B2B cold email under GDPR: what is actually allowed
A practical guide for non-lawyers to legitimate interest, the Article 14 notice, the ePrivacy layer and how national rules differ, with a checklist you can copy.
Every B2B team asks the same question before the first campaign: are we allowed to email businesses that never asked to hear from us? In most of Europe the answer is yes, under conditions. The conditions are the whole of this article.
The confusion usually comes from mixing up two laws. GDPR decides whether you may hold and use the data. The ePrivacy rules, written into a separate national law in each country, decide whether you may send the message. You have to satisfy both, and the second one is where countries disagree with each other.
This article is general information, not legal advice. For your own situation, ask a qualified lawyer in your country.
A business address and a named person are not the same thing
GDPR protects personal data: information about an identified or identifiable living person. A company is not a person. The registered address of a bakery, its switchboard number and a general mailbox like [email protected] identify a legal entity, so the regulation has much less to say about them.
The line moves as soon as a human appears in the record. An address built from someone's first and last name is personal data, and so is a listing that says "owner: Maria Santos". A sole trader is the hardest case: for a one-person business the company address often is the person's address, so one row in your spreadsheet is business data and personal data at once.
A workable rule for non-lawyers: treat any record that names a human being as personal data, and prefer the business's own published channels when you have the choice.
Legitimate interest, the usual basis for B2B outreach
GDPR gives six legal bases. For cold outreach only two are realistic: consent, which by definition you do not have yet, and legitimate interest.
Recital 47 says that processing personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. Note the word "may". The European Data Protection Board has been explicit that direct marketing is not automatically legitimate and that you have to show it is, through a three-part test:
- A real interest. Something specific, present and lawful. "We sell scheduling software to dental clinics and want to reach clinics in Lyon that do not have it" is an interest. "We want more leads" is not.
- Necessity. Could you achieve the same result with less personal data? If a generic company mailbox does the job, you do not need a named person's address.
- A balancing test. Do the person's rights and reasonable expectations override your interest? Someone contacted at a work address about something genuinely relevant to their job is far more likely to expect the message than a private individual at home.
What tips the balance your way is unglamorous: the offer matches what the business does, you collect the minimum, you identify yourself honestly, and saying no is free and easy. What tips it against you is a bought list, a hidden sender and an opt-out form with three fields.
Write the assessment down before the campaign, not after a complaint. One page is enough. If you cannot explain why a bakery owner would expect an email about bakery software, you do not have a case.
The information duty when the data did not come from the person
Article 14 covers exactly the situation cold outreach is in: you obtained personal data from somewhere other than the person it describes, such as a public listing or a company website. When that happens, you owe them information.
The list is fixed: who you are and how to reach you, the purposes and the legal basis, the categories of data you hold, who else receives it, how long you keep it, where you got it and whether the source was public, and their rights, which are access, rectification, erasure, restriction, objection and complaint to a supervisory authority. If you rely on legitimate interest, name that interest.
The timing is what people get wrong. The default is a reasonable period and at the latest one month after you obtained the data. But if you use the data to contact the person, the deadline moves forward to the first communication. For cold email that is the first email itself, not the second one.
In practice a short paragraph at the bottom of the message does the job: who you are, where you found the business, why you are writing, and a link to a privacy page carrying the full list. Article 14 has exemptions, including disproportionate effort, but do not lean on them for marketing. Writing the paragraph is cheaper than arguing about the exemption.
The ePrivacy layer, and why the country decides
Even with a solid legitimate interest, the act of sending unsolicited electronic marketing is governed by the ePrivacy rules. They arrived as a European directive rather than a regulation, so every country wrote its own version, and the versions genuinely differ. Three sketches, at a high level.
The Netherlands. The spam rules sit in the Telecommunications Act and are enforced by the ACM, the consumer and markets authority. A common myth is that the Dutch ban only protects consumers. It does not: it covers businesses as well, so the starting point for messages to companies is consent, with narrow exceptions such as an existing customer relationship. Either way, the sender must be clearly identifiable and every message needs a fast and free way to unsubscribe.
Germany. The strictest of the three. Email advertising generally requires prior express consent under the law on unfair competition, the courts have not carved out a general exemption for business recipients or generic company mailboxes, and the burden of proving consent sits with the sender. Treat Germany as a consent-first market.
France. The most workable of the three for B2B. The regulator, the CNIL, accepts that prospecting a professional at a professional address can rest on legitimate interest, as long as the message relates to that person's job, the sender is identifiable and every message offers a simple, free way to object. Generic addresses such as contact@ or info@ belong to the company rather than to an individual.
One distinction matters everywhere: several countries treat a sole trader like a consumer, because legally a one-person business is a natural person. If your list cannot tell a limited company from a sole trader, apply the stricter rule to that row.
So segment by country before you send, not after. Where consent is effectively required, use another channel first, and keep cold email for the countries with an opt-out regime.
Records, removal requests and the suppression list
Records of processing. Article 30 asks controllers to keep a written record of their processing: purposes, categories of data and of people, recipients, retention periods, transfers and a general description of your security measures. There is an exemption for organisations under 250 employees, but it falls away when the processing is regular rather than occasional. An outreach programme is regular by definition, so keep the record.
Removal requests. When someone replies "take me off your list", that is an objection. For direct marketing an objection is absolute: no balancing test, you stop. Act quickly, do not ask for a reason and do not demand identity documents when the request comes from the address in question.
The suppression list. Here is the trap. If you honour "delete me" by deleting the whole record, you will find the same business in next quarter's search and email it again. Keep the bare minimum needed to recognise the address, in a separate list used only to block sending, and check every campaign against it. That one field is not a breach of the erasure request, it is how you keep the promise.
What the rules ask, and how Leadralia handles it
| Requirement | What it means in practice | How Leadralia handles it |
|---|---|---|
| A lawful basis | Legitimate interest, assessed and written down first | Public business data only: the public listing and the business's own website, never bought databases or brokers |
| Relevance to the work | The offer matches what that business actually does | You search by business type and area, so the audience is defined before a word is written |
| Transparency at first contact | The Article 14 information reaches the person in the first message | Every message carries a one-line source sentence (the details come from public online sources); who you are and why you write belong in your own text |
| An easy way to say no | A working, free, one-step opt-out in every message | Every message says: send "no" to this address and nothing more arrives; processed automatically for every sender on Leadralia, and mail to Belgium also carries an unsubscribe link |
| Objection and erasure | Act on a removal request quickly and without conditions | A self-serve data-rights portal: a business asks to be removed and it happens instantly |
| Data minimisation | Hold what the purpose needs, nothing more | Name, address, phone, website, rating, reviews and one verified email per business |
| Accuracy | Do not keep mailing dead or wrong addresses | Addresses are verified for deliverability before a send is possible, and hard bounces are remembered |
| No onward sale | The data does not travel to anyone else | Leadralia never sells data, and its own site measures ads only for visitors who agreed |
How Leadralia builds this in
These are product behaviours, not promises on a policy page.
Public business data only. Every record comes from what a business publishes about itself: its public listing and its own website. No bought database, no data broker, which is why the source line in your Article 14 notice is short and true.
The source and the way out ship with the message. Every message ends with a one-line source sentence (the business details come from public online sources) and a line that reads: send "no" to this address and you will receive nothing more. Whatever reaches that address is processed automatically, for every sender on Leadralia, and mail to Belgium also carries an unsubscribe link. You cannot accidentally send a campaign without them.
Verification before, a record after. Addresses are verified for deliverability before a send is possible, hard bounces are remembered, and every charge and refund is written to your wallet history.
Removal is self-serve and immediate. A business that does not want to be in the system says so through a data-rights portal on the site, and it happens at once. Leadralia never sells data and works under GDPR.
For the rest of the product in plain words, read what Leadralia does.
Cold email checklist
Copy this and run it before every campaign.
- Write the legitimate interests assessment: the interest, why the data is necessary, why the recipient would expect the message.
- Check the rules for every country in the list and split it. Consent-first markets do not get the cold email.
- Flag the sole traders. If you cannot tell a company from a one-person business, apply the stricter rule.
- Prefer the business's own published channel over a named person's address.
- Make the offer relevant to that type of business. If the same message fits every industry, the balancing test will not save it.
- Put the Article 14 notice in the first message, with a link to the full privacy information.
- Give a free, easy way to say no in every message, and test it yourself.
- Identify yourself honestly: real sender name, real company, a reply address a human reads.
- Verify the addresses so you are not mailing dead mailboxes.
- Check the campaign against your suppression list, and add every opt-out the same day.
Frequently asked questions
Do I need consent for B2B cold email in the EU?
Under GDPR, usually not: legitimate interest is the normal basis for relevant B2B outreach, provided you can show the three-part test and offer an easy opt-out. Under the national ePrivacy rules it depends on the country. Germany effectively requires prior consent, the Netherlands takes consent as the starting point for business recipients too, and France accepts opt-out for professional addresses when the message relates to the person's job.
What exactly has to be in the first email?
Who you are and how to reach you, why you are writing and on what legal basis, where you got the contact details and that the source was public, how long you keep the data, the recipient's rights including objection and complaint, and a free, easy way to say no that works. A short paragraph plus a link to a privacy page covers it.
Someone asked to be deleted. Do I delete the record or keep it?
Stop messaging immediately and remove the marketing record, but keep the minimum needed to recognise the address on a suppression list. That is the only way to be sure you never contact them again after the next search refreshes your data. Note the request and the date.
Bottom line
B2B cold email in Europe is legal in most countries and genuinely useful, as long as you treat it as a regulated activity rather than a numbers game. Have a real interest, write to people it is relevant to, tell them where you found them in the first message, make refusing trivial, respect refusals forever, and check the national rules first.
Leadralia puts those steps inside the product: public business data only, a source line and a "send no" opt-out in every message, verification before sending, instant self-serve removal, and no data sale. To see what a compliant list of your market looks like, run one search for free. No card needed.
Find every business in any area, with the email behind each one.
Free to try: your first 25 businesses and 5 email addresses, no card needed.