AFF Lab
Cold Email Strategy

Is cold email legal in Latvia in 2026? GDPR and B2B practice

Is cold email lawful in Latvia in 2026? GDPR 6(1)(f) legitimate interest in B2B context, DVI practice, concrete scenarios for compliant outreach.

Written by Mark Barkan 7 min read
On this page

This is the first question Latvian founders ask us when we discuss cold outreach: is it even legal? Will the Data State Inspectorate (DVI) fine us? Doesn’t GDPR prohibit this kind of activity?

Short answer: yes, B2B cold emails are legal in Latvia and across the EU, when done correctly. With specific conditions and specific limits. This article explains what “correctly” means in practice — not in legal theory, but in daily work scenarios.

Disclaimer: This is not legal advice. It’s a practical explanation based on GDPR articles, the DVI’s published practice, and our experience working through this question with 100+ Latvian clients. If your situation is affected by specific circumstances (regulated industry, sensitive data categories, B2C elements), consult a lawyer.

Foundation: GDPR Article 6

GDPR allows processing of personal data (and B2B emailing a person with a name and a job title is personal-data processing) on six grounds:

  1. Consent (6(1)(a))
  2. Contract performance (6(1)(b))
  3. Legal obligation (6(1)(c))
  4. Vital interest (6(1)(d))
  5. Public interest (6(1)(e))
  6. Legitimate interest (6(1)(f))

For cold email activity, 6(1)(f) — legitimate interest — almost always applies. Consent (6(1)(a)) isn’t needed, because logically: if the recipient had to consent before you send the first email, cold outreach as such would be impossible. That’s not what the legislator intended.

The legitimate interest test

6(1)(f) requires data processing to be justified by a three-part test. This is a formal document you can actually write down and save in your company files (DVI can request it):

1. Purpose test. What is the legitimate purpose? Answer: “Offering a B2B service to another B2B company whose profile matches our ideal customer definition.”

2. Necessity test. Can this purpose be achieved otherwise, less invasively? Answer: “Not with available resources for a small or medium B2B company. Advertising, exhibitions and partner networks are alternatives, but they don’t replace directed, personalized contact, which is the most economically efficient way in the B2B SaaS / services sales context.”

3. Balancing test. Do the data subject’s interests, rights and freedoms outweigh your legitimate interest? Answer: “No, when: (a) the recipient is in a professional role and we contact them in connection with their professional duties; (b) the email is publicly available or obtained from professional sources; (c) the recipient is offered a clear and easy opt-out mechanism; (d) the content directly relates to the recipient’s professional activity.”

If all three tests pass, you’re acting within legitimate interest. This is the same basis German, French and Scandinavian B2B SaaS companies use.

Concrete conditions that make B2B cold email lawful

At the text level of GDPR these aren’t all mandatory, but in practice this is what separates a legitimate B2B cold email from spam that DVI would fine:

1. Professional contexts only

Send to [email protected], not [email protected]. Personal email even in a professional role is a higher GDPR risk. Assess: does this person at this email address receive professional offers from others? If yes — lawful. If no — excessive.

2. Clearly identified sender

The email must clearly show:

  • Your first and last name
  • Your company’s legal name
  • Your company’s registered address
  • Registration number (in Latvia — UR number; in other jurisdictions, the equivalent)
  • Opt-out mechanism (clear message “reply STOP if you don’t want further emails”)

This is what most spam senders skip, and that’s why they’re spam. By meeting these requirements, you’re a justifiably legitimate sender.

3. Clearly identified purpose

Email content must clearly relate to the recipient’s professional interests. If you send a SaaS marketing tool offer to someone whose LinkedIn says “Head of Growth at SaaS company” — that’s legitimate. If you send the same offer to someone whose profile says “Plumber” — that’s not legitimate.

4. Honoring opt-outs

If a recipient replies “unsubscribe”, “stop”, “no”, “remove” — terminate all further contacts within 1-2 business days. Maintain an opt-out list and check it before every next campaign. This is critical. Ignoring opt-outs is the single surest path to a DVI complaint.

What you can’t do — even if tempting

These scenarios are explicitly unlawful or high-risk. We consistently steer Latvian companies away from:

Using personal emails in B2B context. [email protected] in a profile as “CEO at TechCo” — bad idea. Technically possible (the person publicly displayed themselves), but the GDPR balancing test in this case is much closer to personal level. Risks outweigh benefit.

Buying data from untrusted sources. “B2B database 100,000 EU contacts for €50” — almost certainly contains illegitimately sourced data. You inherit the complaints and liability. Apollo, Lemlist, Lusha data sources are acceptable; “B2B leads.xyz” style sources — no.

Using data outside the stated purpose. If you acquired a contact for the purpose of “B2B SaaS offer”, you cannot use it for e-commerce marketing or political campaigning.

Targeting special data categories. Health, religion, political affiliation — fully outside the legitimate interest basis. Even if someone publicly writes about it, you cannot use it in B2B context without consent.

Ignoring opt-outs. Complaints to the Data State Inspectorate about “I opted out and they kept sending” are the single highest spam complaint reason. If you build a reputation as such a sender, fines start.

DVI’s practice — concrete examples

The DVI publishes decisions on its website. Reading them, we see which scenarios cause problems:

Fined scenarios:

  • B2C cold email campaigns without opt-in
  • Ignoring opt-outs
  • Lists bought from illegal sources
  • Incomplete sender identification
  • Improper handling of special data categories (medical, financial data)

Practically unfined scenarios:

  • B2B cold emails with proper identification, justified legitimate interest, clear opt-out mechanism
  • LinkedIn InMail and cold connection — DVI usually treats these as internal platform communication
  • Moderate-volume personalized emails based on publicly available professional profiles

We haven’t seen DVI fine a B2B SaaS company for properly configured, moderate-volume personalized cold emails to other B2B companies. Risk exists theoretically, but in practice it’s close to zero if you follow the conditions described above.

Latvian specifics vs Germany or France

GDPR is a unified EU regulation, but local supervisory authorities interpret some topics differently.

Germany — strictest on cold outreach. Bundesdatenschutzgesetz (BDSG) adds requirements on top of GDPR. German B2B cold emails are still lawful, but with specific conditions on what content and what information must be included.

France — CNIL actively fines spam. B2B cold emails are permitted, but with low tolerance for opt-out ignoring.

Scandinavia — Mostly similar to Latvia. Data protection authorities follow GDPR balancing test outcomes.

Latvia — Middle position. DVI is consistent but not aggressive. We consider Latvia’s regulatory environment as friendly to properly configured B2B cold outreach.

Practical takeaway: if you can prove compliance with the strictest jurisdictions (Germany, France), you’re well protected in all EU markets, including Latvia.

Practical pre-launch checklist

Before clicking “send” on the first cold email campaign, verify:

  • Sender identification in email footer: name, company, legal address, registration number
  • Opt-out mechanism clear and easy to access (usually one line in footer)
  • Sending targets match ICP definition (B2B, professional role, not personal emails)
  • Data sources documented and verifiable (Apollo / Lemlist / Sales Navigator + verification)
  • Opt-out list created and will be automatically updated
  • Legitimate interest test documented and saved in internal files (not just in your head)
  • Data processing register (DPR/RPA) updated with this activity

These steps take 2-3 hours the first time and then only 15-20 minutes for each new campaign. That’s negligible compared to potential fine costs if you operate without a basis.

Why this is a competitive advantage, not just defense

Many Latvian founders see GDPR as an obstacle. We see it the opposite way — as a filter that leaves only serious senders in the market.

Most spam comes from senders who don’t follow GDPR. When you do, your email stands out from that noise. Higher deliverability, higher reply rate, fewer complaints.

Real statistic from our clients: properly GDPR-compliant campaigns average 30-40% higher inbox deliverability than campaigns that skip these layers.

If you want us to handle this for you

Our Sales Pilot and retainer services include a full GDPR compliance layer:

  • Legitimate interest test documented for each campaign
  • Processing register maintained
  • Sender identification properly configured
  • Opt-out list maintained across different campaign jurisdictions

In Latvia in 2026, cold email is legal in B2B context. But only when done correctly. This article is the minimum starting point to prepare yourself to do it correctly.

Related reading