Table of Contents
- Is cold email legal for B2B outbound under GDPR?
- What is legitimate interest, and does it actually cover your outbound?
- What must every GDPR compliant cold email include?
- Which countries are stricter than the GDPR baseline?
- Does GDPR apply if your company is not based in the EU?
- How long can you legally keep a prospect's data if they never reply?
- What happens if your outbound is not GDPR compliant?
- Build a GDPR compliant cold email system in six steps
- Can an outbound partner actually handle this for you?
- Conclusion
- Key Takeaways
- Key Terms Glossary
- Related reading
GDPR compliant cold email is legal for B2B outbound across the EU and UK, but only when the legal basis, the mandatory disclosures, and the retention window are built into the system before the first message goes out, not patched on afterwards because a prospect complained.
That distinction is where most companies get it wrong. They treat GDPR as a copy problem, adding an unsubscribe line and calling it done, when it is actually a system design problem: who you contact, why, what you keep, and for how long. This guide walks through what the regulation actually requires for B2B outreach, where the rules tighten by country, and how we build GDPR compliant cold email into every outbound system we run.
Is cold email legal for B2B outbound under GDPR?
Yes. GDPR compliant cold email is legal for business-to-business outreach across the EU and UK when the sender relies on "legitimate interest" (Article 6(1)(f)) as the legal basis rather than prior consent, and when the message meets a short list of mandatory conditions.
The regulation does not ban unsolicited contact outright. It requires a lawful reason for processing the recipient's data, and legitimate interest exists precisely for cases like this: a genuine business reason to contact someone in a professional capacity about something relevant to their role. Where companies fall down is assuming that basis is automatic. It has to be established and it has to be documented, which is the part most outbound programmes skip entirely.
What is legitimate interest, and does it actually cover your outbound?
Legitimate interest covers your outbound when the contact is professional, the offer is genuinely relevant to the recipient's role, and you can show you considered a less intrusive way to reach them.
Regulators expect a three-part balancing test behind that basis, sometimes called a legitimate interest assessment:
- Purpose. You have a real, specific business reason for contacting this person, not a generic "might be interested" justification.
- Necessity. Email is a reasonable and proportionate way to reach them for that purpose, and you are not collecting more data than the outreach requires.
- Balancing. The recipient's right to privacy is weighed against your business interest, and a professional, role-based, easily-declined message tips that balance in your favour.
A one-page written assessment, kept on file, is what turns "we think this is fine" into a documented, defensible legal basis. Most B2B senders that get challenged were doing the right thing operationally and simply never wrote it down.
What must every GDPR compliant cold email include?
Every GDPR compliant message needs four elements regardless of country: a clear sender identity, a working opt-out, a route to your privacy information, and a purpose that is actually relevant to the recipient's job.
- Real sender identity. The company name and a real reply address, so the recipient can verify who is contacting them. No disposable domains standing in for the real sender.
- A working, honoured opt-out. A functioning unsubscribe path, and once someone uses it, suppression that is permanent across every future campaign, not just the one they replied to.
- A link to your privacy information. Somewhere the recipient can see what data you hold and how to request its deletion.
- Role relevance. The message has to relate to the recipient's professional function. A finance director hearing about accounts payable automation is defensible; the same message to a personal address is not.
Which countries are stricter than the GDPR baseline?
Some EU member states layer national rules on top of GDPR, and the practical requirements for B2B outbound vary more than most senders expect.
| Jurisdiction | Legal basis for B2B cold email | Practical requirement |
|---|---|---|
| GDPR baseline (most of the EU) | Legitimate interest | Role-based contact, opt-out, documented assessment |
| Germany | Narrower reading of legitimate interest | Courts have historically expected a closer, pre-existing business connection; treat cold outreach here more conservatively |
| France, Netherlands, Ireland | Legitimate interest, role-based contact accepted | Broadly aligned with the GDPR baseline for genuine B2B contacts |
| UK (post-Brexit) | UK GDPR plus PECR | Same legitimate interest logic, with PECR adding specific electronic marketing conditions |
| United States (for comparison) | CAN-SPAM | Opt-out and sender identification required; no EU-style legitimate interest test |
Applying the loosest EU reading to a German buyer is a common, avoidable mistake. A system built for international expansion has to treat these as different rule sets, not one rule with local flavour.
Does GDPR apply if your company is not based in the EU?
Yes. GDPR applies under Article 3(2) whenever you are processing the personal data of people located in the EU or UK, regardless of where your company is registered or where your servers sit.
This is the part that catches non-EU companies off guard when they start expanding into European markets. Contacting someone physically located in Germany or France triggers GDPR obligations even with no EU office or other EU footprint. Extraterritorial scope is why a compliant international expansion plan needs outreach compliance as a line item, not an afterthought once the first prospect complains.
How long can you legally keep a prospect's data if they never reply?
Keep a non-responsive prospect's data only as long as you can justify an active, ongoing purpose for it, and delete or archive it once that purpose ends.
GDPR sets no fixed number of days, only a principle: storage limitation, meaning data is kept only as long as necessary for the purpose it was collected for. Most compliant systems apply a rolling window, commonly 12 to 24 months of no engagement, after which a contact is re-qualified against a fresh purpose or removed. Across the campaigns we manage at Danish Lead Co., roughly a third of records in any target list are excluded before a single message goes out, for do-not-contact status, duplication, or a mismatch against the qualified profile, based on aggregate data from our case studies.
What happens if your outbound is not GDPR compliant?
Non-compliant outbound exposes you to regulatory penalties, but the more common consequence is quieter: complaints to your email providers that get your sending domains flagged before a fine ever enters the picture.
GDPR's own penalty structure caps at whichever is greater of 4% of global annual turnover or 20,000,000 euros (Article 83), the statutory ceiling rather than a typical outcome for a B2B sender running a reasonable legitimate interest process. The more immediate risk is operational: a pattern of complaints signals to mailbox providers that a domain sends unwanted mail, and deliverability degrades for every legitimate message sent afterwards. Compliance and inbox placement are the same problem viewed from two directions.
Build a GDPR compliant cold email system in six steps
- Confirm your legal basis before the first send. A short legitimate interest assessment covering purpose, necessity, and balancing for the specific campaign, not a blanket policy for the whole company.
- Restrict targeting to role-based, business-relevant contacts. Job function and company relevance, not personal addresses or roles with no plausible connection to the offer.
- Build the mandatory disclosures into the template. Sender identity, opt-out, and a privacy information link belong in the message structure so no individual sender can skip them.
- Set and enforce a retention window. Decide up front how long a non-responsive contact stays active, and automate the removal.
- Route every opt-out to a permanent, cross-campaign suppression list. A recipient who opts out of one campaign should never appear in another.
- Document the decision, not just the outcome. Keep the assessment on file so the reasoning survives a regulator's or a prospect's question, rather than being reconstructed after the fact.
That is the same discipline we apply across our outbound systems: compliance as a property of the infrastructure, checked once at the system level.
Can an outbound partner actually handle this for you?
A partner running outbound across multiple countries should already have this built into the default system, not treat it as a custom request.
We have run compliant outreach for clients expanding across borders, including an aviation supplier that opened 53 qualified conversations across more than 30 countries in 46 days, where jurisdiction-aware targeting and suppression were part of the system from day one. If a prospective partner cannot describe their legitimate interest process or how suppression carries across campaigns, their compliance approach likely lives in a document nobody follows. Danish Lead Co. holds a 5.0 rating across 32 reviews on Clutch, Trustpilot, and Google; read more about us or see how we structure this for your market.
Conclusion
GDPR compliant cold email is achievable for B2B outbound, and the requirements are specific enough to build into a system once rather than relitigate on every campaign: a documented legal basis, role-based targeting, mandatory disclosures baked into the template, a retention policy that actually gets enforced, and suppression that carries across every campaign a contact ever touches. Get those five things right and the legal question stops being a source of anxiety and becomes a design spec.
If you are expanding outbound into the EU or UK and want a system built compliant from the first send rather than patched after a complaint, book a conversation with our team and we will walk through exactly how we structure legitimate interest, retention, and suppression for your specific markets.