Netherlands (ACM) and the B2B Email Question Across Jurisdictions
Dutch spam rules under Telecommunicatiewet Art. 11.7 (ACM), the ICO's B2B marketing guidance, and a cross-jurisdiction answer to 'can I email business addresses without consent?' for UK, France, Germany, and the Netherlands.
Reference9 min read
Who it is for Compliance teams, Senders
Applies to senders on any platform
If you send marketing email to business addresses in Europe, whether you need consent depends on the country each recipient is in. "B2B email doesn't need consent" is one of the most dangerous generalisations in email compliance.
The ePrivacy Directive's opt-in rule (Art. 13) protects natural persons, and lets each member state decide how far to protect legal persons, so the answer for business-to-business (B2B) email changes at every border. Below are the Dutch rules, enforced by the Authority for Consumers and Markets (ACM), the UK's B2B guidance from the Information Commissioner's Office (ICO), and a worked comparison of the UK, France, Germany and the Netherlands.
A campaign to a mixed European B2B list must satisfy the strictest rule that applies to each recipient. The recipient's country determines the rule, not the sender's.
Netherlands: Telecommunicatiewet Article 11.7 (regulator: ACM)
The Dutch prohibition on spam is in Article 11.7 of the Telecommunicatiewet, and the Autoriteit Consument en Markt (ACM) enforces it. The ACM regulates consumers and markets; it is not the data protection authority, which is the Autoriteit Persoonsgegevens (AP) and handles the GDPR side.
The core rule is opt-in. Unsolicited electronic commercial messages (email, SMS, and explicitly also channels such as WhatsApp) require the recipient's prior consent. Consent cannot be obtained through:
- pre-checked boxes;
- pressure tactics;
- burial in general terms and conditions.
The consent request must clearly refer to promotional or solicitation messages. A requirement particular to the Netherlands is that the sender must be able to prove the consent for up to 5 years after sending. This is the most concrete retention period for consent that any EU regulator publishes, so design consent records to meet it.
B2B scope. Since 1 October 2009, the prohibition also covers legal persons. Dutch law extended the opt-in to business recipients and ended the earlier opt-out regime for B2B. The ACM's current guidance makes no distinction between B2B and business-to-consumer (B2C) mail: the rules apply in the same way to all recipients. The ACM page no longer describes this history, so the 2009 extension date is confirmed from legal commentary: CMS's "Dutch new law prohibits B2B spam" and summaries by Dutch law firms.
Exception for existing customers. Unsolicited messages may be sent to existing customers about products or services related to earlier purchases, provided that:
- recipients can easily unsubscribe; and
- the sender's identity is clearly disclosed.
Sender identification. The sender must be clearly identifiable by business name or email address. Aliases are not allowed.
Unsubscribe. Every message must include an opt-out that is:
- fast, with no complex questionnaires;
- free, with no payment and no demand for more personal data.
Tell-a-friend campaigns are lawful only if all five of these conditions are met:
- the person sharing forwards the message voluntarily, and no incentives may be offered;
- the forwarded message shows contact information for complaints;
- the person sharing can see the complete message before it is sent;
- personal data used for the forwarding is deleted afterward and not reused;
- the website is protected against automated abuse for spam.
Compare the UK, where the ICO concludes that refer-a-friend email with an incentive generally cannot be sent lawfully at all (see UK PECR).
Scope and liability. The rules apply to sends throughout the European Economic Area (EEA): the EU plus Iceland, Norway and Liechtenstein. Outside the EEA, local rules apply. Liability falls not only on the party that transmits the message but also on the instigator and on third-party service providers that help distribute it. PECR and CASL cast the same net over senders and instigators, which is why ESP terms of service must bind customers to these rules.
United Kingdom: ICO guidance on business-to-business marketing
The ICO's dedicated B2B guidance is under review following the changes made by the Data (Use and Access) Act. It rests on the distinction in the Privacy and Electronic Communications Regulations (PECR) between corporate subscribers and individual subscribers, introduced in UK PECR — Electronic Mail Marketing and developed here for B2B mail.
Who is a corporate subscriber
Corporate subscribers are bodies with their own legal personality: companies, corporations sole, limited liability partnerships, Scottish partnerships, some government bodies, and any other body corporate separate from its members. An employee's work email address or phone number at a corporate body counts as the corporate subscriber's, because the subscriber is the employer.
Some businesses are treated as individual subscribers: sole traders, partnerships that are not limited liability partnerships (LLPs) in England, Wales and Northern Ireland, and other unincorporated groups of individuals. They receive the full protections given to individuals.
The PECR email rule for B2B
| Recipient | Does marketing email need consent under PECR? |
|---|---|
| Corporate subscriber (any employee address at a company or LLP) | No, but you must not disguise or hide your identity, and you must give a valid address for opting out or unsubscribing |
| Sole trader, or partnership that is not an LLP | Yes: consent or the soft opt-in |
For corporate subscribers, PECR does not literally require you to honor the opt-out. The ICO's position is that the required opt-out address clearly means corporate subscribers should be able to unsubscribe, so you should comply with a corporate subscriber's opt-out. Where personal data is involved, you may be required to, under the right to object. Keep a "do not email" list of corporate opt-outs and screen new B2B lists against it.
The soft opt-in for sole traders and partnerships requires all four conditions: the details were obtained during a sale or the negotiation of a sale; you market only your own similar products or services; you offered a clear opt-out when you collected the details; and you offer an opt-out in every message. The ICO gives the example of an online building supplies company whose customers are mostly sole traders. It uses the soft opt-in for all customers at checkout, with an explanation, an opt-out tick box and an unsubscribe link in every email. That uniform design is the safe one.
If you do not know the subscriber type, treat the recipient as an individual. If you cannot tell whether an address belongs to a corporate or an individual subscriber, assuming it is corporate risks breaching PECR, and the ICO says to apply the rules for individual subscribers. In practice, guessing from the domain ("it looks like a company domain") cannot tell a limited company from a sole trader. That is another reason why B2B lists built on consent are better than scraped ones.
The UK GDPR on top of PECR
- A named business contact (a name and number on file, or an address such as firstname.lastname@company.com) is personal data, even in a business capacity. The UK GDPR applies in full, including the absolute right to object to direct marketing. Unnamed contacts ("the IT department", info@company.com) are not personal data.
- Business cards. A card left in a drawer is outside the UK GDPR. Once its details are added to a contacts database, the UK GDPR applies.
- Lawful basis. Where PECR requires consent, use consent. Where it does not, legitimate interests usually fits, subject to the three-part test: identify the interest, show necessity, and balance it against the individual's interests.
- Transparency. Tell business contacts when you collect their details that you will send them marketing. For details obtained from public sources or third parties, provide privacy information within a reasonable period, at most one month.
- Using data for a new purpose. The ICO's example of a conference organiser shows that emailing delegates' verified corporate addresses afterward can pass an assessment of compatibility and of what delegates would expect. Selling delegates' details without having told them fails the fairness test. Buyers of such lists would breach PECR for any individual subscribers, because consent must name the sender.
- Publicly available data (company websites, Companies House, social media, the press). Being publicly available is not consent. PECR still applies to calls, email and fax sent using scraped details, and the UK GDPR applies whenever the data identifies an individual. People on professional networking sites are generally there in a personal capacity, even if a professional one. Messaging them is not "B2B marketing", and both the UK GDPR and PECR apply to direct messages.
- Objections. Honor opt-outs and withdrawals of consent. Put people who object on a suppression list rather than deleting them, so that future lists can be screened (see Right to Object and Erasure). In the ICO's example, a recruitment firm emailing a named HR director at a limited company needs no consent under PECR. When the director asks it to stop, it stops and suppresses the address, because the named address is personal data and the objection is absolute.
The cross-jurisdiction B2B table
"Can I email a business address without prior consent?" in the four main markets:
| UK | France | Germany | Netherlands | |
|---|---|---|---|---|
| Law and regulator | PECR, enforced by the ICO | CPCE Art. L.34-5, enforced by the CNIL | UWG §7, enforced through the courts (competitors and consumer bodies sue; data protection authorities handle the GDPR side) | Telecommunicatiewet Art. 11.7, enforced by the ACM |
| Email to an employee at a corporation | Allowed without consent (corporate subscriber); identity and an opt-out address required | Allowed without consent if the message relates to the recipient's profession, the recipient was informed, and they can object simply and free of charge | Consent required: §7(2) demands prior express consent for email advertising, with no exception for B2B | Consent required: opt-in extended to legal persons on 1 Oct 2009 |
| Generic role address (info@, contact@) | PECR still applies (the rule depends on the subscriber type, not the form of the address), but with no personal data the UK GDPR does not | Outside the consent and objection rules (a legal person, no natural person) | Consent still required (§7(2) protects market participants in general) | Opt-in applies (legal persons are covered) |
| Sole traders | Individual subscribers: consent or the soft opt-in | Individuals: consent (or the exception for existing customers) | Consent | Consent (natural persons are always covered) |
| Exception for existing customers | Soft opt-in: details obtained in a sale or negotiation, your own similar products, an opt-out when collected and in every message | The same idea; requires an actual completed sale or service; an opt-out when collected and in every message | §7(3): address obtained in connection with a sale, your own similar goods or services (courts: interchangeable, or meeting the same need), no objection, a notice that objecting costs nothing, given when collected and in every use | Products or services related to an earlier purchase; easy unsubscribe; clear sender identity |
| Notable extras | Absolute right to object where the address names a person | Pixels used for deliverability need consent outside the exempted scope (see France (CNIL)) | Documented double opt-in is the de facto standard of evidence (Federal Court of Justice (BGH) case law on proving consent), and the Certified Senders Alliance (CSA) certification builds it in (see GMX and WEB.DE) | Consent provable 5 years after sending; WhatsApp in scope |
For Germany, the statutory conditions summarized above for §7(2) and §7(3) are checked against the official English translation at gesetze-im-internet.de, which is not binding and is quoted in Germany — UWG §7 Email Marketing. The German text is the one that applies.
The practical consequence is that the claim "B2B cold outreach is fine in Europe" is false in two of the four largest markets, because Germany and the Netherlands require opt-in even for corporate addresses. It is true only under conditions in France (the message relates to the recipient's profession, the recipient was informed, and they can object). It is true only for genuine corporate subscribers in the UK, where sole traders cannot be told apart in any bought list.
Deliverability adds another layer. Corporate mail passes through gateways and business tenants with their own reputation systems, and cold mail produces the complaints and trap hits described in Consent Methods. Collecting consent remains the only strategy that works in every one of these markets.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- CAN-SPAM Act (United States)
- CAN-SPAM Rulemaking (16 CFR Part 316)
- CASL — Canada's Anti-Spam Legislation
- Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail