GDPR Lawful Basis Legitimate Interest for B2B Outreach
Legitimate interest is the lawful basis most B2B teams lean on for outbound — and the one most often claimed without the paperwork to back it. Here's the three-part test, the country-level traps, and when consent is the safer call.

The GDPR lawful basis legitimate interest is what most B2B teams lean on for cold outreach. It can work. But it only holds up if you can show your reasoning in writing, and if the country you are emailing allows the channel at all.
TL;DR
The GDPR lawful basis legitimate interest is real, and it works for B2B outbound. Article 6(1)(f) allows it. Recital 47 names direct marketing as a possible legitimate interest. It is not a loophole. It is also not a free pass.
It only holds if you document it. Write a Legitimate Interests Assessment (LIA) covering purpose, necessity, and balance. Write it before you send, not after a complaint lands.
GDPR is not the only law in the room. The ePrivacy Directive governs the channel, and national rules differ: PECR in the UK, UWG in Germany, CNIL guidance in France. Germany wants consent even for B2B email. The UK and Ireland allow legitimate interest for corporate subscribers.
Where you get the data matters. Scraped personal Gmail addresses fail the balancing test almost every time. A role-relevant address at a business domain is far easier to defend.
Transparency is the price of the basis. Send an Article 14 notice within one month or at first contact. Put a working opt-out in every message. Honour it within days, not next quarter.
This is an operational guide written by a content team, not a law firm. Get counsel before you rely on any of it.
What is a lawful basis under the GDPR?#
Think of the GDPR as a locked building. To walk in with someone's personal data, you need a key. There are exactly six keys cut, and no more. You pick one before you open the door. You write down which one you used. You cannot swap keys halfway through because the first one broke.
Those six keys are the lawful bases in Article 6: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Any processing of personal data needs one of them. A work email like first.last@company.com is personal data, because it identifies a living person.
Two things trip B2B teams up here:
"It's a company email, so it isn't personal data." Wrong. If it identifies an individual, it is personal data. Only generic addresses like
info@orsales@fall outside scope, and even those get murky when one person is obviously behind them."We'll figure out the basis if someone asks." Also wrong. Accountability under Article 5(2) means you must be able to demonstrate compliance. Retro-fitting a basis after a data subject access request is like writing the exam answers after you have seen the grade.
Why do B2B teams pick legitimate interest?#
Because the alternative is impossible. Consent must be freely given, specific, informed, and unambiguous. You cannot get valid consent from someone you have never contacted. If cold outbound required consent, cold outbound could not legally exist in the EU. So Article 6(1)(f) is the door. Processing is lawful when it is "necessary for the purposes of the legitimate interests pursued by the controller…". The rest of that clause matters just as much. Your interest must not be overridden by the rights and freedoms of the person you are contacting.
Recital 47 then says the quiet part out loud: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." Regulators have not walked that back. The UK's ICO publishes a detailed guide to legitimate interests. It treats B2B marketing as a normal use case with normal conditions attached.
The catch is the word "may". The GDPR lawful basis legitimate interest is conditional, not automatic. The condition is a balancing test you have to actually run.
How do the six lawful bases compare for outbound?#
| Lawful basis | Realistic B2B use | Effort to rely on | Right to object? | Verdict for cold outbound |
|---|---|---|---|---|
| Consent — Art. 6(1)(a) | Newsletter sign-ups, gated content, event lists | High — granular capture, timestamped proof, easy withdrawal | Withdrawal, any time | Only works for inbound-generated contacts |
| Contract — Art. 6(1)(b) | Onboarding, billing, support for existing customers | Low | No | Never covers prospecting |
| Legal obligation — Art. 6(1)(c) | Tax records, KYC, statutory retention | Low | No | Irrelevant to marketing |
| Vital interests — Art. 6(1)(d) | Life-or-death emergencies | N/A | No | Not applicable |
| Public task — Art. 6(1)(e) | Public authorities only | N/A | Limited | Not applicable |
| Legitimate interests — Art. 6(1)(f) | Cold email, enrichment, lead scoring, account research | Medium — documented LIA + Art. 14 notice + opt-out | Absolute for direct marketing (Art. 21(2)) | The only workable basis, if you do the work |
Note the fourth column. Under Article 21(2), the right to object to direct marketing is absolute. There is no balancing and no "we'll consider it". Someone says stop, you stop, and you record that suppression for good. That one rule is the practical price of this basis. It is also why your suppression list has to be a system of record, not a spreadsheet somebody forgets to import.
What is the three-part test, exactly?#
The LIA is three questions. Answer them in writing. Date the document. Re-run it whenever your targeting changes in a real way.
Purpose test — is there a legitimate interest? State it concretely. Not "growing the business", but "contacting IT decision-makers at 200–1,000 employee logistics firms in the Netherlands about a warehouse-routing product relevant to their stated role". Commercial interests count as legitimate. Vague ones do not survive scrutiny.
Necessity test — is the processing necessary? Could you reach the same people a less intrusive way, with similar results? "Less intrusive" does not mean "less effective". No regulator will accept "you could have run ads" as a reason to ban outreach. It does mean you should not collect twelve data points when three would do. Data minimisation is part of necessity.
Balancing test — do the person's rights override your interest? Most assessments are won or lost here. Is the person acting in a professional capacity? Is your message relevant to their actual job? Did the data come from a source they would expect? Is the volume proportionate? Is objecting trivially easy?
The ICO suggests a useful sanity check: would this person be surprised or annoyed to learn how you got their details? Say a CFO at a mid-market manufacturer gets a short, relevant note about spend controls at their work address. The honest answer is no. Now say a junior designer gets a crypto pitch at a personal Gmail scraped from a forum. The honest answer is obviously yes, and no amount of paperwork saves it.
The four inputs that decide your balancing test#
Source of the data. Public professional sources and vendor databases with disclosed provenance are defensible. Scraped personal accounts, breached dumps, and broker lists with no named source are not. That is why where your data comes from belongs in your LIA, not just in your procurement notes.
Role relevance. Targeting by job function is the strongest signal that you had a reason to contact this person rather than 40,000 random people.
Message proportionality. Two follow-ups is normal business communication. Eleven is harassment. A regulator reads the whole sequence, not just the first email.
Ease of objection. A one-click unsubscribe, or a plain "reply STOP and I'll remove you" in the footer, shifts the balance your way. Hiding it does the opposite.
Does the GDPR lawful basis legitimate interest cover cold email?#
Here is the part most articles skip: GDPR governs the data, ePrivacy governs the channel. You need to clear both. A passing LIA gives you the right to process the address. Whether you may send an unsolicited message to it is decided by the ePrivacy Directive, as each country implements it. Those implementations diverge sharply.
| Country | B2B email to corporate address | Practical read |
|---|---|---|
| United Kingdom | Legitimate interest OK for corporate subscribers (PECR carve-out) | Send with LIA + notice + opt-out; sole traders and partnerships are treated as individuals |
| Ireland | Permitted to business addresses with opt-out | Similar posture to the UK |
| Netherlands | Permitted to legal-entity addresses | One of the more workable markets |
| France | Permitted if the message relates to the recipient's professional role (CNIL guidance) | Relevance is the whole ballgame |
| Germany | UWG §7 effectively requires prior consent for email, B2B included | Treat cold email as high-risk; use LinkedIn or phone first |
| Italy / Spain | Restrictive, consent-leaning interpretations | Get local counsel before scaling |
Two conclusions follow. First, there is no single "EU-compliant" playbook. Your posture is country by country, so your CRM needs a country field that actually drives sending rules. Second, channel choice is a compliance lever. Where email is restricted, a call to a published business line or a LinkedIn outreach touch may sit on firmer ground. HubSpot's GDPR resource hub is a decent plain-English starting point for how a large vendor handles this.
What does compliant data sourcing look like in practice?#
Compliance is mostly upstream. Once a bad record reaches your sequencer, you have already lost the argument. A defensible pipeline looks like this:
Source from providers who disclose provenance. You need to answer "where did this come from?" in one sentence. If your vendor cannot tell you, you cannot tell a regulator. A domain search or email finder workflow finds role-based business addresses from a company domain, so the origin is easy to describe.
Prefer business domains over free mail. A
@company.comaddress in a work context is much easier to justify than a personal@gmail.com. Filter free-mail domains out of outbound lists by default.Verify before you send. Bouncing into dead mailboxes hurts deliverability. It also signals stale data, which is an Article 5(1)(d) accuracy problem, not just a marketing one. Run lists through an email verifier and drop anything that does not come back clean.
Record the metadata for every contact. Source, capture date, lawful basis, country, suppression status. Five fields. If you cannot produce them on demand, your accountability story is fiction.
Delete what you don't use. Storage limitation is a real principle. A list you have not touched in 24 months is a liability, not an asset.
Re-run the LIA when targeting changes. A new vertical, a new country, or a new message type means a new assessment. Version them.
What are the most common mistakes teams make?#
Six failures show up again and again when teams lean on the GDPR lawful basis legitimate interest.
Claiming legitimate interest without writing anything down. This is the most frequent failure by a wide margin. Under accountability rules, an undocumented basis is no basis at all. A two-page LIA per campaign family takes an afternoon.
Confusing "publicly available" with "fair game". Someone who publishes their email on a conference page has not agreed to join a 50,000-contact sequence. Public availability is one input to the balancing test, not a substitute for it.
Ignoring Article 14. When you collect personal data from somewhere other than the individual, you owe them a privacy notice. It is due within one month, or at first contact if that comes sooner. Most teams satisfy this with a clear line and link in the first email. Most teams also forget it entirely.
Treating unsubscribes as marketing preferences. They are objections under Article 21(2). They apply across the whole organisation, not just the sequence they came from, and they last forever. Cross-tool suppression is a real engineering task.
Assuming an enrichment vendor's compliance transfers to you. It does not. They are a processor or a separate controller. You are the controller for your outreach. Their DPA reduces your risk, but it does not remove your duty.
Volume as strategy. Nothing sinks a balancing test faster than 100,000 sends into a market you do not operate in. Tight targeting is better for reply rates. It is also the evidence that your interest was legitimate.
Legitimate interest vs consent: which should you choose?#
| Question | Choose legitimate interest | Choose consent |
|---|---|---|
| Contact has never engaged with you | Yes | Not possible |
| Contact filled in a form or attended your webinar | Possible, but consent is cleaner | Yes |
| Target market includes Germany, Italy, Spain | Risky for email | Yes, or switch channel |
| You want to send newsletters or product blasts | Weak fit | Yes |
| You want to run 1:1 role-relevant outbound | Strong fit | Overkill and unobtainable |
| You need the ability to keep contacting after objection | Never — objection is absolute | Never — withdrawal is absolute |
The honest summary: use the GDPR lawful basis legitimate interest for targeted, role-relevant, low-volume outbound in permissive markets. Use consent for anything that looks like broadcast marketing. Where both are open to you, consent is the stronger position. It just costs you reach.
How do you run this without slowing the team down?#
Build the GDPR lawful basis legitimate interest into your tooling once. That beats relying on rep discipline forever.
Add a lawful basis field and a source field to every contact record in your CRM, filled in automatically at import.
Gate sequences on country rules: block email sends to DE/IT/ES contacts unless a consent flag exists.
Put the Article 14 notice line into your email template footer so it cannot be left out.
Wire your unsubscribe endpoint to a central suppression table that every tool reads before send.
Schedule a quarterly list hygiene job: re-verify, purge stale records, re-run LIAs. A bulk verify pass across your database costs less than one complaint investigation.
Keep your LIAs in the same repo or drive as your DPAs, versioned and dated.
None of this is glamorous. All of it is the difference between "we rely on legitimate interest" being a defensible statement and a hopeful one.
Where to start#
The GDPR lawful basis legitimate interest works for B2B outbound when three things are true. Your targeting is genuinely relevant. Your data provenance is explainable. Your paperwork exists before the first send. Get those right and the basis holds up. Get sloppy on one of them and you are relying on nobody complaining, which is a strategy, but not a compliant one.
The upstream half is a tooling problem you can solve today. Tomba's Email Finder surfaces role-relevant business addresses from a company domain, with a sourcing trail you can point to. Every record you push into a sequence has an origin you can name and a business context you can justify. Start on the free tier (25 searches a month). Check Tomba pricing when you are ready to scale — Starter runs $49/mo, Growth $99/mo, and Pro $249/mo. Build the compliant list first. The rest of the assessment gets much easier to write.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author