GDPR Email Compliance Checklist for B2B Cold Outreach 2026
Cold email is legal in most of the EU — but only if you can prove why. Here is the GDPR email compliance checklist your outbound team should be able to pass on any given Monday.

Cold email is legal in most of the EU. It is only legal if you can show your work. This GDPR email compliance checklist covers what you need on file before you press send.
TL;DR
- GDPR does not ban cold email. It bans cold email you cannot explain, log, or stop.
- For B2B outbound, your lawful basis is legitimate interest (Article 6(1)(f)). Write the balancing test down first.
- Article 14 catches most teams out. If you got the data from a third party, say so in the first email.
- National ePrivacy rules still apply. What is fine in the Netherlands is a fine in Germany.
- The fixes are dull: source records, verified addresses, a real opt-out, a delete date, and a suppression list that outlives your CRM.
This GDPR email compliance checklist is written for revenue teams. It is not legal advice. Run it past counsel in your target markets if the deals are big.
What does GDPR actually say about cold email?#
Almost nothing, directly. GDPR is a data law, not an email law. A work email like firstname.lastname@company.com is personal data. So you need three things: a lawful basis, a notice to the person, and a way to honour their rights.
The rules about sending live in the ePrivacy Directive. Each country writes its own version — PECR in the UK, UWG in Germany, LSSI in Spain. That is why advice online contradicts itself. One writer means GDPR. The other means German competition law. Both are right.
Here is the stack this GDPR email compliance checklist has to cover, in order:
- A lawful basis (Article 6). For outbound, that is legitimate interest, not consent. Consent must be freely given. A stranger cannot give it. Article 6 in full takes ten minutes to read.
- A notice (Article 14). You got the data elsewhere, so you owe the person some facts: who you are, why you write, what you hold, where it came from, and what rights they have. Send it at first contact, or within a month.
- A national ePrivacy rule. This decides whether you need consent before you send, for that country and that recipient.
- Rights handling (Articles 15–21). Access, erasure, and the right to object to marketing. The last one is absolute. If they say stop, you stop.
- Records (Article 30). A short register of what you process and why. "We're only 12 people" is not the exemption most teams think it is.
Miss one and the rest will not save you.
Is B2B cold email legal under GDPR?#
Yes, in most member states, if three things hold. Recital 47 says direct marketing may count as a legitimate interest. That one line holds up the whole European outbound industry.
The test is the Legitimate Interest Assessment, or LIA. It has three parts. Every item in this GDPR email compliance checklist rests on it, so show your work on each one.
- Purpose test. What is the interest? "Selling warehouse software to logistics managers" counts. "Growing our list" does not.
- Necessity test. Is email a fair way to get there? Could you reach the same people another way? If one trade magazine covers your whole market, your case is weaker.
- Balancing test. Would this person expect your email? A CTO at a 300-person SaaS firm, pitched a relevant tool at a work address: yes. A nurse's private Gmail, scraped from a PDF and pitched crypto: no.
The rule of thumb is simple. Relevance is your best defence. The tighter your list, the stronger the balancing test. Reply rates go up too. Sloppy targeting is a legal risk and a sales problem at once.
How do the major email laws compare?#
Most teams run one sequence into every region and hope. That is where fines start. The laws differ on the point that matters most. Do you need permission before you press send?
| Rule | Region | B2B cold email without consent | Opt-out required | Max penalty |
|---|---|---|---|---|
| GDPR + ePrivacy | EU/EEA | Usually yes, via legitimate interest | Yes, in every message | €20M or 4% of global turnover |
| PECR | UK | Yes, to corporate subscribers (Ltd, LLP, plc) | Yes | £500,000 (plus UK GDPR fines) |
| UWG §7 | Germany | No — prior consent generally required | Yes | Injunctions, cease-and-desist costs |
| CAN-SPAM | USA | Yes | Yes, honoured within 10 days | $53,088 per email |
| CASL | Canada | No — express or implied consent required | Yes | CA$10M per violation |
Two things fall out of that table. First, "GDPR compliant" is not a box you tick once. It is a stance per country. Second, the US and Canada sit at opposite ends. So one global sequence is wrong somewhere.
Detail matters inside the EU too:
| Country | Practical position on B2B cold email | What to change |
|---|---|---|
| Germany | Strictest. Prior consent expected for advertising email, including B2B | Use LinkedIn, phone, or events for first touch |
| France | Permitted if the message relates to the person's professional role | Keep the pitch tightly role-relevant |
| Netherlands | Permitted to legal entities on an opt-out basis | Standard sequence, clear unsubscribe |
| Italy | Consent-leaning; regulator has been active on marketing | Reduce volume, raise personalisation |
| Spain | Consent required unless a prior commercial relationship exists | Segment existing customers separately |
| Ireland | Permitted to business addresses with opt-out | Standard sequence, honour objections fast |
Regulators publish new guidance often. Treat this as a starting map, not a fixed one. The European Data Protection Board issues the opinions that move these lines.
What goes in a GDPR email compliance checklist?#
Work through this before your next campaign. Not after the first complaint.
Before you build the list
- Write the LIA. One page, dated, signed by whoever owns outbound. Store it where a regulator can find it fast.
- Draw the ICP tight. A narrow list makes the balancing test easy to argue.
- Pick your countries. Route the strict ones to other channels.
- Check your data source. Ask the vendor for its legal basis and keep the answer. Tomba publishes where its data comes from for this reason.
While you build the list
- Prefer work addresses.
sales@andfirstname@company.comsit better than a scraped Gmail. - Log the source and date for every record. If you cannot say where an address came from, you cannot answer Article 14.
- Verify before you send. Dead mailboxes hurt your sender reputation and add data you then have to justify. Run every list through an email verifier.
- Skip sensitive targeting. Health, politics, religion, and unions raise the bar a lot.
In every message
- Give your legal name and a postal address.
- Say how you found them. "I got your address from our B2B data provider while researching logistics teams" works. It also beats pretending.
- Add a one-click opt-out. Not "reply STOP" in grey 9pt type.
- Link a privacy notice that actually mentions prospecting.
After you send
- Act on objections in days, not the 30-day limit. Marketing objections are absolute.
- Keep one suppression list, keyed on a hashed email, outside your CRM. It has to survive tool changes.
- Set a delete date. Most teams drop quiet prospects after 6–12 months.
- Log every request and how fast you answered. Article 30 records are cheap now and costly to rebuild later.
How do you document legitimate interest without hiring a lawyer?#
Keep it short. The LIA is the spine of any GDPR email compliance checklist, and a usable one fits on a page. It answers seven questions.
- Who is the controller? The legal entity, not the brand.
- What is the interest? One sentence. Be concrete.
- Whose data, and how much? Name, work email, job title, employer, public profile. Nothing more.
- Where did it come from? Name the source. Add your view of its lawfulness.
- Why email? Say what else you weighed and why it falls short.
- What is the impact? How many emails, how often, and how easily they can stop it.
- What safeguards apply? Suppression list, delete date, country rules, no sensitive data.
Review it whenever your targeting shifts. A dated history often reads better than the text itself. It shows a habit, not a document written in a panic.
What data practices are safe, and which ones get you fined?#
Fines rarely follow one big mistake. They follow small shortcuts. Stack enough of them and the balancing test falls apart.
| Practice | Compliance posture | Why |
|---|---|---|
| Verified role-based work addresses from a documented provider | Low risk | Clear source, professional context, defensible necessity |
| Pattern-guessed addresses sent unverified | Elevated risk | High bounce rate, no source record, weak necessity argument |
| Personal Gmail/Outlook addresses of employees | High risk | Private context defeats the balancing test |
| Bulk-scraped lists with no provenance | High risk | Cannot satisfy Article 14 source disclosure |
| Purchased lists with no vendor legal basis on file | High risk | You inherit the original collection defect |
| Enriched CRM records for existing customers | Low risk | Existing relationship strengthens expectation |
Note that verification shows up twice. It is more than a deliverability trick. An unverified list means you hold data on people who may not use that address. That is an accuracy problem under Article 5(1)(d). Cleaning your list is a control that also guards your domain.
Enriching beats sourcing cold. Contact enrichment on accounts you already know sits on firmer ground than net-new discovery.
How long can you keep prospect data?#
As long as you can justify. No longer. GDPR sets no number, so teams keep everything forever. That is the worst answer. Endless storage undercuts the necessity argument in your own LIA.
Retention is the line teams skip in a GDPR email compliance checklist. Here is a safe default for outbound:
- Engaged (opened, replied, met): keep while the relationship is live. Review once a year.
- Unengaged: 6–12 months from last contact, then delete or anonymise.
- Objected or unsubscribed: keep a hashed suppression entry for good. Delete the record and you will re-import them next quarter.
- Bounced or invalid: delete now. You are storing wrong data for no reason.
Automate the clock. A policy nobody runs counts against you. The GDPR overview explains how storage limits tie into the other principles.
What happens when someone objects or asks for erasure?#
Two requests. Two answers.
An objection to direct marketing under Article 21(2) is absolute. There is no test and no debate. Stop marketing, add them to suppression, and confirm it. Same day if you can.
An erasure request under Article 17 goes further. They want the data gone. If legitimate interest was your only basis and they object, you delete. Keep the hashed entry you need for suppression. Then log the deletion.
The trap is scatter. Your CRM, sequencer, warehouse, and someone's spreadsheet all hold copies. List every system that holds prospect data. Check that each one can delete. If the answer is "we'd have to ask the vendor," fix that first.
What does a compliant outbound stack look like in practice?#
Five parts. None of them exotic.
- Sourcing with provenance. Every record arrives with a source and a date, set by the tool, not typed by an SDR.
- A verification gate. Nothing enters a sequence unverified. Catch-all domains get flagged, not guessed.
- A country router. Germany, Italy, and Spain go to LinkedIn or phone. The rest run email.
- A suppression service. One list, checked at send time, tied to no single tool.
- A retention job. Scheduled, logged, and reported to whoever signed the LIA.
Build it once and the panic stops. Most of the cost lands in month one. After that it is upkeep. If budget is the blocker, weigh it against the price of your data tooling. The controls cost less than the data. They cost far less than an investigation.
Where should you start this week?#
Pick the two biggest wins in this GDPR email compliance checklist. Write the LIA. Make source-of-record required on every new contact. Those two move you from hoping nobody asks to being able to answer. The rest is polish.
Then fix the data itself. Compliance and results pull the same way here. Precise, verified, well-sourced contacts get more replies and a stronger balancing test. Use Tomba Email Finder to source work addresses with a logged origin and built-in checks. Then every record can answer the two questions that matter. Where did this come from? Is it real? The free tier gives you 25 searches a month, so you can test the workflow first.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author