GDPR for email outreach
The GDPR (General Data Protection Regulation) is the EU/UK data-protection law that governs how you process personal data, including email addresses, of people in those regions. For cold B2B outreach it generally requires a lawful basis — most commonly legitimate interest — plus transparency, an easy opt-out, and honoring data-subject rights like access and erasure.
How it works
You must identify a lawful basis before processing someone's data. Legitimate interest can support relevant B2B outreach if you document a balancing test, contact people in their professional capacity, are transparent about where you got their data, and provide a simple way to opt out and be forgotten.
Why it matters
GDPR is stricter than U.S. CAN-SPAM and carries large fines (up to the greater of tens of millions of euros or a percentage of global turnover). Emailing EU/UK contacts without a lawful basis and proper opt-out handling is a real legal and financial risk, not a formality.
What goes into a legitimate interest assessment for cold email?
A legitimate interest assessment is usually written as three questions. The purpose test asks what interest you are pursuing, for example offering scheduling software to operations managers. The necessity test asks whether emailing this person is a reasonable way to pursue it, or whether a less intrusive route exists. The balancing test asks whether the person would reasonably expect the contact and whether their interests override yours.
Write the answers down per campaign, not once for the whole company. A tight ideal customer profile strengthens the balancing test, because a head of finance receiving an offer about invoice automation is more expected than a random employee receiving the same message. This is general information; data protection counsel should review your assessment.
What must you tell a prospect whose data you did not collect from them?
Article 14 covers data obtained from a source other than the person. It generally requires telling them who you are, why you process their data, the lawful basis, the categories of data, where it came from, how long you keep it and what rights they have. When you use the data to contact them, that information is due at the latest at the first communication, and in any case within one month of obtaining it.
In practice many teams add a short line to the first email naming the data source and linking to a privacy notice that holds the full detail. Keep the first message readable; the notice can carry the length.
How should objections and erasure requests be handled?
The right to object to direct marketing is absolute under Article 21. Once someone objects, you must stop processing their data for that purpose, with no balancing test. An erasure request under Article 17 asks you to delete their data, but a minimal suppression entry is commonly kept so the person is not re-imported from the next vendor list. Access requests generally need a response within one month.
A hypothetical: a team imports 3,000 EU contacts, and 60 object in the first week. Each of those 60 must be suppressed across every channel and every list, including lists a colleague uploads later. The do-not-contact list entry is how that holds over time.
What do fines look like, and where do national rules differ?
The upper tier of GDPR fines reaches EUR 20 million or 4% of worldwide annual turnover, whichever is higher. National electronic marketing rules sit alongside GDPR and can be stricter. In the UK, PECR treats corporate subscribers differently from individuals, and sole traders and some partnerships are treated like individuals. Some EU member states apply consent requirements to B2B email more broadly. Autocloz keeps suppression and consent records in one engine across channels; for the product's security posture see the security page, and compare U.S. rules in the CAN-SPAM entry.
How Autocloz handles it
Autocloz keeps an auditable consent and suppression record and honors opt-outs and erasure requests across every channel from one suppression engine, so the opt-out and data-subject-rights obligations are enforced consistently rather than tracked by hand.
FAQ
Can I send cold email to EU contacts under GDPR?
Often yes, on a legitimate-interest basis for relevant B2B outreach — but you must document the basis, contact people in their professional role, be transparent about your data source, and offer an easy opt-out. Some member states (and PECR in the UK) add stricter rules.
What is the difference between GDPR and CAN-SPAM?
CAN-SPAM (U.S.) allows unsolicited commercial email with honest headers and a working opt-out. GDPR (EU/UK) regulates personal-data processing more strictly, requiring a lawful basis, transparency and data-subject rights — a higher bar than CAN-SPAM.
Related terms
Cold email deliverability is the share of your outbound cold emails that actually reach the recipient's inbox (not spam, not blocked). It depends on domain authentication (SPF, DKIM, DMARC), sender reputation, mailbox warmup, list hygiene and content — not just whether the email was 'sent'.
DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email standard that tells receiving mail servers what to do with messages that fail SPF or DKIM checks — and sends you reports. It prevents spoofing of your domain and is now effectively required by Gmail and Yahoo for bulk senders.
SPF (Sender Policy Framework) is an email-authentication standard that lets a domain owner publish, in DNS, the list of mail servers allowed to send email on the domain's behalf. Receiving servers check the sending IP against that list to help detect spoofing and decide whether to trust the message.
DKIM (DomainKeys Identified Mail) is an email-authentication method that attaches a cryptographic signature to each message. The receiving server verifies the signature against a public key in the sender's DNS, proving the message wasn't altered in transit and genuinely came from the signing domain.