This is a plain-language starting point, not legal advice. GDPR obligations depend on your specific data, processes, and jurisdiction — talk to a qualified privacy lawyer before making compliance decisions for your business.
"Is cold outreach even legal under GDPR" comes up constantly, and the honest answer is: usually yes, with conditions, and the conditions are more about how you use the data than whether you're allowed to have it. Here's the shape of it.
GDPR covers people, not companies
The regulation protects personal data about identifiable individuals. A company's registered address or VAT number isn't personal data on its own. But a named individual's work email — jane.doe@company.com — is personal data, full stop, regardless of whether it's a work or personal address. The "B2B" in B2B contact data doesn't exempt it from GDPR; it just changes which lawful basis you're likely to rely on.
Legitimate interest is the usual basis for B2B outreach
Most B2B prospecting relies on "legitimate interest" rather than consent as its lawful basis under Article 6. Broadly, this means you can process someone's professional contact data to reach out about something genuinely relevant to their role, without having asked permission first — as long as you've weighed your interest against their rights and it doesn't override them. This is why a relevant, well-targeted B2B sales email is treated differently from an unrelated bulk blast: relevance to the person's actual job is doing real legal work here, not just being polite.
Where legitimate interest stops covering you
A few situations complicate the legitimate-interest basis:
- Email marketing to individuals in specific countries also triggers separate national ePrivacy rules layered on top of GDPR (Germany and others have historically been stricter here than the general EU baseline) — a legitimate-interest basis under GDPR doesn't automatically clear every national marketing-communication rule.
- Irrelevant targeting undermines the basis. Legitimate interest depends on the outreach being relevant to the recipient's professional role. A generic list blast to titles that have nothing to do with your product is weaker ground than a targeted send to people whose job the message is actually about.
- An opt-out has to be honored, and honored promptly. Every message needs a working way to opt out, and once someone does, continuing to contact them removes the "legitimate" from legitimate interest.
Right to erasure and right to know applies to purchased or enriched data too
If someone asks where you got their information or asks you to delete it, GDPR's rights of access and erasure apply whether the record came from your own CRM, a purchased list, or an enrichment API. This means your outbound process needs an actual mechanism for finding and removing one person's data on request, not just a policy that says you would if asked. It's worth thinking through before the first request arrives, not while responding to one under time pressure.
What to actually check on a vendor before you buy their data
If you're sourcing contact data from a third party, three questions are worth asking directly: what's their lawful basis for holding this data, do they support deletion requests being passed through to you, and do they document where the underlying data originated. A vendor who can answer all three clearly is a meaningfully lower-risk purchase than one who can't.
The practical takeaway
None of this means B2B outreach into the EU is off-limits — it's a normal, common, lawful activity under the right conditions. It does mean "we bought a list" isn't itself a compliance answer. Relevance, an honored opt-out, and being able to answer a deletion request are the load-bearing pieces, and none of them are especially hard to build into a normal outbound process once you know they're required.