Skip to content
Novot AI
NLBook a call
← Back to knowledge base

May you email customers without consent? The spam ban explained

No, not just like that. Article 11.7 of the Dutch Telecommunications Act prohibits unsolicited commercial messages, including via WhatsApp and SMS. There is one exception: you may approach your own customers about your own similar products or services, provided they can opt out both at collection and in every message. Service email — confirmations, invoices, answers to questions — falls outside the ban, as long as it carries no offer. The burden of proving you were allowed to email is yours, and the ACM supervises it.

Published on

Can you simply send a commercial email?

No. Sending unsolicited commercial messages is prohibited in the Netherlands, unless the recipient gave permission in advance or is already a customer of yours. That rule sits in article 11.7 of the Dutch Telecommunications Act (Telecommunicatiewet) and is commonly called the spam ban. It is not only about email. The law speaks of electronic messages, which covers a WhatsApp message, an SMS or a push notification carrying an offer just as much.

That makes the rule more practical than it sounds. Email and text messages are the channels where your customers actually are: according to Statistics Netherlands, in 2025 more than 90 percent of the population aged 12 and over used these forms of online communication. So anyone automating customer contact is automating precisely the channel this law is about.

For AI the point is sharper still. Article 11.7 explicitly names automated calling and communication systems without human intervention. That is not a leftover from the fax era you can ignore — it is the description of a system that composes and sends messages by itself. Switch something like that on for your mailbox or your WhatsApp number and you are not at the edge of this law but in the middle of it.

What the spam ban actually prohibits

The core of article 11.7, first paragraph, has three parts, and all three must be true before the ban bites. It concerns communication that is unsolicited, with a commercial, idealistic or charitable purpose, sent through an electronic message or an automated communication system. If one part is missing, the message falls outside the ban. A reply to a question the customer asked is not unsolicited. An invoice has no commercial purpose. A paper letter is not an electronic message.

Two things are often misunderstood. First, the ban does not only protect consumers: business recipients are covered too. The idea that "B2B email is free" is wrong. Second, it is not only about selling. The law also names idealistic and charitable purposes, so a request to donate or to support a cause falls under it just as much as a discount campaign.

Equally important is who has to prove that everything was in order. That is you, the sender. You must be able to show that the recipient gave permission beforehand, or that the existing-customer exception applied. A list of addresses without a known origin is therefore not evidence but the opposite: if you cannot show where an address came from, you cannot show that you were allowed to email it.

The Netherlands Authority for Consumers and Markets (ACM) sums the rule up on its own guidance page in three sentences: only send to people who gave permission in advance, make clear who the sender is, and make unsubscribing easy. Those three points work well as a self-test. If you cannot answer yes to all three, you do not send the message.

The exception: you may approach your own customers

The exception that matters most to a small business sits in the same article, in the third paragraph. In short: contact details you obtained when selling your own product or service may be used to approach that same customer about your own similar products or services. The regulator puts it in plain words: you may send existing customers unsolicited messages about products or services related to earlier purchases, they must be able to unsubscribe, and it must be clear that you are the sender.

Four conditions hang on that exception, and they all apply at the same time.

  • The details come from a sale. Not from a purchased list, not from a trade fair, not from a website you scraped. From a transaction between you and that customer.
  • It concerns your own similar products or services. Not a partner's, and not something from a completely different part of your range.
  • At the moment the address was collected, a clear and explicit opportunity to object was offered. Free of charge and easy. An order form that never mentions the address will also be used for offers does not meet that condition.
  • Every following message offers that opportunity again. Once, at the point of purchase, is not enough.

In practice things go wrong around the word similar. An installation company that fitted a heat pump may approach that customer about maintenance on the same installation. The same company suddenly offering solar panels or an insurance policy is a good deal further from the original purchase. There is no list that says where the line runs; the question is whether the customer could reasonably have expected this when buying from you. The further you move from the earlier purchase, the more you need permission instead of the exception.

Another common mistake: someone who only requested a quote or downloaded a brochure is not a customer. No sale took place, so the exception does not apply. If you want to email that person later, you need permission, or you simply ask for it during the conversation itself.

When is permission real permission?

Consent is a concept from the GDPR, and it is stricter than a checkbox. It must be freely given, specific, informed and unambiguous (article 4(11) GDPR). Freely given means you may not withhold anything if someone says no. Specific means the consent is about something: "newsletter with offers" is not the same as "messages about your appointment". Informed means the person knows in advance who will email them and about what. Unambiguous means the person actively did something.

The Dutch Data Protection Authority is clear about this: you may not assume that someone consents implicitly, and pre-ticked boxes are not allowed. That touches more forms than you would think. A box that is already ticked, a line saying "by continuing you agree to our newsletter", or a chat window that quietly adds someone to the mailing list at their first question — none of those is valid consent.

In practice this means you must keep consent, not just collect it. Record per person when it happened, through which form or conversation, and with which wording alongside it. If that wording changes, keep the old version too. Without that record you have nothing to show when a complaint arrives, because the burden of proof is yours.

Withdrawing must be as easy as giving (article 7(3) GDPR). Someone who unsubscribes is withdrawing consent. From that moment you may not send them commercial messages — not even "one last time, to check whether that was really intended".

Every commercial email needs a way to unsubscribe

This is the rule most often forgotten for one-off messages. An unsubscribe link does not belong only in the monthly newsletter; it belongs in every message with a commercial purpose. Article 11.7 requires that opportunity again with every message sent, free of charge and by easy means. It must also be clear who the sender is, with an address where someone can genuinely opt out.

Three things to check in your own setup:

  1. Does the unsubscribe link work without logging in? An opt-out that only works after creating an account is not easy.
  2. Does the unsubscribe arrive everywhere? If your newsletter tool and your customer system hold two separate lists, the customer unsubscribes from one and keeps receiving mail from the other. That is the same violation as doing nothing.
  3. Can someone opt out in the channel they are actually in? On WhatsApp nobody emails an unsubscribe address; there people expect "stop" to simply work. Make sure you recognise and process those words.

Note the difference between unsubscribing from advertising and unsubscribing from everything. Someone who no longer wants offers may still be emailed about their pending order or appointment. Those messages are not advertising, and stopping them would be unreasonable. The reverse also holds: that service email is not a back door for slipping in an offer after all.

Service message or advertising? The purpose decides, not the template

The line between a service message and a commercial message is the most important line in this whole subject, and it does not run along the type of email but along its purpose. A service message is needed to do what you agreed: confirm the order, move the appointment, say the engineer is running late. A commercial message is meant to sell something, or to get the customer to do something they had not asked about.

The awkward case is the mixed message: an appointment reminder with a campaign at the bottom, or an invoice with a recommendation inside it. The law looks at the purpose of the communication, not at the label you stuck on the template. As soon as part of the message is commercial, that part must pass the test: consent or the customer exception, plus a way to unsubscribe. A service message does not automatically become advertising because of one sentence, but neither does it automatically stay a service message because the word "service" sits above it.

Per type of message: is prior permission needed, and on what does that judgement rest?
Type of messagePrior permission needed?Basis
Reply to a question the customer askedNoThe message was solicited; article 11.7 is about unsolicited communication
Order confirmation, invoice or shipping noticeNoService message: needed to perform the contract, no commercial purpose
Appointment confirmation or reminderNoService message tied to a live appointment
Fault notice or product recallNoInformation about a delivered product, no commercial purpose
Offer to an existing customer about a similar productNo, provided thatCustomer exception: details from an earlier sale, your own similar range, chance to object at collection and in every message
Offer to an existing customer about something entirely differentYesFalls outside "own similar products or services"
Newsletter to someone who only requested a quoteYesNo sale took place, so no customer relationship within the meaning of the exception
Newsletter to a purchased or scraped address listYesThe permission was not given to you and cannot be demonstrated
WhatsApp campaign to your customer baseNo, provided thatElectronic message: the same conditions as for email
Service message with an offer inside itYes, for the commercial partPurpose counts, not the template; the commercial part falls under the ban
Message to someone who unsubscribedNot allowedConsent was withdrawn; only service needed for the contract remains

Why an AI reply has to know that difference

As soon as an AI assistant answers your mailbox or WhatsApp, the line from the previous section moves out of a template and into a system that makes a choice per message. That is a real difference. A template is assessed once and predictable afterwards. A language model phrases things afresh every time, and the temptation to let it "think along" is strong: a customer asks about the delivery time and gets a recommendation with it. That is meant helpfully, and it changes the legal character of the message.

There are three places where this goes wrong concretely.

  • The reply sells along. A response to a question is solicited communication. A spontaneous offer attached to it is not. If the system may decide by itself to sell something, it can turn any service email into a commercial message without anyone noticing.
  • The system builds a list of its own. Every incoming email yields an address. If that address is automatically added to a campaign, you end up emailing people who never bought anything and never permitted anything.
  • The system does not recognise an unsubscribe. "Please no more email", "stop" and "take me off the list" arrive as ordinary messages. If an assistant replies politely but does nothing with it in the records, the violation simply continues.

The practical fix is not cleverer prompting but a boundary in the system itself. Decide in advance which message types may go out independently — confirmations, reminders, answers to questions — and which always pass a human, namely anything containing an offer. Record that the model may not add addresses to marketing lists. And make sure unsubscribe words become an action in your customer system, not a sentence in a reply.

Something else plays a part here. An AI that gives factually incorrect information about a product, a price or a delivery time legally amounts to a misleading commercial practice — that follows from article 193c of Book 6 of the Dutch Civil Code, and intent is not a requirement there. Selling inside an automated message is therefore doubly risky: not only must you be allowed to email, the content must also be correct.

Who supervises all this?

The spam ban is enforced by the Netherlands Authority for Consumers and Markets. The ACM supervises the rules in chapter 11 of the Telecommunications Act and publishes its own guidance about them for business owners. Complaints from recipients end up with that same regulator; consumers are directed there through the ConsuWijzer helpdesk.

The ACM is also the regulator for unfair commercial practices. That matters because in automated customer contact those two things can coincide in a single message: an unsolicited offer that also contains an incorrect claim is two violations in one email.

There is a second track as well. An email address and a phone number are personal data, so the GDPR applies alongside. The Dutch Data Protection Authority supervises that. For you it means this: you need not only a ground to be allowed to email (Telecommunications Act), but also a lawful basis to process the data and a privacy statement that explains what you do with it (GDPR). Those two questions are often mixed up, but they stand apart and both have to be answered.

And then there is a party that is not a regulator but decides along anyway: your email provider. Complaints about unsolicited mail lead to filtering and blocks. That is not a legal judgement, but the effect is immediate and it hits your ordinary service email too.

What to check before you switch anything on

Run through this list before putting an automated channel into use. It takes an hour and it prevents most of the trouble.

  1. Where does each address come from? Split your file into: gave permission, is a customer (with date and purchase), and the rest. That last group may not be approached commercially.
  2. Can you demonstrate consent? Per person: when, where, and with which wording. No record means no consent.
  3. Are you staying within similar offerings? Note next to each type of campaign which earlier purchase justifies it. If you cannot, it is a consent campaign.
  4. Does every commercial message carry a way to unsubscribe? Test it for real, in a clean browser, without logging in.
  5. Does an unsubscribe work across all systems at once? Unsubscribe yourself and see whether you disappear from every list.
  6. Does your system know what a service message is? Draw up the list of templates allowed to go out alone, and put anything containing an offer behind human approval.
  7. Does the channel recognise an opt-out in plain language? Send "stop" and "no more email" to your own number and watch what happens in the customer system.
  8. Is it in your privacy statement? Purpose, lawful basis and the option to object, in plain language.

The summary fits on a postcard: you may email people who allowed it and your own customers about what they previously bought from you, always with a working unsubscribe button and a clear sender. Everything beyond that is a risk you take knowingly, and with an automated channel you take that risk not once but with every message the system sends.

See what Novot AI can do for your business.

Book a call