GDPR vs PECR - Which One Actually Matters for Cold Email?
This is where most people get confused. They think GDPR is the main thing to worry about. It's not.
GDPR is about data protection - how you collect, store, and use personal data. It matters for your infrastructure and your processes. But it doesn't ban cold email.
PECR (Privacy and Electronic Communications Regulations) is what actually restricts cold email. PECR is the rules about sending unsolicited electronic messages. That's your real constraint.
Here's the critical difference:
- GDPR: Applies to how you handle data. You need a legal basis for processing someone's email address. The most common one for cold email is "legitimate interest" - meaning you have a legitimate reason to contact them, and your interest outweighs their privacy.
- PECR: Applies to what you actually send them. It says you generally can't send unsolicited marketing emails to individuals without prior consent. But there are exceptions - and this is where cold email still works.
So here's what you need to do: check PECR rules for your target country, and make sure your data handling passes a GDPR sniff test. Do both, and you're in the clear.
The PECR Rules by Country - The Short Version
PECR isn't one unified rule. Each EU country has slightly different implementations. Here's what matters for cold email:
UK and Germany - Stricter
UK and Germany operate under a "prior consent" model. This means you generally need explicit opt-in before sending marketing emails to individuals.
Cold email to individuals here is risky unless you have consent or a strong argument that your message isn't marketing - it's a business inquiry.
That said, B2B emails to business addresses (like [email protected]) are treated differently. If you're emailing a company's general inbox, not a personal mobile number, you have more flexibility.
Most Other EU Countries - More Flexible
France, Spain, Italy, Netherlands, and most others operate under a "soft opt-in" or "prior notification" model. You can send unsolicited emails if you include clear unsubscribe information and don't mislead about who you are.
Cold email here is legally defensible if you follow basic rules.
The Practical Reality
Most European regulators care about three things:
- You're being transparent about who you are
- You're making it easy to unsubscribe
- You're not being a spammer - i.e., you're sending legitimate business inquiries, not mass marketing blasts
If you do these three things consistently, you're following the spirit of the law. Regulators aren't hunting individuals sending thoughtful business emails. They're going after people sending 10 million emails a day with no unsubscribe option.
How to Stay Compliant - The Checklist
Let's get practical. Here's what you need to do before you hit send:
Data Source
- Use reputable, verified lead lists. Don't scrape email addresses from LinkedIn or random websites.
- Make sure your data provider can confirm their source. If they can't, find a different provider.
- For warm outreach (referrals, connections), document the source. "John referred me to you" is valuable.
Your Email
- Use your real name and company name in the From line. No aliases, no hidden identities.
- Include your company address in the signature. This is non-negotiable in Europe.
- Include a clear, working unsubscribe link. Make it obvious. No tricks.
- If you're B2B, target business email addresses. Personal email addresses are higher risk in strict countries.
Your List Hygiene
- Remove anyone who has bounced or unsubscribed. Keep records.
- Don't keep email addresses longer than necessary. If someone doesn't respond in 6 months, consider removing them.
- Maintain a suppression list. If someone unsubscribes, they're off forever.
Your Sending Infrastructure
- Use a dedicated IP or shared IP from a reputable ESP. Gmail and Outlook flagging you as spam isn't just a compliance issue - it's a business problem.
- SPF, DKIM, and DMARC records configured correctly. This shows you're legitimate.
- Keep reply rates healthy. If you're getting unsubscribes and spam complaints, regulators notice patterns like this.
The Gray Areas - What You Should Know
There are some things that regulators are still figuring out in 2026:
LinkedIn outreach: Technically, connecting on LinkedIn and then emailing isn't cold email - it's reaching out to a connection. This is much safer legally. But if you're buying LinkedIn data and emailing people based on that, you're in gray territory. UK and Germany specifically are cracking down on this.
AI-generated personalization: Personalized emails are better for compliance (shows intent, not spam). But if your personalization is obviously AI-generated and inaccurate, it might be seen as misleading. Keep it real.
B2B vs B2C: Business email addresses get more flexibility than consumer emails. Target businesses, not individuals on personal accounts.
What Happens If You Get It Wrong
Regulators in Europe don't usually go after small agencies. They go after the big offenders sending millions of emails. That said, if someone files a complaint and you're obviously not following the rules, you could face fines under GDPR - up to 4% of annual revenue in serious cases.
More realistically: your emails get filtered, your ISP reputation tanks, and your campaigns stop working.
The compliance stuff isn't just legal - it's about getting results. Clean lists, proper infrastructure, transparent sending - these all make your emails actually land in inboxes.
The Honest Closing
Cold email in Europe works. It works really well, actually. But you need to do it right - legally, technically, and strategically.
If you're running a service business or agency and want to scale with cold email without spending weeks on compliance research and infrastructure setup, that's exactly what we do at BEC Growth. We handle the legal side, the technical side, the list sourcing, the copy, the campaigns - everything. Our clients sign 5-20+ new clients per month using cold email alone, and they never have to worry about whether they're compliant or if their emails are landing.
If you'd rather DIY, at least use this guide as your checklist. The rules aren't complicated - just follow them consistently.