Is Cold Outreach Legal in Germany, Austria and Switzerland? (2026 Guide)
The DACH region has the strictest cold outreach rules in the Western world, and they differ by country and by channel. What is allowed, what is risky, and how compliant outbound is set up in practice.
Key takeaways
- B2B cold outreach in DACH is regulated, not banned. The rules differ sharply by channel: LinkedIn is the least critical, phone and email carry real requirements.
- Germany, Austria and Switzerland are three different legal frameworks. A campaign that is fine in Munich can be a violation in Vienna.
- The practical safeguards are always the same: documented research, a recognizable business reason, low volume, a clean sender identity and an opt-out in every message.
- This is orientation, not legal advice. Before a large campaign, have your setup reviewed by a lawyer who knows UWG and data protection law.
One sentence before anything else: this article explains the landscape so you can ask the right questions. It is not legal advice, laws change, and details depend on your specific case. For a binding assessment, talk to a lawyer. That disclaimer out of the way, here is the honest picture, because the fear around this topic is mostly fear of the unknown.
The short answer
B2B cold outreach in the German-speaking region is regulated, not forbidden. Thousands of companies do it every day, compliantly. What trips people up is that the rules differ along two axes at once: by channel (LinkedIn vs phone vs email) and by country (Germany vs Austria vs Switzerland). Most horror stories come from companies that copied a US playbook and ignored both axes.
Germany
The two relevant frameworks are the UWG (the unfair competition act) and the GDPR.
For phone calls to businesses, the UWG requires so-called presumed consent: you need a factual reason to assume the specific business would be interested in your offer. A targeted call to a logistics company about logistics software clears a very different bar than a random dial from a bought list.
Email is regulated more strictly than most founders expect, and stricter than phone for B2B. The law treats advertising email without prior consent as an unreasonable nuisance, with a narrow exception for existing customer relationships. This is why serious German outbound providers put so much weight on research quality, recognizable business relevance, restrained volume and a clean opt-out, and why bought lists are not just useless but a legal liability.
The GDPR governs the data side: processing business contact data can be based on legitimate interest, but that requires an actual balancing of interests, transparency and functioning deletion processes. "It is B2B, so GDPR does not apply" is a myth; business email addresses of identifiable people are personal data.
Austria
Austria is stricter than Germany. Advertising calls without prior consent are prohibited, including B2B, and electronic advertising has its own requirements, including the ECG list maintained by the regulator RTR: a register of addresses that must not receive commercial email at all, which any serious campaign has to be checked against. In practice, compliant Austrian outbound leans more heavily on LinkedIn as the entry channel, with phone and email reserved for warmer stages.
Switzerland
Switzerland is not an EU member and not a GDPR country. Its own framework, the revised FADP (revDSG) and the Swiss UWG, sets its own requirements: mass electronic advertising generally requires consent, correct sender identification and a rejection option, with an exception for existing customers. Enforcement culture differs from the EU, but the direction is the same: precision beats volume. Anyone targeting both Swiss and EU buyers needs both frameworks handled cleanly, which is a setup question, not an afterthought.
And LinkedIn?
Across all three countries, a personal, individually sent LinkedIn message to a business contact is the least critical form of cold outreach, which is one reason it plays such a large role in DACH outbound. The caveat is different in kind: aggressive automation violates LinkedIn's own terms and risks the account, so volume discipline matters here too, just for a different reason.
What compliant outbound looks like in practice
Whatever the channel and country, the same safeguards keep showing up in every setup that holds:
- Documented research. You can show why this specific company was contacted, and which signal made the offer relevant.
- Recognizable business relevance. The message is about their business, in the first sentence, not about your product.
- A real sender. Clean identification, real name, working reply address, company identifiable.
- Opt-out in every message. Honored immediately and permanently.
- Low volume. Which happens to be exactly what deliverability and reply rates want too. Compliance and performance point the same way in DACH.
- No bought lists. Ever. Legally toxic and commercially useless.
If you want to see what this looks like as a running system, our cold email agency and B2B lead generation pages walk through the setup, and our DACH agency comparison shows how local providers handle it.
The uncomfortable truth about the fear
Here is what we see in practice: the companies most afraid of DACH outreach rules are usually the ones who have never read them, and the companies that get burned are the ones who ignored them at industrial scale with bought lists and blast volumes. Between those extremes sits a wide, well-lit corridor where compliant, effective outbound lives. The rules are not the reason your pipeline is empty. They are, honestly, a moat: they punish the lazy operators and reward anyone willing to do the research.
Frequently asked questions
Is cold calling businesses legal in Germany?
Yes, under the UWG's presumed consent standard: you need a factual reason to assume the specific business is interested in your offer. Random dialing from bought lists does not meet that bar; researched, relevant targeting can. B2C cold calling without express consent is prohibited.
Is cold email illegal in Germany?
Advertising email without prior consent is treated as an unreasonable nuisance under German law, with a narrow existing-customer exception. That is why compliant German outbound relies on documented research, clear business relevance, low volume and clean opt-outs, and why the setup deserves legal review before scale.
Do the same rules apply in Austria and Switzerland?
No. Austria is stricter than Germany, prohibiting advertising calls without prior consent and maintaining the ECG list of addresses that must not receive commercial email. Switzerland follows its own revised FADP and UWG rather than the GDPR. Each country needs its own setup.
What is the safest channel for cold outreach in DACH?
A personal, individually sent LinkedIn message is the least legally critical starting point in all three countries. The constraint there is LinkedIn's own terms: aggressive automation risks the account. Phone and email work as follow-on channels with the right setup.
So is cold outreach banned in Germany or not?
There is no general ban. B2C cold calling without express consent is prohibited; B2B outreach is regulated channel by channel: phone under the presumed-consent standard, email far more strictly with an existing-customer exception, LinkedIn largely uncritical. 'Cold outreach is banned' and 'anything goes in B2B' are both wrong, and both myths cause real damage.
Does the GDPR apply to B2B contact data?
Yes. Business email addresses of identifiable people are personal data. Processing them for outreach can rest on legitimate interest, but that requires an actual balancing test, transparency duties and working deletion processes. 'It is B2B, so GDPR does not apply' is one of the most expensive myths in German sales.