Skip to content

Cold Email Laws in Austria: A Three-Email Sequence Has a Price

September 5, 2026. Austria is the one country where the standard three-email cold sequence has literally been tried in court and priced. In December 2024 the Federal Administrative Court upheld fines against a video marketing agency owner for a three-step sequence sent to a company managing director: 600 euro for the first email, 600 for the second, and 800 for the "just checking one last time" follow-up, which was treated as intentional because it went out after the authority had already asked him to explain the first two. Austria's rule is opt-in for everyone, business recipients included, the courts read consent to the GDPR standard, and the famous Austrian "Robinson list" is misunderstood twice over. Here is the law as it stands in the Telecommunications Act 2021 and how it has been applied.

The rule: Section 174 of the TKG 2021

Section 174(3) of the Telekommunikationsgesetz 2021 makes it inadmissible to send electronic mail, including SMS, for direct marketing without the recipient's prior consent. The word is recipient, with no consumer limitation. The federal ministry's own guidance states the ban applies in the business and non-business sphere alike, and in July 2026 the Federal Administrative Court rejected the B2B argument expressly.

  1. Direct marketing is read widely. Any content that promotes a product, service or idea counts, including an invitation to visit a website. Calling it a newsletter or information does not help.
  2. Consent means GDPR-grade consent. A listing in a directory or on a company website is not implied consent, and an unsubscribe link does not cure its absence, because Section 174 is an opt-in rule.
  3. The existing-customer exception has four cumulative conditions under Section 174(4): the address was obtained in connection with a sale to the sender's own customer; the message advertises the sender's own similar products; the recipient was given a free and easy way to refuse at collection and in every message; and the recipient has not refused in advance, in particular by registering on the ECG list. A purchased lead is not a business relationship, so the first condition fails for every cold list.
  4. Some things are prohibited even with consent under Section 174(5): concealing the sender's identity, failing to make the message recognisable as commercial and identify the principal, and omitting an authentic address for a stop request.
  5. Foreign senders are caught. Section 174(6) deems an offence not committed in Austria to have been committed where the unwanted message reaches the user's connection.
  6. The old 50-recipient rule is gone. The 2003 Act required consent for any email to more than 50 recipients regardless of content. That clause was deleted from December 1, 2018, three years before the 2021 Act, and sources still repeating it are out of date.

The ECG list, and what it does and does not do

Section 7(2) of the E-Commerce Act obliges RTR, the regulator, to keep a free list on which persons and companies can register to refuse commercial email, and providers who send commercial email lawfully without prior consent must observe it. Senders check addresses at RTR's query page, singly or by uploading a file, or through a REST API after registering for a key; addresses can be submitted hashed, batches of up to 150,000 are the guideline, and the API returns the addresses that are not on the list. Whole domains can be registered. RTR said in 2016 that the list was being queried about a thousand times a day.

Two corrections to what is usually written about it. First, the ECG list is not the Robinson list run by the chamber of commerce for postal mail; they are different lists for different channels. Second, ignoring the ECG list carries no fine of its own: the E-Commerce Act's penalty section does not list Section 7. Its legal effect sits inside Section 174(4) of the TKG, where registration destroys the existing-customer exception. For a cold emailer, who never had that exception, the list changes nothing about the underlying offence, which is sending without consent.

Penalties

Under Section 188 of the TKG 2021, sending email contrary to Section 174(3) or (5) carries a fine of up to 50,000 euro, with substitute imprisonment of up to six weeks if it cannot be recovered; that figure is unchanged in the version taking effect on October 1, 2026. Marketing calls without consent carry up to 100,000 euro. Commercial or repeated commission is an aggravating factor and the unlawful gain must be taken into account. Breaching the E-Commerce Act's labelling duties costs up to 3,000 euro. In every published case the fine came with 10 percent of its value as authority costs and a further 20 percent if an appeal was lost, and the managing director was personally liable with the company jointly liable.

The cases

The December 2024 decision described above is the clearest. The owner knew only that a website existed to check the list and had not checked it; emails one and two were fined at 600 euro each after a reduction, and email three at 800 euro as at least conditionally intentional, roughly 1,700 euro in total with costs. In May 2025 a sole trader with a law doctorate sent one email advertising addressable TV to a lawyer whose address came from the firm's website and who was on the ECG list; the court refused a warning or "advice instead of punishment" and confirmed 500 euro, 1 percent of the maximum, 650 euro with costs. In July 2026 a managing director who had bought B2B contact data from a directory publisher and sent a "newsletter" with product links argued that purchased data implied consent and that B2B was different; the court confirmed the fine, noted that the seller's own terms forbid inferring consent from listed addresses, and held that having no pre-send consent check and no staff instructions meant no effective control system. The Administrative Court held in 2017 that 31 newsletters to one recipient were one continuing offence, but that the authority may raise the fine step by step towards the ceiling with the number of emails and recipients, and that sending without a consent control system points to intent.

The Data Protection Authority has added a second front. In October 2025 it held that the lawfulness of a marketing email is governed by Section 174 as the specific rule, so a GDPR legitimate-interest assessment is excluded, and that a breach also infringes the recipient's right to secrecy, which lets the recipient complain to the DPA as well. In a separate 2025 decision it ordered a B2B data broker to erase a professional's record and notify recipients.

What it means for operators

Austria removes every argument outbound teams normally make. There is no B2B exception, no implied consent from a website or directory, no legitimate-interest route, and no cure by unsubscribe link. The fines in practice are small, a few hundred euro per email, but they are personal to the managing director, they rise with each follow-up, and a follow-up sent after a complaint is treated as intentional. If Austria is in your territory, the compliant approach is consent captured through a channel you may use, then email, and a single check against the ECG list for any customer marketing. Recruitment outreach and genuinely non-commercial messages sit outside the rule, but the courts read commercial widely.

Checklist for Austrian sends

  1. Consent before the first email, to the GDPR standard, logged per contact.
  2. No purchased lists. The July 2026 decision is directly on point.
  3. Identify the sender, label the message commercial, include a stop address, even where consent exists.
  4. Check the ECG list for any existing-customer campaign; registration switches the exception off.
  5. Stop on first complaint. The follow-up is the expensive email.
  6. Put a consent control system in writing. Its absence is read as intent.

Austria's neighbours are covered in our guides to Germany, which is also opt-in for B2B, and Switzerland, where the penalty is criminal. For the DACH region as a whole, the compliant pattern is consent capture first, then sending through infrastructure that enforces suppression across every identity, which is how our cold email service runs German-speaking segments.

Want a DACH outreach plan that starts with consent, not a purchased list?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

No. Section 174(3) of the Telecommunications Act 2021 prohibits sending email for direct marketing without the recipient's prior consent, and the word recipient carries no consumer limitation. The federal ministry states the ban applies to businesses and non-businesses alike, and the Federal Administrative Court rejected the B2B argument expressly in July 2026.

A free list kept by the regulator RTR under Section 7(2) of the E-Commerce Act, on which persons and companies register to refuse commercial email. Senders who lawfully email without prior consent, in practice existing customers, must check it, and registration switches off the existing-customer exception in Section 174(4). Ignoring the list carries no separate fine; the offence is sending without consent. It is not the postal Robinson list.

Up to 50,000 euro per case under Section 188 of the TKG 2021, with substitute imprisonment of up to six weeks if unrecoverable; unsolicited marketing calls carry up to 100,000 euro. Published cases show 500 to 800 euro per email, plus 10 percent costs and 20 percent more on a lost appeal, imposed on the managing director personally with the company jointly liable.

No. In July 2026 the Federal Administrative Court confirmed a fine against a managing director who bought business contact data from a directory publisher and argued the purchase implied consent. The court noted the publisher's own terms forbid inferring consent from listed addresses and held that a purchased lead is not a business relationship for the existing-customer exception.

Yes. Section 174(6) deems an offence not committed in Austria to have been committed at the place where the unwanted message reaches the user's connection. The ministry itself notes that proceedings against senders abroad are hard to pursue, but the law applies to them.

No. The Austrian Data Protection Authority held in October 2025 that Section 174 of the TKG 2021, implementing Article 13 of the ePrivacy Directive, is the specific rule governing marketing email, so a GDPR Article 6 legitimate-interest assessment is excluded. A breach also infringes the recipient's right to secrecy, giving them a separate route to complain to the DPA.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us