Skip to content
Wrenwire
Docs

B2B cold outreach in Austria

Austria is often treated as a variant of the German market. For sending practice that shortcut holds only so far: the consent requirement resembles the German one, but the Austrian provision says something the German one does not say expressly, and it is exactly the part that concerns foreign senders.

What Austrian law requires

The basis is Section 174 TKG 2021. Sending unsolicited electronic messages for advertising purposes requires the recipient’s prior consent. The construction is opt-in, as in Germany, and just as in Germany it cannot be sidestepped by assuming that business contacts are easier.

Subsection 6, or why sending from Poland is no shelter

This is the difference worth remembering. Section 174(6) TKG provides that offences committed abroad are deemed committed at the place where the unsolicited message reaches the user’s connection.

In other words, the place-of-effect rule is written directly into the administrative penal provision rather than derived from general conflict-of-laws rules. Sending from Poland to a recipient in Austria makes you answerable in Austria, and a Polish choice-of-law clause in your terms does not change that. Independently, Article 6 of the Rome II Regulation leads to the same result, and it cannot be derogated from by agreement.

The existing-customer exception

Section 174(4)(1) TKG offers a narrower path for your own customers, but ties it to the sale of goods or a service. As in the other DACH markets, that means signing up for a free plan does not open the path: no sale took place, so there is no existing customer within the meaning of the provision.

What Wrenwire blocks before launch

Austria falls under the same pre-flight checklist as Germany and Switzerland. A campaign will not start until the legal basis is declared, the sender’s legal details are complete, SPF, DKIM and DMARC are configured for the sending domain, and the unsubscribe-link signing key is in place.

The basis is one of three: existing consent, existing customer, or knowingly accepted risk, recorded alongside the campaign.

It is worth understanding why the product runs the three DACH markets through one mechanism while the documentation separates them. The operational requirements the system enforces converge across all three legal orders: consent, sender identification, a working unsubscribe. The provisions behind them are distinct, and their differences can matter when a specific campaign is assessed.

The Article 14 GDPR notice applies unchanged

Austria is in the Union, so the GDPR information duties apply without modification. For data gathered from public sources, the Article 14 notice has to be delivered at the first communication. Wrenwire injects it into the body of the first message at save time, and does so regardless of market, because this duty has no market gate.

Deliberately waiving the sender-details block, if a campaign chooses that, does not remove this notice. They are two independent obligations.

The suppression list

Unsubscribes act at organization level, not per campaign. An address that has opted out once stays suppressed in every campaign that follows, and the filter runs before every hand-off of contacts to sending.

LinkedIn and phone

LinkedIn is governed by the platform’s terms, and a message there is a conversation inside somebody else’s service, so no sender block is required. The legal basis still applies. Sending is not automated: a human sends the messages.

Phone has its own basis and its own limits, separate from email.


Legal position as at 6 September 2026. This page describes how the product behaves and cites the provisions that behaviour rests on. It is not legal advice and does not determine whether your campaign is lawful.