You're probably worried about GDPR right now. You've heard horror stories about €20 million fines, cease-and-desist letters, and entire cold email campaigns getting shut down. The problem is that most of the advice online is either overly conservative (telling you cold email is basically illegal in Europe) or dangerously vague ("just get consent somehow").
Here's the reality: You can run compliant cold email campaigns to European prospects. You just need to understand what GDPR actually requires, not what people on Twitter say it requires.
The Core GDPR Rule for Cold Email
GDPR doesn't ban cold email. It bans cold email to people without a legal basis to contact them. There's a specific difference between "I don't have consent" and "I have no legal basis," and most people conflate these two things.
Under GDPR, you need one of these to send a cold email:
- Legitimate interest - You're contacting someone about a service that could genuinely benefit their business, and you have a reasonable expectation they might want to hear about it
- Consent - They explicitly said yes before you emailed them
- Contractual necessity - You need to email them as part of an existing contract (rarely applies to cold email)
Most B2B cold email operates under "legitimate interest." This is the legal basis that lets you actually send cold emails in Europe without pre-opt-in consent.
How Legitimate Interest Actually Works in Practice
Legitimate interest means you're contacting someone because:
- You're reaching out to their work email address about something work-related
- The person's role suggests they might actually care about what you're offering
- Your value proposition is clear enough that you're not wasting their time
- You have a reasonable way for them to opt out immediately
Example: Emailing a marketing manager at a mid-market software company about cold email services? Legitimate interest applies. You're contacting them at their work email about their actual job function.
Example: Emailing a CEO's personal Gmail address with vague "partnership opportunities"? That's not legitimate interest. You're fishing, not targeting someone for whom your service is relevant.
The key difference: Are you contacting them because of their role, or because you have their email address?
The Three Things GDPR Actually Requires You to Do
1. Have an Unsubscribe Link in Every Email
This is non-negotiable. Every cold email needs a way to opt out. The unsubscribe link should be clearly visible, not hidden in footer text, and it should work immediately when clicked.
Format that works:
- One-click unsubscribe (the gold standard)
- A working link that removes them from your list within 48 hours
- Visible in the email footer, not buried
Many email platforms handle this automatically. If yours doesn't, add it manually. This single thing prevents most GDPR complaints.
2. Be Transparent About Who You Are
Your email needs to clearly state who's sending it. "From: John" doesn't cut it. The recipient should be able to identify your actual company and have a way to contact you if they want to.
In practice, this means:
- Your company name in the "From" field or in the email signature
- A physical business address in your footer (required if you're in the EU or sending to the EU)
- Contact information so someone can ask questions
This is about transparency, not deception. You're not hiding who you are.
3. Keep Records of Your Legitimate Interest Assessment
This is the one that catches people off-guard. GDPR doesn't just require legitimate interest - it requires you to document why you believe legitimate interest applies.
In practice, this means keeping a record like:
- "We're contacting marketing managers at B2B companies about cold email services because their role suggests relevance to our offering."
- Date you assessed this
- Basic description of your targeting criteria
You don't need a 50-page legal document. A paragraph is fine. If a GDPR authority ever asks why you contacted someone, you can show them this and say "We had legitimate interest because..."
If you can't write down a legitimate interest reason that sounds reasonable to a third party, you shouldn't be sending that email.
What GDPR Doesn't Actually Require (Common Myths)
Myth 1: You need pre-opt-in consent before emailing anyone in Europe. False. You need a legal basis. Legitimate interest is a legal basis. You're good.
Myth 2: You can only email people who signed up for your list. False. Cold email exists specifically for contacting people who didn't sign up yet. As long as you have legitimate interest and offer opt-out, you're compliant.
Myth 3: Your subject line can't be persuasive because it's "deceptive." False. Your subject line just needs to be honest. You can make it compelling without lying.
Myth 4: You need to mention GDPR in your email. False. That would actually be weird and hurt your reply rate. Your unsubscribe link and transparency handle GDPR requirements. You don't need to preach about it.
How to Set Up Your Campaign for GDPR Compliance
Step 1: Define Your Targeting Criteria (Your Legitimate Interest)
Write down exactly who you're targeting and why. Example: "We're emailing CMOs and marketing directors at B2B SaaS companies with 50-500 employees, because these companies typically have budgets for marketing automation and their role suggests they'd find cold email lead generation relevant."
This becomes your legitimate interest documentation.
Step 2: Set Up One-Click Unsubscribe
Most email platforms (Gmail, Outlook, cold email tools) support this now. If you're using a custom solution, add a link that unsubscribes people automatically. Test it works.
Step 3: Include Your Business Info in the Footer
Company name, address, phone. Make it part of your template so every email has it. This isn't just GDPR - it's also required by most countries' anti-spam laws.
Step 4: Monitor Unsubscribe Rates and Honor Requests Immediately
If someone unsubscribes, remove them immediately. If your unsubscribe rate starts climbing, it's a signal your targeting or messaging is off. Fix it.
Regional Variations (UK, Switzerland, etc.)
The UK's PECR rules are stricter than GDPR for some channels (phone, SMS) but cold email essentially follows the same pattern. Switzerland has similar rules. Germany has some businesses being more sensitive to cold outreach, so you might want to be more conservative there.
The core principle holds: legitimate interest for work-related emails to people in relevant roles, with clear opt-out, is compliant across most of Europe.
The Practical Reality
Thousands of agencies and B2B companies run GDPR-compliant cold email campaigns every single day. They do it by following the three core requirements: legitimate interest, unsubscribe links, and transparency about who they are.
The companies that get in trouble are the ones ignoring unsubscribe requests, emailing personal Gmail addresses with no business reason, or pretending to be someone they're not. Don't do those things, and you'll be fine.
That said, understanding the rules and actually implementing them consistently across a running campaign are two different things. You need to audit your infrastructure, monitor your data handling, track your unsubscribes, and maintain documentation. If you're running this at scale across dozens of campaigns, that overhead adds up fast - especially when you also need to focus on actual reply handling and sales conversations.
Related Guides
- B2B Cold Email and GDPR Compliance: What You Actually Need to Know
- B2B Cold Email and Spam Compliance: What Actually Matters (And What Doesn't)
- Cold Email Deliverability Complete Guide: Why Your Emails Aren't Landing in Inboxes
- Cold Email Infrastructure Setup Guide: The Unsexy Foundation That Actually Gets Replies
- B2B Cold Email Lead Generation: The Actual Strategy That Works