Netherlands (ACM) and the B2B Email Question Across Jurisdictions
Dutch spam rules under Telecommunicatiewet Art. 11.7 (ACM), the ICO's B2B marketing guidance, and a cross-jurisdiction answer to 'can I email business addresses without consent?' for UK, France, Germany, and the Netherlands.
"B2B email doesn't need consent" is one of the most dangerous generalisations in email compliance. The ePrivacy Directive's opt-in rule (Art. 13) protects natural persons and lets member states decide how far to protect legal persons — so the B2B answer changes at every border. This article covers the Dutch regime (ACM), the UK's B2B guidance (ICO), and a worked comparison across UK, France, Germany, and the Netherlands. A campaign to a mixed European B2B list must satisfy the strictest applicable rule per recipient, and recipient country — not sender country — determines the rule.
Netherlands — Telecommunicatiewet Article 11.7 (regulator: ACM)
The Dutch spam prohibition lives in Article 11.7 of the Telecommunicatiewet and is enforced by the Autoriteit Consument en Markt (ACM), a consumer/market regulator rather than the data-protection authority (the AP handles the GDPR side).
Core rule — opt-in: unsolicited electronic commercial messages (email, SMS, and explicitly also channels like WhatsApp) require the recipient's prior consent. Consent cannot be obtained through:
- pre-checked boxes;
- pressure tactics;
- burial in general terms and conditions.
The consent request must clearly refer to promotional or solicitation messages, and — a distinctive Dutch requirement — the sender must be able to prove the consent for up to 5 years after sending. (This is the most concrete consent-retention number any EU regulator publishes; design consent records accordingly.)
B2B scope: since 1 October 2009 the prohibition also covers legal persons — Dutch law extended the opt-in to business recipients, ending the previous B2B opt-out regime. The ACM's current guidance draws no B2B/B2C distinction: the rules apply uniformly to all recipients. (Provenance: the 2009 extension date is confirmed from legal commentary — CMS "Dutch new law prohibits B2B spam" and Dutch law-firm summaries — as the ACM page itself no longer narrates the history.)
Existing-customer exception: unsolicited messages may be sent to existing customers about products or services related to prior purchases, provided:
- recipients can easily unsubscribe; and
- the sender's identity is clearly disclosed.
Sender identification: the sender must be clearly identifiable by business name or email address — no aliases.
Unsubscribe: every message must include an opt-out that is:
- fast — no complex questionnaires;
- free — no payment and no demand for additional personal data.
Tell-a-friend campaigns are lawful only under five cumulative conditions:
- the sharer forwards voluntarily — no incentives may be offered;
- the forwarded message displays contact information for complaints;
- the sharer can see the complete message before it is sent;
- personal data used for the forwarding is deleted afterward and not reused;
- the website is secured against automated abuse for spam.
(Compare the UK, where the ICO concludes incentivised refer-a-friend email generally cannot be done lawfully at all — see UK PECR.)
Scope and liability: the rules apply to sends throughout the EEA (EU plus Iceland, Norway, Liechtenstein); outside the EEA local rules apply. Liability attaches not only to the party that transmits but also to the instigator and to third-party service providers assisting distribution — the same sender/instigator net as PECR and CASL, which is why ESP terms of service must bind customers to these rules.
United Kingdom — ICO business-to-business marketing guidance
The ICO's dedicated B2B guidance (under review following the Data (Use and Access) Act changes) rests on PECR's split between corporate subscribers and individual subscribers — introduced in UK PECR — Electronic Mail Marketing and elaborated here for the B2B case.
Who is a corporate subscriber
Corporate subscribers are bodies with separate legal personality: companies, corporations sole, limited liability partnerships, Scottish partnerships, some government bodies, and any other body corporate distinct from its members. An employee's work email address or phone number at a corporate body counts as the corporate subscriber — the subscriber is the employer.
Treated as individual subscribers despite being businesses: sole traders, non-LLP partnerships (English, Welsh, Northern Irish), and other unincorporated bodies of individuals. They get the full individual protections.
The PECR email rule for B2B
| Recipient | PECR consent for marketing email? |
|---|---|
| Corporate subscriber (any employee address at a company/LLP) | No — but you must not disguise or conceal your identity, and must give a valid opt-out/unsubscribe address |
| Sole trader / non-LLP partnership | Yes — consent or the soft opt-in |
For corporate subscribers, PECR does not literally mandate honoring the opt-out, but the ICO's position is that the required opt-out address plainly intends corporates to be able to unsubscribe, so you should comply with a corporate subscriber's opt-out — and you may be required to where personal data is involved (right to object). Keep a "do not email" list of corporate opt-outs and screen new B2B lists against it.
Soft opt-in for sole traders/partnerships — all four conditions: details obtained in the course of a sale or negotiation of a sale; only your similar products/services marketed; a clear opt-out offered at collection; an opt-out offered in every message. The ICO's example: an online building-supplies company whose customers are largely sole traders adopts the soft opt-in for all customers at checkout (explanation + opt-out tick box, unsubscribe in every email) — the safe uniform design.
Unknown subscriber type = treat as individual. If you can't tell whether an address belongs to a corporate or an individual subscriber, assuming corporate risks breaching PECR; the ICO says to apply the individual-subscriber rules. Operationally, domain-based heuristics ("looks like a company domain") cannot distinguish a limited company from a sole trader — another reason consent-based B2B lists beat scraped ones.
UK GDPR layer on top of PECR
- A named business contact (name + number on file, or an address like firstname.lastname@company.com) is personal data even in a business capacity; the UK GDPR applies in full, including the absolute right to object to direct marketing. Unnamed targets ("the IT department", info@company.com) are not personal data.
- Business cards: loose in a drawer — UK GDPR doesn't apply; added to a contacts database — it does.
- Lawful basis: where PECR requires consent, use consent; where it doesn't, legitimate interests usually fits, subject to the three-part test (identify the interest; necessity; balancing).
- Transparency: tell business contacts at collection that you'll market to them; details obtained from public sources or third parties require privacy information within a reasonable period, at most one month.
- Repurposing: the ICO's conference-organiser example shows post-hoc emailing of (verified corporate) delegate addresses can pass a compatibility/expectations assessment — but selling delegate details without having told them fails the fairness test, and buyers of such lists would breach PECR for any individual subscribers because consent must name the sender.
- Publicly available data (company websites, Companies House, social media, press): public availability is not consent. PECR still applies to calls/email/fax using scraped details; UK GDPR applies whenever the data identifies an individual. Individuals on professional networking sites are generally there in a personal (albeit professional) capacity — messaging them is not "B2B marketing", and both UK GDPR and PECR apply to DMs.
- Objections: honor opt-outs and withdrawals; put objectors on a suppression list rather than deleting them so future lists can be screened (see Right to Object and Erasure). The ICO's example: a recruitment firm emailing a named HR director at a limited company needs no PECR consent, but when the director says stop, it stops and suppresses — the named address is personal data and the objection is absolute.
The cross-jurisdiction B2B table
"Can I email a business address without prior consent?" for the four canonical markets:
| UK | France | Germany | Netherlands | |
|---|---|---|---|---|
| Instrument / regulator | PECR / ICO | CPCE Art. L.34-5 / CNIL | UWG §7 / courts (competitors & consumer bodies sue; DPAs handle GDPR side) | Telecommunicatiewet Art. 11.7 / ACM |
| Email to an employee at a corporation | Allowed without consent (corporate subscriber); identity + opt-out address required | Allowed without consent if the message relates to the recipient's profession, they were informed, and can object simply and free | Consent required — §7(2) demands prior express consent for email advertising with no B2B carve-out | Consent required — opt-in extended to legal persons on 1 Oct 2009 |
| Generic role address (info@, contact@) | PECR still applies (rule turns on subscriber type, not address form) but no personal data → no UK GDPR | Outside the consent/objection rules (legal person, no natural person) | Consent still required (§7(2) protects market participants generally) | Opt-in applies (legal persons covered) |
| Sole traders | Individual subscribers — consent or soft opt-in | Individuals — consent (or existing-customer exception) | Consent | Consent (natural persons always covered) |
| Existing-customer exception | Soft opt-in: details in sale/negotiation, own similar products, opt-out at collection + every message | Same idea; requires an actual completed sale/service; opt-out at collection + every message | §7(3): address obtained in connection with a sale, own similar goods/services (courts: interchangeable / same need), no objection, cost-free objection notice at collection and in every use | Prior-purchase-related products/services; easy unsubscribe; clear sender identity |
| Notable extras | Absolute right to object where address names a person | Deliverability pixels need consent outside the exempted scope — see France/CNIL | Documented double opt-in is the de-facto evidence standard (BGH case law on proving consent); CSA certification encodes it — see GMX/WEB.DE | Consent provable 5 years after sending; WhatsApp in scope |
Germany provenance note: the official gesetze-im-internet.de English translation was unreachable at extraction time; the §7(2)/§7(3) summary above is cross-checked against Certified Senders Alliance and German law-firm analyses of the statute and may lack the official wording's nuance.
The operational consequence: a "B2B cold outreach is fine in Europe" claim is false in two of the four largest markets (Germany and the Netherlands require opt-in even for corporate addresses), conditionally true in France (professional-relevance + information + objection), and true only for genuine corporate subscribers in the UK — where sole traders hide indistinguishably in any bought list. Add the deliverability layer — corporate mail flows through gateways and business tenants with their own reputation systems, and cold mail generates the complaints and trap hits described in Consent Methods — and consent-based collection remains the only strategy that works across the map.