PKE Article 398: Marketing Consent Is Required in B2B Too
Marketing consent in B2B is not a matter of interpretation. It follows directly from article 398 of the Electronic Communications Law, which replaced two earlier provisions: article 172 of the Telecommunications Law and article 10 of the Act on Providing Services by Electronic Means. There were two overlapping rules, now there is one. Simpler - yes. Milder - no.
What article 398 of the Electronic Communications Law changed
The provision covers sending commercial information to a subscriber or end user through automated calling systems, telecommunications terminal equipment and electronic mail. The scope is broad on purpose. And it makes no difference whether you send a newsletter from a platform or a script pushes messages out of your own server.
The whole difference sits in a single word. The rule protects the end user, not the consumer. These are two different terms, and only the second one refers to the status of a natural person acting outside their professional capacity. Since the legislator picked the first one, the business nature of the recipient excludes nothing. A CEO reading mail in a company inbox is an end user in exactly the same way as a private person.
We write about this as a team that runs its own fleet of sending servers. We see the effects of bad lists not in studies but in logs: rising bounces, spikes in complaints, correspondence with anti-spam teams. Law and deliverability meet at the same point here. A list without consent ruins your results before anyone files a complaint with a regulator.
Why a company inbox is not an exception
A convenient myth goes around: an address on a company domain is not personal data, so cold email can go out without asking. The first part is sometimes true. The second does not follow from it in any way. We take this apart in more detail in our piece on what cold mailing in Poland allows in 2026.
A named address such as first.last@company.pl identifies a specific natural person. Alongside the PKE, the GDPR then applies as well, with all its information duties. But even a generic address - contact@, office@, reception@ - ends its journey in the inbox of a specific human being. That human being is an end user within the meaning of the provision. Article 398 does not talk about personal data, it talks about the recipient of the message.
The second mistake is subtler. Marketing consent and a legal basis for processing data are two separate things from two separate acts. The controller’s legitimate interest may be enough to keep a record in your database lawfully. It does not replace consent to send. You can have a basis for processing and at the same time no right to send a single message.
Hence the practical conclusion. A list bought from a broker or scraped from company registers and business cards gives you neither of those two things. No consent and no sensible basis. The sheer number of records legalises nothing.
What consent that holds up looks like
Consent has to be freely given, specific, informed and unambiguous. Given before the first send, not after it and not along the way. And watch out for the classic: a request for consent sent by email to someone who never gave it is itself a send covered by the provision.
A correct clause answers four questions:
- Who the data controller is, with the full legal name of the entity.
- Through which channel you will get in touch: email, phone, SMS.
- What the consent covers: type of content, subject matter, whose offer.
- How to withdraw it, as easily as it was given.
Implied consent does not exist. No pre-ticked checkboxes, no inference from a simple file download. And consent forced as a condition of access to material stops being freely given, so it stops being consent. You hand over the material for an address and a confirmation, and marketing is a separate statement next to it.
Keep the channels apart. Email, phone and SMS are three separate consents, not one blanket formula. A clause covering everything at once is weaker as evidence, because it is then hard to show what exactly somebody agreed to.
Tip: a double opt-in confirmation is not only about list hygiene. It is the simplest proof that a human being on the other side clicked a link in their own inbox. One click ends the argument about who typed in the address. We go through this in more detail where we write about when double opt-in is truly necessary, and when it only costs you part of your sign-ups.
Proof of consent: what you actually need in your system
The burden of proof is on the sender. A statement saying “we have consents” is not evidence, it is a declaration. You have to show the record.
The minimum record of a single consent:
- A timestamp with the date and time the consent was given.
- The IP address or session identifier the submission came from.
- The wording of the clause as it stood at that moment, not as it stands today.
- The source of the record: the specific form, page or event.
- The double opt-in confirmation together with the timestamp of the click.
- Unsubscribe history, if the address ever opted out.
Point three tends to get skipped, and it is the one that most often blows up the whole structure. Changing the text of a form must not overwrite old consents. Clauses need versioning, and each record has to be tied to the version in force at the time of sign-up. Otherwise, a year of form edits later, you will not reconstruct what somebody agreed to.
The unsubscribe log matters as much as the consent log. It proves that a withdrawal was handled, and handled fast. Because a complaint usually is not about the first message, but about the one sent after the opt-out.
To be honest about the limits: some of these elements are still on the roadmaps of mailing platforms, ours included. Before you migrate a list, go into the panel and export a test consent record. Look at what it actually stores, not at what the pricing page promises. It is worth comparing at that point which consent and unsubscribe features you really have available in your plan.
Penalties and real operational risk
Liability runs along two tracks. The first is an administrative fine from the President of UKE under the PKE, for the send without consent alone. The second is a separate GDPR procedure covering the processing of data. The proceedings are independent, so one does not absorb the other.
We will not quote amounts or ranges here, because they depend on the circumstances of the individual case. The mechanism matters more: a fine is usually triggered by a recipient’s complaint, and a recipient complains when they cannot unsubscribe or keep getting messages despite opting out.
The business risk hits faster than the legal one. Proceedings take months, a spam filter reacts within hours. Spam complaints push up your complaint rate, and then your domain and IP address land on blocklists. Reputation drops for your entire sending, including to the compliant part of the list.
A cold list has one more trap. Addresses scraped a year ago largely no longer exist, so bounces shoot up. Among them you find spam traps: old addresses revived for the sole purpose of catching senders who do not ask for consent. A single hit can block you at a major filter for weeks.
Our practice on a fleet of sending servers points to a simple asymmetry. Reputation gets wrecked in one campaign and rebuilt over many weeks. Warmup from zero, at volumes far lower than before. There is no point pretending otherwise.
A compliant alternative to cold email in B2B
A single email written by hand, to a specific person, about a specific deal, is not a marketing campaign. The difference lies in scale and automation. A template blasted to two hundred addresses from a list does not stop being commercial information just because it opens with a first name.
You earn consent through channels where the other side decides about the contact themselves:
- LinkedIn and a conversation held on the recipient’s terms.
- A call to the main office asking for the right person.
- A contact form on the recipient’s side, which is a direct invitation.
- Industry events, where you collect consent in person and consciously.
- A lead magnet with separate, clearly marked marketing consent.
With a lead magnet, everything comes down to the word “separate”. Consent squeezed into acceptance of the terms of service is neither specific nor freely given. A separate checkbox, unticked by default, with its own wording. That is it.
Your own list grows more slowly than a bought one. In return, every record has a stored history, higher opens and real clicks. Mail engines read those signals and reward them by delivering to the inbox instead of the spam folder.
Tip: before you send anything from a new address, set up SPF, DKIM, DMARC, a correct Return-Path aligned with the authentication domain, and a PTR record for the IP address. The cleanest list on a badly configured domain still will not land.
How we approach this at MailCraft
We treat legal compliance as a product feature, not as a paragraph in the terms of service. If a platform makes it easy to build a list without consents, it shifts the risk onto the customer and waters it down for itself.
We keep our sending servers in the European Union and manage them ourselves. We know where the data physically sits and who has access to it, because those are our people and our keys. When asked about data processing arrangements, we answer with the name of a location, not with a pointer to a cloud region.
Forms with double opt-in, a consent log and unsubscribe handling are a standard part of the process, not an option in a higher plan. Unsubscribe works from every message and takes effect immediately. You will find more about how we tie this together on the page of our email marketing platform compliant with GDPR and PKE.
Consents collected in forms on your site, in a CRM or in a store have to end up in a single log, otherwise your evidence scatters across several systems. That is why connections with external tools carry the source and the sign-up timestamp along with the address.
We do not promise to get around spam filters. That is not a service, it is somebody else’s problem sold as a feature. We work on sender reputation, authentication and list hygiene, because only those three things genuinely change deliverability.
We also say what is not there yet. Full versioning of consent clauses and evidential export of a single record are on the roadmap, not in the panel. We would rather say it outright than let you discover the gap during an audit.
Summary: a checklist before your first B2B send
Article 398 of the PKE does not distinguish between a private and a business recipient. Consent is always needed, and the domain in the address changes nothing.
Before you hit send, check:
- Consent collected before the first send, not during it.
- Proof of consent stored in the system, with the time, source and wording of the clause.
- Separate statements for email, phone and SMS.
- Unsubscribe working from every message, with a record of opt-outs.
- Correct SPF, DKIM, DMARC, Return-Path and PTR.
While you are at it, audit what you already have. Records without documented consent go to one side. And you do not send to them “just as a test”, because a test is a send too and loads your domain reputation the same way.
A smaller, compliant list gives you higher engagement and steadier deliverability than a big bought database. Consent before sending is the cheapest part of the whole infrastructure.


