GDPR and B2B Cold Outreach: What Founders Get Wrong
GDPR still applies to B2B contact data, even though most founders assume it doesn't. A practical, non-alarmist explanation of what that means for outreach.
The short answer
GDPR applies to B2B cold outreach whenever the contact data identifies a person, which a named work email address does. It does not prohibit cold outreach: legitimate interests is a valid lawful basis for B2B marketing, provided you have done and documented the balancing test, tell people where you got their data, and honour objections immediately. This is a summary, not legal advice.
Key takeaways
- The common founder error is assuming "B2B" means "outside GDPR". It does not: a named work address is personal data.
- Legitimate interests is available and widely used, but it is a test you must actually perform and be able to evidence, not a box to tick.
- Transparency is the requirement most outbound gets wrong: a recipient is entitled to know where you got their details and how to object.
- An objection or opt-out must be honoured immediately and permanently. That means a real suppression list checked before every send.
The most common mistake founders make about GDPR and cold outreach is assuming it only applies to consumer marketing. It doesn’t. A named person’s business email address is personal data, and GDPR applies to processing it, even inside a purely B2B context. What changes for B2B isn’t whether the rules apply, it’s which legal basis is realistically available.
Not legal advice
This is general information, not legal advice for your specific business or market. If compliance is a hard requirement, get advice from a solicitor familiar with data protection law in your jurisdiction.
The legal basis question
GDPR requires a lawful basis for processing personal data. For relevant B2B marketing, the basis most commonly relied on is legitimate interests: the idea that a business has a genuine interest in reaching out, provided that interest is balanced against the individual’s rights, and the message is proportionate and relevant to their role. This is a narrower bar than it might sound: it doesn’t mean any business can email anyone at any company for any reason.
What “relevant and proportionate” actually looks like
- The message is genuinely about a business matter connected to the recipient’s role.
- The data used is limited to what’s needed to identify and reach the right person.
- The frequency and volume of contact is reasonable, not a barrage.
- The recipient has a clear, immediate way to object or opt out.
Where founders commonly get this wrong
- Assuming B2B is exempt entirely.It isn’t. The exemption that matters most for B2B email actually sits in PECR (the UK’s specific electronic marketing rules), not GDPR. See our PECR guide for that distinction.
- Buying or scraping bulk contact lists without checking sourcing.A legitimate interests basis is harder to justify when the data wasn’t gathered with any care about relevance or accuracy in the first place.
- Ignoring opt-out requests, or acting on them slowly. A legitimate interests basis assumes the recipient can object and have that honoured. Delaying that undermines the basis itself.
- Targeting based on anything sensitive. Special category data (health, political opinion, religion, and similar) has no place in B2B targeting and needs a different, much higher bar to process at all.
What “GDPR-compliant by design” should actually mean in practice
- Verified, not guessed or indiscriminately scraped, contact data.
- A genuine, specific, business-relevant reason for each message.
- An opt-out that’s honoured immediately, not on a delayed batch process.
- No special category data used for targeting.
- Data minimisation: collecting and keeping only what’s needed for the purpose.
Retention and data minimisation
GDPR also expects you not to keep personal data longer than needed for the purpose it was collected for. For outbound contact data, that generally means keeping it only as long as you’re actively using it for outreach or need it to honour an opt-out request, not indefinitely.
The practical takeaway
GDPR doesn’t make B2B cold email illegal. It makes sloppy, indiscriminate cold email harder to justify, which, done properly, is close to what good outbound practice already looks like: real targeting, real relevance, and a genuine respect for “no.”
Data minimisation, applied to a prospect record
GDPR requires you to hold what is adequate, relevant, and limited to what is necessary. For outbound, that is a shorter list than most CRMs accumulate: name, role, company, business email, the signal you are contacting them about, and where each came from.
What does not belong: personal email addresses, personal phone numbers, anything inferred about them rather than found, and anything that touches special category data such as health, political opinions, religious belief, trade union membership, sexual orientation. Targeting on any of those is not a grey area, and “it was on their public profile” is not a defence.
Retention: the question nobody sets an answer to
Personal data cannot be kept indefinitely because it might be useful one day. Prospect records need a retention period with a reason attached, and someone has to actually delete against it.
A defensible shape: delete unengaged prospect records after a defined period, keep records of people who became customers under a separate and longer commercial retention period, and keep suppression entries indefinitely, because a suppression list is the one dataset where deletion would cause the harm rather than prevent it. Write the periods down; an undocumented retention policy is functionally the same as not having one.
Rights requests, and the ones outbound actually triggers
| Request | What they are asking | What you must do |
|---|---|---|
| Objection to processing | Stop marketing to me. | Stop, immediately and permanently. Where the objection is to direct marketing there is no balancing test to apply. It is absolute. |
| Access (a DSAR) | What do you hold about me and where did it come from? | Provide it within the statutory period. This is why recording the source of every fact matters operationally, not just editorially. |
| Rectification | This is wrong, fix it. | Correct the record. |
| Erasure | Delete me. | Delete, while retaining the minimum needed to keep honouring the suppression. |
The one to be genuinely ready for is objection, because it arrives constantly and informally, as a one-line reply rather than as a formal request. Treat any “stop emailing me” as an objection and suppress it, without requiring a particular form of words.
Who is the controller when a service sends on your behalf
If a provider runs outbound for you, the usual arrangement is that you are the controller, since you decide who is contacted and why, and the provider is a processor acting on your instructions. That has consequences worth being explicit about:
- The obligations sit with you. Choosing the targeting is the controller decision, and it is not something a provider can absorb on your behalf.
- You need a data processing agreement in place with the provider. Ask for one; a provider that cannot produce a DPA has not thought about this.
- You are entitled to know where the provider sources contact data and what verification it performs, because you are answerable for it.
- Suppression has to flow both ways. An objection received by either party must reach the other.
Transfers outside the UK and EEA
If prospect data is processed on infrastructure outside the UK or EEA, which, for most SaaS tooling, it is, that transfer needs a lawful mechanism, typically an adequacy decision or standard contractual clauses. This is usually handled in the provider’s DPA rather than by you directly, but “we assumed it was fine” is not the position you want to discover you were in.
What a proportionate approach looks like
Nothing above requires a compliance department. In practice it is: a written ICP that explains why these roles are relevant, a written legitimate interests assessment, a short privacy notice you can link to, verified data with recorded sources, a retention period someone actually deletes against, and a suppression list you own and check.
That is a morning of work once, and it converts the entire subject from a background worry into a settled part of the process. See the PECR guide for the electronic-marketing rules that sit alongside this, and our own approach for how it is handled here.
This is the part of outbound No Stress Agents runs for its clients: per-account research, verified contacts, and a drafted email you approve before it sends.
Read our GDPR and PECR approach