GDPR Lead Generation in 2026: Rules, Risks, and What Works
GDPR does not ban cold outreach in the EU — it bans sloppy outreach. Here is what legitimate interest actually allows, which fields you can enrich, and how to build a B2B list that survives an audit.

GDPR lead generation is not banned in Europe. Sloppy outreach is. Here is the lawful basis you need, the data you can keep, and the records that hold up in an audit.
TL;DR
- GDPR does not ban B2B cold email. It bans processing personal data with no lawful basis. For most outbound teams, that basis is legitimate interest, not consent.
- The trap is not the first email. It is the paperwork: no source logged, no Legitimate Interest Assessment (LIA), no opt-out honored, no retention limit.
- Country-level ePrivacy rules override the "B2B is easier" assumption. Germany and Italy are strict. The UK, Netherlands, and Ireland are workable for corporate addresses.
- Role-based addresses (
info@,sales@) are usually not personal data. Named addresses (jana.kovac@) always are, even at work. - The fix is a documented sourcing chain. Enrich from public sources, store where each record came from, verify before send, and delete on request within 30 days.
GDPR lead generation: what does the law actually say?#
GDPR covers personal data — anything that identifies a living person. A work email like jana.kovac@acme.de identifies Jana. It does not matter that Acme pays for the mailbox. Once that address lands in your CRM, you are a data controller with six duties attached.
The law never says "do not send cold email." It says you need one of six lawful bases in Article 6 before you process data. For outbound B2B, only two are realistic:
- Consent (6.1.a) — freely given, specific, informed, and clear. Someone filled in a form and ticked a box that was not pre-ticked. It is the gold standard. It is also useless for cold prospecting, because you cannot ask someone you have never contacted.
- Legitimate interest (6.1.f) — you have a real business reason, the contact is needed for it, and the person's rights do not outweigh it. Nearly all compliant EU outbound runs on this basis. Recital 47 names direct marketing as one example.
The other four bases (contract, legal obligation, vital interests, public task) do not apply to prospecting.
Here is what trips teams up. Article 6 is necessary, but it is not enough. You also owe Articles 13 and 14 (tell people where you got their data), Article 15 (subject access), Article 17 (erasure), and Article 30 (records of processing). On top of GDPR sits the ePrivacy Directive. Each member state writes it into local law in its own way, and it governs the channel: email, phone, SMS.
Is legitimate interest enough for cold email in the EU?#
Usually yes for B2B, if you can show your work. That means a written Legitimate Interest Assessment. It is a three-part test, and you file it once per campaign type, not per contact.
| LIA stage | Question you must answer | What passes | What fails |
|---|---|---|---|
| Purpose test | Is there a real business interest? | "We sell logistics software to supply-chain directors" | "We email everyone and see who bites" |
| Necessity test | Is contacting this person needed to achieve it? | Targeted role + industry + company size | A 200,000-row list bought from a broker |
| Balancing test | Would the person reasonably expect this? | Work address, work-relevant offer, easy opt-out | Personal Gmail, unrelated product, no unsubscribe |
| Documentation | Can you produce it in an audit? | Dated PDF, owner named, reviewed annually | Nothing written down |
The balancing test is where most lists die. A supply-chain director at a freight company expects vendor email about freight software. That same person does not expect a crypto pitch at a personal address. Relevance is a legal argument, not just a way to lift replies.
The UK ICO's direct marketing guidance is the clearest free reference on this. Post-Brexit UK GDPR stays close to EU GDPR, so the reasoning carries over.
Which EU countries make B2B outbound hardest?#
ePrivacy is where the "GDPR is one law" idea falls apart. Same regulation, eleven readings.
| Country | B2B cold email to named work address | Opt-out required | Practical difficulty |
|---|---|---|---|
| United Kingdom | Allowed for corporate bodies (Ltd, PLC) | Yes | Low |
| Ireland | Allowed for corporate subscribers | Yes | Low |
| Netherlands | Allowed with clear opt-out | Yes | Low |
| France | Allowed if offer relates to the person's job | Yes | Medium |
| Spain | Allowed with prior-relationship or job relevance | Yes | Medium |
| Italy | Consent generally required | Yes | High |
| Germany | Consent required in practice (UWG §7) | Yes | High |
| Austria | Consent required for unsolicited email | Yes | High |
Two things follow. First, split your EU list by country before you send, not after a complaint. Second, in Germany, Austria, and Italy, switch channels. Use LinkedIn, events, inbound, or phone where the local rules allow it. Do not assume legitimate interest carries you. German competition law (UWG) even lets competitors sue over unsolicited email, which moves faster and hurts more than a data protection authority.
Sole traders and partnerships count as individuals in most of these countries, not as corporate subscribers. So hello@jana-kovac-consulting.de gets the strict rules, even though it looks like a business.
What data can you legally collect and enrich?#
Data minimisation (Article 5.1.c) means you collect what the job needs and nothing more. In practice, that draws a clean line.
Defensible to collect and store:
- Work email address — the contact route itself, and necessary for the purpose.
- Full name and job title — needed to show the offer fits the person's job in your LIA.
- Employer, industry, headcount, and country — the criteria that justify targeting this person at all.
- Company phone or direct dial — fine if your LIA covers calls and you screen national do-not-call lists.
- Source and collection date per record — not optional. Article 14 says you must disclose the source when the data did not come from the person.
Hard to defend:
- Personal email or personal mobile — almost never needed for B2B. The balancing test tips against you at once.
- Inferred personal traits — age, gender, ethnicity, religion, health. This is special category data under Article 9, and it needs explicit consent.
- Behavioural tracking with no notice — pixel-level email tracking is under growing challenge. Some DPAs treat open tracking as needing consent.
- Bulk scraped social profiles — the Clearview and Meta rulings settled it. "Publicly available" is not a lawful basis on its own.
The source field is the one teams skip and later regret. When a prospect asks "where did you get my address?", you have one month to give a specific answer. "A data provider" will not close the complaint. "Your address was published on acme.de/team on 12 March 2026" will.
That is why where a vendor gets data matters more than raw database size. A provider that shows per-record sourcing hands you an Article 14 answer. A provider selling an opaque 400-million-contact dump hands you a liability.
How do you build a GDPR lead generation list you can defend?#
Six steps, in order. Skip one and you get volume with no defence.
First, build the list:
- Define the ICP narrowly. Write down the job titles, industries, and company sizes your offer truly serves. This document is your necessity test.
- Source from public or licensed records. Company sites, published team pages, professional directories, and licensed B2B databases with a documented source. Not scraped personal profiles.
- Enrich only the fields in your ICP. Use a domain search to pull the addresses that exist at a target company. Then filter to the roles you named in step 1.
Then send and maintain it:
- Verify before you send. Bounces hurt deliverability. Dead mailboxes also mean you are storing data you should have deleted. An email verifier pass fixes both.
- Segment by country and apply the strictest local rule. Route Germany, Austria, and Italy to a non-email channel or a consent-first flow.
- Set a retention clock. No engagement after 12 months? Delete. Write the interval into your records of processing, and actually run the job.
Step five is a list-hygiene problem before it is a legal one. A clean, tightly segmented 800-contact list beats an unverified 40,000-row purchase on reply rate and on audit survival. The bulk verify workflow exists so that the compliance pass and the deliverability pass are the same pass.
What does a compliant cold email actually look like?#
Four elements. All are required, and none of them cost you conversion:
- Real sender identity. Put your legal entity name and a physical postal address in the footer. ePrivacy requires it, and so does CAN-SPAM if you also mail the US.
- Source disclosure. One line: "I found your details on your company's team page." That covers Article 14 at first contact. It also tends to lift replies, because it reads as human rather than automated.
- A working one-click opt-out. Not a "reply STOP" line buried in a signature. A link that works and is processed within 72 hours.
- A job-relevant offer. The balancing test turns on what the person would expect. If the offer would confuse them, you have failed the test and probably the campaign.
What you must not do: hide the sender, use a misleading subject line, mail someone after they opt out, or keep sending to a hard-bounced address. The first three break ePrivacy. The fourth is a data quality failure that turns into a compliance failure when the mailbox is reassigned.
When someone opts out, move them to a suppression list. Do not delete the record. You need the minimum data, usually a hashed email, to prove you are honoring the objection. Delete it all and you re-import them next quarter, which is the real violation.
Which tools help versus which create liability?#
Not all lead-gen tooling handles EU data the same way. The differences that matter for compliance are narrow and specific.
| Capability | Why it matters for GDPR | What to require |
|---|---|---|
| Per-record source attribution | Article 14 disclosure and complaint response | Source URL or method visible per contact, exportable |
| Deletion / suppression API | Article 17 requests within 30 days | Programmatic delete, not a support ticket |
| EU data processing option | Chapter V transfer rules | Documented SCCs or EU-hosted processing |
| Verification before delivery | Minimisation — do not store dead data | Real-time SMTP validation, catch-all handling |
| DPA available on standard plans | Article 28 processor requirement | Signable DPA without enterprise negotiation |
| Role-address filtering | Separates personal from non-personal data | Toggle to return only generic addresses |
Watch two vendor types. Chrome-extension scrapers harvest whole LinkedIn result sets. They copy personal data in bulk with no source record and no lawful basis you can inherit, and their terms usually push the liability to you. Waterfall enrichment aggregators chain five providers together, so you end up with five source chains you cannot document.
Cleaner options exist across the market. BookYourData sells verified B2B contacts with an accuracy guarantee and clear opt-out handling. That suits teams who want a purchased list with support behind it. Tomba pricing starts free at 25 searches a month, then $49/mo Starter, $99/mo Growth, and $249/mo Pro. Records come with source attribution, and the Tomba API has a delete endpoint for automating erasure requests. Compare vendors on G2 using the six criteria above, not database size.
What happens if you get it wrong?#
Article 83 caps fines at €20 million or 4% of global annual turnover, whichever is higher. That number gets quoted a lot. It almost never applies to a mid-market outbound team. The real exposure is smaller and more annoying:
- A DPA information request. You get a deadline to produce your LIA, records of processing, and sourcing evidence. If you have nothing, the inquiry widens.
- Individual complaints. One irritated recipient in Germany can trigger a competitor lawsuit under UWG or a DPA inquiry. The cost is legal hours, not headline fines.
- Domain and IP reputation damage. Spam complaints from EU recipients hurt sender reputation for good. That costs more revenue than any fine you are likely to face.
- Procurement blocking. Enterprise buyers now ask how you obtained their contact details during security review. "We bought a list" ends deals.
The right response is not to drop EU outbound. Spend one afternoon writing an LIA. Spend one hour setting retention rules. Then source data from providers that can tell you where each record came from.
How should you get started this quarter?#
Build the paperwork before you build the list. GDPR lead generation gets safe the moment the file exists: write the LIA, name an owner, set your retention interval, and record the sourcing method for every provider you use. That is half a day of work. It turns your outbound program from "hope nobody asks" into "here is the file."
Then keep the list small and correct. Target job titles you can defend. Use an email finder that returns the source alongside the address. Verify every record before it enters a sequence. And take Germany, Austria, and Italy out of the email channel.
Ready to build an EU list you can actually defend? Start with the Tomba Email Finder. The free tier gives you 25 searches a month, enough to test source attribution and verification quality on your own ICP before you pay. Find the right person, know where the data came from, and keep the record clean. Then a subject access request is a five-minute reply instead of a fire drill.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author