Check a cold email against EU and UK rules
How it works
Set the situation
Country, who is receiving it, whether you send from inside or outside Europe, and where the address came from. Those four answers decide the legal basis before a word of the copy matters.
Get the basis
Legitimate interest, the existing-customer exception, or prior consent — with the national rule that produces it quoted, so you can check it yourself rather than take a verdict on faith.
Check the copy
The message is scanned for the things articles 13, 14 and 21 expect: identification, a postal address, an opt-out, where the data came from, a privacy notice, the right to object — plus the deceptive patterns that turn a compliance question into an unfair-practices one.
Take the footer and the LIA
A footer covering the disclosure obligations is generated from your details, and the four-limb legitimate interests assessment is laid out for you to fill in and file with the campaign.
Two sets of rules, not one
The mistake almost everyone makes is treating this as a GDPR question. GDPR governs the personal data: a named person's work address is personal data, so you need a lawful basis to hold and use it, and article 6(1)(f) legitimate interest is usually that basis. But whether you may send an unsolicited commercial email at all is governed separately, by each country's implementation of the ePrivacy Directive. That second layer is where the real variation lives, and it is national law, not EU-wide regulation.
The directive requires prior consent for unsolicited email to natural persons and leaves member states to decide about legal persons. Roughly half took the permissive route and left B2B email to companies on an opt-out footing — the UK, Ireland, France, the Netherlands, Belgium, Sweden, Finland. The rest extended opt-in to everyone. Germany is the strict end and the one that matters commercially, because German competitors bring UWG claims against each other and a cease-and-desist over cold email is a normal event there, not a theoretical risk.
Where legitimate interest actually holds
In an opt-out country, emailing a named person at a business about something connected to their job is a textbook legitimate interest. It holds only while the conditions do. Relevance is the load-bearing one: a message to a CFO about accounting software is defensible, the same list mailed about a fitness product is not, and the difference is not the data, it is whether the recipient would reasonably expect it. The other conditions are procedural — identify yourself, say where you got the address, give a working opt-out, honour it immediately — and they are the ones people skip.
The balancing test has to exist as a record. A legitimate interests assessment is four questions and half a page, and having written it before the campaign is most of what an authority wants to see when a complaint arrives. Writing it afterwards, in response to a complaint, is a different conversation.
Article 14, the clause nobody includes
When you collect someone's data from somewhere other than them — a website, LinkedIn, a directory, a data provider — article 14 says you must tell them, at the latest on first contact, that you hold it, what you are using it for, where you got it, and what rights they have. In practice this is one clause in the first email and a link in the footer: I found your details on your company website, plus a privacy notice link. It costs a line, it is the most commonly missing element in every cold email I audit, and it happens to make the message read as more honest, which is not a coincidence.
Sending from outside Europe
Being in the US, India or Bangladesh does not put you outside the rules. GDPR article 3(2) reaches anyone targeting people in the EU, and the UK GDPR does the same for the UK. Article 27 then requires most non-EU senders to appoint a representative inside the EU and name them where recipients can find them. The exemptions are narrow — occasional processing, low risk — and a systematic outbound campaign into Europe is not occasional by any reading. The practical options are appointing a representative service, or not targeting EU recipients from that entity.
Tracking pixels
An open-tracking pixel writes and reads information on the recipient's device, which several regulators treat as needing its own consent under the same ePrivacy rules that cover cookies. Nobody obtains that consent before a cold email, because obtaining it is impossible. The pragmatic answer for European campaigns is to turn open tracking off, which most experienced senders have done anyway for deliverability reasons — the pixel is a spam signal, and open rates have been unreliable since Apple Mail Privacy Protection started prefetching them.
What this tool is not
It is a structured checklist built from published regulator guidance and national statutes, and it will be out of date before the law is. It does not know your industry, your contract history with the recipient, or whether a national implementation changed last month. Treat a red verdict as a reason to stop and a green one as a reason to keep records, and ask a lawyer in the relevant country before running volume into a consent jurisdiction. For the US, Canadian and Australian side of the same message, the CAN-SPAM checker covers CAN-SPAM, CASL and the Spam Act.
Frequently asked questions
Is cold email legal under GDPR?
GDPR is not the part that decides. You need a lawful basis to process the address — legitimate interest usually works for B2B — and then your right to send the message at all is set by the recipient country's ePrivacy implementation, which varies from opt-out to strict opt-in.
Is info@company.com personal data?
Usually not, which is why generic role addresses fall outside the consent rule in several countries. If the address identifies a person — firstname@ — it is personal data regardless of who pays the bill.
Which European countries require consent even for B2B?
Germany, Austria, Italy, Spain, Denmark, Czechia and Switzerland are the clearest. Poland and Norway are restrictive in practice. Portugal splits by natural and legal person. Verify before a campaign — this is national law and it moves.
Do I need an article 27 representative?
If you are established outside the EU or UK and you systematically target people inside it, yes, and you have to name them where recipients can see. A regular outbound programme is not the occasional processing the exemption was written for.
Does a sole trader count as a business?
Not in most implementations. A sole trader or ordinary partnership is treated as an individual subscriber, so the consent rule applies even though the address looks like a business one.
Are open tracking pixels a GDPR problem?
They are an ePrivacy problem, in the same family as cookies, and consent cannot realistically be obtained before a cold email. Turn tracking off for European recipients.
Does an unsubscribe link make it compliant?
No. It is one of six or seven requirements, and it is the easy one. Identification, source disclosure, a privacy notice, the right to object and a lawful basis all have to be there too.
Last reviewed
What to run next
The checks that most often follow this one.
More in this category
Guides that go deeper
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace and Microsoft 365 inboxes
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.