Every volume sequencer is a US or Australian product that leaves the law to the customer. Instantly's terms make the subscriber "the sole 'sender' and 'initiator'" of every message, "whether created by humans or AI". Instantly's French URL showed only English in the language selector when fetched. Smartlead's DPA says EU data is processed across regions including the US, Australia and India (as reported by Instantly, a competitor). DFY inbox sellers advertise "US IPs" as a feature. Of the 20+ sequencers priced in the economics pass, only La Growth Machine priced in EUR. Smaller French tools such as Emelia (from €31) and Waalaxy (from €19) do too, at SMB scale.
Meanwhile European law decides per recipient. Roughly 13 of 31 EU/EEA countries and Switzerland require consent even for B2B cold email, and about 11 allow opt-out to companies (EU/EEA country matrix, built from DLA Piper and ICLG country chapters). The recipient's country decides, not the sender's. A Düsseldorf court applied German law to a Belgian software company over three emails, at a €3,500 dispute value and €403.50 net in warning-letter fees (AG Düsseldorf, 30 Apr 2026).
The opening
Turn the law into code, and make Europe a product feature rather than a disclaimer.
| Component | Why it is needed | Evidence |
|---|---|---|
| Recipient-country rule engine (allow / warn / block) × address type (generic vs named) | The same campaign is lawful in Ireland and actionable in Germany; BE, NO, HU and NL turn on generic vs personal addresses | EU/EEA country matrix; DLA Piper |
| Art. 14 notice in step one, localised | KASPR was fined €240,000 partly for missing and English-only notices and for answering access requests with "public sources" | GDPR and ePrivacy |
| Provenance record per contact | Source, date, basis, notice sent; Slovakia requires consent proof 4 years after withdrawal; Italy requires consent recorded with date | Data sourcing law |
| Global objection list across workspaces | Art. 21(3) objection is unconditional; post-warning sends cost €3,000 per email in KG Berlin's reckoning | Germany |
| EUR pricing, EU hosting, EU IPs, EU subprocessors | EU procurement asks; Leadfeeder leads with "Built & Hosted in EU" | Non-English markets |
| DACH mailbox providers as destinations | No vendor documents routing or seeds for GMX/WEB.DE, T-Online, IONOS or OVH | ESP matching (inference from absence) |
The law research found no mainstream sequencer that gates sends by recipient jurisdiction. Incumbents push the question to the user, as Instantly's terms do. That absence was checked against the vendor docs and terms reviewed, not against every product.
§7(2) Nr. 2 UWG requires prior express consent for every advertising email, B2B included, and one email is actionable. Germany is therefore the worst market to send into. The product's German customers are agencies and companies selling out of Germany, to France, Ireland, the Nordics, UK corporates and the US. Inside Germany, the product's job is to block cold sends to German recipients without a consent record and support the consent-first funnel: phone (B2B presumed consent allowed), LinkedIn, then email once permission is recorded (Germany).
Who pays and how much
The buyers are European agencies and B2B teams whose clients or lawyers ask the question US tools cannot answer. Examples in the record: Danish Lead Co., which runs 110+ client teams and 500,000+ emails a month on Smartlead, and the French and Benelux tool users of LGM and Overloop (Non-English markets).
Willingness to pay is shown indirectly. EU buyers pay Cognism a median of $32,750 a year (Vendr) for "Europe's most trusted B2B data", and lemlist, a French-built, bootstrapped tool, reached $50M ARR in April 2026 (founder-announced). A Europe-made tool can be large, though lemlist won on multichannel, not compliance.
No source sizes the European share of cold-email software spend. Woodpecker, a listed Polish vendor, gets over 90% of sales from the US (2021), which shows an EU address alone buys no EU market. Interview 30 European agencies before assuming the segment pays a premium for compliance.
Pricing should match the volume tools in EUR (€39–99 entry, flat agency tiers; see Agency operating system) and charge for evidence, not access. A "compliance pack" with LIA templates, consent ledger and audit export is the upsell, not a toll on sending.
Why incumbents have not closed it
- It costs them volume. A rule engine that blocks German, Austrian, Italian, Spanish and Polish recipients without consent cuts sends for every customer who emails them today. Volume is their meter.
- Their legal posture is "you are the sender". Taking on per-recipient legal logic implies a duty of care their terms are written to avoid (Platform liability: what the sequencer itself risks).
- They are not in Europe. Entity, hosting, IPs, language and support hours all sit in the US or Australia. lemlist is the exception, and its Sending Policy still frames bought or scraped lists as a deliverability risk that must "follow the local privacy regulations", leaving the law to the customer.
What you would build first
- The ruleset as versioned data, with a source and a confidence level per row (H/M/L as in EU/EEA country matrix), and unclear countries defaulting to strict. Have counsel review the opt-out tier before launch.
- Country and address-type detection from TLD, company HQ and enrichment, plus a generic-vs-named classifier.
- Step-one notice injection in the recipient's language, naming source, purpose, legal basis and an objection link.
- Contact provenance and a one-click access answer.
- A global, hashed objection list across all workspaces, with an "Abmahnung received" flag.
- EU hosting, EU egress IPs and an EU-only subprocessor list, then GMX/WEB.DE, T-Online and IONOS as seed and routing destinations.
How the leaders would respond
Instantly could add a country filter in a sprint. It would be a filter, not a ruleset with sources, and it would be off by default. lemlist is the real threat: French, EUR-priced, multilingual, $50M ARR. It could ship country gating and EU hosting faster than anyone. Smartlead would likely add an EU data region for enterprise deals. The moat is the maintained, sourced ruleset, the EU legal entity and the credibility of being the vendor that says no.
Scores, argued
Pain: 3. The pain is acute for a minority (EU agencies with legal-minded clients, anyone who has received an Abmahnung) and latent for most, who send anyway and price in the risk (Germany). Not a 4 until a regulator or court hits a sender visibly.
Gap: 5. No volume sequencer gates by recipient country, injects Art. 14 notices, logs provenance or offers EU hosting with EUR pricing. Nobody ships it.
Size: 3. Europe is a real share of the market but unmeasured, and the opt-in half of the continent shrinks the cold-email pool. It is a segment, not the whole market. It grows if the product also serves EU senders targeting the US and UK.
Moat: 4. A sourced, versioned 31-country ruleset, an EU entity, EU infrastructure, languages and a compliance reputation take years to build. They also run against US incumbents' volume incentives and their "you are the sender" stance.
Speed: 3. Legal review, EU infrastructure and localisation take months. You also cannot cold email German prospects for your own product, which slows go-to-market (Go-to-market plan).
Safety: 4. Compliance-forward design lowers law and reputation risk. The residual risk is overclaiming: "GDPR-compliant cold email" stated as a blanket promise invites cease-and-desist letters (GDPR and ePrivacy).
What would kill it
European buyers say they value compliance but buy on price and deliverability, so the rule engine becomes a checkbox nobody pays for. Or lemlist ships country gating plus EU hosting first and owns the narrative. A third risk is regulatory drift: the Digital Omnibus loosens GDPR enough that the provenance layer looks like overhead. It is not expected to apply before mid-2027.
What this means for an entrant
- Sell from Germany, not into it. Target EU agencies and teams prospecting into France, Ireland, the Nordics, Portugal, UK corporates and the US. The product blocks German, Austrian and other opt-in recipients by default (UK: PECR and DUAA 2025, France, United States: CAN-SPAM and state email laws).
- Stack it with Agency operating system. That is the strongest pairing in this list. Agencies run many clients across many countries, the rule engine runs per client workspace, and a shared objection list across clients is the feature no US tool offers.
- Stack it with The reply desk. Opt-out detection in replies, Art. 21 suppression and audit logs are the same compliance story, after the send.
- Pair with Microsoft-first outbound if interviews confirm Microsoft dominance among your European buyers, and with EU data sources rather than a database (Data at cost).
- Never market "GDPR-compliant cold email" as a blanket claim. Market "we tell you, per recipient, whether you may send" (Cold email law: the jurisdiction matrix).
- Keep the ruleset public. A published, versioned country table is content marketing and a trust asset competitors would have to rebuild (The wedge).