GDPR for Sales and Marketing: A 2026 Compliance Playbook
Legitimate interest, not consent, is what most B2B outbound runs on — and most teams get the paperwork wrong. Here is what GDPR actually requires of sales and marketing in 2026, with the tests, timelines, and tooling that hold up under scrutiny.

TL;DR — what GDPR for sales and marketing actually asks of you:
- GDPR does not ban cold email in B2B. Most EU outbound rests on legitimate interest (Article 6(1)(f)), not consent. Write the three-part test down before you send, not after a complaint.
- ePrivacy, not GDPR, decides whether you may send. GDPR covers the data. ePrivacy covers the channel, and each member state wrote its own version. Germany and Italy are strict. The UK, Ireland, and the Netherlands allow B2B email.
- Role accounts (info@, sales@) carry less risk than personal-format addresses. They may not name a real person at all.
- What you must have on file: a lawful basis, a privacy notice link in email one, a working opt-out, deletion within 30 days, and a data source you can name.
- Your tools are processors under Article 28. Ask each one for a DPA, a named data source, and EU-safe transfer terms.
What does GDPR for sales and marketing actually require?#
Three duties, and that is the whole of it. You need a lawful reason to hold a person's data. You have to tell them you hold it. You have to stop when they ask. The rest is paperwork.
Think of it like a library card. You do not need the author's consent to read a book. But the library has to log who borrowed it, tell borrowers what it records, and wipe that record on request. Sales data works the same way. You rarely need consent to have a contact. You always need a good reason and a paper trail.
The rules cover the data of anyone in the EU or EEA. Where your company sits does not matter. A San Francisco SDR emailing a Munich CTO is in scope. So is a CRM in Virginia that holds French buyer records.
Four duties do most of the work in a B2B revenue team:
- Lawful basis (Art. 6) — pick one before you touch the data, usually consent or legitimate interest. You cannot swap later to rescue a bad campaign.
- Transparency (Arts. 13–14) — tell the person you hold their data, why, and where you got it. For data you did not collect yourself, Article 14 gives you one month from the day you got it, or your first contact, whichever comes first. All prospecting data counts.
- Data subject rights (Arts. 15–21) — access, fixes, erasure, and objection. An objection to direct marketing under Article 21(2) is absolute. There is no test to argue. You stop.
- Accountability (Art. 5(2)) — you must be able to show all of the above. If it is not written down, it did not happen.
Fines run to €20 million or 4% of global annual turnover, whichever is higher. In practice, most B2B sales cases in the EDPB's public record land far lower. The ones that hurt tend to involve scraped data with no named source.
Is consent or legitimate interest the right basis for B2B outbound?#
Legitimate interest, in almost every B2B case. Consent is the wrong tool for cold outreach. Valid GDPR consent has to be freely given, specific, informed, and clear. A prospect who has never heard of you cannot give it. If they had given it, the email would not be cold.
Recital 47 says it directly: "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." That line is your anchor.
To rely on it, run and record the three-part LIA (Legitimate Interests Assessment):
| Test | Question you must answer | What a passing answer looks like |
|---|---|---|
| Purpose test | Is there a real, specific business interest? | "Contacting IT directors at 200–2,000-seat SaaS firms about an infrastructure product they buy." Not "growth." |
| Necessity test | Is processing this data the reasonable way to achieve it? | Work email + job title + company. Not personal mobile, not home address, not inferred salary. |
| Balancing test | Do the person's rights override your interest? | Business-role data, business channel, relevant offer, easy opt-out, no sensitive categories, no surprise. |
| Documentation | Can you produce it on request? | Dated LIA per campaign type, stored, reviewed when targeting changes. |
| Safeguards | What did you do to reduce impact? | Privacy notice link in email 1, one-click unsubscribe, suppression list, retention cap. |
The balancing test is where teams fail. A bad match kills it. Emailing a hospital buyer about a developer tool is hard to defend. Emailing a VP of Engineering about that same tool is easy.
Two things sink an LIA fast. One is targeting people in a private role rather than a work role. The other is data you cannot trace to a source. That is why your data sources matter as much as your copy.
How do ePrivacy rules change GDPR for sales and marketing by country?#
This is the part that trips up teams who read only GDPR. GDPR tells you whether you may hold the data. ePrivacy tells you whether you may send the message. They are two laws, not one. ePrivacy is a directive, so each member state wrote its own version.
Here is the split for cold B2B email:
| Jurisdiction | B2B email to corporate subscribers | Notes for outbound teams |
|---|---|---|
| UK (PECR) | Allowed without prior consent to corporate subscribers | Sole traders and most partnerships count as individuals — consent needed |
| Ireland | Allowed to business addresses | Must offer opt-out in every message |
| Netherlands | Allowed to business addresses | Opt-out register must be honoured |
| France (CNIL) | Allowed for B2B if the offer relates to the person's role | CNIL guidance is explicit about the professional-relevance condition |
| Germany (UWG §7) | Effectively requires prior consent, including B2B | Highest risk market; competitor lawsuits, not just regulator action |
| Italy | Consent-first in practice | Garante enforces strictly |
| Spain | Prior consent or an existing relationship | LSSI overlays GDPR |
Two rules of thumb keep you out of trouble:
- Split your sequences by country before you send. One all-EU blast is the riskiest thing an outbound team does.
- Treat Germany and Italy as opt-in markets. Use inbound, events, LinkedIn chat, and referrals there instead of cold email.
In the rest of the EEA, job relevance is your shield. That is not a legal loophole. It is the same habit that lifts your response rate.
What data can you legally collect and keep?#
Keep the least data that makes the outreach work. Article 5(1)(c) calls this data minimisation. An eager enrichment stack breaks it fast.
Safe to hold for B2B outbound with a documented legitimate interest:
- Work email address in company-domain format
- Full name and job title as published professionally
- Company name, domain, size band, industry
- Public professional profile URL (LinkedIn, company bio page)
- Source and date for each record — most teams skip this field, and most regret it
Risky or off-limits without a stronger basis:
- Personal mobile numbers — a direct office line is fine. A scraped personal cell is not. Check the phone finder split between work and private numbers before you dial.
- Personal email addresses (gmail.com, outlook.com) used for work contact — these name a real person, so most member states treat them under consumer rules.
- Guessed sensitive traits — health, religion, politics, union ties, sexual orientation. Article 9 sets a much higher bar for these.
- Cookie or pixel data without a valid consent banner — that is ePrivacy again. It is where most fine money has landed.
Role addresses like info@, sales@, or press@ sit in a lower-risk tier. If the address does not name a person, GDPR may not apply to it at all. Several DPAs, the ICO among them, take that view. A domain search for published company addresses is often the easiest first touch in a strict market.
Retention: set a policy and stick to it. One defensible pattern is 24 months from the last real engagement for prospect records, and 12 months for cold ones. Suppression lists have no limit, because you need those forever to honour past opt-outs. Deleting an opt-out record is itself a breach.
What does a compliant cold email look like under GDPR for sales and marketing?#
Five parts. Miss one and the whole sequence is exposed.
- Name the sender. Real person, real company, real business address in the footer. No lookalike domains. No fake alias names.
- Say how you got the data. One line covers most of Article 14: "I found your details on your company website / a B2B business directory."
- Link your privacy notice. It has to list the data, the source, the purpose, the basis, the retention, and the rights. Put the link in the first email, not the third.
- Offer a working opt-out. One click or one reply. "Reply STOP and I'll remove you" is fine if you act on it. A hidden 8-point unsubscribe is not.
- Keep it relevant to the role. The balancing test lives or dies here.
A compliant footer looks like this:
You're receiving this because your role at Acme GmbH suggests our infrastructure tooling may be relevant. I sourced your business email from your company website. Reply "unsubscribe" and I'll remove you immediately and permanently. [Privacy notice] · Northwind Ltd, 14 Example Street, Dublin 2, Ireland.
Note what is missing. No consent claim you cannot back up. No "you opted in at an event" story. No unsubscribe link that just marks you as engaged.
Also: suppression must be system-wide, not sequence-level. Say a prospect opts out of your SDR sequence and still gets a newsletter from another tool. That is a fresh breach. Central suppression is the highest-value plumbing a RevOps team can build. It belongs in the same layer as your revenue operations data model.
How do you vet vendors and data providers?#
Every tool that touches EU personal data for you is a processor, and Article 28 requires a written contract. Buying data does not move the risk. You stay the controller, and you answer for the source.
Run this checklist before you sign:
| Requirement | What to ask the vendor | Red flag |
|---|---|---|
| DPA available | "Send me your standard Data Processing Agreement." | It doesn't exist, or it's buried behind sales |
| Documented data sources | "Where does each field come from?" | "Proprietary" with no detail |
| Transfer mechanism | SCCs, adequacy decision, or EU hosting | Silence about US sub-processors |
| Sub-processor list | Published and versioned | Not disclosed |
| Deletion API/flow | Can you push an erasure request through to them? | Manual email to support only |
| Verification vs. guessing | Does it verify addresses or pattern-guess them? | High "found" rates with no verification signal |
| Security posture | SOC 2 Type II or ISO 27001 | Neither, and no roadmap |
That second-to-last row matters more than it looks. A tool that guesses firstname.lastname@domain.com and fires it into your sequence is creating personal data and testing it on live inboxes. A tool that checks each address against real mail servers touches far fewer wrong records. That is a win for both delivery and data minimisation.
Here is how the main tool types compare on the points that matter for GDPR for sales and marketing:
| Attribute | Tomba | Typical bulk database | Scraper / browser extension |
|---|---|---|---|
| Starting paid price | $49/mo (Starter) | $99–$199/mo | $15–$49/mo |
| Free tier | 25 searches/mo | Usually trial only | Often unlimited-ish |
| Documented data sources | Yes, published | Varies | Rarely |
| DPA offered | Yes | Usually | Frequently not |
| Verification before delivery | Built-in verifier + catch-all handling | Sometimes | Almost never |
| Source field per record | Yes | Sometimes | No |
| Deletion / suppression support | API-accessible | Varies | Manual at best |
For a deeper cost breakdown across tiers, see Tomba pricing. The point holds for any vendor. If you cannot say where a record came from, you have no lawful basis you can defend.
"Compliant vendor" and "good vendor" are two different tests. Peers like BookYourData publish their sourcing and offer DPAs too. The question is whether the fields you buy match the interest you wrote down.
What should your team do in the next 30 days?#
A practical order of work:
- Inventory your data. List every system that holds EU contact data: CRM, sequencer, enrichment tool, spreadsheets, personal exports. The spreadsheets are always the problem.
- Write one LIA per campaign type. Not per campaign. Three or four documents cover a whole outbound motion.
- Publish a prospect-facing privacy notice at a stable URL. Link it from every first email and every signature.
- Build central suppression. One list, synced to every sending tool, kept forever.
- Split sequences by country. Pull Germany and Italy out of cold email volume.
- Collect a DPA from every vendor. File them where legal can find them in an hour.
- Set retention rules in the CRM. Then schedule the delete job for real.
- Train the reps. Most breaches start with a rep exporting a list to a home laptop, not with a broken system.
Want it straight from a regulator? The ICO's guide to legitimate interests is the clearest public read on the three-part test. The European Data Protection Board publishes the guidance that national DPAs follow. On the vendor side, HubSpot's GDPR resources show what a mature CRM setup looks like.
Does GDPR for sales and marketing hurt pipeline?#
Usually the opposite, and the reason is simple. GDPR forces narrow targeting, role relevance, verified addresses, and honest sourcing. That is the same habit that lifts reply rates. Blast-everything outbound was already dying on delivery grounds. Gmail and Yahoo bulk-sender rules did more to end it than any regulator.
The cost is real but front-loaded. A few days of writing. One plumbing project for suppression. One vendor review. After that, compliance rides in your workflow instead of sitting on a to-do list.
Teams struggle when they bolt GDPR onto a spray-and-pray motion. Teams that barely notice it were already sending fewer, sharper, verified emails.
Where does tooling fit into all this?#
GDPR for sales and marketing rests on two facts about your data. You know where each record came from. You know it is correct. Wrong records reach the wrong people, hurt your domain, and grow your data footprint for zero pipeline.
The Tomba Email Finder is built for both. Every result carries its sources, so you can answer the Article 14 question in one click. Each address is verified before you get it, so you are not sequencing guesses. The free tier gives you 25 searches a month to test data quality on accounts you already know, before you commit to $49/mo Starter or $99/mo Growth.
Pair it with the email verifier for list hygiene. Use the Tomba API to wire deletion requests into your suppression list. Then a prospect who says "remove me" is gone from every system, not just the one they replied to.
Start with the data you can defend. The pipeline follows.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author