Cold Email Strategy

    GDPR for B2B Outbound: Emailing Contacts in Europe

    Territorial scope, the assessment behind a legitimate interest send, the national ePrivacy layer that decides whether you may send, and what the first message carries.

    Editorial illustration for GDPR for B2B Outbound
    June 10, 2026Updated September 21, 202611 min read
    Share:
    The short answer

    GDPR reaches any sender that targets people in the EU, wherever the company is registered. B2B outbound normally relies on legitimate interest, which needs a written three part test, while each country's ePrivacy law separately decides whether you may send at all. The first message must say who you are, where the address came from and how to object.

    Key takeaways

    • The Commission's guidance applies GDPR to a non-EU company that offers goods or services to individuals in the EU, so targeting buyers there brings a US sender in.
    • Legitimate interest needs the ICO's three part test, purpose, necessity and balancing, run before the send and recorded.
    • ePrivacy is national: Ireland's regulator starts from affirmative consent, while the UK's PECR allows email to a corporate body.
    • The objection right is absolute for direct marketing: once someone objects, stop and suppress across every campaign.

    Reviewed and updated September 21, 2026

    A sourcing run comes back and part of the list sits in Dublin, Munich, Amsterdam and Manchester. Those rows look exactly like the American ones. Same job titles, same company domains, same shape of address, and the campaign will treat them identically unless somebody decides otherwise before the send. That decision is the whole of what GDPR asks of an outbound team prospecting into European companies.

    Most GDPR writing is aimed at a privacy programme. This page answers the narrow question a B2B sender has: whether these contacts can be emailed, and what the message must say when it lands.

    This is not legal advice. It is an operator's reading of published regulator and Commission guidance, with every source linked so you can check the wording yourself. If you are sending into Europe at volume, have counsel review your process before you rely on any of it.

    Most guidance written about email marketing and GDPR assumes a consumer newsletter list, which is why it lands on consent; B2B outbound to named business contacts runs on legitimate interest instead.

    Guidance written for SMS marketing is the commonest source of confusion and does not transfer: it lands on prior opt-in because separate electronic-communications rules govern that channel, and applying it to B2B email wrongly rules out a lawful basis you already have.

    Prospecting into European companies: does GDPR reach your list?

    Territorial scope follows the person you are contacting rather than the address on your own incorporation documents. The European Commission's Your Europe guidance for business states that the GDPR applies if "your company is established outside the EU but processes personal data in relation to the offering of goods or services to individuals in the EU, or monitors the behaviour of individuals within the EU". A campaign aimed at buyers in Ireland or Germany is an offer of services to individuals in the EU on any ordinary reading of that sentence, so a Delaware entity with a US team and US servers is inside the Regulation the moment it targets those people.

    A work email address that identifies a named person is personal data, and so is the name, the job title and the company sitting beside it in your row. The same page does record one boundary that matters here: GDPR does not apply where "the data subject is a legal person". A generic company inbox naming nobody is a different object from a named individual's work address. Most B2B lists are built of named people, so that boundary rescues very few campaigns.

    1
    Locate the person

    EU or UK? Scope follows the person you target, not where you are registered.

    2
    Name the lawful basis

    Normally legitimate interest: run the three part test and write it down.

    3
    Check the national send rule

    The ePrivacy layer is national law, so the answer is country by country.

    4
    Carry the transparency

    Who you are, where the address came from, why you write, how to object.

    5
    Honour the objection

    Stop on request, permanently, across every campaign and domain.

    The order these questions have to be answered in for a single European contact, before the campaign is built rather than after a complaint arrives.

    What changes when the sender is a US company

    The instinct that a US sender only owes CAN-SPAM is where this goes wrong, quietly, because nothing bounces. The US federal rules are a separate rulebook covered in full in our guide to whether cold email is legal, alongside the state privacy layer such as California. Neither of them displaces GDPR for a European recipient. Two obligations land specifically on the non-EU sender.

    The first is representation. Your Europe states that non-EU based businesses processing EU citizens' data have to appoint a representative in the EU. That is a named contact inside the Union that regulators and individuals can write to.

    The second is the transfer. Pulling European contacts into a US database is a transfer of personal data outside the EU, and the same guidance sets out the routes: the receiving country's protections are deemed adequate, your company puts appropriate safeguards such as specific contract clauses in place with the importer, or you rely on a specific derogation. Sales tooling hides this, because the enrichment vendor, the sending platform and the CRM each move the row again, so know which vendors hold European contacts and on what basis before a campaign.

    Layer one: the lawful basis, and the homework behind it

    Section illustration: Layer one: the lawful basis, and the homework behind it

    Cold outbound to business contacts normally runs on legitimate interest. The Commission's guidance on legal grounds for processing lists it as a ground where processing is necessary "for a company/organisation's legitimate interests, but only after having checked that the fundamental rights and freedoms of the individual whose data is processed are not seriously impacted", and it names the case directly: an organisation may have a legitimate interest where it "processes personal data for direct marketing purposes, to prevent fraud or to ensure the network and information security of its IT systems". That page cites Articles 6 and 13 and Recitals 47 to 49 of the GDPR as its references.

    Relying on that basis is conditional on doing the assessment, and the UK regulator publishes the clearest version of what the assessment is. The ICO's guidance on legitimate interests breaks it into a three part test: a Purpose test (are you pursuing a legitimate interest), a Necessity test (is your use of personal information necessary for that purpose), and a Balancing test (do the person's interests override the legitimate interest). The same page says you should do the test before you start using the information, and that you should record the resulting legitimate interests assessment to help demonstrate compliance.

    For an outbound team that is a short document: what you are trying to achieve, why this role, why an email is proportionate, and why a person in that job would reasonably expect to hear from your category. The necessity test is where sloppy targeting fails, because a list of everyone at a company cannot explain why any row was needed.

    Two operating consequences fall out of the test rather than out of any statute. Provenance is part of your evidence, so record where each address came from and when, which is one of several reasons we source from published business surfaces and do not scrape LinkedIn. And relevance is part of the balance, so an ICP filter that cannot articulate why this role would care is a compliance problem before it is a conversion problem.

    Layer two: ePrivacy, and why a single EU-wide send is the mistake

    A clean lawful basis answers whether you may hold and use the data. It does not answer whether you may send the message. The Commission's own guidance is explicit that an organisation using contact lists for direct marketing "must also ensure that if it uses communication tools, such as email, for the purposes of direct marketing, it complies with the rules set out in the" ePrivacy Directive.

    That second layer is a directive, so it lives in each member state's own national law rather than in one European text, and those national laws do not agree. Two neighbouring regulators publishing in English make the gap concrete.

    In Ireland, the Data Protection Commission's published case study on electronic direct marketing states that "under Regulation 13 of the ePrivacy Regulations (S.I. 336/2011), as a general rule electronic direct marketing requires the affirmative consent of the recipient". Consent is the starting point there.

    In the UK, the Information Commissioner's Office guide to PECR on electronic mail marketing states that "you can email or text any corporate body (a company, Scottish partnership, limited liability partnership or government body)". No consent is the starting point there for that category of recipient.

    Same channel, same continent, opposite defaults. Any position you have read about a member state has to be checked against that country's own regulator or implementing law before you send on it. We do not characterise Germany's or France's position here from second-hand sources, and neither should a campaign plan.

    The operational answer is segmentation. Country belongs in the targeting layer, and each country on the list gets its own answer to the send question before the campaign is built. That is the same discipline Canada demands for different reasons, which is covered in CASL compliance for cold email.

    GDPR layerePrivacy layer
    The questionMay you process this person's data?May you send this message at all?
    Where it livesOne RegulationEach country's own national law
    What it needsA lawful basis, usually legitimate interest, tested and recordedConsent or an exception, country by country
    ExampleAn absolute right to object to direct marketingIreland starts from consent; the UK allows email to a corporate body
    The two layers ask different questions, and satisfying the first one says nothing about the second.

    The UK, where the answer is unusually clear

    Section illustration: The UK, where the answer is unusually clear

    The UK is the one jurisdiction in this family where an outbound team gets a plain answer. The ICO's guide to PECR puts the electronic mail marketing rules in regulation 22, and draws the line by subscriber type. Email to a corporate body is permitted as above. The exclusion is that "sole traders and some partnerships are treated as individuals", so those rows need specific consent or a prior customer relationship, exactly as a consumer would.

    Two conditions apply whoever the recipient is. The same page states that "you must not disguise or conceal your identity, and you must provide a valid contact address so they can opt out or unsubscribe". The ICO also recommends keeping a do not email or text list of any businesses that object, and screening new lists against it, which is the suppression list any competent sender already runs.

    UK GDPR sits on top of PECR rather than beside it, and the ICO's legitimate interests guidance makes the interaction explicit: legitimate interests "can apply for direct marketing but only where the Privacy and Electronic Communication Regulations (PECR) don't require consent". Where PECR does require consent, the softer basis is not available to route around it.

    What the first message has to carry

    The transparency obligation is the one outbound teams miss, because it is triggered by the way cold lists are built. You did not get the address from the person, so the rules for indirectly obtained data apply.

    The Commission's legal grounds guidance, in its section on marketing lists, states that an organisation "must inform individuals, at the latest at the time of the first communication with them, that it is processing their personal data" for advertising, and that they have "the right to object to that processing at any time". The ICO's guidance on the right to be informed sets the same deadline from the other direction: privacy information is owed within a reasonable period and no later than one month, or "at the latest, when the first communication takes place" if you plan to communicate with the person. That page also lists "the source of the personal data" among the things you must disclose when the data came from somewhere other than the individual, and it is explicit that data taken from publicly accessible sources still carries the obligation.

    The right to object is not discretionary once someone uses it. The ICO's legitimate interests guidance says that people have a right to object where your basis is legitimate interests, and that "for direct marketing, this is an absolute right". There is no balancing exercise on the way out. The Commission's guidance says the same operationally: an organisation must ensure it "does not send advertising to individuals who objected" to processing for direct marketing.

    None of that needs a legal paragraph. It needs a sentence saying who you are and where the address came from, a privacy notice link that loads, and a one step way to stop, all of which fits in a single message, and we run one message per campaign.

    The outbound GDPR checklist

    Section illustration: The outbound GDPR checklist

    Before the campaign
    • Segment EU and UK contacts out of the global list
    • Record each address's source URL and collection date
    • Write the legitimate interests assessment and store it
    • Check each country's ePrivacy position with its own regulator
    • Appoint an EU representative if established outside the Union
    • Know which vendors hold European contacts, on what transfer basis
    In the message and after
    • Name the company honestly, with a valid contact address
    • Say how you got the address; link a privacy notice that loads
    • Offer a one step objection route; suppress globally at once
    • Re-verify the list before each send
    An outbound scoped checklist. It covers sending to European contacts and deliberately leaves the rest of a privacy programme to a privacy programme.

    What the fines actually are

    The European Commission's page on enforcement and sanctions describes an escalating range rather than a single number. Where processing is likely to infringe the GDPR a warning may be issued. Where it does infringe, the possibilities include a reprimand, "a temporary or definitive" ban on processing, and "a fine of up to €20 million" or 4% of the business's total annual worldwide turnover. The same page notes that Member States must also provide for other penalties, including "criminal penalties", for infringements not subject to administrative fines.

    The ban on processing is the part worth reading twice: for an outbound team an order to stop processing is a more immediate business event than a fine.

    UK penalties under PECR are currently in motion, and we are not going to state a number the regulator's own page does not. The ICO's "What are PECR?" guidance as published today says the Information Commissioner can serve a monetary penalty notice "imposing a fine of up to £500,000" against an organisation or its directors, and that same page carries a notice that "this guidance is under review and may be subject to change" because of the Data (Use and Access) Act. Higher figures are circulating widely. Check the ICO's live page rather than any summary of it, including this one, before you quote a maximum.

    Where senders actually get caught

    Section illustration: Where senders actually get caught

    Not on the fine print of legitimate interest. Enforcement follows complaints, and complaints follow avoidable behaviours: consumer addresses in a business list, a hidden sender identity, an objection honoured in one campaign but not others, a failing unsubscribe, and one global send built for the most permissive country.

    Every one of those is also a deliverability defect. Accurate identity, a list of real people in relevant roles, and an instant, permanent stop are what keep complaint rates low, and complaint rate is one of the signals mailbox providers weigh when they decide where your mail lands. The compliance work and the deliverability fundamentals pull in the same direction.

    Choosing a sending platform matters just as much, since some tools layer their own consent rules on top of GDPR, as explained in HubSpot's anti-spam policy for cold email.

    Our own operating policy is the narrow version of all of this: one message per campaign with no bumps and no thread replies, addresses found and verified through a waterfall of GetLeads, Prospeo and MillionVerifier rather than guessed, published business sources rather than scraped profiles, suppression applied across every campaign and domain at once, and meeting criteria agreed in writing before a campaign launches. We run outbound campaigns, and we do not sell privacy consulting, compliance software or templates.

    Running outbound into Europe and want the segmentation, provenance and suppression layer built in from the start? Get a free campaign plan and we will walk through how it is set up.

    Statutory and regulator text checked against the sources linked above. This is an operator's summary and not legal advice. Verify current requirements, and take your own advice, before relying on it.

    Questions

    Frequently asked questions.

    Frequently asked questions
    How do I prospect into European companies by email?
    Segment European contacts out first, then answer four questions for each: does GDPR reach the person, what is your lawful basis (normally legitimate interest, tested and written down), does that country's ePrivacy law let you send, and does the first message say who you are, where the address came from and how to object.
    Does GDPR apply to a US company emailing Europe?
    Yes, if it targets people in the EU. The Commission's Your Europe guidance says the GDPR applies to a company established outside the EU that processes personal data in relation to offering goods or services to individuals in the EU. Such a company also has to appoint a representative in the EU and use a lawful route for data transfers.
    Is B2B cold email legal in the UK?
    Under PECR the ICO says you can email or text any corporate body, such as a company or limited liability partnership, without consent, but sole traders and some partnerships are treated as individuals. You must not disguise your identity and must give a valid contact address to opt out. UK GDPR and its legitimate interests test still apply on top.
    What are the GDPR fines for cold email?
    The Commission lists an escalating range: warnings, reprimands, a temporary or definitive ban on processing, and fines of up to €20 million or 4% of total annual worldwide turnover. In the UK, the ICO's PECR page states fines of up to £500,000 and says the guidance is under review after the Data (Use and Access) Act, so check its live page.
    Cold EmailComplianceGDPREmail LawB2B Sales
    Byline

    About the author.

    Ben Carden

    Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.

    Ben Carden · CRO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.