Our approach to GDPR and PECR
GDPR still applies to business contact data, even though most founders assume it doesn’t. Here’s what that means in practice, and what we actually do about it.
Not legal advice
This page explains our own approach in plain language. It isn’t legal advice, and if compliance is a hard requirement for your business, get your own advice for your specific market and sector.
Why this applies to B2B, not just consumer marketing
GDPR covers any personal data, and a named person’s business email address is personal data, even inside a B2B context. The exemptions that apply to consumer marketing don’t apply the same way here. What changes for B2B is the legal basis available, not whether the rules apply at all.
The legal basis we use
We rely on legitimate interests for B2B cold outreach: the message has to be relevant to the recipient’s business role, proportionate, and give them an obvious way to say no. That’s a narrower bar than “anyone can email anyone at a company”, and it’s the reason targeting the right decision-maker with a real, current reason to reach out isn’t just good practice, it’s the compliance mechanism itself.
What “compliant by design” looks like day to day
- Verified contact data.No scraping-and-hoping. A wrong guess isn’t just a bounced email, it’s data processed without a real basis for reaching that specific inbox.
- A real, current reason for the email. Not a mail-merge field. Relevance is the thing that makes legitimate interests hold up as a basis at all.
- Immediate opt-out.Anyone can stop future contact by replying or emailing us directly, and that’s honoured immediately, not on a monthly batch job.
- No special category data.We don’t target based on health, politics, religion, or similar, and we don’t need to: the targeting signal is always business-role and business-context based.
What’s in the UK’s PECR, specifically
PECR adds UK-specific rules on top of GDPR for electronic marketing, including a narrower carve-out for “corporate subscribers” (companies, as opposed to sole traders and some partnerships, who get closer to consumer-level protection). We cover this in more detail, including what counts as a corporate subscriber, in our PECR guide.
What stays your responsibility
We control sourcing, verification, and suppression. You control who gets targeted and what the email says once it’s reviewed by you. Full details of that split live in our Data Processing Addendum.
GDPR and PECR, in short
Yes, when it's done properly. GDPR still applies to business contact data, but legitimate interests is a recognised legal basis for relevant B2B marketing, provided the message is targeted at someone whose role makes it relevant and there's a clear way to opt out. See our PECR guide on the blog for more detail on the UK-specific rules.
It means the campaign is built around relevance and opt-out from the start, not bolted on afterwards: targeting a real decision-maker at a real company, using verified (not guessed or scraped-and-hoped) contact data, and honouring an opt-out immediately when someone asks.
It's shared. We control how contact data is sourced, verified, and suppressed once someone opts out. You control who's targeted and what's said. Both of those have to be right for a campaign to actually be compliant.
Business contacts, at a business email address, about a business-relevant reason to reach out. We don't target personal email addresses or run consumer marketing.
They're suppressed from future outreach immediately, whether they reply directly or email us at hello@nostressagents.com. See our Privacy Policy for the full mechanics.