GDPR Compliant Cold Email: What You Can Legally Send

GDPR Compliant Cold Email: What You Can Legally Send

Martin Rasmussen — Founder & CEO, Danish Lead Co. Martin Rasmussen — Founder & CEO, Danish Lead Co.
10 minute read

Listen to article
Audio generated by DropInBlog's Blog Voice AI™ may have slight pronunciation nuances. Learn more

Table of Contents

GDPR compliant cold email is legal for B2B outbound across the EU and UK, but only when the legal basis, the mandatory disclosures, and the retention window are built into the system before the first message goes out, not patched on afterwards because a prospect complained.

That distinction is where most companies get it wrong. They treat GDPR as a copy problem, adding an unsubscribe line and calling it done, when it is actually a system design problem: who you contact, why, what you keep, and for how long. This guide walks through what the regulation actually requires for B2B outreach, where the rules tighten by country, and how we build GDPR compliant cold email into every outbound system we run.

Yes. GDPR compliant cold email is legal for business-to-business outreach across the EU and UK when the sender relies on "legitimate interest" (Article 6(1)(f)) as the legal basis rather than prior consent, and when the message meets a short list of mandatory conditions.

The regulation does not ban unsolicited contact outright. It requires a lawful reason for processing the recipient's data, and legitimate interest exists precisely for cases like this: a genuine business reason to contact someone in a professional capacity about something relevant to their role. Where companies fall down is assuming that basis is automatic. It has to be established and it has to be documented, which is the part most outbound programmes skip entirely.

What is legitimate interest, and does it actually cover your outbound?

Legitimate interest covers your outbound when the contact is professional, the offer is genuinely relevant to the recipient's role, and you can show you considered a less intrusive way to reach them.

Regulators expect a three-part balancing test behind that basis, sometimes called a legitimate interest assessment:

  • Purpose. You have a real, specific business reason for contacting this person, not a generic "might be interested" justification.
  • Necessity. Email is a reasonable and proportionate way to reach them for that purpose, and you are not collecting more data than the outreach requires.
  • Balancing. The recipient's right to privacy is weighed against your business interest, and a professional, role-based, easily-declined message tips that balance in your favour.

A one-page written assessment, kept on file, is what turns "we think this is fine" into a documented, defensible legal basis. Most B2B senders that get challenged were doing the right thing operationally and simply never wrote it down.

What must every GDPR compliant cold email include?

Every GDPR compliant message needs four elements regardless of country: a clear sender identity, a working opt-out, a route to your privacy information, and a purpose that is actually relevant to the recipient's job.

  • Real sender identity. The company name and a real reply address, so the recipient can verify who is contacting them. No disposable domains standing in for the real sender.
  • A working, honoured opt-out. A functioning unsubscribe path, and once someone uses it, suppression that is permanent across every future campaign, not just the one they replied to.
  • A link to your privacy information. Somewhere the recipient can see what data you hold and how to request its deletion.
  • Role relevance. The message has to relate to the recipient's professional function. A finance director hearing about accounts payable automation is defensible; the same message to a personal address is not.

Which countries are stricter than the GDPR baseline?

Some EU member states layer national rules on top of GDPR, and the practical requirements for B2B outbound vary more than most senders expect.

JurisdictionLegal basis for B2B cold emailPractical requirement
GDPR baseline (most of the EU)Legitimate interestRole-based contact, opt-out, documented assessment
GermanyNarrower reading of legitimate interestCourts have historically expected a closer, pre-existing business connection; treat cold outreach here more conservatively
France, Netherlands, IrelandLegitimate interest, role-based contact acceptedBroadly aligned with the GDPR baseline for genuine B2B contacts
UK (post-Brexit)UK GDPR plus PECRSame legitimate interest logic, with PECR adding specific electronic marketing conditions
United States (for comparison)CAN-SPAMOpt-out and sender identification required; no EU-style legitimate interest test

Applying the loosest EU reading to a German buyer is a common, avoidable mistake. A system built for international expansion has to treat these as different rule sets, not one rule with local flavour.

Does GDPR apply if your company is not based in the EU?

Yes. GDPR applies under Article 3(2) whenever you are processing the personal data of people located in the EU or UK, regardless of where your company is registered or where your servers sit.

This is the part that catches non-EU companies off guard when they start expanding into European markets. Contacting someone physically located in Germany or France triggers GDPR obligations even with no EU office or other EU footprint. Extraterritorial scope is why a compliant international expansion plan needs outreach compliance as a line item, not an afterthought once the first prospect complains.

How long can you legally keep a prospect's data if they never reply?

Keep a non-responsive prospect's data only as long as you can justify an active, ongoing purpose for it, and delete or archive it once that purpose ends.

GDPR sets no fixed number of days, only a principle: storage limitation, meaning data is kept only as long as necessary for the purpose it was collected for. Most compliant systems apply a rolling window, commonly 12 to 24 months of no engagement, after which a contact is re-qualified against a fresh purpose or removed. Across the campaigns we manage at Danish Lead Co., roughly a third of records in any target list are excluded before a single message goes out, for do-not-contact status, duplication, or a mismatch against the qualified profile, based on aggregate data from our case studies.

What happens if your outbound is not GDPR compliant?

Non-compliant outbound exposes you to regulatory penalties, but the more common consequence is quieter: complaints to your email providers that get your sending domains flagged before a fine ever enters the picture.

GDPR's own penalty structure caps at whichever is greater of 4% of global annual turnover or 20,000,000 euros (Article 83), the statutory ceiling rather than a typical outcome for a B2B sender running a reasonable legitimate interest process. The more immediate risk is operational: a pattern of complaints signals to mailbox providers that a domain sends unwanted mail, and deliverability degrades for every legitimate message sent afterwards. Compliance and inbox placement are the same problem viewed from two directions.

Build a GDPR compliant cold email system in six steps

  1. Confirm your legal basis before the first send. A short legitimate interest assessment covering purpose, necessity, and balancing for the specific campaign, not a blanket policy for the whole company.
  2. Restrict targeting to role-based, business-relevant contacts. Job function and company relevance, not personal addresses or roles with no plausible connection to the offer.
  3. Build the mandatory disclosures into the template. Sender identity, opt-out, and a privacy information link belong in the message structure so no individual sender can skip them.
  4. Set and enforce a retention window. Decide up front how long a non-responsive contact stays active, and automate the removal.
  5. Route every opt-out to a permanent, cross-campaign suppression list. A recipient who opts out of one campaign should never appear in another.
  6. Document the decision, not just the outcome. Keep the assessment on file so the reasoning survives a regulator's or a prospect's question, rather than being reconstructed after the fact.

That is the same discipline we apply across our outbound systems: compliance as a property of the infrastructure, checked once at the system level.

Can an outbound partner actually handle this for you?

A partner running outbound across multiple countries should already have this built into the default system, not treat it as a custom request.

We have run compliant outreach for clients expanding across borders, including an aviation supplier that opened 53 qualified conversations across more than 30 countries in 46 days, where jurisdiction-aware targeting and suppression were part of the system from day one. If a prospective partner cannot describe their legitimate interest process or how suppression carries across campaigns, their compliance approach likely lives in a document nobody follows. Danish Lead Co. holds a 5.0 rating across 32 reviews on Clutch, Trustpilot, and Google; read more about us or see how we structure this for your market.

Conclusion

GDPR compliant cold email is achievable for B2B outbound, and the requirements are specific enough to build into a system once rather than relitigate on every campaign: a documented legal basis, role-based targeting, mandatory disclosures baked into the template, a retention policy that actually gets enforced, and suppression that carries across every campaign a contact ever touches. Get those five things right and the legal question stops being a source of anxiety and becomes a design spec.

If you are expanding outbound into the EU or UK and want a system built compliant from the first send rather than patched after a complaint, book a conversation with our team and we will walk through exactly how we structure legitimate interest, retention, and suppression for your specific markets.

Key Terms Glossary

GDPR: The EU's General Data Protection Regulation, governing how personal data, including business contact details, may be collected and processed.
Legitimate interest: One of six lawful bases under GDPR Article 6, and the one most B2B cold email relies on, requiring a documented purpose, necessity, and balancing test rather than prior consent.
UK GDPR: The UK's version of GDPR, retained after Brexit and applied alongside the Privacy and Electronic Communications Regulations (PECR) for electronic marketing.
Storage limitation: The GDPR principle that personal data may only be retained as long as necessary for the purpose it was collected for.
Suppression list: A permanent, cross-campaign record of opted-out contacts, checked before every future send so an opt-out on one campaign is honoured on all of them.
Extraterritorial scope: The GDPR provision (Article 3(2)) applying the regulation to any organisation processing the data of people located in the EU or UK, regardless of where the organisation is based.

FAQs

Is cold email legal under GDPR?
Yes. B2B cold email is legal under GDPR when it relies on legitimate interest, targets role-based professional contacts, and includes a working opt-out and privacy information. B2C outreach to personal addresses faces a higher bar and typically needs prior consent.
Do I need consent to send a B2B cold email in the EU?
No, not in most EU jurisdictions, provided you rely on legitimate interest, the contact is role-based, and you can document the purpose, necessity, and balancing test behind it. Germany is the exception, where courts read legitimate interest more narrowly.
Does GDPR apply to companies outside the EU?
Yes. Under Article 3(2), GDPR applies whenever you process the personal data of someone located in the EU or UK, regardless of where your company is registered or hosted.
What is required for a legitimate interest assessment?
Three tests: purpose (why you are contacting this person), necessity (why email is proportionate), and balancing (their privacy rights against your business interest). A short written record of that assessment is what makes the legal basis defensible if challenged.
How is UK GDPR different from EU GDPR for cold email?
UK GDPR applies the same legitimate interest logic, but sits alongside the Privacy and Electronic Communications Regulations (PECR), which add specific conditions for electronic marketing. A compliant EU approach usually needs only minor adjustment to also satisfy UK requirements.
How long can I keep a prospect's email address if they never reply?
GDPR sets no fixed number, only the storage limitation principle: keep data only as long as you have an active, documented purpose. Most compliant systems apply a rolling window, often 12 to 24 months of no engagement, before re-qualifying or removing the contact.
What happens if a regulator finds our outbound non-compliant?
GDPR's statutory maximum is whichever is greater of 4% of global annual turnover or 20,000,000 euros, the ceiling for the most severe cases rather than a typical outcome. The more immediate risk is reputational: complaints degrade sender reputation with mailbox providers before a regulatory penalty would ever apply.
Can an outbound partner handle GDPR compliance for us?
A capable partner builds legitimate interest assessment, role-based targeting, and cross-campaign suppression into the system by default, and can explain its retention policy without hesitation. Treating compliance as a one-off request rather than a built-in feature is a warning sign.

« Back to Blog