Is cold email legal in Latvia in 2026? GDPR and B2B practice
Is cold email lawful in Latvia in 2026? GDPR 6(1)(f) legitimate interest in B2B context, DVI practice, concrete scenarios for compliant outreach.
On this page
- Foundation: GDPR Article 6
- The legitimate interest test
- Concrete conditions that make B2B cold email lawful
- What you can’t do — even if tempting
- DVI’s practice — concrete examples
- Latvian specifics vs Germany or France
- Practical pre-launch checklist
- Why this is a competitive advantage, not just defense
- If you want us to handle this for you
This is the first question Latvian founders ask us when we discuss cold outreach: is it even legal? Will the Data State Inspectorate (DVI) fine us? Doesn’t GDPR prohibit this kind of activity?
Short answer: yes, B2B cold emails are legal in Latvia and across the EU, when done correctly. With specific conditions and specific limits. This article explains what “correctly” means in practice — not in legal theory, but in daily work scenarios.
Disclaimer: This is not legal advice. It’s a practical explanation based on GDPR articles, the DVI’s published practice, and our experience working through this question with 100+ Latvian clients. If your situation is affected by specific circumstances (regulated industry, sensitive data categories, B2C elements), consult a lawyer.
Foundation: GDPR Article 6
GDPR allows processing of personal data (and B2B emailing a person with a name and a job title is personal-data processing) on six grounds:
- Consent (6(1)(a))
- Contract performance (6(1)(b))
- Legal obligation (6(1)(c))
- Vital interest (6(1)(d))
- Public interest (6(1)(e))
- Legitimate interest (6(1)(f))
For cold email activity, 6(1)(f) — legitimate interest — almost always applies. Consent (6(1)(a)) isn’t needed, because logically: if the recipient had to consent before you send the first email, cold outreach as such would be impossible. That’s not what the legislator intended.
The legitimate interest test
6(1)(f) requires data processing to be justified by a three-part test. This is a formal document you can actually write down and save in your company files (DVI can request it):
1. Purpose test. What is the legitimate purpose? Answer: “Offering a B2B service to another B2B company whose profile matches our ideal customer definition.”
2. Necessity test. Can this purpose be achieved otherwise, less invasively? Answer: “Not with available resources for a small or medium B2B company. Advertising, exhibitions and partner networks are alternatives, but they don’t replace directed, personalized contact, which is the most economically efficient way in the B2B SaaS / services sales context.”
3. Balancing test. Do the data subject’s interests, rights and freedoms outweigh your legitimate interest? Answer: “No, when: (a) the recipient is in a professional role and we contact them in connection with their professional duties; (b) the email is publicly available or obtained from professional sources; (c) the recipient is offered a clear and easy opt-out mechanism; (d) the content directly relates to the recipient’s professional activity.”
If all three tests pass, you’re acting within legitimate interest. This is the same basis German, French and Scandinavian B2B SaaS companies use.
Concrete conditions that make B2B cold email lawful
At the text level of GDPR these aren’t all mandatory, but in practice this is what separates a legitimate B2B cold email from spam that DVI would fine:
1. Professional contexts only
Send to [email protected], not [email protected]. Personal email even in a professional role is a higher GDPR risk. Assess: does this person at this email address receive professional offers from others? If yes — lawful. If no — excessive.
2. Clearly identified sender
The email must clearly show:
- Your first and last name
- Your company’s legal name
- Your company’s registered address
- Registration number (in Latvia — UR number; in other jurisdictions, the equivalent)
- Opt-out mechanism (clear message “reply STOP if you don’t want further emails”)
This is what most spam senders skip, and that’s why they’re spam. By meeting these requirements, you’re a justifiably legitimate sender.
3. Clearly identified purpose
Email content must clearly relate to the recipient’s professional interests. If you send a SaaS marketing tool offer to someone whose LinkedIn says “Head of Growth at SaaS company” — that’s legitimate. If you send the same offer to someone whose profile says “Plumber” — that’s not legitimate.
4. Honoring opt-outs
If a recipient replies “unsubscribe”, “stop”, “no”, “remove” — terminate all further contacts within 1-2 business days. Maintain an opt-out list and check it before every next campaign. This is critical. Ignoring opt-outs is the single surest path to a DVI complaint.
What you can’t do — even if tempting
These scenarios are explicitly unlawful or high-risk. We consistently steer Latvian companies away from:
Using personal emails in B2B context. [email protected] in a profile as “CEO at TechCo” — bad idea. Technically possible (the person publicly displayed themselves), but the GDPR balancing test in this case is much closer to personal level. Risks outweigh benefit.
Buying data from untrusted sources. “B2B database 100,000 EU contacts for €50” — almost certainly contains illegitimately sourced data. You inherit the complaints and liability. Apollo, Lemlist, Lusha data sources are acceptable; “B2B leads.xyz” style sources — no.
Using data outside the stated purpose. If you acquired a contact for the purpose of “B2B SaaS offer”, you cannot use it for e-commerce marketing or political campaigning.
Targeting special data categories. Health, religion, political affiliation — fully outside the legitimate interest basis. Even if someone publicly writes about it, you cannot use it in B2B context without consent.
Ignoring opt-outs. Complaints to the Data State Inspectorate about “I opted out and they kept sending” are the single highest spam complaint reason. If you build a reputation as such a sender, fines start.
DVI’s practice — concrete examples
The DVI publishes decisions on its website. Reading them, we see which scenarios cause problems:
Fined scenarios:
- B2C cold email campaigns without opt-in
- Ignoring opt-outs
- Lists bought from illegal sources
- Incomplete sender identification
- Improper handling of special data categories (medical, financial data)
Practically unfined scenarios:
- B2B cold emails with proper identification, justified legitimate interest, clear opt-out mechanism
- LinkedIn InMail and cold connection — DVI usually treats these as internal platform communication
- Moderate-volume personalized emails based on publicly available professional profiles
We haven’t seen DVI fine a B2B SaaS company for properly configured, moderate-volume personalized cold emails to other B2B companies. Risk exists theoretically, but in practice it’s close to zero if you follow the conditions described above.
Latvian specifics vs Germany or France
GDPR is a unified EU regulation, but local supervisory authorities interpret some topics differently.
Germany — strictest on cold outreach. Bundesdatenschutzgesetz (BDSG) adds requirements on top of GDPR. German B2B cold emails are still lawful, but with specific conditions on what content and what information must be included.
France — CNIL actively fines spam. B2B cold emails are permitted, but with low tolerance for opt-out ignoring.
Scandinavia — Mostly similar to Latvia. Data protection authorities follow GDPR balancing test outcomes.
Latvia — Middle position. DVI is consistent but not aggressive. We consider Latvia’s regulatory environment as friendly to properly configured B2B cold outreach.
Practical takeaway: if you can prove compliance with the strictest jurisdictions (Germany, France), you’re well protected in all EU markets, including Latvia.
Practical pre-launch checklist
Before clicking “send” on the first cold email campaign, verify:
- Sender identification in email footer: name, company, legal address, registration number
- Opt-out mechanism clear and easy to access (usually one line in footer)
- Sending targets match ICP definition (B2B, professional role, not personal emails)
- Data sources documented and verifiable (Apollo / Lemlist / Sales Navigator + verification)
- Opt-out list created and will be automatically updated
- Legitimate interest test documented and saved in internal files (not just in your head)
- Data processing register (DPR/RPA) updated with this activity
These steps take 2-3 hours the first time and then only 15-20 minutes for each new campaign. That’s negligible compared to potential fine costs if you operate without a basis.
Why this is a competitive advantage, not just defense
Many Latvian founders see GDPR as an obstacle. We see it the opposite way — as a filter that leaves only serious senders in the market.
Most spam comes from senders who don’t follow GDPR. When you do, your email stands out from that noise. Higher deliverability, higher reply rate, fewer complaints.
Real statistic from our clients: properly GDPR-compliant campaigns average 30-40% higher inbox deliverability than campaigns that skip these layers.
If you want us to handle this for you
Our Sales Pilot and retainer services include a full GDPR compliance layer:
- Legitimate interest test documented for each campaign
- Processing register maintained
- Sender identification properly configured
- Opt-out list maintained across different campaign jurisdictions
In Latvia in 2026, cold email is legal in B2B context. But only when done correctly. This article is the minimum starting point to prepare yourself to do it correctly.
Related reading
B2B Lead Generation in 2026: The Practitioner's Guide
What works in B2B lead generation in 2026 — ICP, list-building, enrichment, qualification, routing. From production pipelines for clients.
Cold Email Outreach in 2026: The Practitioner's Guide
What works in cold email outreach in 2026 — strategy, copy, sequencing, common failure modes. From running outreach for clients at production scale.
Cold Email Templates That Work in 2026: 6 Production Examples
Six cold email templates that produced 5%+ reply rates for real B2B campaigns in 2025-2026, annotated to show why each line lands.
GDPR Compliance for Cold Email in 2026: What B2B Teams Need to Know
What GDPR actually requires for B2B cold email in 2026, when legitimate interest applies, and the operational compliance steps teams need to run.
Spam Trigger Words to Avoid in Cold Email (2026 Reality)
Honest 2026 guide to spam trigger words in cold email — which still matter, which are myths, and what actually drives spam placement in modern filters.