← All resources

B2B prospecting and GDPR: France, Belgium, the Netherlands

Published September 25, 2026 · 7 min read · CyberNovaLabs.io

The GDPR does not tell you whether you may cold-email a company. National laws implementing Directive 2002/58/EC decide that — and they do not use the same test. Named or impersonal address, link to the recipient's professional activity, an address published to receive offers: what makes a send lawful in Brussels can make it unlawful in Amsterdam.

The short answer

There is no single European rule for B2B prospecting. The GDPR sets the common floor, but it is the national implementation of Directive 2002/58/EC that decides whether you need prior agreement before the first email. The same cold message can be lawful in France, lawful in Belgium when sent to an info@ address, and unlawful in the Netherlands.

In short: France allows business-to-business prospecting without prior consent, subject to three cumulative conditions[1]. Belgium waives consent for messages sent to impersonal addresses of legal entities[3]. The Netherlands requires prior consent, including when writing to a company, with two narrow exceptions[6].

What follows summarises the published position of the competent authorities — CNIL, the Belgian FPS Economy, the Autoriteit Persoonsgegevens and the ACM. It is not legal advice: have your sequence reviewed by counsel before scaling it.

The table to keep in front of you

SituationFranceBelgiumNetherlands
Cold email to firstname.lastname@companyAllowed without consent if the three B2B conditions are met[1]Prior consent: this is a natural person's address[3]Prior consent[6]
Cold email to info@, sales@, contact@Same regime: what matters is the link to professional activity, not the form of the address[1]Consent waived where the address is manifestly that of a legal entity[3]Consent, unless the address was deliberately published to receive offers[6]
Existing customer, similar offerException to consent, with notice and an easy opt-out[1]Exception where details were obtained during a sale, for similar products from the same provider[3]Exception for your own similar products or services[6]
Decisive testThe link to the recipient's professional activity[1]The impersonal nature of the address, and an offer aimed at legal entities[3]Consent, or an address published for that purpose[6]
Cold call to a companyBloctel and the opt-out regime target consumers[9]The Do Not Call Me list must be checked before any canvassing, whatever your company[5]Only if the company published contact details clearly intended for telephone sales[7]

France: a B2B regime, but three cumulative conditions

The principle in Article L. 34-5 of the Postal and Electronic Communications Code is prior consent for electronic marketing addressed to individuals[1][10]. The CNIL stresses that consent must be freely given, specific, informed and unambiguous: a pre-ticked box or acceptance of general terms does not qualify[2].

For business-to-business prospecting, the CNIL describes a distinct regime. Prior consent is not systematically required where three conditions are met[1]:

  1. the message relates to the professional activity of the person contacted;
  2. the person is informed of the origin of their data and of the purpose of the message;
  3. they can easily object to receiving further approaches.

Three points change day-to-day practice. First, the second condition forces you to say where the address came from: a purchased list, an automated extraction or a professional directory cannot be hidden. Second, how a message is classified depends on its objective, not its tone; an apparently informative newsletter can be reclassified as commercial prospecting if its aim is to steer the reader towards an offer[1]. Third, the existing-customer exception only applies after an actual sale or service: merely creating an online account is not enough, and the CNIL has sanctioned that reading[2].

Belgium: the form of the address decides

Article 14 of the Law of 11 March 2003 sets out a general prohibition on using email for advertising without prior, free, specific and informed consent[4]. The Royal Decree of 4 April 2003 provides two exceptions; the second is the one that matters for B2B[3].

Prior consent is not required when writing to legal entities at an impersonal address. The report to the King expressly cites info@, contact@, privacy@, sales@, commandes@ and service-clientele@[3]. Three guardrails come with it:

Two expensive details. The burden of proof lies with the advertiser: it is for you to show that you were exempt from obtaining consent[3]. And objecting is more than an unsubscribe link: every advertising email must carry clear information about the right to object and a reply email address; where someone notifies a refusal, the provider must send an acknowledgement within a reasonable time, free of any promotional content, and update its lists[3].

The Netherlands: consent applies between companies too

The Autoriteit Persoonsgegevens is explicit: Article 11.7 of the Telecommunications Act, the spam ban, requires prior consent, and that rule also applies when one organisation approaches another[6]. Only two exceptions are recognised in a B2B context[6]: the recipient company has deliberately published an address for that purpose — the example given is of the salesaanbiedingen@company.nl type — or the recipient is outside the European Economic Area and the send complies with local rules. The general existing-customer exception applies as well, for your own similar products or services[6].

In other words, an info@ address published on a Dutch website does not by itself entitle you to send an offer there. This is the most expensive gap between Brussels and Amsterdam, and the one that standardised pan-European sequences most often ignore. Objection must remain free and simple, both when the data is collected and in every send[6].

Phone calls do not follow the email rules

Belgium. The Do Not Call Me list must be consulted before any telephone canvassing, whatever the nature or size of your company, and listed numbers must be removed from your contact lists. Access requires a paid licence from the DNCM non-profit; the FPS Economy states fines of up to 80,000 euros[5].

Netherlands. Prior consent is required to call natural persons, which includes sole traders and partnerships[7]. Calling a legal entity is possible only where it has itself made contact details public in a way that clearly shows they may be used for telephone sales; the authority specifies that a number listed in the chamber of commerce register does not count as consent[7]. Withholding your caller ID is prohibited[7]. The ACM, which supervises these rules, has tightened the regime for consumers and small entrepreneurs by removing the ability to call on the sole basis of a past customer relationship[8].

France. Bloctel and the telephone opt-out regime target consumers; business-to-business calls fall outside that scope, which removes neither GDPR obligations nor the duty to identify the caller clearly[9].

What about LinkedIn?

Regulators reason by channel, not by platform. The Autoriteit Persoonsgegevens expressly places email, SMS and in-app messages in the same digital direct marketing category[6], and the Belgian text adopts a very broad notion of electronic mail, covering any contact point that allows advertising to be sent[3]. None of these sources explicitly settles the case of LinkedIn messages: the prudent course is to apply the recipient country's regime rather than to bet on a gap.

Six lines to write before the first send

To document, country by country, before opening the sequence:

  1. Origin of each address: source, date, method. Required in France to inform the recipient[1], useful everywhere in an inspection.
  2. Address type: named or impersonal. That is the Belgian test[3]; it is not the French one[1].
  3. The recipient's country of establishment, not your sender's.
  4. The legal basis relied on: consent, existing-customer exception, or the national B2B regime, with matching evidence. In Belgium the burden of proof is on the advertiser[3].
  5. Objection mechanism: unsubscribe link, reply email address and, in Belgium, an acknowledgement[3].
  6. An objection register, kept and honoured over time, including after you change sending tool.

If any of these six lines is blank for a country, remove that country from the sequence rather than leaving the line empty.

At CyberNovaLabs.io

We build B2B appointment-setting operations across France, Belgium and the Netherlands, with the framing written before the first send: qualification criteria, data origin, legal basis country by country, objection mechanism. No minimum term, priced per appointment or as a fixed fee, on quotation.

Discuss your B2B prospecting with CyberNovaLabs.io

Sources

  1. CNIL — Communications par voie électronique aux prospects et clients : quelles règles respecter ?
  2. CNIL — La prospection commerciale par courrier électronique, SMS-MMS et automate d'appel
  3. Arrêté royal du 4 avril 2003 visant à réglementer l'envoi de publicités par courrier électronique (rapport au Roi)
  4. Loi du 11 mars 2003 sur certains aspects juridiques des services de la société de l'information (article 14)
  5. SPF Economie (Belgique) — Démarchage téléphonique et liste Ne m'appelez plus !
  6. Autoriteit Persoonsgegevens — Digitale direct marketing (artikel 11.7 Telecommunicatiewet)
  7. Autoriteit Persoonsgegevens — Telemarketing
  8. ACM — Strengere regels voor telemarketing
  9. economie.gouv.fr — Bloctel : la réglementation pour les professionnels
  10. Legifrance — Code des postes et des communications électroniques, article L. 34-5
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked