Use a legitimate interest assessment to decide whether a cold email campaign can run before you use personal data. Define the business interest, test necessity, weigh the recipient impact, and record the controls that make the decision fair. An LIA is a self-assessment tool for examining processing impact, avoiding unfair processing risks, and testing lawfulness.1 A plausible business purpose does not carry a campaign by itself. The record also needs to show why the data is needed and why the outreach remains proportionate for the people receiving it.
Start before the campaign
Timing is part of the assessment. If the email is already queued, the document has arrived too late.
When legitimate interests is the proposed lawful basis, the LIA is the fairness test for the processing.2 Complete it before data processing activities begin.3 For B2B prospecting, the LIA is the primary document.4
Create one record for the campaign you intend to run. State the audience, channel, business purpose, personal data involved, data source, and planned controls. A short LIA should cover each campaign, so the reasoning matches the outreach that will actually happen.5
A reviewer should understand the purpose and audience without asking you to explain the campaign from memory. Check that the record answers these questions: What business interest does this campaign pursue? Who is the audience, and what makes this outreach relevant to them? What would someone reviewing the record need to understand before approving it?
Test the purpose
Name the interest clearly enough for a reviewer to evaluate it. Keep the purpose concrete and connected to the campaign you plan to send.
You need a lawful basis to process personal information under the lawfulness, fairness and transparency principle.6 Legitimate interests can support direct marketing, but that possibility does not make every cold email lawful.7 Processing under Article 6(1)(f) must be necessary for the legitimate interests pursued and must not be overridden by the person's interests or fundamental rights and freedoms.8
The LIA can be run as three tests: purpose, necessity and balance.9 In the purpose section, write the interest in terms that let a reviewer test it. A statement such as "we want more pipeline" leaves too much work undone. State what the campaign is trying to accomplish and why this audience belongs in it.
Test the statement with these questions: What makes this a legitimate business interest? Why does this audience belong within that purpose? Does the stated purpose describe this campaign, or could it describe almost any campaign? Continue when the business interest is specific enough to compare with the data requested and the effect on recipients.
Test necessity
Use the necessity test to remove data the purpose does not need. Work through each field and explain its job in the campaign.
The necessity test asks whether processing the personal data is actually necessary to achieve the legitimate interest.10 Check that the request does not exceed what is needed for the stated business purpose.11
List the data you intend to use and write the reason for each field. Ask whether the same purpose could be met with less personal data, a narrower audience, or a less intrusive outreach plan. Keep the answer in the LIA. A reviewer should be able to see the connection between the business interest and each piece of data without reconstructing your process.
For each field and the audience, ask: What would change if this field were removed? Does this audience need the same treatment as every other person in the list? What is the smallest data set that still lets the campaign pursue its purpose? Continue when every field has a specific reason and the audience is no wider than the purpose requires.
Test the balance
Balance the business case against the effect on the people receiving the email. Relevance and safeguards belong in this decision, rather than as details left to the sending team.
An LIA should show that you considered the impact on data subjects and tested whether the business interest is outweighed by the effect on their data protection rights and interests.12 Marketing generally serves the business's interests, so the possible consequences for the individual need careful consideration.13
Each contact should be genuinely relevant to what you are offering, because relevance supports the legitimate interests assessment.14 Under the GDPR, B2B cold email can rely on legitimate interests under Article 6(1)(f) when the message is relevant to the recipient's professional role, the data source is disclosed, and a clear opt-out is included.15 Purpose, necessity, balancing, transparency, the right to object, and applicable national ePrivacy rules still matter for cold email legality.16
Use the message and the operating process in the balance. Ask whether the recipient can understand why they were contacted, whether the source of the data can be explained, and whether opting out is easy. Record the safeguards you will use and the reason they answer the risks you identified.
Check the following: Would this person see the message as relevant to their work? Can you explain where the data came from? Can the person stop further outreach without friction? What would make the contact feel excessive or unexpected? Continue when the campaign's relevance is clear, the recipient-facing controls are ready, and the balance section explains why the business interest still justifies the processing.
Record the decision and controls
A useful LIA leaves someone else with a decision, the reasoning behind it, and the controls they must preserve. Keep the record with the campaign so the decision does not disappear when the sending work changes hands.
A Legitimate Interest Assessment is a documented, campaign-level justification explaining why outreach is relevant, proportionate, and respectful of the recipient's rights.17 Use a fresh documented assessment for each campaign or purpose instead of relying on one blanket legal sign-off.18
Record the conclusion, the purpose, the data needed, the balance reasoning, the audience limits, the data source, the opt-out method, and the applicable ePrivacy checks. The length of the LIA depends on the complexity or sensitivity of the processing activity.19 A straightforward record can stay focused; a more complex or sensitive activity needs enough detail to show how you reached the decision.
An audit document that records privacy-policy details and the conduct of the LIA can provide a demonstrable record of lawfulness.20 Under the GDPR and UK GDPR, the rep needs a documented legitimate-interest basis, must inform the person on request, and must purge the data.21 Give the people handling replies a clear instruction for recording objections and stopping further outreach.
What not to do
Use these as stop signs during review. Each one points to a gap that needs fixing before the campaign runs.
- Do not treat direct marketing as automatic permission to send every cold email.7
- Do not begin processing before the LIA is complete.3
- Do not reuse a blanket assessment when the campaign or purpose has changed.18
- Do not request data that exceeds what the stated business purpose needs.11
- Do not leave applicable national ePrivacy rules out of the decision.16
Take the completed record to the person who approves the campaign before sending. If the purpose is vague or the recipient impact is hard to defend, narrow the campaign or stop it. Where the compliance question reaches beyond this record, ask a lawyer to review the outbound strategy.22