GDPR and legitimate interest in B2B prospecting: what you can and cannot do

Published:

Under GDPR, B2B prospecting does not always require consent: legitimate interest is a valid legal basis when three conditions hold — you have a genuine commercial interest, contacting that person is necessary to pursue it, and your interest is not overridden by the individual's rights and reasonable expectations, assessed through a documented balancing test. The recitals of the GDPR themselves note that direct marketing may constitute a legitimate interest.

A note before anything else: this article is general information, not legal advice. Rules differ between countries — GDPR interacts with national e-privacy laws that treat electronic marketing differently across the EU — and your specific situation matters. Involve qualified counsel before relying on any of this.

Why does GDPR apply to B2B outreach at all?

A common misconception is that GDPR is about consumers. It is about personal data — information relating to an identifiable person — regardless of context. The moment your prospect list contains maria.garcia@company.com, a name, and a job title, you are processing personal data and GDPR applies, even though the relationship you are pursuing is company-to-company.

What changes in B2B is not whether the regulation applies, but how the balancing of interests plays out: contacting a professional, at their professional address, about something relevant to their professional role, sits very differently from cold-messaging a private individual.

What is legitimate interest, exactly?

GDPR requires a legal basis for every processing activity. Consent is the best known, but legitimate interest is equally valid where it genuinely applies — and it is the basis most B2B prospecting relies on.

Relying on it is not a matter of declaring it. You need to pass, and document, the three-step assessment known as a legitimate interest assessment (LIA):

  1. Purpose test — is there a genuine interest? Growing your business by offering relevant services to companies that plausibly need them qualifies as a real commercial interest.
  2. Necessity test — is this processing necessary for that interest? You should be processing the minimum data needed: professional contact details and business context, not everything you can scrape about a person.
  3. Balancing test — do the individual's rights and reasonable expectations override your interest? This is where the quality of your prospecting practice becomes a legal question.

How does the balancing test connect to good outbound practice?

Here is the part most compliance articles miss: the factors that tip the balancing test in your favour are the same factors that make outbound work.

  • Relevance. A message about a genuine business problem, sent to the person whose role owns that problem, is within reasonable professional expectations. A generic blast to anyone with an email address is not. Rigorous ICP work is a compliance asset, not just a performance one.
  • Professional context. Contact professionals at work addresses about work matters. Personal channels and personal data have no place in B2B prospecting.
  • Data minimisation. Collect and store what your outreach needs — role, company, business context, verified work email — and nothing more.
  • Frequency and restraint. A short, spaced sequence that stops respects expectations. Relentless follow-up erodes both your balancing test and your reputation.
  • Traceable sourcing. You must be able to say where each contact's data came from. This is one more reason purchased lists are a liability — as we explain in why buying lead lists hurts your domain, you inherit data with no traceable origin and no way to meet information duties.

Sloppy outbound and non-compliant outbound are, to a striking degree, the same thing.

What duties come with legitimate interest?

Choosing legitimate interest as your basis activates concrete obligations:

  • Information duties. People have the right to know you are processing their data, for what purpose, on what basis, and where it came from. In practice, prospecting operations handle this through their privacy policy and by answering source questions honestly and promptly when asked.
  • Right to object. For direct marketing, the right to object is absolute — no balancing, no discussion. Any "not interested", unsubscribe or objection must result in immediate suppression across your entire sending operation, not just one campaign.
  • Erasure and access. Prospects can ask what data you hold and demand its deletion. Your data infrastructure must be able to find and act on a single contact quickly.
  • Accountability. Keep the LIA, your records of processing, and your suppression logs. If questioned, "we assessed it and here is the document" is a very different conversation from a shrug.

Which mistakes create real risk?

Patterns that regularly get companies into trouble:

  • Buying contact databases and assuming the vendor's compliance claims transfer to you. They do not — the buyer remains responsible for lawful processing.
  • Having no LIA at all, then improvising answers when a recipient formally objects or complains to a supervisory authority.
  • Ignoring objections, or suppressing a contact in one tool while another keeps mailing them.
  • Scraping and storing personal data far beyond what outreach needs.
  • Assuming one EU country's rules apply everywhere. National e-privacy laws differ on electronic B2B marketing; if you prospect across borders, map the rules per market.

Compliance as an operating standard

We operate AVANTAI from Spain, under GDPR, running outbound for ourselves and our clients within exactly this framework — which is why our systems are built with suppression handling, traceable data sourcing and minimisation as defaults rather than afterthoughts. Compliant prospecting is not a constraint on performance; done properly, it is a description of what good prospecting already looks like.

If you want your current outbound practice reviewed — data sourcing, suppression flows, documentation — an outbound audit covers the operational side, and a strategy call is the fastest way to discuss your setup. For the legal side, bring your counsel; this article is not a substitute for legal advice.

[PENDIENTE: legal review]

Chema Fernández

Founder of AVANTAI and director of Cargoback, a B2B transport and logistics company in Spain. He writes about what he applies in his own business.

Frequently asked questions

Do I need consent to send B2B cold emails under GDPR?

Not necessarily. GDPR offers several legal bases, and legitimate interest can cover B2B prospecting when your interest is real, the outreach is relevant to the recipient's professional role, and you pass a documented balancing test. Separate e-privacy rules on electronic marketing also apply and vary by country, so the full answer depends on jurisdiction.

Does GDPR apply to work email addresses?

Yes. A work email that identifies a person — like firstname.lastname@company.com — is personal data. Generic addresses such as info@company.com generally are not, but most useful prospecting data does identify individuals, so GDPR duties apply.

What is a legitimate interest assessment (LIA)?

A documented three-part analysis: identifying your legitimate interest, showing the processing is necessary to pursue it, and balancing it against the individual's rights and reasonable expectations. It is your core evidence of accountability if a regulator or data subject ever asks why you processed someone's data.

What should I do when a prospect asks where I got their data?

Answer, accurately and promptly. GDPR gives them the right to know the source of their data, to object to processing for direct marketing, and to request erasure. If you cannot trace where a contact's data came from, that is a sign your data process needs fixing.