Seegnals

Compliance · 25 August 2026 · 8 min read

GDPR and cold email: legitimate interest in B2B, explained plainly

B2B cold email can be lawful under GDPR without consent, but only if you do the work. Here is what legitimate interest requires and what your process must do.

You want to write to two hundred plant managers in Germany, Austria and Poland who have never heard of you. Nobody has consented to anything. Is that legal?

The short answer is: it can be, and many B2B teams in the EU do it lawfully, but “we are B2B so GDPR does not apply” is wrong, and “we have a legitimate interest” is only true if you have done the assessment and built the process to match. A person’s work email address, with their name in it or attached to it, is personal data. GDPR applies. The question is which lawful basis you rely on and what that basis requires of you.

This article explains legitimate interest as a basis for B2B cold email, the obligations that come with it, the separate layer of national ePrivacy rules, and what your process must do to stand up if someone asks. It is a plain explanation for a sales team and not legal advice. Where your market is strict, talk to a lawyer who knows the countries you sell into.

Why GDPR applies to a work email

GDPR protects natural persons. A company is not a natural person, but the people who work there are, and any information relating to an identifiable person is personal data. “j.novak@example-manufacturing.de” identifies Jan Novák. His job title, his employer and the fact that you emailed him on Tuesday are all personal data about him.

The B2B context matters, but not in the way people hope. It does not remove GDPR; it affects the balancing test described below, because a plant manager can reasonably expect relevant business correspondence at work in a way that a private individual cannot. That is a point in your favour, and it stays inside the framework.

GDPR genuinely does not apply to a generic address with no person behind it (info@, sales@). Those are also poor cold email targets, as the list quality checklist explains, so the exemption is rarely useful.

The lawful basis: legitimate interest

Article 6 of the GDPR lists six lawful bases for processing. For cold email, two are relevant: consent (6(1)(a)) and legitimate interests (6(1)(f)). Consent is clean but, by definition, unavailable for a first contact with a stranger. Legitimate interest is the basis B2B outbound rests on.

The regulation itself supports this. Recital 47 says that processing for direct marketing purposes may be regarded as carried out for a legitimate interest. The full text is on EUR-Lex. “May be” means the door is open, and you still have to walk through it.

To rely on 6(1)(f) you must be able to show three things, usually written up as a legitimate interest assessment.

Purpose. What is the interest? Promoting your product to businesses that could plausibly buy it is a legitimate commercial interest. Write down what you sell and who you sell it to.

Necessity. Is processing this data necessary to pursue that interest? You need a name and an address to write to someone; you do not need their home address, their date of birth or their personal mobile number. Collect the minimum. It is also why a list bought for one purpose should not be reused for another.

Balancing. Do the recipient’s interests, rights and reasonable expectations override yours? This is where the B2B context helps. Someone who buys packaging machinery for a factory can reasonably expect to hear from packaging machinery vendors at work, occasionally, about relevant products. They would not expect daily emails, unrelated products, or emails to a private address. The tighter your targeting, the better the balance.

Write the assessment down, date it, and revisit it when your targeting or process changes. If a regulator or a recipient asks on what basis you processed their data, “we have a legitimate interest” without a document behind it is the wrong answer.

What legitimate interest obliges you to do

Choosing legitimate interest is not a lighter option than consent. It comes with obligations that shape the email and the process around it.

Tell them, in the first email

Articles 13 and 14 set out what you must tell people whose data you process. When the data was not obtained from the person directly (you exported it from a database, found it on a website, or bought a list) Article 14 applies, and it requires you to provide the information at the latest at the time of the first communication with them.

In practice your first email, or something it links to, tells the recipient who you are, why you are writing, that you rely on legitimate interest, where you obtained their details, that they can object at any time, and where to find your privacy notice. Most teams do this with one short sentence and a link to a privacy page that carries the rest.

Keep a source and date column on every prospect so that “where did you get my details” has a factual answer. Seegnals keeps custom fields per prospect, and the import maps CSV columns to them; make source and date two of those columns on every list.

Make objection easy and honour it forever

Article 21(2) gives every data subject the right to object to processing for direct marketing at any time, and Article 21(3) says that once they object, their data may no longer be processed for that purpose. There is no balancing and no review. A reply saying “stop”, a click on an unsubscribe link, a message to your privacy address: all of them are objections.

Your process must make this simple and make it stick. Simple means an unsubscribe link in every message and a working reply address. Seegnals adds a one-click unsubscribe header (RFC 8058) as well as the link in every message; the details are in one-click unsubscribe for cold email. Sticking means a suppression list that the next import is checked against, so the person does not reappear when a colleague exports a fresh list next quarter.

Suppression list by address and by domain An objection is permanent. The suppression list is what makes it permanent across future imports, and domain-level entries cover whole organisations you have agreed not to contact.

Keep the data accurate and do not keep it forever

Storage limitation and accuracy are principles under Article 5. A cold list is a snapshot; people change jobs. Re-verify lists before reuse, remove addresses that autoreply as “no longer with the company”, and set a retention rule for prospects who never engaged. Anyone can also ask what you hold about them and where it came from, and tidy records make that a ten-minute job.

The second layer: ePrivacy and national rules

GDPR is not the only law in play. The ePrivacy Directive (2002/58/EC), also on EUR-Lex, deals specifically with unsolicited electronic communications. Its Article 13 requires prior consent for direct marketing email to natural persons, and leaves it to each member state to decide how to protect the interests of business subscribers.

That last part is why the answer to “is B2B cold email legal in the EU” is “it depends on the country”. Member states have transposed Article 13 differently, and some apply a consent requirement to business recipients too, through unfair competition or telecommunications law rather than through data protection law. A campaign that is defensible under GDPR in one country can still be a breach of national marketing law in another.

The practical consequence for a small team: before sending into a country, find out how it treats unsolicited email to businesses, from a lawyer or the national regulator’s guidance. Do not assume your home country’s rule applies to your recipients. Segment campaigns by country so each rule can be applied precisely; it also makes it easier to send in the prospect’s timezone.

Your tool is a processor; you are the controller

Under GDPR you, the sender, decide why and how the data is processed. That makes you the controller. The tool you send through processes data on your instructions, which makes it a processor. Two consequences follow.

First, you need a data processing agreement with the tool provider. Seegnals provides a DPA on request; the customer is the controller. Whichever tool you use, ask for one before you upload a list.

Second, the location of the processing matters. Transfers outside the EEA require additional safeguards and add to your assessment. Seegnals runs its application in Germany and its database in Ireland, both within the EU, with no transfer outside the EEA for core processing. The reasoning is set out in EU hosting and data residency for cold email tools, and the technical details are on the security page.

None of this transfers your responsibility. A compliant tool does not make a non-compliant campaign lawful; it lets you run a lawful campaign without building the plumbing yourself.

What this looks like in an actual email

Putting the obligations together, a first cold email that respects legitimate interest tends to have the following properties:

  • It is sent to a named person whose role plausibly relates to what you sell, at their work address.
  • It is about that relationship: your product, their likely need.
  • It says, briefly, where you found them and that they can tell you to stop.
  • It links to a privacy notice that names legitimate interest as the basis and explains the right to object.
  • It carries an unsubscribe link and a one-click unsubscribe header.
  • It is one of a small number of messages over a bounded period, after which you stop; the sequencing rules in how many follow-ups belong in a sequence are also a proportionality argument.
  • Every objection is honoured the same day and recorded in a suppression list that future imports are screened against.

A team that does all of this has a defensible position under GDPR and has done the groundwork for the national ePrivacy question. A team that does none of it is relying on nobody asking.

What to do this week

  1. Write a one-page legitimate interest assessment for your outbound: purpose, necessity, balancing. Date it and store it where the whole team can find it.
  2. Add source and export date as custom fields on every prospect list, and fill them before import from now on.
  3. Check that every message carries an unsubscribe link and that objections by reply, click or email to your privacy address all end in the suppression list the same day.
  4. List the countries you send into and find out, for each, how national law treats unsolicited email to business recipients. Segment campaigns by country.
  5. Ask your sending tool for its data processing agreement and confirm where your prospect data is stored.

Questions people ask

Is cold emailing allowed under GDPR?

It can be, in a B2B context, on the basis of legitimate interest, provided you have assessed and documented that interest, informed the recipient, made objection easy and honoured it. National ePrivacy rules add conditions that differ by country.

Do I need consent to send B2B cold emails in the EU?

Under GDPR itself, not necessarily. Legitimate interest is an available basis for direct marketing. Under some national transpositions of the ePrivacy Directive, consent is required even for business recipients. The answer depends on the recipient's country.

What is a legitimate interest assessment for cold email?

A documented three-part test: what your interest is, why processing this data is necessary to pursue it, and whether the recipient's interests and reasonable expectations override yours. You keep it on file and revisit it when your process changes.

How quickly must I stop emailing someone who objects?

Immediately and without charge. Under GDPR the right to object to direct marketing is absolute; once exercised, you may no longer process that person's data for that purpose.

Where should a cold email tool store data for GDPR purposes?

Ideally within the EU or EEA, under a data processing agreement with the tool provider acting as your processor. You remain the controller and are responsible for the lawful basis.

Written by

Seegnals Team

Product and outbound at Seegnals. Written by the people who build Seegnals and run its own outbound on it. Every claim about the product is checked against the code before it goes out.

See it on your own list

Connect a mailbox, import a CSV and send the first campaign. Free trial, no card.