DEV Community

Mirage Cloud IA
Mirage Cloud IA

Posted on

Cold Outreach in Europe Without Breaking the Rules

There are two wrong beliefs about cold outreach in Europe. One is that GDPR made it illegal. The other is that if you scrape a list and send to it, nobody will notice.

Both are wrong, and the truth in between is workable. B2B prospecting is legal in most European jurisdictions if you do it properly, and doing it properly happens to also be what makes it effective.
The legal position, briefly
Two regimes apply at once. GDPR governs the handling of personal data. The ePrivacy rules govern unsolicited commercial messages.

Individuals, including consumers and sole traders, generally require prior consent for marketing email.

Business contacts at a company, meaning a person in their professional capacity, can generally be contacted on a legitimate interests basis in most member states, provided the message relates to their professional role, you identify yourself clearly, you explain how you got their details, and you offer an easy opt-out.

The B2B position varies by country. Some member states are noticeably stricter, and Germany in particular is more restrictive than the general picture. If you are prospecting across borders, check the local position rather than assuming a single European rule.

Telephone prospecting has its own regime, including national opt-out registers, and in France the rules on cold calling have tightened considerably in recent years. If you are calling rather than emailing, check the current position specifically, because it has changed more than once.
What legitimate interests actually requires
It is not a free pass. It requires a balancing assessment: your interest in contacting them against their reasonable expectation of privacy. Write it down once, briefly. It is the document a regulator asks for and almost nobody has.

Practically, an outreach programme sits comfortably within legitimate interests when:

You contact people whose professional role plausibly relates to what you sell
Your message is relevant to that role
You identify your company clearly, with real contact details
You say where you got their details
Opting out is one click and permanently honoured
You keep a suppression list and actually check it

It sits outside when you have bought a scraped list, are sending to personal addresses, or are contacting people with no plausible connection to your offer.
The information duty people forget
Under GDPR, when you obtain personal data from a source other than the individual, you have to tell them within a reasonable period, at the latest when you first contact them, including where the data came from and what rights they have.

In practice this means a line in the first email pointing to your privacy notice, and saying where you found them. "I found your details on your company website" is both compliant and, incidentally, more polite than pretending otherwise.
Practices that keep you out of trouble and work better
Small, researched batches beat volume. Fifty properly targeted messages outperform two thousand generic ones on reply rate, and they generate almost no complaints. Complaints are what draw regulatory attention, and they also destroy your sending reputation.

Use role-based professional addresses. Contact people through their company, not through personal email found somewhere else.

Never buy a list. Beyond the legal exposure, purchased lists carry spam traps, high bounce rates and complaint rates that damage deliverability for everything you send, including invoices and transactional email.

Authenticate your domain. SPF, DKIM and DMARC. Major mailbox providers increasingly filter unauthenticated bulk mail regardless of its content. This is now table stakes.

Use a separate sending domain for prospecting so a reputation problem does not affect ordinary business mail.

Honour opt-outs immediately and permanently. Maintain a suppression list across all campaigns. Someone who unsubscribed and gets contacted again eighteen months later is the person who complains.
Messages that get replies
Short. Under 120 words. Long cold emails are deleted unread.

Specific to them. A sentence showing you know what the company does. Not a merge field, a real observation. This is what separates outreach from spam in the recipient's mind, whatever the law says.

One clear question. Not a pitch, a calendar link and three attachments. A question that can be answered yes or no in ten seconds.

No fake familiarity. "Following up on my last email" when there was no previous conversation is transparent and it costs you credibility immediately.

Two follow-ups maximum, spaced a week apart, then stop. Persistence past that point produces complaints rather than meetings.
Where AI helps and where it creates risk
Research and drafting genuinely benefit. Understanding a prospect's business, drafting a first message, adapting a template to a specific context. Mirage Cloud includes a sales agent scoped to prospecting and conversion with Gmail and Pipedrive integrations.

Two real risks. Generated personalisation that is obviously generated is worse than none, because it signals volume rather than attention. And tools that promise to build or enrich lists automatically often do so from sources with no lawful basis, which transfers the compliance problem to you. The vendor's terms will say the responsibility is yours, and they will be right.
The one-line version
Contact professionals, in their professional capacity, about something plausibly relevant, with a real signature, a stated source and a working unsubscribe. That is legal in most of Europe and it is also, by some distance, the version that works.

Top comments (0)