You're ready to scale your business with cold email. You've got a list of prospects, a solid pitch, and the infrastructure set up. Then someone mentions GDPR and suddenly you're second-guessing everything.
Here's the reality - most people either ignore EU email laws completely or overthink them so much they never send a campaign. Both approaches are wrong. The truth is somewhere in the middle, and it's actually manageable once you understand what's really required.
The Main Laws You Need to Care About
There are three key regulations that affect cold email in the EU. Get these right and you're in a solid position.
GDPR (General Data Protection Regulation)
GDPR applies to anyone sending emails to EU residents, regardless of where your business is located. This is the big one, but it's not as restrictive as people think.
The core requirement - you need a legal basis for contacting someone. For cold email, your legal basis is usually "legitimate interest." This basically means you're reaching out because it makes business sense for both parties, and you're not being creepy about it.
What this means in practice:
- You can email someone's work email address if you found it legitimately (their website, LinkedIn, public directories, etc.)
- You cannot buy email lists of EU residents from random brokers
- You need to be able to prove where you got the contact information if asked
- Your email must include a way for people to opt out - more on this below
PECR (Privacy and Electronic Communications Regulations)
PECR is the UK and EU's specific ruleset for electronic marketing. It's stricter than GDPR in some ways.
The key rule - for B2B emails to corporate addresses (not personal mobile numbers), you generally don't need prior consent. This is your green light for cold email campaigns targeting business decision makers.
However, for personal email addresses or mobile numbers, you typically need prior consent first.
In practical terms for most B2B agencies and service businesses - you're targeting work emails at companies. You're fine. Just make sure you're reaching the right email format (usually [email protected] or similar).
ePrivacy Directive
This one is less relevant to traditional cold email, but worth knowing about. It mainly applies to marketing via SMS or push notifications. For email, PECR covers you.
What Your Emails Actually Need to Include
Every email you send needs certain information. This isn't optional - it's the law.
- Your business name - people need to know who's contacting them
- Contact information - a phone number, email, or address where they can reach you. Most people use their company's main contact email
- A clear unsubscribe option - this is critical. Include a link or instruction that makes it easy for someone to opt out. "Reply with UNSUBSCRIBE" or a link to an unsubscribe page both work
- If you have a registered office address, include it - this looks professional anyway and keeps you compliant
These elements don't need to be in the email body itself. Many agencies put this information in a footer or signature line. Just make sure it's there.
How to Build a Compliant Email List
This is where most people mess up. They source their contact list wrong and everything that follows is technically illegal.
What's allowed:
- Company websites - scrape contact pages, team pages, leadership bios
- LinkedIn - you can manually collect or use tools that pull from public profiles
- Industry directories and databases - as long as they don't explicitly forbid it
- Business registration records (Companies House, official registries)
- News articles and press releases
- People who previously engaged with your content or website
What's not allowed:
- Buying lists from random data brokers claiming to be "GDPR compliant"
- Using personal email addresses of employees without consent
- Scraping email addresses from forums or comments sections
- Using emails from unverified data sources
The rule of thumb - if you can't point to where you got the email address from, don't use it.
Legitimate Interest - The Key to Cold Email in the EU
Most people don't understand this, so let me explain it clearly.
You have a "legitimate interest" to contact someone when:
- You're solving a real problem their business has
- You're targeting the right person (decision maker, relevant department)
- You're not being intrusive or deceptive about it
- The benefit to them outweighs the minor inconvenience of receiving an email
This is actually the standard for good cold email anyway. You're supposed to be reaching out to people who could genuinely benefit from what you offer - not just blasting random contact lists hoping something sticks.
If you're doing that kind of targeting, you're already aligned with legitimate interest requirements.
What Happens if You Get It Wrong
People worry about fines. GDPR fines can be significant - up to 20 million euros or 4% of global revenue for serious violations. But those are for large-scale breaches or deliberate violations.
In reality, what happens more often:
- Someone complains to their data authority
- You get contacted asking for proof of your legal basis
- If you can't prove it, you have to stop and potentially pay a smaller fine
- Your email service provider might shut you down
The point - it's not worth the risk. Compliance is straightforward enough that you might as well do it right.
The Practical Checklist
Before you send a campaign to EU prospects:
- Document where every email came from
- Make sure your emails include your business name and contact information
- Include a clear unsubscribe mechanism
- Target work emails at relevant decision makers
- Keep your pitch relevant to their actual business
- Honor unsubscribe requests immediately
That's it. Do these things and you're compliant.
The Real Bottleneck
Here's what most people don't realize - compliance isn't the hard part. The hard part is everything else. Finding the right prospects, getting their actual email addresses, writing copy that works, managing replies, following up appropriately, handling objections.
If you're running a service business or agency and you want to scale using cold email, you need to handle all of this correctly. And you need to do it in compliance with EU regulations.
A lot of business owners either hire someone to figure out the legal side, or they hire an agency that handles the entire process - compliance, list building, copy, sending, and reply management. The second option is why BEC Growth exists. We handle everything, including making sure every campaign meets EU requirements. If you're trying to figure out how to get consistent client flow through cold email without becoming a compliance expert, that's exactly what we do.