The question we are asked most often, usually inside the first ten minutes of a call, is whether cold B2B outreach is legal in Europe. The short version: contacting a business through a contact route that business published itself is generally permitted across most of the world, including the United States, the United Kingdom and France, and two European jurisdictions are strict enough that Knockwire excludes them by default. The rest of this post is the longer version, and the reasoning behind the default.
We are engineers rather than lawyers, and this is a map we drew in order to pick product defaults. Read it as the shape of the rules, not as advice you can rely on.
01Where cold B2B outreach is permitted without prior consent
Across most markets, writing to a business at a route that business published is treated as ordinary commercial correspondence rather than as an intrusion. Three markets carry nearly all of our volume, and all three sit in that category.
- United States. The federal rule for commercial messages, CAN-SPAM, is an opt out regime rather than an opt in one, and it was drafted about email. A submission to a published business contact form is not the surface it was written for. State privacy statutes generally bite on how you handle data rather than on the act of making contact.
- United Kingdom. The direct marketing rules in PECR attach to electronic mail and they exempt corporate subscribers from the consent requirement. Sole traders and most partnerships are treated as individuals and fall outside that exemption. UK GDPR still governs whatever personal data you hold about the person who reads the message.
- France. The regulator has been explicit for years that professional contact for a professional purpose does not require prior consent, provided the message relates to the recipient's role and there is a plain way to object.
The pattern is the same in all three. The rule turns on the nature of the recipient and the relevance of the message, not on whether you had permission to know the company existed.
02Germany and Italy, and why we exclude them by default
Two jurisdictions do not follow that pattern, and they are the reason Knockwire ships with an exclusion list rather than a green light.
Germany treats unsolicited advertising under its unfair competition law, UWG section 7, as an unreasonable nuisance requiring prior express consent, and the German courts have not carved business recipients out of it. Advertising pushed through a company's own contact form has been litigated there rather than assumed to be safe, which is about as clear a signal as a jurisdiction can send.
Italy, under the Garante, similarly starts from consent for marketing communications and does not offer a broad business exemption of the kind France applies.
So Knockwire excludes Germany and Italy by default. A pass that reads a German company records the rejection under "not allowed to knock" with the jurisdiction named, exactly like any other gate. Nothing is researched further, nothing is drafted, and nothing is delivered.
A tenant can change that. It is a deliberate policy change, made in writing, by somebody who has taken advice, and the audit trail records who changed it and when. What the product will not do is quietly relax the default because a pass came back with too few qualified companies that month. A compliance setting that drifts under commercial pressure is not a compliance setting.
03Legitimate interest and the balancing test
Inside the EU and the UK, the processing itself needs a lawful basis under GDPR, and for B2B outreach that basis is normally legitimate interest rather than consent. Direct marketing is named in the recitals as capable of being a legitimate interest, which is a starting point rather than a conclusion.
The balancing test is the part that gets skipped. It has a recognisable shape, and it is four questions:
- Is the interest real and specific? "Growing revenue" is not. "Contacting data companies whose published scraping stack we can measurably reduce the cost of" is.
- Is the processing necessary to achieve that interest, or would something less intrusive do the same job just as well?
- Would the recipient reasonably expect it, given where the data came from and where they chose to publish it?
- What is the actual impact on any individual involved, and is there a simple, obvious way for them to object?
Published business contact routes make three of those four straightforward to answer. The data was published by the company for the express purpose of being contacted. The expectation is not a stretch. The impact on any individual is one message arriving in a queue that exists to receive messages.
We write the balancing reasoning down per tenant rather than treating it as a formality, because a lawful basis you cannot articulate six months later is not much of a basis.
04A published form is a lower risk surface than an inbox
There is a real difference in risk between a form and a scraped personal inbox, and it is not a technicality.
A scraped inbox is personal data obtained without the person's involvement, delivered to a place that person treats as theirs. Every limb of the balancing test gets harder: the expectation is weaker, the intrusion is higher, and the provenance of the address is often something you would rather not have to explain to a regulator.
A published contact form inverts most of that. The company chose the route, published it, and staffed it. The recipient is usually a role rather than a named individual. The whole attempt is auditable, because the form is the record: which fields were filled, with what content, and what the page said in response.
That is a difference in risk rather than a licence. The message still has to be relevant, still has to say plainly who sent it, and still has to offer a way to object. Knockwire knocks under a real named person at a real address, with no personas and no disposable inboxes anywhere in the product, because a message you would not put your own name on is a message you should not be sending.
05What this map does not settle
Three things this map deliberately leaves open:
- Sector rules. Regulated industries carry their own contact restrictions that sit on top of the general position, and they are not visible from a company registry.
- The sole trader boundary. In the UK especially, a one person business can fall on the individual side of the line, and the registry data is frequently not enough to tell you which side you are on.
- Jurisdictions we have not mapped. Everything outside the EU, UK and US is handled today by an explicit allow list rather than a permissive default, so silence from us is an exclusion rather than a permission.
The practical upshot for anyone weighing this up: the legal question is less about outreach in the abstract and more about which surface you chose and whether you can show your reasoning afterwards. A published form, a relevant message, a named sender, a written basis, and a jurisdiction list you can defend will put you in a considerably better position than a clever argument about a purchased list.
Email sending is not part of any of this today. It is on the roadmap for Q4 2026 and it stays marked as unbuilt until it ships. When it does, it will need its own version of this map, because the rules that are relatively relaxed about published forms are markedly less relaxed about email.