Cold Outreach in Germany — Presumed Consent Is a Test, Not a Loophole
ComplianceCold OutreachGDPRUWGOutbound

Cold Outreach in Germany — Presumed Consent Is a Test, Not a Loophole

T. Krause

German B2B outbound is legal, which is why so many teams get it wrong. The rules turn on whether the specific business you called has a plausible objective interest in the specific thing you sell — a test applied per call, not per campaign. Here is what that means for your list, your scripts and your suppression obligations.

Two sales teams work the same German market with the same product. One believes cold calling businesses is illegal and has quietly stopped, losing a channel that works. The other believes B2B means the rules do not apply and is calling anyone with a phone number. Both are wrong in ways that cost them, and the second one is accruing a liability that will not surface until someone complains.

German outbound sits in a narrow, genuinely workable band. Cold calling a business is conditionally legal. Cold emailing a business is conditionally legal. The condition in both cases is not a checkbox you tick — it is a judgement about whether this business plausibly wants to hear about this offer, and it is applied one prospect at a time.

That structure is unusual, and it has a consequence most compliance guides skip: the legality of your campaign is not a property of the campaign. It is a property of your targeting.

Three Rulebooks, Stacked

German outbound is governed by layers that interact, and teams routinely satisfy one while breaching another.

The UWG is what actually stops the call. The Gesetz gegen den unlauteren Wettbewerb — the Act Against Unfair Competition — governs unsolicited advertising through §7, framed as "unzumutbare Belästigung", unreasonable nuisance. This is the rulebook with the immediate consequences, and it is enforced substantially through competitor warnings rather than only by regulators. Your competitors can and do act on it.

GDPR governs the data behind the call. Article 6(1)(f) provides legitimate interest as a lawful basis for processing prospect data without consent, provided your interest does not override the individual's rights. This lets you hold and process the list. It does not authorise the contact itself.

ePrivacy decides which one wins. Under GDPR Article 95 and Recital 173, where the two overlap, ePrivacy takes precedence — and it lets member states impose stricter national rules on electronic communication. Germany has. This is why a legitimate-interest assessment that satisfies your reading of GDPR does not settle whether the call is lawful under the UWG.

The practical upshot: satisfying GDPR is necessary and not sufficient. Teams that stop at the LIA have done the paperwork for the wrong exam.

What Presumed Consent Actually Requires

For B2B telephone contact, the UWG standard is mutmaßliche Einwilligung — presumed consent. Consumers get a far stricter rule: calling a private individual without prior express consent is effectively banned. Businesses get this narrower opening, and it is narrower than the phrase suggests.

It requires concrete indications, not a plausible story. The test is whether there are specific grounds to believe this business has an objective interest in this particular offer. Not whether businesses in general might benefit. Not whether you could construct an argument. Specific grounds, tied to this prospect.

The standard example is worth memorising. A joinery that installs roof windows may plausibly call a roofing wholesaler — the connection to the recipient's actual trade is direct and obvious. The same joinery may not call a tax firm to sell office chairs. Every business needs chairs; that is exactly why "they might need it" fails the test. Universal applicability is evidence against a specific interest, not for it.

It is assessed per prospect, which makes it a targeting rule. This is the part with real operational consequences. If your list is "every business in Bonn with a website," presumed consent cannot hold for it, because no single justification covers a dental practice, a roofer and an accountant. A tightly segmented list is not merely more effective — it is the mechanism by which the calls become lawful.

Automation removes the concession entirely. Advertising via an automated calling machine is always an unreasonable nuisance without prior express consent, with no B2B relief whatsoever. As AI-driven dialling spreads, this is the distinction that quietly moves a compliant operation into a non-compliant one — the targeting did not change, the dialling method did.

The exposure is real: calling without a valid basis can draw fines up to €300,000, and failing to document consent properly can draw a separate penalty of up to €50,000. Note that those are two distinct failures. You can have a defensible basis and still be penalised for being unable to show it.

Email, and Why Germany Is the Hard Case

Germany is the strictest market in Europe for cold email, and the gap between it and, say, the Netherlands is wide enough that a single European sequence is usually non-compliant somewhere.

The baseline leans toward prior consent. §7 UWG treats unsolicited commercial email as a nuisance by default. There is a narrow B2B path under legitimate interest, but it is materially tighter than the telephone route and considerably tighter than most sequencing tools assume.

Enforcement is not theoretical. B2B cold email penalties across the EU have ranged from around €500 for small operators to more than €900,000 — the SOLOCAL decision by France's CNIL in 2025 sitting at the upper end. The mid-range outcomes are the common ones, and they land on companies that believed B2B meant exempt.

Documentation is a five-year obligation. Your legitimate-interest assessment must be retained for at least five years. One assessment can cover multiple campaigns aimed at a similar audience, which makes segmentation do double duty: it is what makes the outreach defensible and what keeps the paperwork finite.

A per-country policy is not optional at scale. Once you are working more than one European market, the honest architecture is a rule per country deciding which channels are permitted for cold contact, applied before a message is queued. Teams discover this after their first complaint, and rebuild the sequencing layer to accommodate it.

Building It So Compliance Is Structural

Compliance that lives in a policy document is compliance that depends on whoever is working the list today. The version that survives an audit is enforced by the system.

Record the justification with the segment, not in someone's head. When you build a list, write the sentence: why does this group plausibly want this offer? If it cannot be written in one specific sentence, the segment is too broad, and you have learned that before dialling rather than after a complaint. Store it with the segment so it is still there in eighteen months.

Make the suppression list attach to the person and survive re-import. A do-not-contact obligation follows the individual, not the campaign. The failure mode is mundane: someone opts out in March, a fresh scrape in September reintroduces them under a slightly different company name, and they get called again. The second call is far worse than the first, because it demonstrates that your opt-out does not function. Suppression must be checked at import and at send, and match on phone and domain rather than on name.

Log every contact attempt with its channel and timestamp. The €50,000 documentation penalty is for being unable to demonstrate a basis you may well have had. Contemporaneous logs are the difference between a defensible position and a plausible-sounding recollection. This is also, not coincidentally, the data you need to know which sequences work.

Gate automated dialling behind an explicit decision. Given that automation voids the B2B concession entirely, any dialling automation needs a deliberate authorisation step rather than a settings toggle someone flips to raise throughput.

Write the LIA before the first send, and keep it boring. A page: what you collect, why, why it does not override the recipient's rights, how they object. Written in advance it is a defence. Written after a complaint it reads exactly like what it is.

What the Distinction Buys You

The teams that treat German compliance as a constraint end up either paralysed or exposed, and often both — over-cautious on email, careless on the phone, with no documentation for either.

The teams that treat it as a targeting discipline discover something faintly annoying: the compliant list is the better list. A segment tight enough that you can write one sentence explaining why these businesses want this offer is a segment with a materially higher connect rate. The legal test and the sales test are asking nearly the same question, and the law is simply less forgiving of a vague answer.

Presumed consent is not a loophole to be argued into. It is a test of whether you know who you are calling and why. Teams that can answer that pass both examinations at once; teams that cannot were going to have a bad quarter regardless of what the regulator did.

Cookie settings

We use strictly necessary cookies to keep this site working. Optional analytics cookies help us improve it — they only load if you accept.

Read the cookie notice