Blog / Compliance / No.002

GDPR and B2B outreach: consent or legitimate interest

Two bad answers dominate this question. One says GDPR banned cold outreach in 2018, the other says business contact is exempt. The real position sits between them and is legible if you read the instruments in order.

Mohamad · KnockwireMay 5, 20269 min readCompliance

There are two standard answers to whether you may contact a business in Europe without asking first, and both are wrong. The first says GDPR banned cold outreach in 2018. The second says business-to-business contact is carved out, so send what you like. The real position sits between them, it is legible if you read the instruments in the right order, and legitimate interest is the hinge it turns on. What follows is our working understanding, written down because we build product decisions on it.

01What GDPR governs, and what it does not

GDPR governs personal data: information relating to an identified or identifiable living person. Recital 14 says so directly, and excludes data about legal persons. A company is not a natural person, and is not protected by GDPR simply for existing.

So a generic company address carries a weaker personal-data claim than a named individual work address. Compare the two:

  • A contact form with no named recipient, or a role address such as info@ or sales@ at a company of a hundred people, identifies an organisation and a function. There is no particular person on the other end, and often no stable one.
  • [email protected] is personal data. It identifies one individual, it is theirs, and using it for work changes nothing. Both the ICO and the EDPB treat work contact details of an identifiable person as in scope.

Weaker is not none, and this is where people overreach. A role address can still identify a person: info@ at a two-person consultancy is one named human, and several regulators analyse it that way. And if you researched somebody or personalised on anything about them, you processed personal data to produce the message even when the destination is generic. The envelope does not decide the analysis. The processing does.

Publication matters too, but less than people hope. A company that publishes a contact page has invited contact by that route, which is a real input to the reasonable expectations test below. It is not consent, and treating it as consent is the most common mistake here. A Door, in our vocabulary, is a public contact route, and we prefer forms with no named recipient. We do not guess individual work addresses from a naming pattern: common practice, ruled out rather than deferred.

02Legitimate interest is a lawful basis, not a slogan

Article 6(1)(f) makes legitimate interest a lawful basis, and Recital 47 says direct marketing may be regarded as carried out for one. That recital is quoted constantly and almost always misread. It says may be regarded: permission to run the test, not the result. Legitimate interest for B2B marketing is real and conditional, and the condition is a documented assessment rather than an assertion.

It has three parts, and all three have to hold:

  • Purpose. Is there a real, specific, present interest? "Growing the business" fails, because it describes anything a company might do. "Contacting companies that publish a developer contact page and already run scraping infrastructure, about a scraping product" is specific enough to be argued about, which is what makes it a purpose.
  • Necessity. Is the processing actually needed for that purpose, and would something less intrusive get you there? If a published directory, an existing relationship, or an inbound channel would work, the balance does not rescue you. Necessity is a real constraint, not a box.
  • Balance. Weigh your interest against the rights, freedoms and reasonable expectations of the recipient. Relevance carries most of the weight. A message about a problem the recipient has written about publicly, sent to a channel they published, sits very differently from the same text sent to ten thousand addresses in the hope that a few land.

The word doing the work is documented. Write the assessment before the campaign, keep the version, and record what changed when the targeting did. If a regulator or a recipient asks, that document is the evidence. One produced after the complaint arrives is not an assessment, it is a defence, and it reads like one.

It also carries an obligation people skip. Article 14 covers data you did not get from the person themselves, and requires you to tell them what you hold, why, and where it came from, at the latest when you first make contact. So the first message has to say where the details came from. Most cold outreach never does.

03ePrivacy is the rule that actually bites

Here is the part that gets skipped, and the part that generates the enforcement. GDPR gives you a lawful basis for processing the data. The ePrivacy Directive governs the act of electronic marketing itself, a separate instrument with separate requirements, so you can satisfy Article 6(1)(f) in full and still be barred from sending.

Article 13 sets opt-in for unsolicited electronic marketing to natural persons. Article 13(5) then hands the position for legal persons to the member states, requiring only that their interests be sufficiently protected. That single deferral is why there is no European answer here, only twenty-seven national ones, and because a directive is transposed rather than applied directly, those implementations diverged permanently.

As we currently read them, and this map is reviewed rather than assumed:

  • Germany requires prior express consent for advertising by electronic mail under UWG §7, with no business carve-out. German courts have been consistent about it: an unsolicited advertising email to a company inbox is an unreasonable nuisance, and the recipient being a business does not help you.
  • Italy requires prior consent for electronic marketing under Article 130 of the Codice Privacy, and the Garante has applied it to business recipients.
  • Austria takes the same line under its telecommunications act. Consent first, and being a company does not change it.
  • France distinguishes B2B explicitly. The CNIL position is that contacting a professional at a professional address about their role needs no prior consent, provided they are informed at collection and can object.
  • Ireland, and much of the rest of the EU, treat corporate subscribers on an opt-out basis: send until they object, subject to the GDPR duties above.

So the question is not "is this GDPR-compliant", which is close to meaningless alone. It is "which national implementation applies to this recipient", decided by where the recipient sits, not where you sit. A campaign lawful into Dublin and unlawful into Munich is the normal case, not an edge case.

A suppression list that expires is not a suppression list. It is a cooling-off period you invented on the objector's behalf.

Knockwire excludes prior-consent jurisdictions by default. A Read from Germany, Austria or Italy is Turned down at the jurisdiction gate, the reason is written at the moment of the decision, and it appears in the refusal ledger where anyone can count it. The operator can switch a country back on, which is the point: doing so is a deliberate act with a named person attached, taken on their own legal advice. It is never the default and never happens quietly.

One honest note on scope. A submission through a company's own public contact form is not the classic Article 13 case, which aims at electronic mail and automated calling, and is generally analysed under GDPR and national unfair-competition rules instead. That is part of why we deliver that way. It is not a loophole and would not survive being used at volume. Email sending is not built: it is scheduled for Q4 2026, so the Article 13 and UWG §7 reading above is us working out rules before we need them, not describing what we do today.

04The UK position: PECR and the corporate subscriber

The UK kept PECR after Brexit, and PECR draws a line GDPR does not: individual subscribers versus corporate subscribers. Regulation 22, the consent rule for unsolicited marketing email, applies to individual subscribers. Limited companies, LLPs, Scottish partnerships and public bodies are corporate subscribers, and regulation 22 does not reach them. Marketing email to a limited company inbox needs no PECR consent. That much of the carve-out story is true.

The half that is untrue is the half that generates the fines. UK GDPR still applies to any personal data in or behind that message, so you need a lawful basis, you owe the Article 14 notice, and the right to object stands. Regulation 23 applies whatever the subscriber type: do not conceal who is sending, and give a valid address for opt-outs. "B2B is exempt" is a claim about one regulation, read as though it covered all of them.

There is a trap in the classification itself. Sole traders and, in England, Wales and Northern Ireland, unincorporated partnerships are individual subscribers under PECR, and from the outside they look exactly like small companies: a website, a brand, a team page, no incorporation. Companies House settles this, not the website. We do not attempt that classification automatically. A UK Read we cannot confidently place as incorporated is Turned down rather than guessed, and the recorded reason names the missing evidence.

05Objection, suppression, and what immediately means

Article 21 gives an absolute right to object to direct marketing, and absolute is the correct word. No balancing exercise, no assessment, no legitimate interest survives it. Somebody says stop, and you stop, permanently. The one thing you keep is the fact of the objection, because you need it to keep honouring it. That is the suppression list: the only place where "we kept your details because you told us to go away" is the right answer rather than an excuse.

Most implementations manage immediately and fail on permanently. A suppression list that holds up in practice has properties worth stating:

  • Tenant-wide rather than per campaign. An objection to one campaign is an objection, not feedback on that campaign.
  • Keyed on the domain as well as the address, so the objector leaving the company does not mean their successor receives the message that was refused.
  • Checked before the Draft is written, not before the Knock, so no human is ever asked to approve a message that could not lawfully go.
  • Permanent, with no expiry, no reactivation window, and no assumption that silence since then means the position has changed.
  • Durable against rediscovery. The source that surfaced them last quarter will surface them again, and the ledger should show the same refusal reason each time.

Test that last one in any tool you evaluate, ours included. If a suppressed company can re-enter as a fresh candidate under a slightly different name, suppression is a filter on sending, not on the process.

Not legal adviceThis describes the shape of the rules as we understand them and use them, not advice for your situation. National implementations differ, regulator positions move, and none of this accounts for how you collect data or what you intend to say. Have counsel confirm your own position before you send at any volume.

Knockwire reads the internet, throws out the companies that will never buy from you, and knocks on the doors of the ones that will. Run it on your own domain and read your own refusals.

Run it on my siteAll posts