GDPR Compliant Database: How to Build B2B Lists Legally
Most B2B contact databases sell you "GDPR compliant" data that would not survive a regulator's first question. Here is what compliance actually requires, and how to audit a vendor before you buy.

TL;DR
- A "GDPR compliant database" is not a certification — no regulator issues one. It is a claim about your processing, and the liability sits with you as controller, not with the vendor.
- B2B outreach in the EU almost always runs on legitimate interest (Article 6(1)(f)), not consent. That is legal, but only if you can produce a balancing test, honour objections, and send an Article 14 notice.
- The seven checks that actually matter: lawful basis documentation, source provenance, Article 14 notice, suppression handling, DPA + sub-processor list, transfer mechanism, and deletion SLAs.
- Country rules override the vibe: Germany and France treat B2B email differently than the UK or Netherlands. "EU-wide compliant" is usually a simplification.
- Pick vendors that show you where each record came from. Ability to answer "how did you get this?" in one click is the single strongest compliance signal.
What Does "GDPR Compliant Database" Actually Mean?#
It means far less than the badge on a vendor's pricing page implies.
Think of it like a knife shop. The shop can sell knives legally all day long. Whether your use of the knife is legal depends entirely on what you do with it. GDPR works the same way: a data vendor can lawfully hold and license business contact data, but the moment you import it and email someone, you become the controller and you must justify the processing.
That distinction matters because of how enforcement works. The European Data Protection Board and national authorities almost never fine the list broker first — they fine the company whose name is in the "From" field, because that is the company the recipient complained about.
So when a vendor writes "GDPR compliant database," translate it as: we believe our collection and licensing of this data is defensible. It says nothing about whether your campaign is.
Three things a compliant setup requires, all of which are on you:
- A documented lawful basis — for cold B2B outreach, almost always legitimate interest, with a written Legitimate Interest Assessment (LIA) on file.
- Transparency — Article 14 requires you to tell people you hold their data when you did not collect it from them directly, normally within one month or at first contact.
- Working rights machinery — objection, access, erasure, and rectification requests must be actionable within 30 days, including for records you bought.
Is Consent Required for B2B Email in the EU?#
No — and this is the most expensive misconception in outbound.
GDPR does not require consent for cold B2B email. Article 6 lists six lawful bases and consent is only one of them. Recital 47 explicitly names direct marketing as a possible legitimate interest. What trips people up is that GDPR is not the only law in play: the ePrivacy Directive governs unsolicited electronic communication, and it is transposed differently in each member state.
That produces a patchwork:
| Country | Cold B2B email to a corporate address | Practical note |
|---|---|---|
| Germany | Restrictive — prior consent expected in most cases (UWG §7) | Highest complaint and Abmahnung risk in the EU |
| France | Legitimate interest accepted for role-relevant B2B | CNIL requires the offer relate to the person's job function |
| Netherlands | Permitted for B2B with opt-out | Straightforward; honour objections fast |
| UK (post-Brexit) | Permitted to corporate bodies under PECR | Sole traders and partnerships count as individuals |
| Spain / Italy | Legitimate interest accepted, opt-out mandatory | Italy's Garante is active on suppression failures |
| Ireland | Permitted for B2B, opt-out mandatory | DPC is the lead authority for many US tech firms |
The pattern: generic role addresses at large companies carry the least risk; named personal addresses at small firms and sole traders carry the most. A info@ or sales@ mailbox at a 500-person company is barely personal data at all. firstname.lastname@ at a two-person consultancy is effectively a private individual's address.
How Do You Audit a Vendor's GDPR Claims?#
Ask for artifacts, not assurances. Seven checks, in order of how much they tell you:
- Source provenance per record. Can the vendor tell you, for a specific email, where it came from — public web page, company site, user contribution, partner licence? If the answer is a vague "multiple public sources," the record cannot support your Article 14 notice.
- Data Processing Agreement. A real DPA under Article 28, signable without a sales call, listing purposes, retention, and security measures.
- Sub-processor list. Published, versioned, with notice-of-change terms. Vendors that hide this usually have an enrichment chain they would rather not disclose.
- Transfer mechanism. If data leaves the EEA, you need Standard Contractual Clauses plus a transfer impact assessment. "Our servers are in the US" is not a mechanism.
- Suppression and objection handling. When someone objects to you, does the vendor also suppress them, or will the same record reappear in your next export?
- Deletion SLA. Documented turnaround for erasure requests that propagates to backups and derived datasets.
- Accuracy process. Article 5(1)(d) requires data to be accurate and kept up to date. A vendor with no re-verification cycle is failing a principle, not just a nicety.
Run these against any provider before signing. Most "GDPR compliant" claims fail at check 1 or check 5.
What's the Difference Between Scraped, Purchased, and Verified Data?#
The three sourcing models carry very different risk profiles, and the price difference between them is not where the risk lives.
| Attribute | Scraped lists | Bulk purchased database | Verified / sourced discovery |
|---|---|---|---|
| Typical cost | Near zero (tool + time) | $1,000–$20,000 flat file | $49–$249/mo, credit-based |
| Provenance per record | None | Rarely available | Usually available per record |
| Article 14 notice feasible | No | Difficult | Yes |
| Suppression propagation | Manual, you build it | Vendor-dependent | Usually API-driven |
| Freshness | Snapshot, decays fast | Often 12–36 months old | Re-verified on request |
| Bounce rate (typical) | 15–40% | 8–25% | 2–8% |
| Regulator's view | Indefensible | Defensible only with paperwork | Defensible |
| Best for | Nothing you'd sign your name to | Static TAM research | Live outbound |
The "flat file" model is where most compliance failures originate. You buy 200,000 rows, the file is a static snapshot, and there is no channel back to the vendor when someone objects. Two years later you cannot say when the record was collected, from where, or whether the person already unsubscribed from a different campaign.
Credit-based discovery tools invert that. You look up contacts as you need them, each lookup is logged, and the provenance travels with the record. That is not a marketing distinction — it is the difference between having an audit trail and not having one.
If you want to see what per-record transparency looks like in practice, Tomba publishes its data sources and returns source URLs alongside each result from the email finder, so you can point to the exact public page a business address appeared on.
How Do You Write a Legitimate Interest Assessment?#
An LIA is a one-to-two page document. It is not hard, and not having one is the easiest way to lose an enforcement conversation.
Three parts, per the ICO's guidance on legitimate interests:
- Purpose test. What is the interest? "Contacting procurement managers at manufacturing firms with 50+ employees about a quoting tool that reduces their turnaround time." Specific beats generic — "growing our business" fails this test.
- Necessity test. Could you achieve the same result with less intrusive processing? If inbound alone could realistically fill your pipeline, your necessity argument is weak. For most early-stage B2B, it genuinely cannot, and that is a defensible answer.
- Balancing test. Would the person reasonably expect this contact? A CFO receiving a pitch about treasury software at their work address: yes. A junior designer receiving a pitch about industrial lubricants at their personal-format work address: no.
Write it once per campaign archetype, not per contact. Store it where a DPO could find it in under a minute. Re-review when you change targeting criteria.
The practical upshot for list building: narrow, role-relevant targeting is not just better for reply rates — it is what makes your lawful basis hold. A tightly scoped list of 400 people who plausibly want to hear from you is both more compliant and more effective than 40,000 scraped rows.
What Does a Compliant Outbound Stack Look Like?#
Here is the architecture that survives an audit, layer by layer.
Discovery layer. Use a provider that returns provenance. Search by company domain rather than uploading a personal-name list — domain search against a target account surfaces role-based and published business addresses, which sit at the low-risk end of the spectrum. Avoid tools whose only input is a personal profile URL scraped without notice.
Verification layer. Bounce management is a compliance issue, not just a deliverability one. Article 5(1)(d) accuracy obligations mean sending to addresses you know are stale is a data-quality failure. Run every list through an email verifier before send, and re-verify anything older than 90 days.
Suppression layer. Maintain a single global suppression list at the domain and address level. Every objection, unsubscribe, and complaint goes in and never comes out. Check exports against it before import, not after. This is the control that most teams skip and most regulators ask about first.
Notice layer. Your first email must include an Article 14 disclosure. It does not need to be long. Something like: "You're receiving this because your role is listed publicly on [company].com. We found your address via a business contact database. To be removed from our records entirely, reply 'remove' and we'll delete you within 48 hours." That sentence, plus a working process behind it, resolves the majority of complaints before they become filings.
Records layer. Keep, per campaign: the LIA, the target criteria, the export date and source, the notice text used, and the suppression log. If you can produce those five artifacts, you are ahead of the vast majority of outbound teams.
How Do the Major B2B Data Vendors Compare on Compliance?#
Compliance posture varies more than feature sets do. This is a directional comparison based on publicly documented practices — verify current terms directly with each vendor before signing.
| Vendor | Model | Per-record provenance | Published sub-processors | EU entity / SCCs | Entry price |
|---|---|---|---|---|---|
| Tomba | Credit-based lookup | Yes — source URLs returned | Yes | SCCs in DPA | Free (25/mo), then $49/mo |
| BookYourData | Curated B2B database | Yes — documented sourcing and verification | Yes | SCCs available | Pay-as-you-go credits |
| Apollo.io | Contributory network + database | Partial | Yes | SCCs | Free tier, paid from ~$49/user/mo |
| ZoomInfo | Contributory + community-sourced | Partial | Yes | SCCs, EU notice portal | Enterprise quote only |
| Generic scraped list broker | Static flat file | No | No | Often none | $500–$5,000 per file |
Two vendors here deserve specific notes. BookYourData publishes its verification methodology and sourcing approach openly, which is a meaningfully better starting position than the flat-file brokers it competes against on price — if you want a curated static list, that transparency is what to look for. Tomba is credit-based rather than list-based, which means provenance travels per lookup instead of per file; see Tomba pricing for the tier breakdown.
The row worth avoiding entirely is the last one. A vendor selling a 200,000-row CSV with no provenance, no DPA, and no suppression channel is selling you a liability, and the low price is why it looks attractive.
What Are the Most Common Compliance Mistakes?#
Ranked by how often they show up in actual complaints:
- No suppression propagation. Someone objects, you delete them from your sequencer, then re-import the same list next quarter and email them again. This turns one annoyed person into a filed complaint.
- Personal addresses treated as business addresses.
@gmail.comand@outlook.comin a "B2B" list means someone's personal inbox. Different rules, much higher risk. Filter them out at import. - No Article 14 notice. Most cold emails include an unsubscribe link and stop there. Unsubscribe is not the same as telling someone how you got their data.
- Retention with no end date. Records kept "until we clean the CRM" fail storage limitation. Set a policy — commonly 24 months from last engagement — and automate it.
- Sending to Germany with a generic approach. German B2B email rules are stricter than the EU baseline. Either segment Germany out or run a consent-first motion there.
- Assuming the vendor's compliance covers yours. It does not. Controller obligations are not transferable.
For definitions of the terms above, our B2B glossary covers the data and outreach vocabulary in plain language.
Is a GDPR Compliant Database Worth the Higher Cost?#
Yes, and the maths is not close.
Compare a €2,000 flat file of 100,000 unverified rows against a €49/month credit-based tool. The flat file looks 40x cheaper per contact. Then account for what actually happens: 20% hard bounce rate torching your sending domain, no provenance to answer a single subject access request, and a suppression process you have to build yourself. One serious complaint that escalates to a national authority costs more in legal hours than a decade of subscription fees — before any fine.
The more mundane argument is that compliant data performs better. Provenance requires the record to have been findable in a public business context, which correlates with the person actually holding that role. Verified, role-relevant, freshly sourced contacts bounce less, reply more, and keep your domain reputation intact. Compliance and deliverability push in the same direction.
There is no regulator-issued certificate to buy. There is only the question of whether you can answer "how did you get my email address?" — with a specific, checkable answer — the first time someone asks. Build your stack so that answer takes ten seconds to produce.
Start with data you can explain. The Tomba Email Finder returns the source URL alongside every business address it finds, so each record in your CRM carries its own provenance trail — the artifact that makes an Article 14 notice and a legitimate interest assessment possible instead of theoretical. The free tier includes 25 searches a month, with paid plans starting at $49/mo. Run your next target account through it and check what comes back in the sources field before you send a single email.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author