share this with your network
Every few weeks someone on a sales team tells me, with total confidence: "we can't cold email/cold call/do LinkedIn outbound in Europe because of GDPR." Shortly after someone on LinkedIn writes: "GDPR doesn't apply to B2B." Both are wrong, and both are right, depending on which of the 27 EU countries they're actually thinking of.
That's a problem. GDPR itself is one regulation, applied pretty much the same way everywhere. However, GDPR is not what decides whether you can pick up the phone, send an email, or slide into someone's LinkedIn DMs without asking first. That's decided by the ePrivacy Directive and other legislation. Every member state converted it into national law slightly differently. Add 27 sets of national marketing and competition laws on top, and you get a genuinely messy picture that most sales teams are navigating - basically based on gut feeling.
Earlier last week we built the matrix we wished existed in response to some content on LinkedIn, specifically: B2B cold outreach to a named business contact, without prior opt-in, channel by channel, country by country.
The Outreach Matrix
Debatable / conditional - verify locally
Prior opt-in consent required
| Country | Phone | SMS | English (EF EPI) | |||
|---|---|---|---|---|---|---|
| Austria | Consent needed | Double opt-in | Untested | Opt-in | Opt-in | 616 · Very High |
| Belgium | Opt-out (DNCM) | Opt-in | Untested | Opt-in | Opt-in | 608 · Very High |
| Bulgaria | Consent for named individuals; opt-out for legal-entity lines | Opt-in | Untested | Opt-in | Opt-in | 594 · High |
| Croatia | Opt-out | Opt-out | Legit. interest | Narrower rules | Narrower rules | 617 · Very High |
| Cyprus | No clear data — falls to GDPR baseline | Opt-in | Untested | Opt-in | Opt-in | 537 · Moderate |
| Czech Republic | Opt-in (since 2022) | Opt-in | Untested | Opt-in | Opt-in | 582 · High |
| Denmark | Opt-out (no consumer register applies to companies) | Opt-in | = email (FO ruling) | Opt-in | Opt-in | 611 · Very High |
| Estonia | Opt-out | Opt-out | Legit. interest | Less clear | Less clear | 561 · High |
| Finland | If role-relevant | Role-based test | Untested | Role-based test | Role-based test | 603 · Very High |
| France | Opt-out (business #) | Opt-out (3 conditions) | Tolerated | Less clear | Less clear | 539 · Moderate |
| Germany | Presumed consent | Double opt-in | UWG case law | Opt-in | Opt-in | 615 · Very High |
| Greece | Opt-out | Opt-in | Untested | Opt-in | Opt-in | 592 · High |
| Hungary | Opt-out | Opt-out | Legit. interest | Less clear | Less clear | 590 · High |
| Ireland | Opt-out | Role-relevant | Legit. interest | Stricter than email | Stricter than email | Native (official language) |
| Italy | Opt-out (check RPO) | Opt-in | Untested | Opt-in, no soft opt-in | Opt-in | 513 · Moderate |
| Latvia | Opt-out | Opt-out | Legit. interest | Less clear | Less clear | 598 · High |
| Lithuania | Opt-out | Opt-in | Untested | Opt-in, no soft opt-in | Opt-in | 543 · Moderate |
| Luxembourg | No clear data | Opt-out | Legit. interest | Less clear | Less clear | 576 · High |
| Malta | Opt-out | Opt-in | Untested | Opt-in | Opt-in | Official language (bilingual) |
| Netherlands | Not on DNC scope | Opt-in (incl. legal persons) | Legit. interest | Opt-in | Opt-in | 624 · Very High |
| Poland | Opt-in (new ECL, Nov 2024) | Opt-in, no soft opt-in | Untested | Opt-in | Opt-in | 600 · Very High |
| Portugal | Opt-out (Robinson list, natural persons) | Depends on address type | Untested | Same test as email | Same test as email | 612 · Very High |
| Romania | Opt-in (statutory interpretation) | Opt-in | Untested | Opt-in | Opt-in | 605 · Very High |
| Slovakia | Opt-out (Robinson-type list) | If publicly available | Legit. interest | Less clear | Less clear | 606 · Very High |
| Slovenia | No clear data | Opt-out | Legit. interest | Less clear | Less clear | Not separately EF-ranked |
| Spain | If role-relevant | Opt-in | Untested (AEPD active) | Opt-in | Opt-in | 540 · Moderate |
| Sweden | Subject to objection | Role-relevant | Legit. interest | Less clear | Less clear | 609 · Very High |
Click a country name to jump to its chapter below. English column: EF English Proficiency Index 2025 score and proficiency band, or native/official-language status where the EF EPI doesn't score the country.
The AI Act layer: what changes if your outbound uses AI
If any part of your outbound stack uses AI - an AI voice agent making the actual call, an AI SDR sending personalised LinkedIn messages, an AI-generated voice note, or a chatbot qualifying replies - the EU AI Act (Regulation (EU) 2024/1689) adds a transparency layer on top of everything else in this matrix, and it is already in force.
- Since 2nd of February 2025: a short list of prohibited AI practices (Art. 5) has applied EU-wide, including AI systems that exploit a person's vulnerabilities or use subliminal/manipulative techniques to materially distort behaviour - relevant if an AI outbound tool is tuned for persuasion tactics that cross that line.
- Since 2nd of August 2026 (current as of this writing): Article 50 transparency duties are enforceable. Anyone deploying a chatbot, voice assistant, or other AI system that interacts directly with people must disclose - clearly, at first contact - that the person is talking to AI, unless it's already obvious from context. Penalties run up to €15 million or 3% of global turnover - whichever is higher.
- The deployer, not just the provider, carries this duty. Using a third party's AI SDR or chatbot tool doesn't shift the disclosure obligation onto the vendor - if you deploy it, you're on the hook for making sure it happens.
- The distinction that actually matters for outbound: drafting vs. live interaction. An AI that drafts a cold email or LinkedIn message which a human then reviews and sends is, on the current reading, probably outside Art. 50(1) altogether - the provision targets AI systems "intended to interact directly with natural persons" and a one-way, human-approved message isn't a live interaction; the human is doing the interacting. At the precise moment an AI SDR tool starts handling the back-and-forth after that first message - replying to the prospect's responses on its own - that's squarely "an AI system interacting directly with a natural person" and no amount of careful human review of the opening message exempts the autonomous conversation that follows.
- Deferred to 2 December 2027: the heavier "high-risk" obligations (Annex III - risk management, technical documentation, human oversight, etc.) were pushed back from their original August 2026 date by the June 2026 Digital Omnibus package. This deferral does not cover Article 50 or the Art. 5 prohibitions, which stayed on schedule - a common point of confusion.
- Practical read: Germany's UWG already requires callers to identify themselves and not suppress caller ID; the AI Act adds a parallel, EU-wide "and say you're an AI" duty for any AI-mediated live interaction. The two obligations stack rather than substitute for each other.
Sources
EU-wide: GDPR Art. 6(1)(f) & 21 (EUR-Lex); ePrivacy Directive 2002/58/EC Art. 13 (EUR-Lex); AI Act Art. 50 full text, incl. the Art. 50(4) human-review/editorial-control exemption (artificialintelligenceact.eu) and its August 2026 / December 2027 phase-in (Digital Applied).
Email/SMS, all 27 states: statute names and B2B position per country from Fieldfisher's Jan 2024 survey - fieldfisher.com.
Phone: Germany/Austria/Netherlands/France/Nordics/Baltics - Ripe Leads survey; Belgium/Bulgaria/Croatia/Cyprus/Czechia/Greece/Hungary - XpandFlow guide; Italy RPO register - Garante Privacy; Spain Art. 66.1(b) LGT - BOE/AEPD circular; remaining ten states - primary-source verification pass citing each national statute directly.
LinkedIn: Germany - OLG Hamm 3 May 2023 (18 U 154/22); Denmark - Forbrugerombudsmanden case rulings (InMails, connection requests).
Denmark phone/Robinson list correction: Forbrugerombudsmanden's own overview of the telephone-sales rules (official guidance), confirming the Robinson list is a Consumer Contracts Act (forbrugeraftaleloven) register that does not cover companies, only natural persons including sole proprietors on personal lines.
English proficiency: EF English Proficiency Index 2025, the primary published ranking (ef.edu/epi; full report PDF via the same page), based on 2.2 million EF SET test-takers in 2024. Country job-function breakdowns (e.g. the IT/Legal/Strategy figures cited for France) are drawn from each country's individual EF EPI profile page.
Country notes
A short chapter per country with the specific statute, the reasoning behind the verdict, and anything English-language-specific worth knowing.
Austria
- Legal basis: Telecommunications Act (TKG) §174 governs calls; email/SMS also fall under TKG opt-in rules with double opt-in advised. Applies to B2B as well as B2C - Austria is the German-speaking market that does not soften for business subscribers.
- Phone: an unsolicited B2B call sits on genuinely weak legal ground here without consent, an existing relationship, or a documented inbound enquiry - treat Austria as an earn-the-call market, not a cold-call one.
- English: Very High proficiency (EF EPI 616, rank #3 in the World) - English-language outreach is not a barrier for the professional audience you'd be targeting.
Belgium
- Legal basis: Article XII.13 of the Code of Economic Law + Royal Decree of 4 April 2003 for email; phone screens against the Do-Not-Call-Me list (DNCM, dncm.be) rather than requiring consent.
- Phone: check dncm.be before dialling, then proceed - no consent needed for a business number that isn't registered or hasn't personally objected.
- English: Very High (EF EPI 608) - safe to run outreach in English, though Belgium's French/Dutch split means matching the region's language often still lands better.
Bulgaria
- Legal basis: Electronic Communications Act, Art. 261 (email/SMS/phone). A 2021 amendment narrowed the definition of protected "subscriber" to consumers/natural persons only.
- Phone, the nuance: calling a legal-entity subscriber line is opt-out. Calling a named individual's direct or mobile line is the consent-required scenario - the same distinction that matters across most of Central/Eastern Europe. Bulgaria also runs a legal-entity opt-out register under the E-Commerce Act, checked by the Commission for Consumer Protection.
- English: High proficiency (EF EPI 594) - workable for outreach to management-level contacts, less safe to assume for generalist roles.
Croatia
- Legal basis: Electronic Communications Act (Official Gazette No. 76/2022) sets a B2B opt-out position across the main channels.
- One of the more genuinely permissive markets in the matrix for a first cold touch on any channel, provided the pitch is role-relevant and an opt-out is offered.
- English: Very High (EF EPI 617, #2 globally) - among the strongest English-speaking populations in the EU, a real point in Croatia's favour for English-only outreach.
Cyprus
- Legal basis: Regulation of Electronic Communications and Postal Services Law 112(I)/2004, s.106 (automated calls/fax/email to natural persons); Decree on Legal Persons No. 34/2005 extends some protection to companies.
- Live human voice calls are not squarely addressed by s.106, so they default to plain GDPR analysis (legitimate interest + right to object) rather than a clear statutory opt-out - treat as conditional, not confirmed green.
- English: Moderate (EF EPI 537) - still workable given Cyprus's British-administrative history and widespread English use in business, but don't assume universal fluency outside larger firms.
Czech Republic
- Legal basis: Act No. 127/2005 Coll. on Electronic Communications, §96. A carve-out for public-directory numbers was abolished from 1 July 2022, moving telemarketing to a full opt-in regime for natural and legal persons alike.
- This is now one of the strictest markets in the matrix across every channel - plan on consent-based outreach here, not cold contact.
- English: High (EF EPI 582) -
- no language barrier for the outreach itself, the constraint is purely legal.
Denmark
- Legal basis: Markedsføringsloven (Marketing Practices Act) no. 866 of 15 June 2022, §10 for email/SMS/LinkedIn; Forbrugeraftaleloven (Consumer Contracts Act) §4 for phone.
- The Robinson list: is a consumer opt-out register under the Consumer Contracts Act - it protects private individuals, not companies, and does not apply to a call to a registered business (A/S, ApS) as such. Calling a Danish company's main line is legal without consent by default. The Robinson list becomes relevant in one specific B2B scenario: calling a sole proprietor (enkeltmandsvirksomhed) on a personal/mobile number where the line is treated as belonging to a natural person - that call is illegal if the person is Robinson-listed or has personally objected, even though the recipient is technically "in business." Worth checking before dialling personal mobiles.
- Email and LinkedIn are the genuinely locked channels here: the Forbrugerombudsmanden has ruled directly and repeatedly that InMails and even plain connection-request pitches count as "elektronisk post" under §10 - same opt-in rule as email, fines starting around DKK 10,000 / €1350 per case.
- English: Very High (EF EPI 611, #7 Globally) - no language constraint at all for Danish B2B audiences.
Estonia
- Legal basis: Electronic Communications Act, read alongside GDPR. Follows the standard Baltic pattern - opt-out for B2B email and for live calls to business numbers.
- One of the cleaner Baltic markets to open cold across every non-SMS channel.
- English: High (EF EPI 561) - solid for professional outreach, particularly among the tech and startup sector Estonia is known for.
Finland
- Legal basis: Information Society Code (917/2014), Chapter 24, §§200 & 202. The recurring test across every channel is the same: is the message individually addressed and relevant to the recipient's professional role, or generic/role-based.
- A relevance-anchored pitch to a named decision-maker clears the bar on most channels; a generic blast to a personal address does not.
- English: Very High (EF EPI 603) - no barrier to English-only outreach.
France
- Legal basis: Article L34-5, Code des postes et des communications électroniques (email); CNIL's own published doctrine on the B2B exception. Phone: business lines fall outside the consumer-protection regime (Bloctel, calling-hour limits) entirely.
- The French B2B email exception, precisely: unsolicited email to a named professional is fine without prior consent only when all three hold - (1) the address is their professional one, (2) the pitch is relevant to their role, (3) they're informed at first contact with a working one-click opt-out in every message. The CNIL has fined Orange, Cdiscount, Free and Brico Privé for getting the mechanics wrong, not for using the exception.
- A grey zone worth flagging: dialling a manager's personal mobile sourced from a social profile looks much more like calling an individual than calling the business, and French policy is trending toward tighter consumer telephone rules through 2026 - err toward published business lines.
- English: Moderate (EF EPI 539) - this is where the job-function data matters: France's national average masks a big split - IT scores 593, Strategy & Project Management 625, Legal 546, versus a 539 national average. Your actual buyer personas (IT, legal, ops leadership) test meaningfully higher than the general population.
Germany
- Legal basis: Gesetz gegen den unlauteren Wettbewerb (UWG) §7 governs every channel here - not GDPR. This is unfair-competition law, not data-protection law, which is exactly the kind of "it's not all GDPR" case worth flagging: Germany's restrictions on cold outreach exist to protect businesses from commercial nuisance, independent of whether personal data is involved at all.
- Phone: §7(2) requires express consent for consumers and at least presumed consent for B2B - a real, narrowly-read test requiring concrete circumstances suggesting the specific company has an actual interest in that specific offer. German courts do not accept "any manufacturer might want this."
- LinkedIn: §7 explicitly extends to "elektronische Post" delivered via social platforms. OLG Hamm (3 May 2023, 18 U 154/22) confirmed social-media messages count; AG Düsseldorf (20 Nov 2025, 23 C 120/25) confirmed a LinkedIn connection does not imply consent to follow-up email marketing. Cease-and-desist letters from competitors are, in practice, a bigger day-to-day risk here than regulatory fines.
- English: Very High (EF EPI 615, #4 in the World, one of the largest year-on-year gains) - no language barrier.
Greece
- Legal basis: Law 3471/2006, Art. 11 (paras. 1, 3 and 7) for email/SMS; live phone calls are opt-out, screened against the operator-level do-not-call registration.
- Phone is your cleanest opt-in-free channel here; email needs consent regardless of soft-opt-in exceptions for existing customers.
- English: High (EF EPI 592) - workable for professional outreach.
Hungary
- Legal basis: a stack of GDPR + Act V of 2013 (Civil Code) + the Advertising Act (Act XLVIII of 2008) + the E-commerce Act (Act CVIII of 2001) + the Electronic Communications Act (Act C of 2003) - Hungary's B2B opt-out position for direct marketing is explicitly a general-law construction rather than a single ePrivacy carve-out.
- One of the more open markets in the matrix across phone, email, and LinkedIn.
- English: High (EF EPI 590) - solid for professional-level outreach.
Ireland
- Legal basis: European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011. B2B email is opt-out where the pitch relates to the recipient's professional role; otherwise opt-in.
- Consistently one of the greenest markets across channels - a genuinely comfortable market to open cold in, provided the message is role-relevant.
- English: native/official language - no proficiency question at all, though Ireland is not separately scored by the EF EPI for this reason.
Italy
- Legal basis: Italian Personal Data Protection Code (Legislative Decree No. 196/2003, amended by Decree No. 101/2018), Art. 130, for email/SMS; the Garante's own Registro Pubblico delle Opposizioni (RPO) page confirms live calls with a human operator are opt-out for numbers not on the register.
- The register point matters: legal entities can register on the RPO too, not just consumers - so screening against it before a calling campaign is a real, checkable step, not a formality.
- English: Moderate (EF EPI 513) - the widest professional/general gap in the matrix tends to show up here too; verify English comfort with named contacts (job title, LinkedIn profile language, prior English-language content) before assuming it, especially outside Milan/the north.
Latvia
- Legal basis: Law on Information Society Services (4 November 2004). Follows the standard Baltic opt-out-for-business pattern across phone and email.
- A clean market to open cold across most channels.
- English: High (EF EPI 598) - comfortably workable.
Lithuania
- Legal basis: Law on Legal Protection of Personal Data (1996) + Law of Electronic Communications (2004) + Law on Advertising (2000). Live calls to business numbers are opt-out; email is opt-in with a soft-opt-in carve-out that explicitly does not extend to SMS.
- Phone-first is the practical read here - the specialist B2B-calling agencies serving the Baltics are disproportionately based out of Vilnius for a reason.
- English: Moderate (EF EPI 543) - generally fine for business audiences in Vilnius/Kaunas, worth a sense-check for smaller regional firms.
Luxembourg
- Legal basis: Loi modifiée du 30 mai 2005 (privacy in electronic communications), Art. 11. Notably, Art. 11(5) limits the live-call consent requirement in Art. 11(3) to natural-person subscribers - a call to a legal-person subscriber line falls outside the statutory opt-in rule and defaults to GDPR (legitimate interest + right to object). A call to a named individual's personal line is the stricter, opt-in scenario.
- Email is opt-out for B2B under the same general pattern as Belgium and the Netherlands' near neighbours.
- English: High (EF EPI 576) - plus Luxembourg's genuinely trilingual (French/German/Luxembourgish) international workforce and heavy EU-institution presence mean day-to-day business English is more common in practice than the score alone suggests.
Malta
- Legal basis: Processing of Personal Data (Electronic Communications Sector) Regulations, S.L. 586.01, reg. 9. Reg. 9(1) requires prior written consent only for automated calls, fax and email; reg. 9(3) makes live human voice calls opt-out - enforceable fines run up to roughly €23,300 per violation, escalating daily.
- Phone is the clean channel; email needs consent regardless of channel softness elsewhere.
- English: co-official language alongside Maltese - no proficiency barrier, and not separately EF-scored for that reason.
Netherlands
- Legal basis: Telecommunicatiewet (Telecommunications Act), last amended 1 June 2023. This is the correction worth repeating from earlier in this build: the Dutch opt-in requirement for electronic mail explicitly extends to legal persons, not just consumers - contrary to what a lot of marketing blogs claim about the Netherlands being a soft-touch B2B email market. It genuinely isn't.
- Phone stays open: the 2021 consumer telemarketing tightening (consent-or-existing-relationship, retiring the old consumer do-not-call register) left business subscribers on the opt-out side.
- English: Very High - the Netherlands is the #1-ranked country in the entire EF EPI (score 624), true across virtually every professional context.
Poland
- Legal basis: the new Electronic Communications Law (Prawo komunikacji elektronicznej, PKE), in force 10 November 2024, Art. 398 - replaced the old Telecommunications Law Art. 172. This confirmed and hardened Poland's position: prior consent is required for telemarketing, whether directed at consumers or businesses.
- One Warsaw court ruling has carved a narrow space for a genuinely consent-free "may we send you information?" opening question, provided it stays free of any marketing content itself - a thin exception, not a workaround.
- English: Very High (EF EPI 600) - no language constraint, this is purely a legal-basis problem.
Portugal
- Legal basis: Lei n.º 41/2004 (as amended by Lei 46/2012 and Lei 16/2022), Arts. 13.º-A and 13.º-B, for email; Lei n.º 6/99 for phone. Portugal runs the same legal-person carve-out logic as several neighbours: Art. 13.º-A(2) says the consent requirement does not apply to legal persons - unsolicited marketing to a company is fine until it registers on the DGC's national opt-out list for legal entities.
- Individualised email to a named person needs opt-in; a role-based or generic address is opt-out unless the recipient is on the national list.
- English: Very High (EF EPI 612, #6 in the World) - a genuinely strong English-speaking market, ahead of several countries with a reputation for it.
Romania
- Legal basis: Law No. 506/2004, Art. 12. The provision is drafted more broadly than the ePrivacy Directive's minimum - it covers automated systems, fax, email "or other means using publicly available electronic communications services," which the prevailing legal reading extends to live voice-to-voice marketing, with no opt-out mechanism provided. A minority legitimate-interest argument exists but carries real enforcement risk; treat Romania as opt-in across the board.
- Applies to legal entities as well as individuals per practitioner commentary - one of the strictest, broadest markets in the matrix.
- English: Very High (EF EPI 605) - no language barrier, purely a legal-basis constraint.
Slovakia
- Legal basis: Act No. 452/2021 Coll. on Electronic Communications, §116. A November 2025 amendment (driven mainly by the EU Gigabit Infrastructure Act) explicitly reconfirmed that live telemarketing stays opt-out - screened only against the Office for Electronic Communications' do-not-call list - while automated calls/fax/email/SMS stay opt-in.
- Email B2B works on an opt-out basis specifically where the contact's business details are already publicly available.
- English: Very High (EF EPI 606, #10 worldwide - one of the strongest Central European results) - no language barrier.
Slovenia
- Legal basis: Electronic Communications Act (ZEKom-2), Art. 226, in force since 10 November 2022. Live-call marketing to individual (natural-person) subscribers needs consent; the statute does not extend that requirement to legal-person subscriber lines, which fall back to a GDPR opt-out analysis. No national do-not-call register exists to check against either way.
- Email is opt-out for B2B.
- English: Slovenia isn't included in the EF EPI's ranked list (below the minimum sample threshold), so there's no direct proficiency score to cite - treat as an open question to verify per contact rather than assuming either way.
Spain
- Legal basis: Law 34/2002 (LSSI) for email; Law 11/2022 General de Telecomunicaciones, Art. 66.1(b), for phone, with a binding AEPD interpretive circular (2023). This is a genuine correction from an earlier pass: Spain's telecoms law does not require consent as the only basis for commercial calls - Art. 66.1(b) explicitly allows legitimate interest under GDPR Art. 6(1) as an alternative, and Art. 19 LOPDGDD separately presumes lawfulness for calls to a company contact about something relevant to their professional role.
- Email stays the strict channel (LSSI opt-in, soft opt-in applied narrowly in practice); the AEPD is an active enforcer generally, so document the legal basis either way.
- English: Moderate (EF EPI 540) - again worth checking the job-function skew rather than the national average alone. Spain's professional/managerial English levels sometimes run meaningfully above the general population.
Sweden
- Legal basis: Marketing Practices Act (Marknadsföringslag 2008:486, amended 1 September 2022) + Electronic Communications Act (Lag 2022:482). B2B email is opt-out where relevant to the recipient's role; live calls to business numbers are opt-out subject to objection, distinct from the NIX consumer register.
- One of the more open Nordic markets across phone, email, and LinkedIn alike.
- English: Very High (EF EPI 609) - no language barrier.
Research aid, not legal advice - take legal counsel and treat the yellow cells especially as "check with local legal counsel before you scale," not "safe."
Why the same message is fine in one country and a fine in the next
Once you see the pattern, it stops feeling random.
Email and SMS are the strictest columns almost everywhere, because both fall squarely inside the ePrivacy Directive's definition of "electronic mail." The EU default is opt-in. Some countries carve out a softer rule for B2B (an opt-out is enough), but plenty don't - and a few, like Italy and Lithuania, are explicit that even where email gets the softer treatment, SMS doesn't.
Phone is the one channel the Directive deliberately left to national discretion, which is exactly why it's the most fragmented column in the table - and, in practice, often the most workable one. Identify yourself, call the business number, and stop immediately if someone objects, and you're on solid ground in a surprising number of markets.
LinkedIn mostly isn't "electronic mail" in the strict telecoms sense the ePrivacy rules use, so the fallback is plain GDPR legitimate interest with a balancing test - which is why LinkedIn skews greener than email across most of the EU. Two countries break that pattern. Germany's courts have applied the same "unreasonable business disruption" logic from unfair-competition law to unsolicited platform messages, not just email. And Denmark's Forbrugerombudsmanden has ruled directly, more than once, that InMails - and even a plain "saw your profile, let's connect" pitch - count as electronic mail. Same opt-in rule as email, deliberately, so LinkedIn can't become the loophole.
If you're selling into Denmark, that one's worth sitting with. Phone is genuinely open there - and worth a correction from an earlier version of this piece: it's not because of the Robinson list. That list is a consumer register under the Consumer Contracts Act; it protects private individuals, not companies, and doesn't touch a call to a registered business. Danish phone is open simply because no register applies to companies at all by default. The one place Robinson does bite in a B2B context is a sole proprietor's personal mobile - worth checking before you dial one. Email and LinkedIn, meanwhile, are both locked behind consent. That's the opposite of what most reps assume.
WhatsApp is the newest and least tested channel legally, but don't read that as a green light. Regulators would very likely treat it like SMS if it ever got tested, and WhatsApp's own Business Messaging Policy already bans marketing messages to numbers that haven't opted in - so it's a practical dead end for cold outreach even before you get to the legal analysis.
The French exception, because it's the one everyone gets half right
France is the country where people most often misquote the rule. "France allows unsolicited B2B email" is true, but only under three conditions, all at once:
- You're emailing the person's professional address - a personal Gmail used for work doesn't count, that's back to needing consent.
- The pitch is relevant to their role - a generic offer with no connection to their job doesn't qualify.
- They're told at first contact, and given a real, one-click way to opt out in every message.
The CNIL isn't shy about enforcing the edges of this. Orange, Cdiscount, Free, and Brico Privé have all been fined in recent years - not for using the exception, but for using it sloppily: no documented legal basis, or an opt-out link that didn't actually work.
What this actually means for your outreach plan
If there's one takeaway, it's this: pick your opening channel per country, not per campaign. A sequence that leads with LinkedIn works well in most of the EU, but walks straight into trouble in Denmark. A sequence that leads with email works in France and the Nordics-minus-Denmark, but needs a genuine opt-in step in Germany, Austria, Spain, and most of Central and Eastern Europe.
The countries where phone is your cleanest first move more often than people expect: Denmark, Estonia, Hungary, Ireland, Croatia, France, Sweden, and the Netherlands all allow it on an opt-out basis.
None of this is a reason to avoid a market - it's a reason to sequence it correctly. Get the channel order right per country, and the compliance question mostly takes care of itself.
Two things this isn't: purely GDPR, and purely a legal question
Worth saying plainly: most of what's blocking you above isn't GDPR at all. GDPR governs whether you have a lawful basis to hold and use a contact's data - for B2B, that's almost always legitimate interest, and it's rarely the sticking point. What actually stops a channel is a separate, often much older, body of national law: Germany's rules sit in its unfair-competition act, not its data protection act. Denmark's sit in a marketing practices law. Spain's phone rules sit in telecoms law. If someone on your team says "we're GDPR compliant, so we're fine," that's answering a different question than the one that matters.
The other thing worth flagging: whether the message lands at all is a language question as much as a legal one. We added an English-proficiency read to the matrix using the EF English Proficiency Index - and the pattern is reassuring for most of the countries you'd actually be targeting. Every Nordic country, the Netherlands, Germany, Poland, and most of Central Europe score Very High. France, Italy, and Spain sit in the Moderate band nationally - but the job-function data inside the same report shows the gap: France's IT function scores 593 and Strategy & Project Management scores 625, against a 539 national average. Your actual buyer - the IT director, the legal counsel, the ops lead - tests well above the general population almost everywhere. Treat a low national score as "double-check this specific contact," not "don't bother in English."
All that said, English isn't 1:1 interchangable with any country's national language(s). You will almost always convert better approaching any prospect in their own language. You'll find more detailed coverage about the use of English in European countries in our article on the topic.
Last thing on AI, because it's moving fast and there's a real trap in it: if any part of your stack is AI-powered, the EU AI Act now sits on top of everything above it. Since 2 August 2026, anyone deploying a chatbot or voice assistant that interacts directly with a person has to disclose, clearly, at first contact, that they're talking to AI - a flat €15M-or-3%-of-turnover-level obligation.
Here's the trap: it's tempting to assume "AI drafts it, a human reviews and sends it" gets you out of this entirely - and there's a real human-review exemption in the Act that makes that assumption feel safe. It doesn't apply to sales outreach, though. That exemption (Art. 50(4)) is scoped to AI-generated text "published with the purpose of informing the public on matters of public interest" - AI-assisted journalism, essentially, not a cold email to one named prospect. The distinction that actually matters for outbound is different: an AI that drafts a message which a human then reviews and sends is probably outside the disclosure duty altogether, because the rule targets AI systems that interact directly with a person - a one-way, human-approved message isn't a live interaction. But the moment an AI SDR tool starts handling the replies on its own - running the back-and-forth after that first message without a human in the loop - that's exactly the live interaction the rule is written for, and no amount of care spent reviewing the opening line exempts the autonomous conversation that follows it. If you're running or evaluating AI outbound tools, know which side of that line your tool sits on.
Don't let this stop you
B2B prospecting is a little like a puzzle in need of solving. You lay the puzzle using the pieces available to you and within the constraints laid out. Prospect behaviour, technological capabilities, data quality, and indeed legal frameworks all play a role. Your task in Go to Market is to figure out a way through.
Good selling!

