Cold Email Strategy

    GDPR for B2B Outbound: What Emailing Contacts in Europe Actually Requires

    Territorial scope, the assessment behind a legitimate interest send, the national ePrivacy layer that decides whether you may send, and what the first message carries.

    August 13, 202611 min read
    Share:
    The short answer

    GDPR reaches any outbound list holding named contacts in the EU or UK, whatever country the sender is registered in. Cold email normally runs on legitimate interest, which requires a three part test run and recorded before the send, transparency at first contact, and an absolute right to object. National ePrivacy law separately decides whether the send is allowed.

    Key takeaways

    • Territorial scope follows the recipient. The Commission's Your Europe guidance applies the GDPR to a company established outside the EU that processes personal data in relation to offering goods or services to individuals in the EU, or monitoring their behaviour.
    • Legitimate interest is conditional on the work behind it. The ICO's guidance sets a three part test of purpose, necessity and balance, says to run it before the processing starts, and says to record the resulting assessment.
    • GDPR and ePrivacy answer different questions, and the second one is national law. Ireland's regulator states that electronic direct marketing generally requires affirmative consent under Regulation 13, while the ICO states that you can email any UK corporate body.
    • The transparency obligation lands at the first communication, and it covers who you are, the source of the address, and a route to object that is absolute for direct marketing.

    Reviewed and updated August 13, 2026

    A sourcing run comes back and part of the list sits in Dublin, Munich, Amsterdam and Manchester. Those rows look exactly like the American ones. Same job titles, same company domains, same shape of address, and the campaign will treat them identically unless somebody decides otherwise before the send. That decision is the whole of what GDPR asks of an outbound team.

    Almost everything written about GDPR is aimed at a privacy programme: registers, impact assessments, breach drills, cookie banners. Very little of it answers the narrow question a B2B sender actually has, which is whether these specific contacts can be emailed and what the message has to say when it lands. This page answers that one, and stops there.

    This is not legal advice. It is an operator's reading of published regulator and Commission guidance, with every source linked so you can check the wording yourself. If you are sending into Europe at volume, have counsel review your process before you rely on any of it.

    Does GDPR reach your list at all

    Territorial scope follows the person you are contacting rather than the address on your own incorporation documents. The European Commission's Your Europe guidance for business states that the GDPR applies if "your company is established outside the EU but processes personal data in relation to the offering of goods or services to individuals in the EU, or monitors the behaviour of individuals within the EU". A campaign aimed at buyers in Ireland or Germany is an offer of services to individuals in the EU on any ordinary reading of that sentence, so a Delaware entity with a US team and US servers is inside the Regulation the moment it targets those people.

    A work email address that identifies a named person is personal data, and so is the name, the job title and the company sitting beside it in your row. The same page does record one boundary that matters here: GDPR does not apply where "the data subject is a legal person". A generic company inbox naming nobody is a different object from a named individual's work address. Most B2B lists are built of named people, so that boundary rescues very few campaigns.

    1. Step 1Locate the person

      Is this contact in the EU or the UK? Scope follows the person you are targeting, not where your company is registered.

    2. Step 2Name the lawful basis

      For cold outbound that is normally legitimate interest, which means running the three part test and writing down the result.

    3. Step 3Check the national send rule

      The ePrivacy layer is separate national law in every country, so the answer to whether you may send is decided country by country.

    4. Step 4Carry the transparency

      Who you are, how you got the address, why you are writing, and a working route to object, in the first message.

    5. Step 5Honour the objection

      Stop on request, permanently, across every campaign and every sending domain you control.

    The order these questions have to be answered in for a single European contact, before the campaign is built rather than after a complaint arrives.

    What changes when the sender is a US company

    The instinct that a US sender only owes CAN-SPAM is where this goes wrong, and it goes wrong quietly, because nothing bounces. The US federal rules are a separate rulebook covered in full in our guide to whether cold email is legal, alongside the state privacy layer such as California. Neither of them displaces GDPR for a European recipient. Two obligations land specifically on the non-EU sender.

    The first is representation. Your Europe states that non-EU based businesses processing EU citizens' data have to appoint a representative in the EU. That is a named contact inside the Union that regulators and individuals can write to.

    The second is the transfer. Pulling European contacts into a US database is a transfer of personal data outside the EU, and the same guidance sets out the routes: the receiving country's protections are deemed adequate, your company puts appropriate safeguards such as specific contract clauses in place with the importer, or you rely on a specific derogation. Sales tooling makes this invisible, because the enrichment vendor, the sending platform and the CRM each move the same row again. The practical version for an outbound team is to know which of your vendors hold European contacts and on what basis, before a campaign rather than during an inquiry.

    Layer one: the lawful basis, and the homework behind it

    Cold outbound to business contacts normally runs on legitimate interest. The Commission's guidance on legal grounds for processing lists it as a ground where processing is necessary "for a company/organisation's legitimate interests, but only after having checked that the fundamental rights and freedoms of the individual whose data is processed are not seriously impacted", and it names the case directly: an organisation may have a legitimate interest where it "processes personal data for direct marketing purposes, to prevent fraud or to ensure the network and information security of its IT systems". That page cites Articles 6 and 13 and Recitals 47 to 49 of the GDPR as its references.

    Relying on that basis is conditional on doing the assessment, and the UK regulator publishes the clearest version of what the assessment is. The ICO's guidance on legitimate interests breaks it into a three part test: a Purpose test (are you pursuing a legitimate interest), a Necessity test (is your use of personal information necessary for that purpose), and a Balancing test (do the person's interests override the legitimate interest). The same page says you should do the test before you start using the information, and that you should record the resulting legitimate interests assessment to help demonstrate compliance.

    For an outbound team that is a short, honest document rather than a project. What are you trying to achieve, why this contact and this role in particular, why an email is a proportionate way to do it, and what makes it reasonable to expect a person in that job to hear from a supplier in your category. The necessity test is where most sloppy targeting fails, because a list built by scraping everyone at a company cannot explain why any individual row was needed.

    Two operating consequences fall out of the test rather than out of any statute. Provenance is part of your evidence, so record where each address came from and when, which is one of several reasons we source from published business surfaces and do not scrape LinkedIn. And relevance is part of the balance, so an ICP filter that cannot articulate why this role would care is a compliance problem before it is a conversion problem.

    Layer two: ePrivacy, and why a single EU-wide send is the mistake

    A clean lawful basis answers whether you may hold and use the data. It does not answer whether you may send the message. The Commission's own guidance is explicit that an organisation using contact lists for direct marketing "must also ensure that if it uses communication tools, such as email, for the purposes of direct marketing, it complies with the rules set out in the" ePrivacy Directive.

    That second layer is a directive, so it lives in each member state's own national law rather than in one European text, and those national laws do not agree. Two neighbouring regulators publishing in English make the gap concrete.

    In Ireland, the Data Protection Commission's published case study on electronic direct marketing states that "under Regulation 13 of the ePrivacy Regulations (S.I. 336/2011), as a general rule electronic direct marketing requires the affirmative consent of the recipient". Consent is the starting point there.

    In the UK, the Information Commissioner's Office guide to PECR on electronic mail marketing states that "you can email or text any corporate body (a company, Scottish partnership, limited liability partnership or government body)". No consent is the starting point there for that category of recipient.

    Same channel, same continent, opposite defaults. Any position you have read about a specific member state, including the ones repeated confidently across compliance blogs, has to be checked against that country's own regulator or its own implementing law before you send on it. We are not going to characterise Germany's or France's position here from second-hand sources, and neither should a campaign plan.

    The operational answer is segmentation. Country belongs in the targeting layer, and each country on the list gets its own answer to the send question before the campaign is built. That is the same discipline Canada demands for different reasons, which is covered in CASL compliance for cold email.

    The GDPR layerMay you process this person's data
    • Applies to a work address that identifies a named individual
    • Needs a lawful basis, usually legitimate interest for outbound
    • Requires the three part test, run and written down before the send
    • Requires transparency at the first communication
    • Carries an absolute right to object to direct marketing
    The ePrivacy layerMay you send this message at all
    • Implemented separately in each country's own national law
    • Decides whether consent is needed for the send itself
    • Ireland starts from affirmative consent under Regulation 13
    • The UK allows email to a corporate body under PECR
    • A documented lawful basis does not answer this question
    The two layers ask different questions, and satisfying the first one says nothing about the second.

    The UK, where the answer is unusually clear

    The UK is the one jurisdiction in this family where an outbound team gets a plain answer. The ICO's guide to PECR puts the electronic mail marketing rules in regulation 22, and draws the line by subscriber type. Email to a corporate body is permitted as above. The exclusion is that "sole traders and some partnerships are treated as individuals", so those rows need specific consent or a prior customer relationship, exactly as a consumer would.

    Two conditions apply whoever the recipient is. The same page states that "you must not disguise or conceal your identity, and you must provide a valid contact address so they can opt out or unsubscribe". The ICO also recommends keeping a do not email or text list of any businesses that object, and screening new lists against it, which is the suppression list any competent sender already runs.

    UK GDPR sits on top of PECR rather than beside it, and the ICO's legitimate interests guidance makes the interaction explicit: legitimate interests "can apply for direct marketing but only where the Privacy and Electronic Communication Regulations (PECR) don't require consent". Where PECR does require consent, the softer basis is not available to route around it.

    What the first message has to carry

    The transparency obligation is the one outbound teams miss, because it is triggered by the way cold lists are built. You did not get the address from the person, so the rules for indirectly obtained data apply.

    The Commission's legal grounds guidance, in its section on marketing lists, states that an organisation "must inform individuals, at the latest at the time of the first communication with them, that it is processing their personal data" for advertising, and that they have "the right to object to that processing at any time". The ICO's guidance on the right to be informed sets the same deadline from the other direction: privacy information is owed within a reasonable period and no later than one month, or "at the latest, when the first communication takes place" if you plan to communicate with the person. That page also lists "the source of the personal data" among the things you must disclose when the data came from somewhere other than the individual, and it is explicit that data taken from publicly accessible sources still carries the obligation.

    The right to object is not discretionary once someone uses it. The ICO's legitimate interests guidance says that people have a right to object where your basis is legitimate interests, and that "for direct marketing, this is an absolute right". There is no balancing exercise on the way out. The Commission's guidance says the same operationally: an organisation must ensure it "does not send advertising to individuals who objected" to processing for direct marketing.

    None of that needs a legal paragraph bolted to the bottom of a cold email. It needs a sentence saying who you are and where the address came from, a link to a privacy notice that actually loads, and a one step way to stop. All of it fits inside a single message, which is convenient, because we run one message per campaign and never bump a thread.

    The outbound GDPR checklist

    Before a European campaign goes live
    • Yes: Segment EU and UK contacts out of the global list before the campaign is built
    • Yes: Record the source URL and the collection date on every address, and keep them
    • Yes: Write the legitimate interests assessment before the first send and store it with the campaign
    • Yes: Check the ePrivacy position for each country on the list against that country's own regulator
    • Yes: Appoint an EU representative if your company is established outside the Union
    • Yes: Know which vendors hold your European contacts and on what transfer basis
    • Yes: Name your company honestly in the message and give a valid contact address
    • Yes: Say how you got the address and link a privacy notice that loads
    • Yes: Offer a one step objection route and suppress globally on the first request
    • Yes: Re-verify the list before each send so leavers and dead roles drop out
    An outbound scoped checklist. It covers sending to European contacts and deliberately leaves the rest of a privacy programme to a privacy programme.

    What the fines actually are

    The European Commission's page on enforcement and sanctions describes an escalating range rather than a single number. Where processing is likely to infringe the GDPR a warning may be issued. Where it does infringe, the possibilities include a reprimand, "a temporary or definitive" ban on processing, and "a fine of up to €20 million" or 4% of the business's total annual worldwide turnover. The same page notes that Member States must also provide for other penalties, including "criminal penalties", for infringements not subject to administrative fines.

    The ban on processing is the part worth reading twice. For an outbound team, an order to stop processing a category of data is a more immediate business event than a fine, and it arrives faster.

    UK penalties under PECR are currently in motion, and we are not going to state a number the regulator's own page does not. The ICO's "What are PECR?" guidance as published today says the Information Commissioner can serve a monetary penalty notice "imposing a fine of up to £500,000" against an organisation or its directors, and that same page carries a notice that "this guidance is under review and may be subject to change" because of the Data (Use and Access) Act. Higher figures are circulating widely. Check the ICO's live page rather than any summary of it, including this one, before you quote a maximum.

    Where senders actually get caught

    Not on the fine print of legitimate interest. Enforcement attention follows volume and complaints, and complaints follow a small number of avoidable behaviours: consumer addresses mixed into a business list, a sender identity that hides who is writing, an objection that is honoured in one campaign and not the others, an unsubscribe route that quietly fails, and a single global send built for the most permissive jurisdiction on the list.

    Every one of those is also a deliverability defect. Accurate identity, a list of real people in relevant roles, and an instant, permanent stop are what keep complaint rates low, and complaint rate is one of the signals mailbox providers weigh when they decide where your mail lands. The compliance work and the deliverability fundamentals pull in the same direction.

    Our own operating policy is the narrow version of all of this: one message per campaign with no bumps and no thread replies, addresses resolved through a verification waterfall of MillionVerifier, Prospeo and Findymail rather than guessed, published business sources rather than scraped profiles, suppression applied across every campaign and domain at once, and meeting criteria agreed in writing before a campaign launches. We run outbound campaigns, and we do not sell privacy consulting, compliance software or templates.

    Running outbound into Europe and want the segmentation, provenance and suppression layer built in from the start? Get a free campaign plan and we will walk through how it is set up.

    Statutory and regulator text verified against the sources linked above as of August 2026. This is an operator's summary and not legal advice. Verify current requirements, and take your own advice, before relying on it.

    Questions

    Frequently asked questions.

    Frequently asked questions
    Does GDPR apply to a US company sending cold email to Europe?
    Yes, where the contacts are in the EU. The Commission's Your Europe guidance applies the GDPR to a company established outside the EU that processes personal data in relation to offering goods or services to individuals in the EU, or that monitors their behaviour. The same page adds that non-EU businesses have to appoint a representative in the EU, and that moving the data out is a transfer needing its own basis.
    Can I send cold email under legitimate interest without consent?
    Under the GDPR layer, often yes. The Commission's guidance names direct marketing as a case where an organisation may have a legitimate interest, and the ICO sets out the three part purpose, necessity and balancing test you must run and record first. The separate ePrivacy layer still decides whether the send itself is permitted, and that answer is national.
    What does a compliant cold email to a European contact have to include?
    Your real identity, with no concealment, and a valid contact address, which the ICO's PECR guidance requires. Then the transparency the Commission places at the latest at the time of first communication: that you are processing their data to market to them, where the address came from, and that they may object at any time. A privacy notice that actually loads covers the detail.
    How large are GDPR fines for outbound mistakes?
    The Commission's enforcement and sanctions page describes a ladder rather than one number: a warning, a reprimand, a temporary or definitive ban on processing, and a fine of up to 20 million euro or 4 percent of total annual worldwide turnover. Member States must also provide criminal penalties for infringements outside the administrative fine regime.
    Cold EmailComplianceGDPREmail LawB2B Sales
    Byline

    About the author.

    Ben Carden

    Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.

    Ben Carden · CRO

    Connect on LinkedIn →
    Your next move

    Ready to scale your outreach?

    We build GTM engines that book real meetings. See the receipts.

    Further reading

    Related articles.

    Cold Email Strategy

    CAN-SPAM Act Compliance for B2B Cold Email: What the Law Requires

    The CAN-SPAM Act makes no exception for business-to-business email. Here are the seven requirements, the opt-out clocks, and where liability lands when an agency sends.

    11 min readRead →
    Cold Email Strategy

    CCPA Compliance for Cold Outreach: The B2B Exemption That Lapsed

    CCPA's business-to-business exemption went inoperative on 1 January 2023, so a B2B prospect record for a California resident carries full consumer rights.

    11 min readRead →
    Cold Email Strategy

    Is Cold Email Legal? CAN-SPAM, GDPR, and CASL in Plain English

    Cold email is legal in the US without consent, restricted in Canada, and conditional in the EU and UK. Here is what each regime requires and what it costs.

    6 min readRead →
    Cold Email Strategy

    CASL Compliance for Cold Email: What Canadian Law Actually Requires

    Express versus implied consent, the conspicuous publication route, the narrow B2B exemption, and the 60-day and 10-business-day rules CASL imposes on senders.

    6 min readRead →
    Cold Email Strategy

    11 Cold Email Agencies: What Each One Publishes About Price

    Eight of eleven cold email agencies publish a rate and three publish only terms. Four publish what they count as a qualified lead, and those definitions differ sharply.

    7 min readRead →
    Cold Email Strategy

    How to Write a Cold Email When It Is the Only One You Send

    Cold email writing is mostly deciding, and the deciding happens before the drafting. The order the work runs in, from one verifiable fact to a message worth sending.

    7 min readRead →