Outbound Wiki

GDPR and ePrivacy

Legitimate interest, consent and the ePrivacy rules as they apply to B2B cold email and calls in the EU.

Cold email in the EU needs two checks: one for data processing and one for the email rules. The EU framework is described as consent-based for most direct marketing, and it requires a lawful basis before sending.1 A lawful basis does not settle the legality of each cold email.2 Review the recipient, data source, country rule, reason for contact and exit path. If any point is unclear, stop the send.

Scope and data

Start with the person and the record before choosing a legal basis. A public address or a familiar company name does not settle the question.

The GDPR can apply directly to organizations outside the EEA that offer goods or services in the EEA, monitor behavior there, or process personal data in connection with an EEA establishment.3 Anyone deciding to process data must determine whether personal data are involved and identify the resulting GDPR obligations.4

For each audience, ask:

  • Where is the recipient located?
  • What information identifies or relates to that person?
  • Where did the information come from?
  • Who decided to use it for outreach?

Record the answers against the audience record. Move on only when you know whether personal data are involved and which territorial scope you are reviewing.

Separate the basis from the channel

A lawful basis answers one part of the problem. The email channel has its own rules, so record both decisions separately.

The GDPR identifies lawful bases and recognizes that direct marketing may be a legitimate interest. Every cold email still needs its own legality check.2 Assess purpose, necessity, balancing, transparency, the right to object and applicable national ePrivacy rules in the same review.5

Ask what business purpose the message serves, why email is needed for that purpose and what impact the contact creates for the recipient. Then check the rule that applies to the recipient's country and audience. A completed data protection review does not replace that channel check.

Build the legitimate interest record

Treat legitimate interest as a documented decision, not a label added after the list is built. The record should explain why the audience belongs in the campaign and how the recipient can control further contact.

For B2B cold email, the stated requirements include relevance to the recipient's professional role, transparency about where the data came from, a clear opt-out in every email and documentation of a Legitimate Interest Assessment for each campaign.6

For each campaign, record the purpose, audience selection logic, reason the message fits the recipient's role, expected impact and decision reached. Keep the assessment with the campaign record so another person can understand why the send was approved. If you cannot explain the fit in plain language, do not move the audience into the send queue.

Prepare the message

Make the contact easy to understand and easy to stop. Prepare the explanation before the sequence.

Planning direct marketing requires attention to the transparency requirements imposed by data protection law.7 If consent is the basis, due diligence includes knowing exactly where the lead data came from and being able to prove that proper consent was collected.8

Use the first message to make the sender and reason for contact clear. Keep a record of the data source and the basis used for that recipient. If a colleague cannot answer where the address came from or why the message fits the recipient, send the record back for review.

Handle the exit path

An objection is an action your process must handle. Decide where it is recorded and who checks it before another message goes out.

Organizations must comply with an objection to direct marketing or related profiling.9

Give the recipient a simple way to stop further marketing and make sure the instruction reaches every active audience and campaign using that record. Ask yourself: if this person objects today, where would the next sender see it? If the answer is unclear, pause outreach until the control is clear.

What not to do

These shortcuts create the most uncertainty in a cold email review.

  • Do not treat publicly available information as unrestricted permission to use it for direct marketing. Data protection law and electronic marketing rules may still impose restrictions.10
  • Do not apply one answer across every EU country. The lawful basis, transparency duties, right to object, national ePrivacy rules, audience and message context all affect legality.11
  • Do not plan the campaign without accounting for transparency requirements.7
  • Do not accept a consent claim without tracing the data source and checking that proper consent can be proved.8
  • Do not keep marketing to someone after they object to direct marketing or related profiling.9

Before a send enters production, run this check for each audience and country. One review record should show the data decision, channel decision, campaign reasoning, message explanation and objection control.

Sources

  1. 1
    “The European Union (GDPR and the ePrivacy rules) — consent-based for most direct marketing, with a lawful basis required before you send.”
  2. 2
    “The GDPR text identifies lawful bases for processing and recognizes that direct marketing may be considered a legitimate interest, but that does not make every cold email lawful.”
  3. 3
    “However, the GDPR also significantly extended the territorial scope of EEA data protection laws by applying directly to organizations outside the EEA that offer goods or services in the EEA, monitor behavior in the EEA, or process personal data in connection with an EEA establishment.”
  4. 4
    “Anyone who decides to process data must consider whether this includes personal data and, if so, what the obligations are according to the GDPR.”
  5. 5
    “Purpose, necessity, balancing, transparency, the right to object, and applicable national ePrivacy rules still matter.”
  6. 6
    “Under GDPR, B2B cold email is permitted under the legitimate interest basis (Article 6(1)(f)), but you must demonstrate that your outreach is relevant to the recipient's professional role, be transparent about where you obtained their data, provide a clear opt-out mechanism in every email, and maintain documentation of your Legitimate Interest Assessment for each campaign.”
  7. 7
    “As part of planning your direct marketing activities, you should take into account the transparency requirements that data protection law places on you (see Plan direct marketing).”
  8. 8
    “knowing exactly where the data came from and being able to prove that proper consent was collected”
  9. 9
    “You must comply with such an objection”
  10. 10
    “Data protection law and PECR don’t necessarily prevent you from doing this but there may be restrictions.”
  11. 11
    “No. The lawful basis, transparency duties, right to object, national ePrivacy rules, audience, and message context all matter.”