Skip to content

Cold Email Laws in the Netherlands: Article 11.7 and the GDPR (2026)

The short answer

Cold email to a recipient in the Netherlands is prohibited unless you can prove the recipient agreed to receive it beforehand, and that is true for businesses as well as consumers. The rule is Article 11.7 of the Telecommunicatiewet, the Dutch telecommunications act, and it opens with the burden of proof already assigned: unsolicited commercial electronic messages are banned "unless the sender can demonstrate" prior consent. The regulator, the Authority for Consumers and Markets (ACM), tells senders to be able to prove that consent up to five years after a message goes out. There are two escape routes for B2B senders, and both are narrower than most English-language guides suggest: an address the recipient itself published for the purpose of receiving offers, and your own existing customers.

Everything below comes from the consolidated statute as in force in August 2026, ACM's current business guidance, and the court ruling on the first Dutch B2B spam fine. It corrects several older guides, including earlier material on this site.

The axis almost every guide gets wrong

Most cold email guides sort the Netherlands with a legal-form test: a BV or NV is a legal person, so you may email it with an unsubscribe link; a sole trader is a natural person, so you may not. Both halves of that are wrong under the current statute.

The B2B exception in Article 11.7, third paragraph, applies to "a legal person or a natural person acting in the exercise of his profession or business". A sole trader acting commercially sits inside the same exception as a BV, so legal form is not what protects them. What actually decides the question is the address. The exception only covers electronic contact details that the recipient has designated and published for receiving unsolicited commercial communication, and even then the details must be used "in accordance with the purposes the end-user attached" to them. An info@ address published so customers can reach support is not an address designated for sales pitches. A scraped address is not designated for anything at all.

So the axis is not who the recipient is. It is what the published address is for, and almost no Dutch company publishes an invitation to pitch it. The practical rule collapses back to paragraph 1: consent you can prove.

What Article 11.7 actually says

The structure of the article is worth knowing, because each paragraph is a separate gate:

  • Paragraph 1 bans unsolicited electronic messages for commercial, idealistic or charitable purposes unless the sender can demonstrate prior consent from the end-user. "End-user" includes companies. Charity and non-profit outreach is inside the ban, not outside it.
  • Paragraph 3 is the B2B exception described above, with a second branch: if the recipient is established outside the European Economic Area, Dutch consent rules step aside and the destination country's rules apply instead.
  • Paragraph 4 is the existing-customer exception: contact details obtained from your own customer in the context of a sale may be used for offers about your own similar products or services, provided you offered a free and easy objection at the moment of collection and repeat it in every message.
  • Paragraph 7 imports the commercial-communication rules of Article 3:15e of the Dutch Civil Code and adds two requirements of its own: every message must state the real identity of the party on whose behalf it is sent, and a valid postal address or number where the recipient can demand the messages stop.

The outside-EEA branch cuts both ways. A Dutch agency prospecting into the United States is judged under American rules such as CAN-SPAM rather than Article 11.7. A US or UK sender prospecting into the Netherlands gets no mirror-image relief, because the recipient sits inside the EEA.

The published-address exception, read closely

Because this exception carries most of the weight in vendor marketing, it deserves a close reading. Two conditions stack. First, the recipient must have designated and made the address known for receiving unsolicited commercial messages. Second, your use must match the purpose the recipient attached to it. A procurement page that says "suppliers of packaging materials can offer here" is a designated address, and it is designated for packaging offers, not for pitching SEO services.

The tell for how narrow this is in practice: ACM's own guidance page for businesses does not mention the exception at all. It names prior consent and the existing-customer route, and nothing else. When the regulator's page for senders skips a defense entirely, plan on arguing that defense in writing to a case officer rather than relying on it at scale.

The existing-customer route

Paragraph 4 is the workhorse for lawful Dutch email marketing, and its edges matter. The details must come from a sale, ACM describes it as messages related to earlier purchases, so a whitepaper download or an unpaid trial signup does not obviously qualify. The offer must concern your own similar products or services, not a partner's. And the objection mechanics are mandatory twice over: at collection and in every message afterwards. ACM adds teeth of its own: no pre-ticked boxes, no consent buried in general terms, no alias sender names, and unsubscribing must be fast, free, and not paid for with personal data, so an unsubscribe form that demands details before it works is itself a violation in ACM's reading.

The rule almost every template breaks

Here is a countable test. Take any ten cold email templates from a public template library and count how many carry a postal address. Paragraph 7 requires a valid postal address or number for stop requests in every commercial message, on top of naming the real party behind the send. This applies to consented campaigns too. A perfectly opted-in newsletter with no postal address and a cute sender alias fails Article 11.7 on mechanics alone. If you fix only one thing after reading this page, fix the signature block.

Fines, and what Companeo teaches

The ceiling today is 900,000 euros per violation or, if that is more, 1 percent of the company's turnover, and the maximum doubles when the same or a similar violation recurs within five years of an earlier final fine. Liability is wider than the person who presses send: ACM names the sender who orders the campaign and the suppliers of address files as equally on the hook.

The precedent every Dutch B2B sender should know is Companeo. The company sent close to 15 million commercial emails to mainly business recipients between late 2009 and early 2011, from a quote-request form that subscribed everyone regardless of what they ticked, under a partner-consent clause too vague to mean anything, with mailings sent under a name recipients did not recognize. It took 680 complaints, the fine was 100,000 euros, and the appeals court upheld it in 2016 at a reduced 75,000 euros. The ruling settled three questions senders still ask. The regulator does not have to warn you before fining you. Incorporating abroad does not help: the court applied Dutch law to a Belgian-law company with a Dutch establishment that aimed Dutch-language mailings at Dutch businesses. And deregistering from the trade register mid-case undid nothing.

GDPR is the second lock, not a key

A work email address that names a person is personal data, so a prospect list of [email protected] addresses puts you inside the GDPR before you send anything. Think of Dutch cold email as a door with two locks. The GDPR governs holding and enriching the list. Article 11.7 governs sending to it. In October 2024 the EU Court of Justice ruled in the KNLTB case (C-621/22), against the Dutch privacy regulator's stricter line, that purely commercial interests can qualify as legitimate interests under the GDPR. That ruling loosened the first lock for B2B list-building. It did nothing to the second, because Article 11.7 never asks what your GDPR basis is. Anyone selling you "legitimate interest makes Dutch cold email fine" has unlocked the wrong door. This regime is also not about to change: the EU proposal that would have replaced it, the ePrivacy Regulation, was withdrawn in February 2025, leaving the 2002 directive and Article 11.7 as the law for the foreseeable future.

Thinking of calling instead

The phone route tightened in 2021. Unsolicited marketing calls to natural persons require prior consent, which covers consumers, sole traders and partners in a partnership. Calling the switchboard of a BV remains outside that consent rule, which makes the phone one of the few remaining unsolicited channels for reaching Dutch corporates, subject to the same published-purpose logic for the number you dial. France has since gone further and banned consumer cold calling outright in 2026, see our France cold calling ban analysis, and Dutch enforcement watches the same direction of travel.

What lawful Dutch outreach looks like

None of this means the Dutch market is closed. It means the motion is consent-first:

  • Earn the opt-in before the email. Landing pages, events, webinars, content that trades value for a real marketing opt-in, and referral introductions all produce addresses you may email. LinkedIn outreach runs under the platform's own rules rather than Article 11.7, though the GDPR still governs any scraping behind it.
  • Build the proof while you build the list. Record what was agreed, when, and through which form, and keep it five years. A consent you cannot evidence is treated like no consent.
  • Fix the mechanics in every send. Real sender identity, a working unsubscribe that is free and instant, and a postal address in the footer.
  • Work your customer base. Map which of your products count as similar, and mail existing buyers under the paragraph 4 exception with an objection line in every message.
  • Route true cold volume outside the EEA. The same list-building engine can run consent-first in the Netherlands and conventional cold outbound into the US under CAN-SPAM.

This split-by-jurisdiction design is exactly what our cold email marketing team builds, with the list research and enrichment handled by our lead generation service. Dutch-language guides for the local market live on our Dutch site, imisofts.nl.

The bottom line

The Netherlands is not the permissive middle ground of Europe. It extended its spam ban to business recipients back in 2009, its regulator expects five years of consent evidence, its courts fine without warning, and its two B2B exceptions are narrow enough that ACM does not bother advertising one of them. Read the neighboring regimes together, our Germany guide, the France guide and the GDPR compliance overview, and the pattern is consistent: in Northern Europe the winning outbound motion is consent capture plus flawless mechanics, not bigger lists. For market context beyond the law, tactics, personas and localization, see our Netherlands B2B outreach guide, which we have updated to match the legal reality on this page.

Want outbound that books meetings in the Netherlands without an ACM complaint in the pipeline?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Generally no. Article 11.7 of the Telecommunicatiewet bans unsolicited commercial electronic messages unless the sender can prove prior consent, and the ban covers business recipients as well as consumers. The exceptions are narrow: addresses a company published specifically for receiving offers, your own existing customers for similar products, and recipients established outside the EEA, who fall under their own country's rules.

No. An unsubscribe link does not legalize an unsolicited email in the Netherlands. The B2B exception only covers contact details the company itself designated and published for receiving unsolicited commercial communication, used for the purpose it attached to them. A general contact address on a website does not meet that test.

No. Scraped addresses were never designated by the recipient for receiving offers, so they fail the exception's first condition. ACM's own guidance for businesses does not even mention the published-address exception, which is a good indication of how rarely it applies in practice.

Up to 900,000 euros per violation or 1 percent of the company's turnover if that is higher, and the maximum doubles for a repeat of the same or a similar violation within five years of an earlier final fine. Liability covers whoever presses send, whoever ordered the campaign, and suppliers of the address list. The Companeo case showed ACM does not need to warn a company before fining it.

No. The GDPR and the Telecommunicatiewet are two separate locks. The EU Court of Justice ruled in the KNLTB case in October 2024 that commercial interests can qualify as legitimate interests under the GDPR, which helps with holding and enriching a B2B prospect list. Sending the email is governed separately by Article 11.7, which requires provable consent regardless of your GDPR basis.

No. Dutch law requires consent you can prove, not a specific signup flow. A single clear opt-in is valid if you can evidence what was agreed, when and how, and ACM expects that proof to be available for up to five years after sending. Double opt-in is simply the easiest way to create that evidence, and effectively expected in Germany.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us