GDPR (General Data Protection Regulation)
GDPR (General Data Protection Regulation) is the European Union privacy law regulating collection, processing, and use of personal data — applying to any B2B marketing or sales operation engaging EU residents — requiring lawful basis for data processing, transparency, and individual rights including data access and deletion.
Why This Matters
GDPR fundamentally changed B2B data and outreach practices for any organization engaging EU residents. Key requirements: lawful basis for processing (consent, legitimate interest, or specific exemptions), transparent disclosure of data uses, data subject rights (access, correction, deletion, portability), data minimization (collect only what's necessary), and significant penalties (up to 4% of global revenue or €20M, whichever is higher). For B2B specifically: 'legitimate interest' typically supports cold outreach to business contacts in their professional capacity, but documentation of legitimate interest assessment and clear opt-out mechanisms remain mandatory.
Frequently Asked Questions
Frequently Asked Questions
Does GDPR allow B2B cold outreach to EU contacts?
Generally yes under 'legitimate interest' basis for B2B contacts in professional capacity (corporate email addresses). Requires documented legitimate interest assessment balancing business need against individual privacy. Personal email addresses (gmail, etc.) used for business require stricter consent-based approaches.
What's the penalty for GDPR violations?
Tier 1: up to €10M or 2% global revenue (lower-severity violations). Tier 2: up to €20M or 4% global revenue (higher-severity violations including unlawful processing). Major enforcement actions have produced fines exceeding €500M against largest tech companies.