Confusion about "opt-in vs opt-out" costs agencies money. Some countries allow cold email freely. Others require explicit consent first. Most fall somewhere in between.
This guide maps every European market and shows you how to operate legally in each.
The Three Models Explained
Model 1: Opt-Out (Most Permissive)
Definition: Send cold email freely. Recipients can unsubscribe.
How It Works:
- No consent required before sending
- You send email to business address
- Recipient can opt-out
- You honor opt-out within deadline
- Legal basis: Legitimate interest (GDPR Article 6(1)(f))
Best For: Maximum volume, fastest scaling
Countries: UK, Ireland, Sweden, Finland
Model 2: Single Opt-In (Permissive with Unsubscribe)
Definition: Send with clear unsubscribe option. Recipient opts out if not interested.
How It Works:
- No prior consent required
- Send email with unsubscribe visible
- Recipient can opt-out (30-day window typical)
- Treat as implied business interest
Best For: Good volume with slight compliance rigor
Countries: Luxembourg, Belgium. Earlier versions listed the Netherlands here; that was wrong, see our Netherlands laws guide
Model 3: Double Opt-In (Restrictive, with Exceptions)
Definition: Require explicit consent before sending. Exceptions for business relationships.
How It Works:
- Can't send without prior consent, UNLESS:
- Existing business relationship
- Prior correspondence
- Event registration
- Partner introduction
- Document consent if you have it
- Clear unsubscribe mandatory
Best For: Higher contract value, compliance-conscious markets
Countries: Germany, Austria, Switzerland
Country-by-Country Breakdown
TIER 1: OPT-OUT COUNTRIES
United Kingdom- Model: Opt-out (PECR)
- Can Send: B2B email to business addresses without consent
- Must Include: Clear unsubscribe, sender identification
- Opt-Out Window: 10 business days
- Risk: Low (clear regulation, PECR well-established)
- Fines: Up to £500,000
- Volume Potential: 5,000-30,000 emails/month
- Model: Opt-out (GDPR Article 6(1)(f))
- Can Send: B2B to business addresses without consent
- Must Include: Clear unsubscribe, sender ID, DKIM/SPF/DMARC
- Opt-Out Window: 10 days
- Risk: Low (same as UK, clear precedent)
- Fines: Up to €250,000 or 10% annual turnover
- Volume Potential: 5,000-20,000 emails/month
- Model: Opt-out (GDPR Article 6(1)(f))
- Can Send: B2B to business addresses without consent
- Must Include: Clear unsubscribe, sender identification
- Opt-Out Window: 10 days
- Risk: Low
- Fines: Up to €500,000
- Volume Potential: 3,000-10,000 emails/month (smaller market)
- Model: Opt-out (GDPR Article 6(1)(f))
- Can Send: B2B to business addresses without consent
- Must Include: Clear unsubscribe, sender identification
- Opt-Out Window: 10 days
- Risk: Low
- Fines: Up to €500,000
- Volume Potential: 2,000-8,000 emails/month (smaller market)
Opt-Out Tier Summary:
- Best for: Scaling rapidly, maximum volume
- Compliance: Simple (clear unsubscribe, sender ID)
- Risk: Low (well-established regulation)
- Market: 1,200+ SaaS companies across 4 countries
TIER 2: SINGLE OPT-IN COUNTRIES
Netherlands- Model: Opt-in. Telecommunicatiewet article 11.7 requires provable prior consent, with narrow exceptions
- Can Send: Only with provable consent, to addresses published for offers, or to existing customers
- Must Include: Clear sender ID, unsubscribe link, DKIM/SPF/DMARC
- Opt-Out Window: Not applicable, consent comes first. Honor opt-outs at once
- Risk: High without provable consent
- Fines: Up to €900,000 or 1 percent of turnover (ACM), doubled on repeat
- Volume Potential: 5,000-15,000 emails/month
- Special Notes: Dutch copy generates 2.4x higher response. Amsterdam SaaS hub.
- Model: Single opt-in (similar to Netherlands)
- Can Send: B2B to business addresses with unsubscribe
- Must Include: Clear sender ID, unsubscribe, DKIM/SPF/DMARC
- Opt-Out Window: 30 days
- Risk: Medium
- Fines: Up to €20 million
- Volume Potential: 2,000-5,000 emails/month
- Model: Single opt-in (GDPR Article 6(1)(f))
- Can Send: B2B without consent, must allow opt-out
- Must Include: Clear sender ID, unsubscribe, DKIM/SPF/DMARC
- Opt-Out Window: 30 days
- Risk: Medium
- Fines: Up to €20 million
- Volume Potential: 500-1,500 emails/month (very small market)
Single Opt-In Tier Summary:
- Best for: Balanced volume and compliance
- Compliance: Medium (unsubscribe visible, 30-day window)
- Risk: Medium (less legal precedent than opt-out)
- Market: 150+ SaaS companies, tight-knit ecosystem
TIER 3: DOUBLE OPT-IN COUNTRIES (WITH EXCEPTIONS)
Germany- Model: Double opt-in with exemptions (UWG Section 7)
- Can Send Without Consent IF:
- Existing business relationship
- Prior correspondence
- Event registration
- Partner introduction
- Cannot Send: Cold email to unknown contacts
- Must Include: Clear unsubscribe, sender ID, German language preferred
- Opt-Out Window: 10 days (strict)
- Risk: High (strict regulation, aggressive enforcement)
- Fines: Up to €300,000 (and competitor lawsuits)
- Volume Potential: 1,000-5,000 legal emails/month
- Note: Highest contract value per customer (larger companies)
- Model: Double opt-in with exemptions (similar to Germany)
- Can Send Without Consent IF: Same as Germany
- Cannot Send: Cold email to unknown contacts
- Must Include: Clear unsubscribe, sender ID, German language preferred
- Opt-Out Window: 10 days
- Risk: High
- Fines: Up to €300,000
- Volume Potential: 500-2,000 emails/month
- Model: Double opt-in (Swiss Privacy Law)
- Can Send Without Consent IF: Existing relationship, event registration
- Cannot Send: Cold email to unknown contacts
- Must Include: Clear unsubscribe, sender ID
- Opt-Out Window: Immediate
- Risk: Medium-High (strict but smaller enforcement)
- Fines: Up to 100,000 CHF (~€106,000)
- Volume Potential: 1,000-3,000 emails/month
Double Opt-In Tier Summary:
- Best for: High-value customers, long sales cycles
- Compliance: Complex (requires consent OR exemption pathway)
- Risk: High (strict enforcement, competitor lawsuits)
- Market: 700+ SaaS companies (Germany dominant), premium pricing
Quick Reference: Volume Potential by Country
| Country | Model | Monthly Volume | Best For |
|---|---|---|---|
| UK | Opt-out | 5,000-30,000 | Highest scale |
| Ireland | Opt-out | 5,000-20,000 | Scale + English |
| Sweden | Opt-out | 3,000-10,000 | Quality growth |
| Finland | Opt-out | 2,000-8,000 | Niche growth |
| Netherlands | Opt-in (art. 11.7) | Consent-based | SaaS-dense market |
| Belgium | Single opt-in | 2,000-5,000 | Secondary market |
| Germany | Double opt-in (exc.) | 1,000-5,000 | Premium pricing |
| Austria | Double opt-in (exc.) | 500-2,000 | Secondary market |
| Switzerland | Double opt-in (exc.) | 1,000-3,000 | Premium pricing |
More country guides
Every market we have researched from its primary statute, each with the regulator, the consent model and the penalties:
- Cold Calling Laws in the UK: CTPS, AI Voices and the New Fine Ceiling: UK B2B cold calling is legal after TPS and CTPS screening, but AI voice calls need prior consent per three ICO fines. Since Feb 2026 the ceiling is 17.5m or 4%.
- Is Cold Email Legal in Australia? Spam Act Rules (2026): Yes, with inferred consent for B2B. Australian Spam Act consent rules, ACMA enforcement, penalties up to $2.2M per day, and a compliant cold outreach checklist.
- Cold Email Laws in Austria: A Three-Email Sequence Has a Price: Austria is opt-in for every recipient, business or not. A court priced a three-step cold sequence at 600, 600 and 800 euro, and the ECG list is widely misread.
- Cold Email Laws in Belgium: The info@ Exception Has a Catch: Belgium exempts emails to impersonal company addresses, but named addresses need consent, the DPA rejected legitimate interest in 2025, and fines are now x10.
- Cold Email Laws in Brazil: The First LGPD Fine Was a List: Brazil has no anti-spam statute and the LGPD allows cold email under legitimate interest. But the first fine ANPD ever issued was over a contact list.
- Cold Email Laws in Canada: CASL Compliance Guide (2026): Complete CASL compliance guide for cold email in Canada. Learn implied consent for B2B, express consent requirements, CAD $10M penalties, and practical outreach
- Cold Email Laws in Denmark: Every Sending Domain Is a Separate Fine: Denmark's spam ban covers companies and consumers alike, treats named and generic addresses the same, and its fine tariff counts each sending domain separately.
- Is Cold Email Legal in France? CNIL + GDPR Rules (2026): Yes for B2B under legitimate interest. CNIL rules for cold email in France, the B2C consent mandate, penalties up to 4% of revenue, and a compliance checklist.
- Cold Email Laws in Germany: UWG & GDPR Guide (2026): Complete guide to German cold email laws, UWG requirements, GDPR compliance, and legal workarounds for B2B outreach in 2026.
- Cold Email Laws in Hong Kong: What the UEMO and PDPO Require: Hong Kong allows cold email without consent under the UEMO, but the PDPO criminalises using personal data to send it. The split, penalties and B2B carve-out.
- Cold Email Laws in India: IT Act & Email Regulations (2026): India cold email laws, IT Act Section 5, DND registry, IAMAI guidelines, and B2B outreach compliance for 2026.
- Cold Email Laws in Ireland: Per-Email Fines, But Warned First: Ireland allows 5,000 euro per email and 250,000 euro on indictment, yet the DPC's largest published penalty is 6,000 euro. The rules, the pattern, a checklist.
- Cold Email Laws in Italy: Article 130 and the Garante (2026): Cold email to Italy needs prior consent under Article 130 of the Privacy Code, and companies are covered too. Why the Garante lets you phone first, what the 2026 Lex Iuris decision actually fined, and what lawful outreach looks like.
- Cold Email Laws in Japan: Opt-In, With One B2B Exception That Still Works: Japan has been opt-in since 2008, but Article 3 keeps a carve-out for published business addresses. What that allows, what it does not, and the penalties.
- Cold Email Laws in Mexico: Your Email Has to Name the Regulator: Mexico's cold email rule is not in its privacy law. It is in the consumer law, and Article 17 says your ad must carry PROFECO's own contact details too.
- Cold Email Laws in the Netherlands: Article 11.7 and the GDPR (2026): Cold email to the Netherlands requires provable prior consent under Article 11.7 Telecommunicatiewet, for businesses too. The two narrow B2B exceptions, ACM fines up to 900,000 euros, the Companeo precedent, and what lawful Dutch outreach looks like.
- Cold Email Laws New Zealand: A .nz Address Is Enough: New Zealand's spam law tests the message, not the sender. Section 4(2)(f) says an address ending in .nz creates a New Zealand link, so a US sender is in scope.
- Cold Email Laws in the Philippines: No Spam Act, One Big Trap: The Philippines has no anti-spam law and its regulator has blessed cold email. But education counts as sensitive data there, and that breaks your basis.
- Cold Email Laws in Qatar: Two Regimes, Opposite Defaults: Qatar's mainland law demands prior consent before any marketing email, but firms inside the QFC follow an opt-out rule instead. Here is the full split.
- Cold Email Laws Saudi Arabia: Everyone Cites the Wrong Law: Saudi cold outreach is governed by a CST telecom regulation, not only the PDPL. Promotional messages are blocked by default, and consent inside a privacy policy does not count.
- Cold Email Laws in Singapore: PDPA Guide (2026): Singapore cold email laws for 2026: PDPA consent and opt-out rules, the DNC registry, penalties, and a compliant B2B outreach strategy that lands.
- Cold Email Laws in South Africa: Opt-In Only, One Ask Allowed: POPIA repealed South Africa's opt-out spam rule in 2021. Now it is one consent request, marketing only to a yes, and guessed email addresses count as evidence.
- Cold Email Laws in South Korea: Two Exceptions, and Neither Is B2B: Korea's Network Act Article 50 allows just two exceptions to prior consent, and a published business address is not one. Fines, labels and the two year clock.
- Cold Email Laws in Spain: LSSI Article 21 and the GDPR (2026): Cold email to Spain needs prior express consent under LSSI Article 21, with no B2B exemption and no legitimate interest route. Fines, the customer exception, the dead three emails rule, and what lawful Spanish outreach looks like in 2026.
- Is Cold Email Legal in Sweden? GDPR + EKMR Rules (2026): Yes, B2B cold email is legal in Sweden under GDPR legitimate interest. EKMR sender rules, the 48-hour unsubscribe rule, GDPR fines up to 4% of revenue, and an 8% reply-rate playbook.
- Cold Email Laws in Switzerland: The Penalty Is Criminal: Switzerland files cold email under competition law, not privacy law. Article 3(1)(o) UCA sets three duties and Article 23 makes a wilful breach criminal.
- Cold Email Laws in the UAE: TDRA Rules & B2B Guide (2026): Cold email laws in the UAE for 2026: TDRA rules, DPA compliance, consent, penalties, and safe B2B outreach for Dubai and Abu Dhabi senders.
- Cold Email Laws in the UK: PECR Guide (2026): Complete PECR and GDPR compliance guide for cold email in the UK. Learn B2B soft opt-in, corporate subscriber exceptions, ICO enforcement, penalties. 2026 legal
- Cold Email Laws in the United States: CAN-SPAM Guide (2026): Complete CAN-SPAM compliance guide for cold email in the US. Learn requirements, penalties up to $51,744/email, and state-level laws. 2026 legal framework.
Strategy by Market Type
For Opt-Out Countries (UK, Ireland, Sweden, Finland)
- Build large lists (5,000-10,000 per country)
- Use legitimate interest as legal basis
- Clear unsubscribe mechanism
- Fast domain warmup (2-3 weeks)
- High volume capacity = maximize reach
For Single Opt-In Countries (Netherlands, Belgium)
- Build lists (5,000-8,000 per country)
- Netherlands: provable opt-in consent (article 11.7)
- Honor opt-outs immediately
- Use local language (Dutch = 2.4x response)
- Medium-high volume with cultural customization
For Double Opt-In Countries (Germany, Austria, Switzerland)
- Use exemptions (existing relationships, event registration)
- OR collect explicit consent via landing page
- Focus on quality over quantity
- Premium pricing (higher contract value)
- Longer sales cycles but higher win rates
- Language matters (German preferred)
Common Mistakes
- Treating all of Europe the same
- Different countries = different rules. Know your market.
- Confusing PECR (UK) with full GDPR opt-in
- UK is opt-out. Germany is double opt-in. Not the same.
- Ignoring single opt-in as "middle ground"
- The Netherlands requires provable consent (article 11.7). Belgium has its own opt-in regime.
- Assuming "legitimate interest" works everywhere
- Germany requires exemptions or consent. Legitimate interest alone insufficient.
- No unsubscribe testing
- Test your unsubscribe flow before campaign launch. In every market.
Your Market Selection Strategy
If You Want Maximum Volume:
- Focus on UK (5,000-30,000/month)
- Add Ireland (5,000-20,000/month)
- Then Sweden/Finland (small but easy)
If You Want Premium Pricing:
- Focus on Germany (higher CAC, higher deal value)
- Add Austria as secondary
- Solve compliance = defensible moat
If You Want Balanced Approach:
- UK as primary (volume)
- Netherlands secondary (SaaS-dense, consent-based)
- Germany tertiary (premium pricing, quality)
Next Steps
- Identify your target market(s)
- Read the specific country guide(s)
- Understand opt-in/opt-out model for your market
- Build list accordingly
- Implement compliance controls
- Start small (500 emails), test deliverability
- Scale based on response data
Europe isn't one market. It's 9+ distinct markets with different rules. Master one. Own it. Then expand.
---