
GDPR doesn't ban cold outreach — it regulates how you do it
GDPR doesn't ban B2B cold outreach in the EU. It regulates how you do it, and most teams either over-comply out of fear or under-comply out of not knowing the rules — both of which cost pipeline for no good reason.
The legal basis almost every B2B sender relies on is legitimate interest, under GDPR Article 6(1)(f). Recital 47 explicitly names direct marketing as an activity that may qualify — the regulation anticipates this exact use case, rather than treating it as a loophole someone found. But "may qualify" is doing real work in that sentence. It's not automatic.
The three-part test that actually matters
Legitimate interest holds up when it passes three checks, and this is worth actually running through per campaign rather than treating as a formality:
- Purpose. Is there a genuine, specific business reason for contacting this person — not "everyone could theoretically use this," but a real fit between what you sell and their role.
- Necessity. Is processing their contact information actually required to reach them this way, or is there a less intrusive path that would work just as well.
- Balancing. Does your business interest outweigh their privacy interest, given the context — a Head of Sales getting outreach about sales tooling is a much easier case than a CFO getting the same email. Regulators expect this documented as a Legitimate Interest Assessment, not just reasoned through informally. It's not bureaucracy for its own sake — it's the actual defense if a data protection authority ever asks why a given campaign was lawful.
What "B2B" actually buys you
The threshold is genuinely lower in B2B than B2C. Someone contacted at a business email address, in their professional capacity, has a reasonable expectation that vendor outreach happens — that's part of what a business email address is for. Cold outreach to a personal inbox, with no professional context at all, sits in much shakier territory.
That doesn't mean "B2B" is a blanket pass. Relevance still matters — a specific, defensible reason this specific person's role connects to what's being offered, not a mass send with B2B as the only qualifying logic.
The parts most guides skip
Two requirements get less attention than the legal basis itself, and they're where a lot of real friction actually shows up:
- Transparency about where the data came from. You don't need to recite a privacy policy in a cold email, but if someone asks how you got their information, there needs to be a real, specific answer — not a shrug.
- An opt-out that actually works, and gets honored immediately. This is the right to object under GDPR Article 21, and it's not optional or best-effort. Once someone opts out, that has to stick.
Germany (and the rest of DACH) adds a layer on top
Plain GDPR is only part of the picture if a meaningful share of outreach targets Germany specifically. German law adds UWG Section 7 on top of GDPR — commercial email rules that function as what's sometimes called "lex specialis," a more specific law that governs the particular question of electronic communications, layered over the general GDPR framework rather than replaced by it. In practice, that means German campaigns need their own review, not just a general EU-wide GDPR read. Given how much emphasis gets placed on the general GDPR question and how little on this specific layer, it's one of the more commonly missed details for teams prospecting into the DACH region.
Why this shapes the tooling question too
A lot of this comes back to where contact data actually comes from and how current it is. A legitimate interest basis is easier to defend when the outreach is genuinely relevant and current — reaching someone in a role they've actually just moved into, at a company that's actually shown a real reason to care, rather than a stale record from a database scraped a year ago and never re-verified. Compliance and data freshness aren't separate problems; a system that verifies who it's contacting in real time has an easier time explaining why that contact was relevant than one working off an old, static list.
:::warning This is general information, not legal advice. Specific campaigns, especially ones targeting Germany or other DACH markets, are worth a real legal review rather than relying on a blog post — including this one. :::
FAQ
:::expand[Do I need consent to send a B2B cold email under GDPR?] No. Legitimate interest under Article 6(1)(f) is the basis most B2B outreach relies on, provided it passes the purpose, necessity, and balancing test and includes a working opt-out. :::
:::expand[Does GDPR apply differently to LinkedIn outreach than email?] GDPR itself applies to processing personal data generally, regardless of channel. Email carries an additional layer of national rules in some countries (Germany's UWG Section 7, for instance) that don't map directly onto LinkedIn messaging, so the compliance picture isn't identical across channels. :::
Curious how this plays into finding contacts in the first place? Signalist vs. Apollo covers the live-lookup vs. static-database tradeoff in more depth.
