Why EU privacy laws vary from country to country
If you run B2B email campaigns across EU markets, you already know that "we're GDPR compliant" is not the whole answer. EU privacy laws by country create a patchwork of requirements that go well beyond the GDPR baseline, and getting that wrong means fines, blocked campaigns, or both.
GDPR is a Regulation, which means it applies directly in every EU member state without each country needing to pass its own transposing legislation. But GDPR contains what lawyers call "opening clauses", provisions that explicitly allow member states to legislate in specific areas. Employment data, health data, the age at which minors can consent to digital services, and how aggressively national Data Protection Authorities (DPAs) prioritize enforcement are all areas where member states have exercised this flexibility. The result is a regulation that is uniform in principle but meaningfully variable in practice.
Supplementary national laws compound this variation. Germany's BDSG (Bundesdatenschutzgesetz) adds requirements on top of GDPR, particularly around employee data rights and works council involvement. France's loi Informatique et Libertés has been updated to align with GDPR but retains distinct provisions. As one compliance practitioner framing captures it: GDPR is intentionally "fairly light on specifics," which creates interpretation risk that national DPAs fill differently, and they do.
Which EU country has the strictest privacy laws? Germany and Iceland are consistently cited as the strictest EU/EEA jurisdictions. Germany enforces its BDSG supplementary law with aggressive DPA action and strong works council data rights. Iceland's privacy legislation predates GDPR and is considered among the most stringent globally. For B2B marketers, Germany's double opt-in requirement for email marketing is the most operationally consequential strict-country rule you will encounter.
The practical implication: if you send outreach across multiple EU markets, you must comply with the strictest applicable standard for each market, not just the GDPR baseline. A campaign architecture that works in Ireland may be non-compliant in Germany.
GDPR and PECR: the shared foundation
Understanding EU privacy laws starts with two overlapping frameworks that work together for any marketer running electronic outreach.
GDPR governs all personally identifiable information. It is the omnibus framework: any collection, storage, processing, or transfer of data that can identify an individual falls under its scope, regardless of where the processing organization is headquartered. For a full breakdown of what GDPR requires, the GDPR compliance guide covers the regulation's key obligations in detail.
PECR (Privacy and Electronic Communications Regulations) adds specific rules for electronic marketing, email, SMS, cookies, and direct marketing calls. GDPR sets the consent standard; PECR specifies how that consent applies to electronic outreach. Both must be satisfied for compliant B2B email marketing. Complying with GDPR alone is not sufficient if your campaigns involve electronic communications.
The philosophical grounding matters here. The right to privacy in Europe traces to the 1950 European Convention on Human Rights. GDPR is not merely a compliance checkbox, it is an expression of a fundamental right, which explains why EU enforcement is structurally more aggressive than US consumer-protection-based approaches. This is not a regulatory quirk; it is a design feature.
The most operationally significant structural difference for B2B marketers: GDPR defaults to opt-in. No data processing without prior consent, unless another lawful basis applies. All major US state privacy laws, CCPA, CPRA, VCDPA, CPA, default to opt-out. Processing is allowed until the individual objects. As a best practice, ZoomInfo recommends that your privacy policies adhere to the strictest measures, because it is not always clear where your contacts reside. For more on building a GDPR compliance program, see our full guide.
How EU privacy law compares to US data privacy law
The EU and US take fundamentally different approaches to data privacy, and those differences have direct operational consequences for B2B marketers running cross-border campaigns.
The EU model is an omnibus, rights-based framework. GDPR applies to all sectors, all data types, and any organization anywhere in the world that processes the personal data of EU residents. There are no industry carve-outs. A SaaS company headquartered in Austin that markets to companies in Germany is subject to GDPR for those contacts.
The US model is a sector-specific patchwork. HIPAA governs health data. FERPA governs education records. GLBA governs financial services. Outside those sectors, federal law offers limited consumer data protection. State-level laws have stepped into that gap: California's CCPA and its successor CPRA are the closest US analogs to GDPR, granting California residents rights over their personal data and imposing obligations on businesses. But CCPA uses an opt-out model and applies only to California residents. Virginia's VCDPA and Colorado's CPA follow similar opt-out structures. Even experienced compliance professionals are tripped up by subtle differences between these state laws that appear similar on the surface.
The American Privacy Rights Act (APRA) is the current federal legislative effort to create a national framework, but it has not been enacted as of this writing.
Framework | Jurisdiction | Consent Model | Enforcement Body | Max Penalty |
|---|---|---|---|---|
GDPR | EU / EEA | Opt-in | National DPAs | €20M or 4% of global annual turnover |
CCPA/CPRA | California | Opt-out | California AG / CPPA | $7,500 per intentional violation |
VCDPA | Virginia | Opt-out | Virginia AG | $7,500 per violation |
CPA | Colorado | Opt-out | Colorado AG | $20,000 per violation |
Cross-border data transfers: what B2B marketers need to know
If your marketing automation platform, CRM, or advertising platform stores EU contact data on US servers, you need a lawful transfer mechanism. Transferring personal data from the EU to a country without an adequacy decision is prohibited under GDPR unless a recognized transfer mechanism is in place. Three main options exist: Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and adequacy decisions.
SCCs are the most commonly used mechanism. They are pre-approved contract clauses that the European Commission has determined provide adequate protection for personal data transferred outside the EU. Most US-based SaaS vendors rely on SCCs. BCRs are used for intra-group transfers within multinational organizations, they require DPA approval and are more complex to implement, but they provide a durable internal framework for global data flows.
Adequacy decisions are the simplest path: the EU has formally recognized certain countries as providing adequate protection for personal data, meaning transfers to those countries require no additional mechanism. Current adequate countries include:
United Kingdom
Switzerland
Japan
South Korea
Canada (commercial organizations)
Israel
New Zealand
Andorra
Argentina
Faroe Islands
Guernsey
Isle of Man
Jersey
Uruguay
The EU-US relationship has been structurally unstable on this front. The EU-US Data Privacy Framework (DPF) was adopted in July 2023 as the replacement for Privacy Shield, which was invalidated by the Schrems II ruling in 2020. The DPF faces ongoing legal challenges from privacy advocates, and its long-term stability is not guaranteed. Organizations relying solely on the DPF for EU-US data transfers should maintain SCCs as a backup mechanism, treating cross-border transfer compliance as a solved problem is a risk you cannot afford.
The practical step: verify which transfer mechanism your MAP, CRM, and ad platform vendors rely on, and confirm that mechanism is current. For a deeper look at building a compliance strategy that covers cross-border transfers, see our full guide.
EU privacy laws by country: what marketers need to know
The country-level variation in EU privacy law is where campaigns either hold up under scrutiny or fall apart. The entries below cover the rules that matter most for B2B email marketing and outreach. You can also explore these rules visually on ZoomInfo's interactive EU Privacy Laws Map.
For each country, the key evaluation criteria are:
Informed consent required: Does the country require explicit prior consent before sending marketing emails?
Opt-in for business emails: Is opt-in required specifically for emails sent to business (professional) email addresses?
Soft opt-ins allowed: Can implied consent from a prior commercial relationship substitute for explicit opt-in?
Unsubscribe required: Must all marketing and outreach emails include an unsubscribe mechanism?
Country | Informed Consent Required | Opt-in for Business Emails | Soft Opt-ins Allowed | Unsubscribe Required |
|---|---|---|---|---|
Austria | Yes | Yes | Yes | Yes |
Belgium | Yes | Conditional (not required for generic addresses or existing customers) | Yes | Yes |
Denmark | Yes | Yes (including generic addresses) | Yes | Yes |
Finland | Yes | Conditional (not required if product/service relates to recipient's role) | Yes | Yes |
France | Yes | Conditional (not required if product/service relates to profession and prior notice given) | Yes | Yes |
Germany | Yes (double opt-in) | Yes | Yes | Yes |
Ireland | Yes | Conditional (not required for commercial/official activity emails) | Yes | Yes |
Italy | Yes | Yes | Yes | Yes |
Netherlands | Yes | Conditional (not required for professional contact information provided for business use) | Yes | Yes |
Spain | Yes | Yes | Yes | Yes |
Sweden | Yes | Conditional (not required for generic addresses) | Yes | Yes |
Switzerland | Yes | Yes | Yes | Yes |
United Kingdom | Yes | Conditional (some business emails exempt; sole traders require opt-in) | Yes | Yes |
Austria
Austria requires informed consent to send marketing emails to individuals. This consent, needed prior to outreach, must be free, informed, and unambiguous. Opt-in consent is required for sending emails for the purposes of direct marketing, or when an email is sent to more than 50 recipients. An unsubscribe link is required for all outreach and marketing emails. Soft opt-ins are allowed. Opt-ins are not required for collecting and sending to generic email addresses.
Belgium
Belgium requires informed consent when sending marketing emails. In cases of generic email addresses or existing customers, opt-in is not necessary. Soft opt-ins are permitted. All emails must contain an unsubscribe link.
Denmark
Informed consent is required in all cases, even for generic email addresses. Soft opt-ins are allowed. All emails must contain an unsubscribe link.
Finland
Informed consent is required when sending marketing emails. Direct marketing to generic email addresses is permitted if the recipient has not objected to or prohibited it. Prior consent is not required if the product or service advertised is substantially related to the recipient's job title or description, like advertising a sales enablement tool to a salesperson. Soft opt-ins are permitted. All emails must have an unsubscribe link.
France
Informed consent is required when sending marketing emails, unless the marketed product or service is related to the individual's profession and at the time the email address was collected, the individual was informed their information would be used for marketing purposes and given an opportunity to opt out. Generic emails do not require an opt-in. Soft opt-ins are allowed. All emails must have an unsubscribe link.
Germany
Germany requires double opt-in consent to send marketing emails to individuals. The individual's consent should first be obtained through electronic means, such as checking a consent box in an online form, and then an email or similar notification should be sent to the individual requiring them to take an action to confirm their consent. This double opt-in requirement is enforced under Germany's BDSG (Bundesdatenschutzgesetz) supplementary law, which adds obligations on top of the GDPR baseline. Germany is consistently cited as one of the strictest EU enforcers, with an active DPA and strong works council data rights that affect how employee data can be processed. Soft opt-ins are permitted. All emails must have an unsubscribe link.
Ireland
Informed consent is required to send marketing emails unless the email is sent to an email address used in the context of a commercial or official activity, and the message relates solely to that commercial or official activity. Soft opt-ins are allowed. All emails must have an unsubscribe link.
Italy
Informed consent and opt-in are required for all cases. Soft opt-ins are permitted. All emails must have an unsubscribe link.
Netherlands
Informed consent is required to send marketing emails, unless the email is sent to a person acting in the exercise of their profession or business and the sender is using contact information "intended and provided by the user" for such purposes. Soft opt-ins are allowed. Opt-in is not required for generic email addresses. All emails are required to have unsubscribe links.
Spain
Informed consent is required when sending marketing emails to individuals. Soft opt-ins are permitted. All emails must have an unsubscribe link.
Sweden
Informed consent is required when sending marketing emails to individuals. Opt-ins are not required for generic email addresses. Soft opt-ins are permitted. All emails must have an unsubscribe link.
Switzerland
Informed consent is required when sending marketing emails to individuals. Soft opt-ins are permitted. All emails must have an unsubscribe link.
Switzerland sits outside the EU but is closely aligned with EU data protection standards. The nFADP (new Federal Act on Data Protection), which came into effect in September 2023, is Switzerland's primary data protection law. Understanding how swiss privacy regulations vs GDPR compare is important for any marketer with Swiss contacts in their database.
The nFADP aligns closely with GDPR principles but is not identical. Key similarities: both require a lawful basis for processing personal data, both grant individuals rights of access, correction, and deletion, and both require organizations to implement appropriate technical and organizational security measures. Key differences: the nFADP applies to the data of Swiss residents (not EU residents), does not require organizations to appoint a Data Protection Officer (DPO) in most cases (unlike GDPR, which mandates a DPO for certain processing activities), and requires breach notification to the Swiss Federal Data Protection and Information Commissioner (FDPIC) within 72 hours of becoming aware of a breach. The nFADP also introduces a new concept of "high-risk processing" that triggers enhanced obligations, similar in spirit to GDPR's Data Protection Impact Assessment (DPIA) requirement.
For B2B marketers: Switzerland is on the EU's adequacy list, meaning data transfers between the EU and Switzerland are permitted without additional transfer mechanisms. However, if you process Swiss resident data, you must comply with nFADP requirements separately from your GDPR obligations.
United Kingdom
Informed consent is required when sending marketing emails to individuals, but some business emails do not require opt-ins. Emails to sole traders and some partnerships do require opt-in consent. Soft opt-ins are permitted. All emails must have an unsubscribe link.
Following Brexit, the UK operates under UK GDPR, a retained version of the EU GDPR that applies to the processing of UK residents' data. The UK is currently on the EU's adequacy list, though that status is subject to ongoing review. For practical purposes, organizations processing both EU and UK resident data should maintain compliance with both frameworks.
How ZoomInfo supports compliant B2B outreach
ZoomInfo, an all-in-one AI GTM Platform, makes data privacy simple for B2B marketing and demand gen teams operating across EU markets.
Its compliance infrastructure is built into the data layer itself. ZoomInfo holds ISO 27001, ISO 27701, SOC 2 Type II, and TRUSTe GDPR certifications, so the verified B2B data powering your GTM motions meets the strictest EU standards. These are not add-on compliance features, they are structural properties of how the data is maintained and governed.
The data foundation matters for compliance in a practical way: ZoomInfo maintains 500M contacts and 200M+ verified business emails through continuous multi-source verification with 300+ human researchers. For marketers running EU campaigns, that means relying on current, accurate contact data rather than stale lists that create both compliance risk and wasted spend. Outdated contact data is not just an efficiency problem, sending to contacts who have changed roles, left organizations, or opted out is a compliance exposure.
Visit ZoomInfo's privacy center for GDPR resources, compliance documentation, and tools for your go-to-market compliance.
Frequently asked questions about EU privacy laws
Do EU countries all have the same privacy laws?
No. GDPR is a directly applicable EU Regulation, meaning it applies uniformly across all member states without transposition. However, GDPR contains "opening clauses" that allow member states to legislate in specific areas, employment data, health data, age of digital consent, and DPA enforcement priorities. Supplementary national laws such as Germany's BDSG add requirements on top of the GDPR baseline, creating meaningful country-level variation in EU privacy laws by country. For a deeper look, see our guide to GDPR compliance.
Which European country has the strictest privacy laws?
Germany and Iceland are consistently cited as the strictest EU/EEA jurisdictions. Germany enforces the BDSG supplementary law on top of GDPR, with strong works council data rights and aggressive DPA enforcement. Iceland's privacy legislation predates GDPR and is considered among the most stringent globally. For B2B marketers, Germany's double opt-in requirement for email marketing is the most operationally consequential strict-country rule when assessing EU privacy laws by country.
How is EU data privacy different from US data privacy law?
The EU uses an omnibus rights-based framework: GDPR applies to all sectors and all organizations processing EU resident data, regardless of where those organizations are headquartered. The US uses a sector-specific patchwork, HIPAA for health, GLBA for finance, plus state-level laws. The most operationally significant difference: GDPR defaults to opt-in consent, meaning no data processing without prior consent, while US state laws like CCPA default to opt-out, meaning processing is allowed until the individual objects.
Does the US have a law similar to GDPR?
The US has no federal equivalent to GDPR. The California Consumer Privacy Act (CCPA) and its successor the CPRA are the closest US analogs, they grant California residents rights over their personal data and impose obligations on businesses. However, CCPA uses an opt-out model and applies only to California residents. The American Privacy Rights Act (APRA) is a current federal legislative effort but has not been enacted.
What is the difference between GDPR and PECR?
GDPR is the omnibus EU data protection regulation governing all collection and use of personally identifiable information. PECR (Privacy and Electronic Communications Regulations) adds specific rules for electronic marketing, email, SMS, cookies, and direct marketing calls. PECR works alongside GDPR: GDPR sets the consent standard, PECR specifies how that consent applies to electronic outreach. Both must be satisfied for compliant B2B email marketing. For more on how these EU privacy laws interact, see our GDPR compliance guide.
Is the EU-US Data Privacy Framework still valid?
As of this writing, yes. The EU-US Data Privacy Framework (DPF) was adopted in July 2023 as the replacement for the Privacy Shield framework, which was invalidated by the Schrems II ruling in 2020. However, the DPF faces ongoing legal challenges from privacy advocates, and its long-term stability is not guaranteed. Organizations relying on the DPF for EU-US data transfers should maintain Standard Contractual Clauses (SCCs) as a backup mechanism. See our compliance strategy guide for practical steps on managing transfer risk.
