Revenue Strategy & OperationsExplainer3 min readUpdated September 2026

GDPR and B2B Prospecting in the UK and EU

GDPR applies to B2B prospecting because a work email or a job title tied to a named person is personal data. Outreach to people in the UK and EU needs a lawful basis (usually legitimate interests), a clear notice about where you got their details, an easy way to object, and a check of the separate marketing rules that apply to the channel you use.

This is a general guide, not legal advice. Rules differ by country and change, so have a privacy attorney review your outbound program, especially if you email or call at scale.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Does GDPR cover business contact details?

Yes. GDPR protects information that identifies a person, and a name plus a company email address or direct phone number does. It doesn't matter that the person is acting in a professional role. The UK has its own version, UK GDPR, alongside the Privacy and Electronic Communications Regulations (PECR), which govern electronic marketing.

Two separate sets of rules apply to most outreach. Data protection law covers how you collect, store and use the contact's details. Marketing rules, sometimes called ePrivacy rules, cover whether you can send that particular email, text or call. You have to satisfy both.

Can you rely on legitimate interests for outreach?

Often, yes, but you have to earn it. Legitimate interests is a lawful basis that requires a three-part assessment, commonly documented as a legitimate interests assessment:

  1. Purpose: what business interest are you pursuing, and is it real and specific?
  2. Necessity: is contacting this person needed for that purpose, and is there a less intrusive way?
  3. Balance: does the individual's reasonable expectation and right to privacy outweigh your interest?

A relevant message to someone whose role matches what you sell usually passes more easily than a broad blast. Write the assessment down and keep it with your records. Consent is the other route, and some countries expect it for email marketing even to business addresses, so check the rule for each country you target.

How do email and phone rules differ across the UK and EU?

Channel rules vary, so treat each country separately:

  • UK email: PECR generally lets you send B2B marketing to corporate subscribers, such as a limited company's employee address, without prior consent, but sole traders and some partnerships are treated as individuals and usually need consent. Include your identity and a working opt-out.
  • EU email: national laws implement the ePrivacy rules differently. Some countries, Germany is often mentioned, take a strict approach that expects prior consent even for B2B. Confirm each country with local counsel.
  • Phone: in the UK, screen numbers against the Telephone Preference Service and its corporate counterpart before cold calling. Other countries have their own do-not-call systems.

If you can't get country-specific advice, restrict outreach to markets you've cleared and skip the rest until you can.

What notices and opt-out handling do you owe prospects?

When you obtain someone's details from a third party, GDPR expects you to tell them who you are, why you have their data, where it came from and how to object, generally within a month of getting it and no later than your first message to them. In practice, teams put this in a short privacy notice linked from every outreach email.

The right to object to direct marketing is absolute. When someone objects, stop and add them to a suppression list that every tool checks. Don't delete the record entirely, because you need to remember not to contact them again. Keep one suppression list that your CRM, sequencer and data tools all check.

How do you vet a data provider before you use its contacts?

Whatever tool supplies your contacts, you remain responsible for how you use them. Before buying, ask the provider in writing:

  • Where does the data come from, and how is it collected and refreshed?
  • How do individuals get notified, and how are opt-outs and deletion requests fed back to you?
  • Where is the data stored, and what safeguards apply to transfers outside the UK or EEA?
  • Do you offer a data processing agreement, and what do you say about subprocessors?

Cognism markets itself to European sellers and is worth including in a shortlist, but confirm its compliance practices for your use case rather than assuming. See the comparison with ZoomInfo and Apollo, the overview of CASL and GDPR outbound compliance and the prospect list guide. For calls, see finding direct dials with the same care about consent and screening.

Executive Capability Standard

What Good Looks Like

Outreach into the UK and EU rests on a documented lawful basis, a country-by-country channel check, a source notice and a suppression list every tool respects.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read the regulator's guidance on direct marketing and note the rules for each country you sell into.
2. Do Manually:Write a legitimate interests assessment and a short privacy notice, then apply them to one pilot campaign.
3. Delegate:Assign a privacy owner, in-house or a retained attorney, to approve markets and templates.
4. Automate:Sync opt-outs and objections across your CRM and sequencer, and screen phone numbers against the relevant preference services.
5. Buy:Choose a data provider that documents its sourcing and supports opt-out feedback, after reviewing its terms with counsel.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Cognism

Fits when you sell into Europe and want a data provider that focuses on compliance-aware contact data, subject to your own review.

Visit Cognism→

Frequently Asked Questions

Does GDPR apply to B2B cold email?

Yes, when the recipient is an identifiable person, including at a business address. GDPR governs how you handle their data, and separate marketing rules govern whether you may send the email. Check both.

Do you need consent to email business contacts in the EU?

It depends on the country and the type of recipient. Some countries allow B2B email under legitimate interests, and others expect consent. Have local counsel confirm the rule for each market before you send.

What is a legitimate interests assessment?

It's a short written test covering your purpose, why contacting the person is necessary and whether their privacy rights outweigh your interest. Keep it on file for outbound campaigns that rely on legitimate interests.

How quickly must you honor an opt-out?

Stop as soon as you can. GDPR gives individuals an absolute right to object to direct marketing, and you should suppress the address across every tool right away. Don't wait for a batch process.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides