GDPR and cold email: what's actually allowed
GDPR does not ban cold email outright, and it is not a US-only concern either. Here is what the regulation actually asks of B2B outbound — and what it does not permit.
2026-06-06 · 7 min read
On this page
A common misconception is that GDPR requires opt-in consent for every email, full stop. That is not quite right — but the bar for B2B cold outbound is still real, and getting it wrong has consequences.
Legitimate interest, not consent, is the usual basis for B2B outbound
GDPR recognizes several lawful bases for processing personal data. For unsolicited B2B outreach — reaching a business contact at their work address about something relevant to their role — "legitimate interest" (Article 6(1)(f)) is the basis most senders rely on, not consent. That is a real basis, not a loophole, but it comes with obligations: the interest has to be genuinely balanced against the recipient's rights, the outreach has to be relevant to their role, and — critically — they have to be able to object easily.
Where legitimate interest does not stretch
- Consumer / personal-address outreach is a different, harder case, and country-level ePrivacy rules (which vary by EU member state) often require opt-in consent for it regardless of GDPR's legitimate-interest basis.
- Purchased or scraped lists with no relevance to the recipient's role weaken the legitimate-interest balancing test badly.
- Continuing to email someone after they have objected is not a gray area under any basis — it is a violation.
The rights that actually come up in practice
- Access — a recipient can ask what data you hold about them.
- Erasure — a recipient can ask you to delete it.
- Objection — a recipient can object to being contacted at any time, and you must stop.
Of the three, objection is the one that has to work on every single send, not just on request — which is why a working suppression list is the practical backbone of GDPR-compliant outbound, not a nice-to-have.
Suppression is the objection-handling mechanism
A suppression list checked on every send, combined with a working RFC 8058 one-click unsubscribe on every message, is what turns "the right to object" from a policy statement into something that actually happens. The unsubscribe has to take effect before the next send goes out — not at the end of the day, not on the next campaign cycle.
Data residency and processors
Beyond the outreach itself, GDPR also governs where the underlying data lives and who processes it. If you are evaluating a cold-email vendor, ask where your data (and your recipients' data) is hosted and who the sub-processors are — details we publish at /legal/security and /legal/gdpr.
None of this replaces reading the regulation or talking to counsel for your specific case — see the disclaimer above. What it should do is make the shape of the requirement clear enough to ask your vendor (or yourself) the right questions.
Warmed pools, a reputation circuit-breaker, suppression on every send — per send, via API or MCP.