The question “Can I use legitimate interests for cold email?” mixes two legal tests.
First, the GDPR asks whether you have a lawful basis for processing a person’s contact details. Legitimate interests is one possible basis under Article 6(1)(f), but it requires a real interest, necessity, and a balancing exercise that considers the person’s rights and reasonable expectations. The EDPB’s small-business guide explains those three elements.
Second, national rules implementing the ePrivacy Directive decide whether an unsolicited electronic marketing message may be sent. A lawful basis for holding an email address does not automatically give permission to use it for marketing.
Start with the recipient’s country and the communication channel
Article 13 of the ePrivacy Directive sets the EU framework for unsolicited communications. Member States implement that framework in national law, so a campaign covering several countries needs a country-by-country check. Rules can also differ between email, SMS, automated calls, and person-to-person calls.
For Spain, Article 21 of the Law on Information Society Services and Electronic Commerce prohibits promotional email or equivalent electronic messages that were not requested or expressly authorised. It contains a limited existing-customer exception when:
- there was a prior contractual relationship;
- the contact details were obtained lawfully;
- the sender markets its own products or services;
- those products or services are similar to what the customer originally bought; and
- every message provides a simple, free way to object.
That exception is often called a soft opt-in. It is not a general permission to email every business contact in a database.
Business contact data does not settle the marketing question
Spanish data-protection law may support processing limited professional contact data in certain business contexts. That can help answer the GDPR lawful-basis question. It does not disapply Article 21 of the LSSI or turn a prospecting list into an authorised email campaign.
The useful distinction is:
| Decision | Question to document |
|---|---|
| GDPR lawful basis | Why may we collect, store, select, and otherwise process this contact data? |
| Electronic-marketing rule | Why may we send this particular message through this channel in the recipient’s country? |
| Transparency | What did we tell the person about the source, purpose, rights, and objection route? |
| Objection | Can the person stop direct marketing easily and immediately? |
Article 21 GDPR also gives people a right to object at any time to processing for direct marketing. Once they object, the data must no longer be processed for that purpose. See the official GDPR text.
A defensible campaign review
Before sending, record:
- The countries where recipients are located.
- How each address was obtained.
- Whether the recipient is an existing customer and, if so, what they bought.
- The national rule and exception relied on for the channel.
- The GDPR lawful basis for the associated processing.
- The privacy information supplied when data came from another source.
- The suppression process for objections and unsubscribes.
If the answer depends on “our product is relevant to them,” stop. Relevance alone is not the legitimate-interests test and is not an ePrivacy permission.
What GDPR.Direct can and cannot do
GDPR.Direct can help you draft a privacy notice that records a marketing purpose, lawful basis, recipients, retention approach, and rights route. It cannot decide whether a particular list or campaign is lawful across every recipient country. That decision depends on the source of the data, the relationship, the channel, the message, and national law.
Review Article 6 before choosing a lawful basis, then have a qualified privacy professional review any multi-country or high-volume campaign.
This article is educational information, not legal advice.