Skip to content

Cold Email Laws in Ireland: Per-Email Fines, But Warned First

September 5, 2026. Ireland is the last large English-speaking market most outbound teams add to a sequence without checking the rules, on the theory that an EU country with a Data Protection Commission in Dublin must simply be "GDPR, so no." The actual law is narrower and stranger than that. The statute puts the burden of proving consent on the sender, treats every email as a separate offence, and allows a fine of up to 250,000 euro on indictment. Yet the largest penalty the DPC has ever published for marketing offences is 6,000 euro, and in 2025 it closed 275 investigations, sent 50 warning letters and prosecuted nobody. Here is what the regulation actually says, what the regulator actually does, and what a business sending to Irish inboxes should do about the gap.

The statute: S.I. 336/2011, Regulation 13

Ireland implemented the ePrivacy Directive through S.I. No. 336 of 2011. Regulation 13 is the whole game for email, and it has not been amended since 2011; the 2019 and 2022 instruments that touched the Regulations changed definitions, not this rule.

  1. Individuals are opt-in. Regulation 13(1) bars direct marketing email to a subscriber or user who is a natural person without prior consent. "User" is defined to include a natural person using a service for private or business purposes, so a named employee on a work mailbox is a natural person.
  2. The B2B carve-out has two limbs, and you need both. Regulation 13(2) says an email is not treated as sent to a natural person if the address "reasonably appears to the sender" to be used mainly in the recipient's commercial or official activity, and the message relates solely to that activity. Pitching your agency's services to [email protected] fits. Pitching Jane a holiday does not.
  3. Companies are opt-out. Regulation 13(4) covers subscribers other than natural persons: marketing to a legal entity becomes an offence once the recipient has told you it does not consent. The DPC's Viking Direct case study confirms this is the rule for business subscribers.
  4. Every message needs a valid contact address and must not disguise the sender. Regulation 13(10)(c) and 13(12). The absence of a working opt-out address is an offence on its own.
  5. The existing-customer exception is 12 months wide. Regulation 13(11) allows marketing of similar products to someone whose details were collected in the context of a sale, with an objection route at collection and in every message, only where the sale was not more than 12 months earlier.
  6. The onus is on you, per email. Regulation 13(14) places the burden of establishing unambiguous consent on the defendant, and 13(13)(b) makes each email a separate offence.

What the fines are on paper

On summary conviction the penalty is a class A fine, which the Fines Act 2010 caps at 5,000 euro, and it applies per email. On indictment a body corporate faces up to 250,000 euro and a natural person up to 50,000 euro. Regulation 25 adds a separate offence for any officer whose consent, connivance or neglect led to the company's offence, and Regulation 16(2) gives anyone who suffers loss a right to damages. The DPC may prosecute without first attempting an amicable resolution.

What the DPC actually does

The published record from the DPC's own prosecution releases reads very differently from the statute. Guerin Media, a publisher, was warned in 2013 and 2016, convicted in 2018 on four sample charges including emails to three individuals at their workplace addresses, and fined 4,000 euro. It was prosecuted again in 2022 for three emails from a stale contact list and fined 6,000 euro plus 1,000 euro costs. That 2022 outcome is the largest the DPC has published. Viking Direct, prosecuted under the business-subscriber rule for one email sent after three opt-outs, got the Probation Act. Alpha Wealth sent two emails to two people in January 2023 after a 2022 warning and was told to pay 500 euro to each recipient. In 2024 the DPC concluded 146 investigations, prosecuted eight companies and the outcomes totalled 9,725 euro in charitable donations, with Supermac's paying the most at 3,500 euro for five emails sent after an opt-out. Sky Ireland, Google Ireland and Stella Novus each paid 1,500 euro, and all three had used third-party processors.

Then 2025. Complaints about electronic marketing rose to 245, 73% of them about email. The DPC concluded 275 investigations, up 88%, and issued 50 warning letters. Its 2025 annual report records no marketing prosecution at all.

What it means for operators

Read the pattern, not the maximum. In every prosecution the DPC has published, the company had been warned or convicted before, and the trigger for court was usually an ignored opt-out or a message to someone who had already said no. The practical rule for a business sending into Ireland is therefore simple: the first complaint is a warning letter, the second is a court date, and an ignored unsubscribe is what turns one into the other. That makes suppression hygiene, not consent paperwork, the thing to get right first. If your sending infrastructure cannot guarantee that an opt-out on one domain suppresses the contact across every domain and every sequence, you are running the exact fact pattern the DPC prosecutes.

Second, use the B2B carve-out honestly. Regulation 13(2) is genuinely useful: a relevant, work-related pitch to a work address is not treated as marketing to a natural person. It fails the moment the offer stops relating solely to the recipient's commercial activity, or the address does not reasonably look like a work address. Consumer-style offers, prizes and generic newsletters to named employees do not qualify.

Third, remember that GDPR still sits underneath. Recital 47 says direct marketing may be a legitimate interest, Article 21 gives an absolute right to object that you must flag at the latest in the first communication, and Article 14 requires privacy information at first contact when you sourced the address elsewhere. The DPC's own legal-bases guidance says consent is usually required under Regulation 13 and legitimate interest fills the space ePrivacy leaves, which for email is mostly the 13(2) work-address case.

Fourth, the 12-month soft opt-in is the trap for agencies inheriting client lists. A customer from 2024 is not a customer for this purpose. Check the date of the last sale before a "past clients" campaign goes out.

A compliance checklist for Irish sends

  1. Segment by address type. Named work addresses under 13(2), generic and legal-entity addresses under 13(4), consumers under 13(1). Different rules, different risk.
  2. Keep the offer inside the recipient's commercial activity for every 13(2) send, and be able to say why the address reasonably appeared to be a work address.
  3. One suppression list across all sending domains, honoured immediately. This is the single behaviour that separates a warning letter from a prosecution.
  4. Identity and a working address in every email. Missing either is an offence even where consent exists.
  5. Log consent evidence per contact. Regulation 13(14) puts the onus on you.
  6. Date-check the soft opt-in. Twelve months from the sale, not from the last email.

Ireland sits alongside the UK in treating corporate subscribers as opt-out and individuals as opt-in, but with a narrower B2B test and a regulator that prosecutes repeat offenders in the District Court rather than issuing six-figure notices. If you want the market context, our guide to cold email in Ireland covers Dublin's tech sector; for the EU-wide rules underneath, see GDPR cold email compliance. If you would rather have the segmentation and suppression built once and run for you, that is what our cold email service does for every market we send into.

Sending into Ireland and want the segmentation built right?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Largely yes, with two tests. Under Regulation 13(2) of S.I. 336/2011 an email to a named work address is not treated as marketing to a natural person if the address reasonably appears to be used mainly for the recipient's commercial activity and the message relates solely to that activity. Emails to companies themselves (generic or legal-entity addresses) are opt-out under Regulation 13(4). Consumer-style offers to named employees need prior consent.

On summary conviction a class A fine of up to 5,000 euro, applied per email because each message is a separate offence. On indictment up to 250,000 euro for a company and 50,000 euro for an individual. Officers can be prosecuted separately for consent, connivance or neglect, and recipients who suffer loss can claim damages. In practice the largest published outcome is 6,000 euro.

Rarely, and only after a warning. Published prosecutions include Guerin Media (4,000 euro in 2018 and 6,000 euro in 2022), Viking Direct (Probation Act), Alpha Wealth, Supermac's and several others whose outcomes were charitable donations of 500 to 3,500 euro. In 2024 eight companies were prosecuted for a combined 9,725 euro. In 2025 the DPC sent 50 warning letters and published no prosecutions.

No. A legal entity is a subscriber other than a natural person, so Regulation 13(4) applies: you may email until the company tells you it does not consent, after which each further email is an offence. Every message must still identify the sender and include a valid address for opt-out requests.

Twelve months from the sale. Regulation 13(11) permits marketing of your own similar products to someone whose details you obtained in the context of a sale, provided you offered an objection route at collection and in every message, and only where the sale was not more than 12 months before the email.

The sender. Regulation 13(14) places the onus of establishing that the recipient unambiguously consented on the defendant. Keep a per-contact record of the basis you relied on, whether that is consent, the Regulation 13(2) work-address test, or the Regulation 13(4) business-subscriber rule.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us