GDPR and B2B Prospecting in the UK and EU
GDPR applies to B2B prospecting because a work email or a job title tied to a named person is personal data. Outreach to people in the UK and EU needs a lawful basis (usually legitimate interests), a clear notice about where you got their details, an easy way to object, and a check of the separate marketing rules that apply to the channel you use.
This is a general guide, not legal advice. Rules differ by country and change, so have a privacy attorney review your outbound program, especially if you email or call at scale.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Does GDPR cover business contact details?
Yes. GDPR protects information that identifies a person, and a name plus a company email address or direct phone number does. It doesn't matter that the person is acting in a professional role. The UK has its own version, UK GDPR, alongside the Privacy and Electronic Communications Regulations (PECR), which govern electronic marketing.
Two separate sets of rules apply to most outreach. Data protection law covers how you collect, store and use the contact's details. Marketing rules, sometimes called ePrivacy rules, cover whether you can send that particular email, text or call. You have to satisfy both.
Can you rely on legitimate interests for outreach?
Often, yes, but you have to earn it. Legitimate interests is a lawful basis that requires a three-part assessment, commonly documented as a legitimate interests assessment:
- Purpose: what business interest are you pursuing, and is it real and specific?
- Necessity: is contacting this person needed for that purpose, and is there a less intrusive way?
- Balance: does the individual's reasonable expectation and right to privacy outweigh your interest?
A relevant message to someone whose role matches what you sell usually passes more easily than a broad blast. Write the assessment down and keep it with your records. Consent is the other route, and some countries expect it for email marketing even to business addresses, so check the rule for each country you target.
How do email and phone rules differ across the UK and EU?
Channel rules vary, so treat each country separately:
- UK email: PECR generally lets you send B2B marketing to corporate subscribers, such as a limited company's employee address, without prior consent, but sole traders and some partnerships are treated as individuals and usually need consent. Include your identity and a working opt-out.
- EU email: national laws implement the ePrivacy rules differently. Some countries, Germany is often mentioned, take a strict approach that expects prior consent even for B2B. Confirm each country with local counsel.
- Phone: in the UK, screen numbers against the Telephone Preference Service and its corporate counterpart before cold calling. Other countries have their own do-not-call systems.
If you can't get country-specific advice, restrict outreach to markets you've cleared and skip the rest until you can.
What notices and opt-out handling do you owe prospects?
When you obtain someone's details from a third party, GDPR expects you to tell them who you are, why you have their data, where it came from and how to object, generally within a month of getting it and no later than your first message to them. In practice, teams put this in a short privacy notice linked from every outreach email.
The right to object to direct marketing is absolute. When someone objects, stop and add them to a suppression list that every tool checks. Don't delete the record entirely, because you need to remember not to contact them again. Keep one suppression list that your CRM, sequencer and data tools all check.
How do you vet a data provider before you use its contacts?
Whatever tool supplies your contacts, you remain responsible for how you use them. Before buying, ask the provider in writing:
- Where does the data come from, and how is it collected and refreshed?
- How do individuals get notified, and how are opt-outs and deletion requests fed back to you?
- Where is the data stored, and what safeguards apply to transfers outside the UK or EEA?
- Do you offer a data processing agreement, and what do you say about subprocessors?
Cognism markets itself to European sellers and is worth including in a shortlist, but confirm its compliance practices for your use case rather than assuming. See the comparison with ZoomInfo and Apollo, the overview of CASL and GDPR outbound compliance and the prospect list guide. For calls, see finding direct dials with the same care about consent and screening.
What Good Looks Like
Outreach into the UK and EU rests on a documented lawful basis, a country-by-country channel check, a source notice and a suppression list every tool respects.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
Does GDPR apply to B2B cold email?
Yes, when the recipient is an identifiable person, including at a business address. GDPR governs how you handle their data, and separate marketing rules govern whether you may send the email. Check both.
Do you need consent to email business contacts in the EU?
It depends on the country and the type of recipient. Some countries allow B2B email under legitimate interests, and others expect consent. Have local counsel confirm the rule for each market before you send.
What is a legitimate interests assessment?
It's a short written test covering your purpose, why contacting the person is necessary and whether their privacy rights outweigh your interest. Keep it on file for outbound campaigns that rely on legitimate interests.
How quickly must you honor an opt-out?
Stop as soon as you can. GDPR gives individuals an absolute right to object to direct marketing, and you should suppress the address across every tool right away. Don't wait for a batch process.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
ZoomInfo vs Cognism vs Apollo.io: B2B Sales Intelligence Platforms Compared
Compare ZoomInfo, Cognism, and Apollo.io for B2B contact data, phone verification, GDPR compliance, buyer intent signals, and sales pipeline coverage.
Running Outbound Into Canada and the EU Without a Legal Mess
What CASL and GDPR require before you send cold outbound to Canada or the EU, and when to build the compliance checks yourself versus buying tooling.
Building a B2B Prospect List Without ZoomInfo
How to build a targeted B2B prospect list without ZoomInfo: define the filter, pick sources, verify contacts and size the list from your win rate.
How to Find Direct Dial Numbers for B2B Prospects
Six ways to find B2B direct dials, a simple test to compare data vendors' phone numbers, and the calling rules to check before you dial.
A Churn Reduction Playbook for Small B2B SaaS Companies
A practical order of operations for reducing B2B SaaS churn: diagnose it, fix onboarding and failed payments, build save plays and measure retention.
Pricing Objection Scripts for B2B Sales Calls
Word-for-word responses to the five B2B price objections reps hear most, with the questions to ask first and what to trade instead of discounting.