Contents

B2B Telemarketing After August 11, 2026: What Remains Permissible, According to the CNIL

,

Updated on 03/09/2026

Updated on September 3, 2026. Sources: Légifrance, DGCCRF, CNIL.

As of August 11, 2026, the ban on making calls without prior consent has been in effect. It applies to consumers. The business your sales representative is speaking with online is not covered by this ban.Article L223-1 is part of the Consumer Code and protects individuals acting outside the scope of their professional activities. Cold calling between businesses has therefore remained permissible since the law of August 11, 2026, took effect, subject to certain conditions. And these conditions make you liable.

If your teams are calling executives or procurement managers about a matter related to their line of work, the opt-in requirement does not apply to you. The GDPR, however, does. This page explains how to implement the rules: what changes need to be made to your contact list, your script, and your CRM now that the regulation is in effect.

Why B2B Is Exempt from the Requirement for Prior Consent

Law No. 2025-594 of June 30, 2025, amends Article L223-1: a business may no longer contact a consumer by telephone for marketing purposes without prior consent. This consent must be freely given, specific, informed, unambiguous, and revocable, and the business is responsible for providing proof of it.

The word that determines everything is “consumer.” A purchasing manager contacted on his work phone regarding a purchasing matter is acting within the scope of his job. The opt-in requirement does not apply to him.

However, the scope remains defined. A name, a direct phone number, and a job title identify a natural person: you are indeed processing personal data. Only the legal basis changes. On its page dedicated to telephone marketing, updated on June 10, 2026, the CNIL citeslegitimate interest as the basis for business-to-business marketing, subject to specific conditions.

The requirements that must be met, in plain language

Four requirements, all of which are verified in a compliance report.

  • The subject of the solicitation must be related to the profession of the person being approached. This is the key requirement set by the CNIL. A fleet management solution offered to a logistics director: relevant. Offering loan insurance to the same director simply because their number is in your database: irrelevant and outside the scope.
  • Information at the time of collection. The individual must know who is processing their data, for what purpose, and what their rights are. In the case of indirect collection (directory, trade show, purchased database), this information must be provided at the time of initial contact or through an explicit reference to your privacy policy.
  • A simple and free right to opt out. Individuals must be able to say “no” effortlessly and at no cost, and the CNIL recommends a checkbox that is unchecked by default. In practice: a sentence in the script, a dedicated email address that works, and immediate action taken.
  • Compliance with the GDPR as a whole. Record of processing activities, defined retention periods, access security, oversight of data processors, and handling of requests for access and erasure.

A useful clarification, since confusion is common: Article D223-9 of the Consumer Code sets a limit of four calls per consumer over a rolling 30-day period, with call times Monday through Friday from 10 a.m. to 1 p.m. and 2 p.m. to 8 p.m. These limits govern consumer solicitation and do not apply to B2B transactions. Many companies will apply them across the board simply because it’s easier to configure. This is an organizational choice, not a legal requirement.

The Special Case: The Owner of a Very Small Business and His or Her Personal Social Security Number

That is where the real risk lies, and it deserves more than just a footnote.

A tradesperson, a business owner, or an independent consultant often uses a single phone number for everything: clients, suppliers, and family. Most often, it’s a personal cell phone. Nothing in your records indicates which side of the border the number is located on.

Whether someone is considered a business contact or a consumer depends not on the number dialed, but on the capacity in which the person is being contacted. If the offer falls within the scope of their profession, it remains within the professional framework described by the CNIL. If it pertains to their private life (home insurance, investments, home improvements), the person is being contacted as a consumer: prior consent is required, and the burden of proof lies with you.

In between, there is a real gray area, and the analysis depends on the specific situation: the origin of the number, the wording of the offer, and the context in which the data was collected. No general rule can replace an examination of the specific case. If you have any doubts about an entire segment of your database, the prudent approach is to treat it as B2C and obtain proper consent. The procedures are detailed in our Consent Verification Checklist. For an interpretation of the texts, please refer to the DGCCRF Fact Sheet and, in sensitive cases, legal counsel. The foregoing is factual information, not legal advice.

What You Need to Change in Your Prospecting File

The file is the first place an inspection looks. Five construction sites.

  1. Document the source of each data point. A “source” column should be filled out with details such as: business directory, website form, May trade show, or Supplier X database, along with the date it was acquired. A row without an identifiable source is indefensible.
  2. Record the date the data was collected and the date it was last updated. A retention period is only justified if you know how long you have had the data.
  3. Verify that the privacy notice exists and remains accessible. Forms, data collection pages, legal notices: the purpose of marketing must be stated there, along with a reminder of the right to object.
  4. Filter out or isolate personal phone numbers. Exclude mobile numbers collected outside of a professional context from cold-call campaigns. It’s better to have a separate segment than to mix them with company direct lines.
  5. Centralize opt-out requests. A single list, updated in real time, consulted before each campaign. A refusal communicated to a sales representative must block the number company-wide.

What Needs to Be Changed in the Call Scripts and in the CRM

As for the script, three additions are all it takes. They can be done in fifteen seconds.

  • State your identity at the beginning: first name, last name, company. Make it absolutely clear who is calling.
  • State the business purpose in the very first sentence, explicitly linking it to the listener’s role. This fulfills the requirement set by the CNIL and, incidentally, keeps the conversation going beyond ten seconds.
  • Explain the right to opt out in plain language, including how to exercise it.

The sales pitch, objections, and structure of the call are topics for another discussion: we cover them in our guide to telemarketing and on our page dedicated to cold calling.

On the tool side, the key issue is traceability: a block list that actually prevents dialing, automatic timestamping of each attempt, the source of the record, and a searchable history. If your outbound calls go through a predictive dialer, make sure the do-not-call list is checked before dialing and not after the call is answered: this is the point that most often fails during an audit. The same requirement applies to an automated dialer used in high-volume campaigns: the blocking rule must be built into the dialing tool itself, not in an Excel file that someone has to remember to open.

👉 Kavkom integrates with the CRM systems your sales team already uses. View the list of all our integrations.

Frequently asked questions

Will business-to-business cold calling be banned as of August 11, 2026?

No. The prohibition set forth in Article L223-1 applies to solicitation of consumers. Telemarketing between businesses is still permitted, subject to certain conditions: the purpose must be related to the profession of the person being called; information must be provided at the time of data collection; the right to opt out must be simple and free of charge; and the GDPR must be complied with.

Is prior consent required before calling a company?

Not under Article L223-1: The CNIL considers legitimate interest to be the legal basis for B2B marketing. Consent is required again as soon as the individual is approached in their capacity as a consumer for a product unrelated to their professional activity.

Do the hours 10 a.m.–1 p.m. and 2 p.m.–8 p.m. apply to B2B calls?

These time restrictions and the limit of four calls over a 30-day period are set forth in Article D223-9 of the Consumer Code and are intended to regulate unsolicited contact with consumers. They are not legally enforceable in B2B transactions. Nevertheless, some companies apply them uniformly to simplify the setup of their campaigns.

Does Bloctel protect business phone numbers?

Bloctel was discontinued on August 11, 2026, and replaced by a consumer-side opt-in system. In B2B, the relevant mechanism was never Bloctel but rather your internal do-not-call list.

Is it okay to call an executive’s cell phone if I find the number on a work network?

It depends on the situation. If the number was provided in a professional context and your offer relates to the person’s business, the call falls within the framework described by the CNIL. If the number clearly belongs to the private sphere, or if the offer does not relate to the person’s profession, the analysis shifts to the consumer’s perspective. Document the origin of the number: this will justify your decision.

What are the consequences of noncompliance?

For violations of consumer solicitation rules, Article L242-16 provides for an administrative fine of up to €75,000 for an individual and €375,000 for a legal entity per violation; these penalties are cumulative when multiple violations occur concurrently (Article L522-7). The decision is published at the expense of the sanctioned party. In the B2B sector, violations relate to the GDPR and fall under the jurisdiction of the CNIL.

Get through this without disrupting your production

Kavkom provides 100% cloud-based business phone service with a native predictive dialer, time-stamped call history, and call blocking management at the dialing level. All features are included at no extra cost, with no long-term commitment, prorated billing, and immediate activation. If you need to update your campaigns now that the new regulations are in effect, request a demo.

Optimize your B2B campaigns without disrupting your operations: 100% cloud-based business telephony, a native predictive dialer, and blocked numbers at the dialing level.

Schedule a demo

Overview Kavkom

Related articles

Your telephony grows with you. No obligation.

4.7 on Capterra and Trustpilot,
based on 116 reviews collected.

Illustration vectorielle de d'un logiciel de téléphoie pour expliquer la tarification, avec une image d'une personne qui tiens une carte de crédit