Stacked Creator

An independent publication on cold email, lead data and sales CRMs, edited in Japan.

No. 08 Guides, filed under Guide

Cold Email and GDPR: Which of 8 EU Countries Need Consent, and What the GDPR Adds (2026)

Cold email and GDPR: national email law comes first. In 4 of the 8 EU countries we checked, even emailing a company generally needs consent.

On this page 13 sections

Under the GDPR you can often email a business contact on legitimate interests. In the EU, though, that’s the second question. The first is whether national email law lets you send the email at all, even to a company.

Quick answer

National email law comes first (we go by the recipient’s country): of eight countries we checked, Germany, Spain, Italy and the Netherlands generally require consent even for companies; the other four allow some business email. Then the GDPR for named contacts: a legitimate-interests record, a notice by your first email, honoring objections. Tracking needs consent (EDPB). Checked October 2, 2026.

Not legal advice. We read the laws and regulator pages linked here on September 29, 2026 and checked them again on October 2, 2026. No lawyer has reviewed this page. It covers email to business prospects in the EU. It doesn’t cover consumer marketing, SMS, calls or website cookies, or the UK, where PECR and the UK GDPR apply instead. Our overview shows how the EU rules compare with the US, UK, Canada and Australia.

Why isn’t the GDPR the first question for cold email in the EU?

Because the rules for marketing email sit in each country’s own law. If that law doesn’t allow the email, no GDPR legal basis can make it lawful.

Those national laws implement the EU’s ePrivacy Directive, which sets the minimum. The Directive requires prior consent for marketing email (article 13(1)), but only for subscribers “who are natural persons.” For companies, each country just has to make sure their “legitimate interests” are “sufficiently protected” (article 13(5)). That’s why the answer for a business address changes at every border. Some countries extended the consent rule to companies; others didn’t.

The European Data Protection Board (EDPB), the body of EU data protection regulators, confirms the order in its draft guidelines on legitimate interests. National rules “may occasionally impose consent requirements that go beyond” the Directive, it says, for example “with respect to direct marketing towards professionals.” And if national law doesn’t permit the email, “there would be no legitimate interest that the controller could invoke” for it.

No single EU rule will replace the national ones for now. The Commission withdrew its proposed ePrivacy Regulation in a notice of October 6, 2025 (OJ C/2025/5423), so the 2002 Directive and the national laws built on it still apply.

Which country’s law? We go by the recipient’s country. That’s our reading of how these laws apply, not a rule any of the texts states, and we didn’t check how far each law reaches senders abroad. At least one reaches further: the Dutch act also has a rule for business recipients outside the EEA (11.7(3)(b)). If you send from an EU country, check its law too.

The answer is at the start of each cell in the second column, for a company’s shared address, and the third, for a named employee or sole trader. The last column lists what every email to that country must include.

Country and lawA company or generic address (info@, sales@)A named employee or a sole traderEach email must also carry
Germany9
Unfair Competition Act (UWG) s.7; no version date on the page
Consent needed: prior express consent (s.7(2) no. 2). The looser “presumed consent” rule for businesses covers phone calls only (s.7(2) no. 1). Exception: your own customers, for similar products, on four conditions (s.7(3))Consent needed, as for a companyA sender identity that isn’t hidden, and a valid address for stop requests (s.7(2) no. 3)
Spain10
Information Society Services Act (LSSI) arts 20–22; consolidated text last updated January 23, 2025
Consent needed: only if the recipient asked for it or expressly authorized it (art. 21.1). “Recipient” includes companies (annex, d). Exception: an earlier contract, for similar products, with an opt-out (art. 21.2)Consent needed, as for a companyClearly commercial, with the sender clearly identifiable (art. 20.1), and a valid email or other electronic address for opting out (arts 21.2, 22.1)
Italy11
Privacy Code art. 130; text in force since September 19, 2018
Consent needed from the “contraente” (art. 130(1)–(2)), a term that includes companies and other legal persons (art. 121(1-bis)(f)11). Exception: addresses your customers gave you in a sale, for similar services, with an opt-out each time (art. 130(4))Consent neededA sender identity that isn’t disguised, and a contact point where the person can exercise their GDPR rights (art. 130(5))
Netherlands12
Telecommunications Act art. 11.7; version in force from August 15, 2026
Only if you can show prior consent (11.7(1)), or you use contact details the company designated and published for this kind of message, for the purposes it attached to them (11.7(3)(a)). Existing customers: similar products, with an opt-out (11.7(4))Only if you can show consent or use published contact details, as for a company (11.7(3) also covers people acting in their profession or business)Your real identity, and a valid postal address or number for stop requests (11.7(7))
France13
CNIL guidance of June 10, 2026, on CPCE art. L34-513 (version in force since July 26, 2020)
No consent needed. L34-5 requires consent only for a natural person’s contact details, and the CNIL puts generic addresses such as info@ or contact@ outside its B2B principlesNo consent needed, but only for a message about the person’s job (the CNIL’s example: presenting software to a company’s IT director). They must also have been told their address could be used for prospecting, and be able to objectWho is sending, and a simple way to refuse further messages (CNIL); valid contact details for stop requests, and a subject related to what you offer (L34-5)
Ireland14
S.I. 336/2011 reg. 13, as made; the Irish Statute Book’s directory (updated to September 17, 2026) lists no amendment to reg. 13
No consent needed, but stop once the company tells you it doesn’t consent (reg. 13(4))Consent needed (reg. 13(1)), unless the address reasonably appears to be used mainly for work and the email relates only to that work (reg. 13(2)). Then only the stop-on-request rule appliesA valid address where you can be contacted (13(10)(c)), a sender identity that isn’t concealed, and a valid address for stop requests (13(12))
Sweden15
Marketing Act (2008:486) ss.19–20; amended up to SFS 2022:656
No consent needed: the s.19 consent rule covers marketing to a natural personConsent needed for a natural person, with an existing-customer exception (s.19). The Act doesn’t say whether a named work address counts, and we didn’t check the regulator’s guidanceA valid address for stop requests, also when you email a company (s.20)
Belgium16
Royal Decree of April 4, 2003 on email advertising, arts 1–2; no update date on the page
No consent needed if the address is impersonal (art. 1, 2°) and clearly belongs to the company. The decree’s explanatory report gives info@, contact@ and sales@ as examplesConsent needed: the report says [email protected] addresses belong to natural persons. Exception: your own customers, for similar products (art. 1, 1°)The decree covers opt-outs: confirm each one by email and act on it within a reasonable time, and keep a list (art. 2). The Directive (art. 13(4)) requires Belgium to ban hidden senders and emails without a valid stop address; we didn’t check where Belgian law does this

Law checked: October 2, 2026. Laws change; open the linked text before you rely on a row. Not covered: the other 19 member states. We couldn’t open the official texts for Austria, Denmark or Finland when we built the table on September 29.

Two exceptions in this table are missing from some country lists online: Belgium’s for impersonal company addresses, and the Netherlands’ for addresses a company published for this kind of message. And Germany’s “presumed consent” for businesses is a phone rule. For email, the statute asks for prior express consent from companies too.

Does emailing name.surname@company change anything?

Yes, for the GDPR: a named work address is personal data, and [email protected] is not. Those are the European Commission’s own examples, and the GDPR covers any information about an identifiable person (article 4(1)). So the GDPR steps below apply to every named address on your list, but not to a shared mailbox that identifies no one.

National email laws draw their own line, shown in the table’s third column. Belgium, for example, needs consent for name.surname addresses but not for impersonal ones, while Ireland and France allow named work addresses when the email is about the person’s job.

How do you document legitimate interests for a prospect list?

Write it down before the first send: what you want to achieve, why emailing these people is necessary for it, and why they’d expect to hear from you. The GDPR requires you to be “able to demonstrate compliance” (article 5(2)).

Recital 47 is the line sellers quote: direct marketing “may be regarded as carried out for a legitimate interest.” The same recital says this “would need careful assessment,” including whether people “can reasonably expect” the processing. The EDPB’s draft guidelines set three conditions that must all be met: a legitimate interest, necessity, and a balancing test the person’s rights don’t win. They say to make the assessment at the outset and document it. For marketing, they add, consider less intrusive means, and ask whether the person would expect marketing about this kind of product.

One way to record it for a single campaign:

FieldWhat to writeWhy it’s there
PurposeWhat you’re offering, and to which roles at which kind of companyThe interest you rely on (article 6(1)(f)); it also goes in your notice (article 14(2)(b))
Recipient country and its email ruleThe result from the table above for each country on the list, and what you did with the rows that need consentNo legitimate interest can be invoked if national law doesn’t permit the email (EDPB)
Where the addresses came fromThe source for each batch, and what the supplier told you about how it collected themYour notice must name the source (article 14(2)(f)). A list supplier must be able to show the data was obtained lawfully and may be used for advertising (European Commission)
Why email, and why this personHow the offer relates to the person’s role, and why fewer people or less data wouldn’t doNecessity and “data minimisation” (EDPB)
Reasonable expectationsWhy someone in this role would expect an email like thisRecital 47; EDPB
SafeguardsTracking off, objections honored before the next send, a short retention periodThey can tip the balancing test (EDPB)
Outcome, date and who decidedGo or no-go, and for which countriesAccountability (article 5(2))

An example layout, not a form the law prescribes. GDPR, EDPB and Commission texts checked October 2, 2026.

What must your first email to an EU prospect say?

If you didn’t get the address from the person, the GDPR requires a privacy notice within a month, or with your first email if you send sooner. The right to object must be stated clearly and separately (articles 14(3) and 21(4)).

The timing rule says “at the latest within one month,” or, if you use the data to contact the person, “at the latest at the time of the first communication” (article 14(3)). The EU regulators’ transparency guidelines, endorsed by the EDPB, read the two together: if you email before the month is up, the notice is due with that email (WP260 rev.01).

The full notice covers who you are, how to reach you, the purpose and legal basis, and your legitimate interest. It also covers the categories of data, where you got them, how long you keep them, and the person’s rights, including the right to complain to a data protection authority (article 14(1) and (2)).

Not all of it has to sit in the email. The same guidelines accept a layered notice with a link to the rest. But the first layer, which for cold email is the email itself, should give the purpose, your identity and a description of the person’s rights. The objection line has its own rule: bring it “explicitly” to the person’s attention, “presented clearly and separately from any other information” (article 21(4)).

Opening lines that map to those rules might look like this. We wrote them for this page; we haven’t sent them to anyone.

Example lineWhat it covers
“Why you’re getting this: I found your work address on [source] and wrote because [reason tied to your role].”The source (article 14(2)(f)) and why they’d expect it (recital 47)
“We rely on our legitimate interest in [purpose]. You can ask to see, correct or delete your data, and complain to your data protection authority. Full notice, including how long we keep your data: [link to notice].”Purpose, legal basis and the interest (article 14(1)(c) and 14(2)(b)), and the person’s rights (14(2)(c) and (e)), which the guidelines want in the first layer; the retention period and the rest sit behind the link
“You can object at any time: reply ‘stop’ and we won’t email you again.” (on its own line)The right to object, stated separately (article 21(2) and (4)); your reply address is where they can ask you to stop (ePrivacy article 13(4))
“[Your name], [company name], [postal address]”Your identity and contact details (article 14(1)(a)) and a sender who isn’t hidden (ePrivacy article 13(4)); a postal address also meets the Netherlands’ “postal address or number” wording (11.7(7))

After that first email, stop as soon as someone objects. The data “shall no longer be processed” for marketing (article 21(3)), and the EDPB’s draft calls this right unconditional. If a prospect asks where you got their address, tell them what you know about the source within one month (articles 12(3) and 15(1)(g)). Belgium and Ireland add opt-out rules of their own; see their rows in the table.

Can you track opens and clicks in emails to EU prospects?

Only with consent, on the EDPB’s reading. A tracking pixel or tracked link stores information on the recipient’s device and reads it back. ePrivacy article 5(3) allows that only with consent, unless it’s strictly necessary.

The EDPB’s Guidelines 2/2023 name the email case directly: a sender “may include a tracking pixel to detect when the receiver reads the email.” Sending pixels and tracked links “does constitute storage.” Collecting what they send back is “gaining of access.” The EDPB’s legitimate-interests draft adds that consent is then likely the right legal basis for the data you collect, which normally rules out legitimate interests for it.

France’s regulator has written rules for this. The CNIL’s recommendation on tracking pixels in email (April 14, 2026) applies to pixels in any email, whatever the recipient: customer, prospect or employee (Q&A of July 22, 2026). Tracked links aren’t directly covered, the Q&A says, but French law’s consent rule for trackers still applies to them (article 82 of the French Data Protection Act).

The recommendation lets a sender skip consent for a pixel used only to measure deliverability, but only in transactional emails and emails the recipient consented to. The Q&A says a prospecting email sent without consent under the existing-customer exception doesn’t qualify.

A change is proposed but not adopted. The Commission’s Digital Omnibus proposal of November 19, 2025 would move these consent rules into the GDPR, while keeping consent as the main rule for accessing a device. The European Parliament’s tracker, updated August 1, 2026, shows it not yet adopted.

In practice: send to EU recipients with open and click tracking off, and judge campaigns by replies. That costs less than it sounds; see why open data from cold email is unreliable anyway.

Who enforces these rules, and what can a breach cost?

Two sets of enforcers. Each country’s data protection authority enforces the GDPR (article 51). Its fines go up to €20 million or 4% of worldwide annual turnover, whichever is higher, for breaches of the core principles and people’s rights (article 83(5)). The email laws are enforced by whoever each country names, under penalties it sets (ePrivacy article 15a).

The Directive also makes countries let anyone “adversely affected” by a breach of their email rules go to court, including an email provider protecting its business (article 13(6)). Three of the eight countries, from their own texts:

CountryWho acts on a marketing emailMaximum in the text
IrelandProsecution: each unsolicited email is a separate offence (reg. 13(13))A fine on summary conviction; on indictment, up to €250,000 for a company and €50,000 for an individual (reg. 13(15))
SpainThe data protection agency imposes the fines for the email offences (LSSI art. 43.1)Up to €30,000 for sending without meeting art. 21 (art. 38.4 d, art. 39.1 c); €30,001–€150,000 for mass sending, or insistent or systematic sending to the same recipient (art. 38.3 c, art. 39.1 b)
GermanyInjunctions sought by competitors, registered trade associations, qualified consumer associations, or chambers of commerce and crafts (UWG s.8(1) and (3))The Act’s €300,000 administrative fine (s.20(2)) covers ad calls and automated calling machines aimed at consumers without consent (s.20(1) no. 1), not email

Law checked: October 2, 2026. We didn’t check the penalties in the Netherlands, Italy, France, Sweden or Belgium.

Which countries this page covers, and how we checked

Eight of the 27 EU countries: the ones whose statute or regulator page we could read on September 29, 2026.

How we researched this: We read each country’s statute, or its regulator’s page, on September 29, 2026, read each one again on October 2, 2026, and cite the section in the table. Seven rows rest on the statute itself; France’s rests on the CNIL’s guidance and the statute it applies. On September 29, some official sites blocked automated access or showed no readable text: Austria’s RIS, Denmark’s Retsinformation, Finland’s Finlex and Ireland’s Data Protection Commission. We left those countries or pages out rather than rely on a secondary summary. EUR-Lex pages didn’t load for us that day either. We read the ePrivacy Directive, the GDPR and the withdrawal notice in the Publications Office of the European Union’s copies, linked in Sources. The tool settings further down come from each vendor’s help center or legal pages, read on the same two days. Nothing here is first-hand: we sent no emails and switched on no settings for this page. The only notes from our own accounts that we link to are on our Apollo pricing page. No lawyer has reviewed this page.

Two loose ends we couldn’t settle from the texts. Belgium’s decree still points to article 14 of a 2003 law, and we didn’t confirm where that rule now sits in Belgium’s Code of Economic Law. And Sweden’s rule for named work addresses is open, as noted in the table.

Is cold email legal in the EU? It depends on the country

Yes, to some recipients. Going by the recipient’s country, as we read these laws:

  • Germany, Spain or Italy: no first cold email without prior consent, to a company or a person. Your own customers buying similar products are the exception.
  • The Netherlands: only to addresses a company published for this kind of message, or with consent you can show.
  • France, Ireland, Sweden or Belgium: company-level addresses don’t need prior consent (in Belgium, impersonal ones only). For named people, check the table; each country draws the line differently.
  • Any named address you do email: a legitimate-interests record, a notice and a separate objection line in the first email, and tracking off.
  • The other 19 member states: read that country’s law before sending; the GDPR steps alone aren’t enough.

Which sending-tool settings help when you email EU prospects?

The first test on this page, whether a country’s law lets the email go out at all, is the one settings handle worst. The nearest setting, Apollo’s EU-wide block, can’t tell Germany from France as Apollo describes it, and none of the help articles we read describes a per-country option. So that sort happens in your list. After it, settings can switch tracking off, block people who objected and record your legal basis. Whether a send is lawful stays your call, and this isn’t legal advice.

Start in the spreadsheet. Add a recipient-country column and remove the rows for countries that need consent you don’t have, before you import anything. For a list you send by hand, add a notice page on your site and plain-text emails with tracking off. Keep objections in a sheet you check before every send. Settings earn their place once several people send from shared lists. Each row below pairs a rule above with a feature the vendor’s own help center documents, and says whether it acts per campaign or across a whole team.

Rule on this pageWhat a tool can doLimits the vendor documents
Tracking needs consent (ePrivacy art. 5(3))Apollo: an admin switch, “Forbid tracking on emails sent to residents of the European Union,” works across the workspace. Apollo then inserts no tracking pixels or tracking links for those contacts (help, September 29, 202617). lemlist: switch off “Track email opens” and “Track link clicks” in each campaign’s Settings > Tracking (help, July 15, 202618)Apollo’s switches work only when Apollo can determine a prospect’s location. Apollo lists open tracking itself on its Professional and Organization plans (help, September 4, 202617). lemlist tracks opens and clicks by default, campaign by campaign. It blocks sending with tracking on until a custom tracking domain is set up
The country’s consent rule (table above)Apollo: “Forbid email sending to residents of the European Union” and “Forbid prospecting of residents of the European Union” block EU-located people for every user in the workspaceThe switches cover the whole EU. The help article describes no per-country option, so as described they can’t let France through while holding Germany back
Objections (GDPR art. 21(3))lemlist: “Do not contact” blocks a person on every channel across all campaigns, and the activity log records when, from what source and by whom (help, September 24, 202618)lemlist lists it on all plans; see what each lemlist plan costs
Records of your legal basis (GDPR art. 5(2))HubSpot: a contact property, “Legal basis for processing contact’s data,” with values including “Legitimate interest - Lead” and “Freely given consent from contact” (knowledge base, September 28, 202619)Data privacy settings must be turned on first; listed for all products and plans

Help-center articles read September 29, 2026 and checked again October 2, 2026; dates are the pages’ own. Apollo’s help article adds one limit on removals: if someone asks Apollo to delete them from its database, people you’d already saved to your workspace aren’t deleted automatically. Vendors change features and plans often, so confirm each point in your own account.

What vendors’ own documents say about compliance: the two we read leave the legal questions above with you. Apollo’s help center says it “can’t advise whether GDPR applies to your business or whether your current processes are compliant,” and that you’re responsible for configuring Apollo. Instantly’s data processing addendum (last updated September 10, 2026) names you as the controller and Instantly as the processor. It applies Module Two of the EU standard contractual clauses to EEA transfers where you’re the controller. The GDPR makes the controller answer for compliance (article 5(2)), so the legal basis, the notice and each country’s consent rule stay with you, whichever tool you use.

For what Apollo costs beyond these switches, see what Apollo’s Free plan includes, with notes from our own Free account. If you’re choosing between lemlist and Instantly for other reasons, see how lemlist and Instantly compare on channels and price.

If your team prospects in Apollo, its switches line up with the table’s first two rows and cover every user at once. Match them to the country table before you rely on them. An EU-wide block also holds back the French or Irish company addresses the country table lets you email, so treat it as a safety net behind your country column, not a replacement for it.

Apollo.io

Best fit if you already find and email prospects in Apollo and want tracking or sending blocked for EU-located contacts across your team, not campaign by campaign. The switches are EU-wide and work only when Apollo knows where a contact is; Apollo’s help article doesn’t say which plans include them (checked October 2026).

Visit Apollo

Ad · Paid link: we earn a commission if you sign up through this link. It doesn’t change our recommendation.

FAQ

Is cold email legal in Germany?

Only with the recipient’s prior express consent, and that applies to a company’s address too (UWG s.7(2) no. 2). The exception is your own customers, for similar products, on four conditions (s.7(3)).

Does the GDPR apply if I email EU prospects from the US or the UK?

Very likely, if you’re pitching your services to named people in the EU. The GDPR covers a business outside the EU that processes the data of people in the EU in connection with “the offering of goods or services” to them (article 3(2)(a)). Such a business must also name a representative in the EU in writing (article 27). The exception is processing that is occasional, involves no large-scale processing of sensitive or criminal-offence data, and is unlikely to put people at risk. France’s CNIL adds that it can act against senders outside the EU whose email pixels track people in France. For the US, UK, Canada and Australia too, see how each of the five laws reaches senders in other countries.

Do I need double opt-in?

None of the sections cited above uses the term or requires a confirmation step for consent. What they ask for, where consent is needed, is consent you can prove. The Dutch rule bans the email unless the sender “can show” prior consent (11.7(1)). In an Irish prosecution, the sender must prove the recipient consented (reg. 13(14)).

Does a sending or data tool make your emails GDPR compliant?

No: the GDPR puts compliance on the controller, the business that decides why and how the data is used (articles 4(7) and 5(2)). If you decide whom to email, why, and with which tool, that’s you. A tool can switch off tracking, block contacts or record your legal basis, but no setting gives you consent a country requires or writes your legitimate-interests record and notice for you.

How long can I keep a prospect’s data if they never reply?

The GDPR sets no number of days. Data must be kept “for no longer than is necessary for the purposes” (article 5(1)(e)), and your notice must state the period or the criteria you use to set it (article 14(2)(a)). Pick a period for the campaign, write it in your legitimate-interests record, and delete non-responders when it ends.

Sources

  1. Directive 2002/58/EC (ePrivacy Directive), consolidated text of December 19, 2009, articles 5(3), 13 and 15a (the latest consolidation in the Publications Office’s records) — Publications Office of the European Union, accessed October 2, 2026
  2. Regulation (EU) 2016/679 (GDPR), OJ L 119, May 4, 2016 (PDF), recital 47 and articles 3, 4, 5, 6, 12, 14, 15, 21, 27, 51 and 83, checked against the English corrigendum of May 23, 2018 — Publications Office of the European Union, accessed October 2, 2026
  3. Withdrawal of Commission proposals, OJ C, C/2025/5423, October 6, 2025 (lists COM(2017) 10, the ePrivacy Regulation proposal) — Publications Office of the European Union, accessed October 2, 2026
  4. Legislative Train: Digital package (Digital Omnibus), updated August 1, 2026 — European Parliament, accessed October 2, 2026
  5. Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR, version 1.0 (adopted October 8, 2024, for public consultation), paragraphs 6, 12, 115, 117, 119, 121, 122 and footnote 143, and the consultation page (lists only version 1.0) — European Data Protection Board, accessed October 2, 2026
  6. Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, version 2.0 (adopted October 7, 2024), paragraphs 48–51 — European Data Protection Board, accessed October 2, 2026
  7. Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01, revised April 11, 2018), paragraphs 27 and 35–36, and the EDPB’s list of endorsed WP29 guidelines — European Data Protection Board, accessed October 2, 2026
  8. Data protection explained and Can data received from a third party be used for marketing? — European Commission (no date shown), accessed October 2, 2026
  9. Gesetz gegen den unlauteren Wettbewerb (UWG), s.7, s.8 and s.20 — Federal Ministry of Justice, gesetze-im-internet.de, accessed October 2, 2026
  10. Ley 34/2002 de servicios de la sociedad de la información y de comercio electrónico (LSSI), consolidated text last updated January 23, 2025, arts 20–22, 38, 39, 43 and annex — Boletín Oficial del Estado, accessed October 2, 2026
  11. Codice in materia di protezione dei dati personali (D.Lgs. 196/2003), art. 130 and art. 121 — Normattiva, accessed October 2, 2026
  12. Telecommunicatiewet, art. 11.7, version in force from August 15, 2026 — wetten.overheid.nl, accessed October 2, 2026
  13. Code des postes et des communications électroniques, art. L34-5 — Légifrance; La prospection commerciale par courrier électronique, SMS-MMS et automate d’appel (June 10, 2026), Pixels de suivi dans les courriers électroniques : la CNIL publie ses recommandations (April 14, 2026) and Questions-réponses sur la recommandation pixels (July 22, 2026; questions 1, 2, 3 and 5) — CNIL, all accessed October 2, 2026
  14. S.I. No. 336/2011, European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, reg. 13, and the legislation directory for 2011 statutory instruments (updated to September 17, 2026) — Irish Statute Book, accessed October 2, 2026
  15. Marknadsföringslag (2008:486), ss.19–20, amended up to SFS 2022:656 — Sveriges riksdag, accessed October 2, 2026
  16. Arrêté royal du 4 avril 2003 visant à réglementer l’envoi de publicités par courrier électronique, arts 1–2 and the Rapport au Roi — Justel, Belgian Official Journal, accessed October 2, 2026
  17. Configure GDPR Settings on Apollo (updated September 29, 2026) and Use Open Tracking (updated September 4, 2026) — Apollo.io Knowledge Base, accessed October 2, 2026
  18. Disable email tracking (July 15, 2026) and Use the Unsubscribes section (September 24, 2026) — lemlist Help Center, accessed October 2, 2026
  19. Track legal basis of processing in HubSpot (last updated September 28, 2026) — HubSpot Knowledge Base, accessed October 2, 2026
  20. Data Processing Addendum (last updated September 10, 2026), Annex 1 and Annex 2 — Instantly, accessed October 2, 2026