GDPR and Email Addresses: What B2B Teams Must Know in 2026
Is a work email personal data under GDPR? Yes — and that changes how you source, store, and send. Here's the 2026 rulebook for B2B prospecting teams.

Every GDPR email address question comes down to three things. Does the address name a person? Which country do they work in? And can you prove where you got it? Answer those, and most of the rest is paperwork.
TL;DR
- A work email address like
firstname.lastname@company.comis personal data under GDPR. A genericinfo@company.comusually is not. - GDPR itself rarely asks for consent on B2B cold email. It asks for a documented legitimate interest basis. Consent rules come from a separate layer — ePrivacy in the EU, PECR in the UK — and they vary by country.
- The five things that actually get companies in trouble: no legitimate interest assessment, no source record, no working opt-out, sending to consumer-style addresses, and ignoring erasure requests.
- Bought lists are the highest-risk input. Provenance you can't reconstruct is provenance you can't defend.
- Practical stack: source with a tool that logs where each address came from, verify before sending, suppress on request, and re-verify every 90 days.
GDPR email address basics: is a work email personal data?#
Yes, if it identifies a person. That's the whole test.
Think of GDPR's definition like a name tag at a conference. If the tag says "Sarah Chen, VP Engineering," it identifies someone. Work or fun, it is still personal data. If the tag just says "Front Desk," it identifies nobody. Email addresses work the same way.
The technical version: Article 4(1) of the GDPR defines personal data as any information relating to an identified or identifiable natural person. sarah.chen@acme.com holds a first name, a last name, and an employer. That is three identifiers in one string. It is personal data, full stop. The "but it's a business address" argument has never survived scrutiny with a regulator.
Where it gets more interesting:
- Named work emails —
s.chen@acme.com,sarah@acme.com,chen@acme.com. Personal data. Full GDPR applies. - Role-based emails —
sales@acme.com,support@acme.com,hello@acme.com. Generally not personal data. The exception is a role held by one identifiable person, such assales@at a two-person company. - Pattern-derived guesses — you inferred
sarah.chen@acme.comfrom a naming convention. Still personal data. Inference is processing. - Hashed or pseudonymised emails — still personal data if you or anyone else can reverse the link. Pseudonymising lowers the risk. It does not take you out of the regulation.
- Truly anonymised aggregates — "47% of contacts at this company use firstname.lastname" is not personal data. Aggregate counts identify nobody.
The practical consequence is simple. The moment a named GDPR email address lands in your CRM, you are a data controller. That brings duties: a lawful basis, transparency, a retention limit, and data subject rights. None of that is a reason to stop prospecting. It is a reason to prospect with a paper trail.
What lawful basis covers B2B prospecting emails?#
Legitimate interest — Article 6(1)(f) — is the standard basis for B2B cold outreach in the EU. Consent is the wrong tool, and almost nobody uses it correctly.
Here's why consent fails for prospecting. GDPR consent must be freely given, specific, informed, and unambiguous. It also has to come before processing. You cannot email someone to ask permission to email them, because that first email is already processing. Consent is a circular trap for cold outreach. Recital 47 says as much: direct marketing "may be regarded as carried out for a legitimate interest."
But legitimate interest is not a free pass. It is a three-part test. You have to run it, and you have to write it down.
| Test stage | Question you must answer | Evidence to keep |
|---|---|---|
| Purpose | Is there a real, specific commercial interest? | Written ICP definition, product-fit rationale |
| Necessity | Is email the least intrusive way to achieve it? | Note on why not phone/post/ads |
| Balancing | Do the person's rights override your interest? | Relevance scoring, seniority/role logic, opt-out record |
The balancing test is where teams lose. Email a Head of Procurement about procurement software, and they can reasonably expect to hear from you. The balance tips your way. Email a junior designer about an unrelated enterprise contract, and it does not. Relevance is not a nice-to-have. It is legally load-bearing.
Write the assessment down. A one-page Legitimate Interest Assessment (LIA) beats a perfect verbal argument. Regulators ask for records, not reasoning. The UK ICO publishes a free LIA template that maps cleanly onto EU practice.
How does ePrivacy change the rules per country?#
This is the part most "GDPR email" guides skip. It is also the part that actually varies.
GDPR sets the lawful-basis layer. The ePrivacy Directive sets the electronic marketing layer on top. Each member state implements it differently, and the UK version is called PECR. Clearing legitimate interest under GDPR does not clear the ePrivacy hurdle.
| Country | B2B cold email to named work address | Notes |
|---|---|---|
| Germany | Restrictive — prior consent generally required (UWG §7) | The strictest major market; "presumed interest" exception is narrow |
| France | Permitted with opt-out, if relevant to the role | CNIL explicitly allows B2B soft opt-out for professional addresses |
| Netherlands | Permitted with opt-out for legal entities | Register-based opt-out list applies |
| Ireland | Permitted with opt-out for corporate subscribers | Common EU-entity base for outbound teams |
| Spain / Italy | Permitted with opt-out, tighter on evidence | Keep source and LIA records readily producible |
| UK (PECR) | Permitted to corporate subscribers with opt-out | Sole traders and partnerships get consumer-level protection |
Two operational takeaways. First, segment your sequences by country — a single EU-wide blast applies the loosest rule to the strictest market. Second, treat sole traders, freelancers, and partnerships as consumers. In the UK and several EU states, that is what they legally are. john@johnsmithconsulting.co.uk is not a corporate subscriber.
What does a compliant B2B email sourcing workflow look like?#
The compliance question is rarely "can we email this person." It is "can we explain, six months from now, where this address came from and why we thought it was relevant." Build for that.
1. Source with provenance, not scraping. Every address should carry a recorded origin. A tool that returns the public sources it saw the address on gives you an audit trail. That is why Tomba documents its data sources. Use domain search to pull contacts at a target company, and each result carries the public pages it was found on. Scraped CSVs and forum-sourced lists carry nothing.
2. Filter to role relevance before enrichment. Don't enrich everyone at a company and decide later. Decide the ICP roles first, then source. It is cheaper, and it feeds the balancing test directly. You can show you targeted people whose job makes the email expected.
3. Verify before sending. Bounces hurt deliverability and data quality alike. GDPR Article 5(1)(d) also requires personal data to be accurate and kept up to date. So an email verifier pass is a compliance control, not just a hygiene step. For domains that accept everything, a catch-all verifier tells you whether the mailbox is real or the server is just being polite.
4. Send with a real identity and a real opt-out. Every email needs: who you are, where you got the data (one sentence is enough), why you're contacting this person specifically, and a one-click way to stop. "Reply STOP" is acceptable; a hidden 6-point unsubscribe is not.
5. Honour objections within days, permanently. An Article 21 objection to direct marketing is absolute. No balancing test, no exceptions. Keep a global suppression list keyed on the email address, not on the CRM record. Otherwise a re-import will resurrect a deleted contact.
6. Set a retention clock. Unresponsive prospects should age out. A 12–24 month retention policy for non-engaged contacts, applied automatically, is defensible. "We keep everything forever" is not.
Which tools handle GDPR provenance best?#
Sourcing tools differ enormously in how much of this work they do for you. The distinction that matters is not "GDPR compliant." No tool can make you compliant, because compliance depends on your purpose and your process. The real distinction is how much evidence the tool hands you.
| Capability | Tomba | Typical scraper / list broker | Full sales-intelligence suite |
|---|---|---|---|
| Source citations per contact | Yes — public sources listed | No | Varies; often aggregate only |
| Built-in verification | Yes — verifier + catch-all check | Rarely | Usually included |
| Named vs role-based flagging | Yes | No | Sometimes |
| Entry price | Free tier (25 searches/mo), then $49/mo | $50–500 per list, one-off | $99–1,000+/user/mo |
| Mid tier | Growth $99/mo | n/a | Seat-based, annual commit |
| Data subject deletion support | Yes, on request | Effectively none | Yes, contractual |
| Bulk workflow | Bulk email finder with per-row source | CSV dump | Yes |
| API for automated suppression | Tomba API | No | Yes |
A few honest caveats. Full-suite platforms like ZoomInfo or Apollo carry deeper firmographic data and formal DPAs, which enterprise procurement teams like. If you need buyer-intent signals and org charts, a finder tool alone won't cover it. BookYourData takes a different and legitimate approach: pay-as-you-go verified lists with an accuracy guarantee. That suits teams who want one clean list rather than a running subscription, and verifying at the point of purchase speaks straight to the accuracy duty.
What none of them do is write your LIA or run your suppression policy. That part is yours.
What are the real penalties, and who actually gets fined?#
Fines for cold email are rarer than LinkedIn posts suggest — but they are real, and they cluster around a few specific failures.
The headline numbers: up to €20 million or 4% of global annual turnover, whichever is higher. Direct-marketing cases rarely hit that ceiling. What usually lands is a five- or six-figure fine from a national authority, plus the drag of a public decision.
The recurring fact patterns:
- No lawful basis on record. The company could not produce an LIA when asked. This is the single most common finding.
- Unhonoured objections. Someone said stop, and the emails continued because the suppression was per-campaign, not global.
- Undisclosed data source. Recipients asked where you got their address and got no real answer. That breaches the Article 14 transparency duty for data you did not collect from the person.
- Consumer addresses in a B2B list. Gmail, Outlook, and personal-domain addresses swept into a "business" campaign.
- Ignored erasure requests. The Article 17 clock is one month. Silence is a violation on its own.
Notice that four of the five are process failures, not sourcing failures. You can source perfectly legally and still get fined for what happens afterward.
How do you handle a data subject request about an email address?#
Assume it will happen. When someone replies "delete my data," you have a one-month statutory clock and a small number of duties.
Access (Article 15): Tell them what you hold, why, where you got it, how long you'll keep it, and who you've shared it with. A short structured reply beats a legal essay.
Erasure (Article 17): Delete the record, but keep the email address on a suppression list. This sounds contradictory and is not. Holding a minimal identifier to prevent future processing is recognised as legitimate. Note the reason in the suppression entry.
Objection (Article 21): For direct marketing, stop immediately. No balancing, no negotiation, no "let me just send one more."
Rectification (Article 16): Fix inaccurate data. If a prospect tells you they left the company, update or remove the row. Don't just note it.
Practical setup: a single inbox alias (privacy@yourdomain.com), a logged ticket per request, and a suppression list that your sending tool checks on every send. If you run outreach through the Tomba API or a CRM integration, wire the suppression check into the send path rather than the import path. Imports get repeated; send paths don't.
What's the fastest way to make your current list defensible?#
Run this audit on the list you already have. It takes an afternoon.
- Split named from role-based. Role addresses need less. Named addresses need everything.
- Flag consumer domains and sole traders. Gmail, Yahoo, iCloud, personal domains, and one-person consultancies come out of the B2B legitimate-interest bucket.
- Check provenance per row. Any row where you cannot name the source is a liability. Re-source it through a tool that records origin, or drop it.
- Re-verify everything older than 90 days. Job changes run at 20–25% a year in tech roles. Stale rows hurt deliverability and accuracy at once.
- Write the one-page LIA. Purpose, necessity, balancing. One page. Date it.
- Build the global suppression list. Every past opt-out, objection, and hard bounce, in one place your sender checks.
If step 3 kills half your list, that's the audit working. A defensible 4,000-contact list beats an indefensible 12,000-contact list on reply rate anyway. The defensible one is relevance-filtered by construction.
Where should you start?#
Start at the source, because everything downstream inherits its problems.
If your addresses arrive as an untraceable CSV, careful sending will not fix the provenance gap. Every GDPR email address you keep should carry three things: a recorded origin, a verification status, and a named-versus-role flag. Get that right, and the rest of your compliance program is paperwork you can actually finish.
The Tomba Email Finder is built for that first step. Search by name and domain, get back a verified address with the public sources it was found on, and export with provenance intact. The free tier gives you 25 searches a month to test the workflow on your own ICP. Tomba pricing then starts at $49/mo for Starter and $99/mo for Growth. Pair it with the verifier, keep your LIA on file, and your outbound stops being a compliance question and goes back to being a sales question.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author