Cold B2B email can be lawful under GDPR, but only if you choose and document a lawful basis, usually legitimate interest, and can show where you sourced each address. That’s the real bar regulators care about. Skip the documentation and even a well-written email becomes a liability. Get it right, and outbound stays a legitimate growth channel, not a legal gamble.
TL;DR:
- Legitimate interest requires a documented purpose, necessity check, assessment of recipient expectations and proportionality, and safeguards such as easy opt outs.
- Consent is safer or required for consumer outreach, behavioral profiling, or special category data; role relevant B2B campaigns can often use legitimate interest.
- Log each address’s source URL, collection date, evidence of public availability, and verifier ID alongside the balancing test; delete records when campaign needs end.
- U.S. law permits cold outreach without prior consent but requires honest subjects, accurate sender details, and working opt outs; apply GDPR when both frameworks apply.
- Authenticate sending domains with SPF, DKIM, and DMARC, use a clear sender address, and remove bounced or compromised addresses from campaign lists.
These two frameworks solve different problems, and mixing them up is where most teams trip. CAN-SPAM, the US rule, does not require prior consent for cold outreach. It cares about honesty and an exit ramp. GDPR cares about why you’re processing someone’s data in the first place, and whether you can prove it.
That last point matters more as teams scale internationally. You don’t get to pick the easier framework just because your company is based somewhere else. The recipient’s rights travel with them.
Work email addresses count as personal data under GDPR, even the generic-looking ones like firstname.lastname@company.com. That surprises people, but it’s the baseline you’re working from. Legitimate interest is the lawful basis most B2B teams lean on for cold outreach, and it holds up when you can defend it with a real balancing test, not a checkbox.
Consent becomes the safer or required basis when you’re emailing individual consumers, doing behavioral profiling, or touching special categories of data. For B2B lists built on role relevance, legitimate interest tends to hold.
Pro Tip: Write your balancing-test justification before you send the first email, not after a complaint lands.
What you record is what defends you later: the purpose statement, the necessity check, and a short note on why the recipient’s role makes the outreach reasonable.
This is the part teams actually use. Treat it as a working list, not a one-time audit.
Pro Tip: Store your sourcing log and legitimate-interest note in the same CRM record as the contact, not in a separate spreadsheet nobody checks.
Sourcing provenance is the piece most teams skip, and it’s the one regulators ask about first. A verifier ID and a timestamp on when you confirmed the address was public takes thirty seconds to log and saves you a scramble later. Combine that with segmentation frameworks that prioritize high-relevance targets, and your balancing test gets a lot easier to defend because the list itself proves proportionality.

A few beliefs keep circulating, and they’re costing people real risk exposure.
Compliance and deliverability run on the same rails. Authenticating your sending domain with SPF, DKIM, and DMARC meets sender-identification expectations and keeps your messages out of spam folders.
Three short logs cover most of what an audit asks for.
During an outbound audit, we pull these three records first because they answer the only question that matters: can you prove the basis for this email. Teams that already have a structured messaging hierarchy tend to have cleaner legitimate-interest notes too, since relevance and compliance documentation feed off the same targeting logic.
We’ve watched teams choose volume over documentation, and it never holds up once a complaint lands. The smarter move is a smaller, better-targeted list with a paper trail behind every send. Defensible recordkeeping isn’t a slowdown. It’s what lets you run outbound at scale without flinching when someone asks you to prove it.
— Antony
Building a documented, scalable outbound engine takes more than a checklist, it takes a system that ties your sourcing, messaging, and governance together. We help B2B tech companies design that system through a Sales Workflow Audit that reviews your current outbound process against exactly the gaps covered above, plus a Revenue System Diagnostics engagement if you need the full picture before you rebuild.

| Service | What it covers |
|---|---|
| Sales Workflow Audit | Reviews sourcing, messaging, and recordkeeping gaps in current outbound |
| Revenue System Diagnostics | Maps where compliance risk sits inside your broader revenue process |
| AI-Enhanced Revenue Architecture | Builds documentation and targeting logic into your outbound tooling |
If you want a compliance-aware look at your outbound system, request an audit through our services page and we’ll start with where your current process is exposed.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
This isn’t a recognized GDPR or CAN-SPAM standard, so definitions vary depending on who’s using the term. Some marketers apply it to list quality, subject-line testing, or send-time splits, but there’s no official compliance meaning behind it. For legal purposes, focus on lawful basis and sourcing documentation instead.
Under GDPR, an email address tied to an identifiable person counts as personal data, including most work addresses. You need a lawful basis, commonly legitimate interest for B2B outreach, along with a documented balancing test and a way to honor data subject rights like access or deletion requests.
In the US, CAN-SPAM requires accurate sender information, honest subject lines, and a working opt-out, without requiring prior consent. Under GDPR, you need a documented lawful basis and respect for data subject rights, and when both frameworks could apply, applying the stricter GDPR obligations is the safer path.
Cold emails aren’t illegal on their own under either CAN-SPAM or GDPR. They become a legal problem when you can’t show a documented lawful basis, when you ignore opt-out requests, or when your sender information is deceptive.
Subscribe to our Insights: Expert productivity tips in your inbox
You'll receive 1-3 emails per month. Your data stays private, always.
Watch our Sales Mates Podcast
October 10, 2026 - 8 min read
Read article Read articleOctober 8, 2026 - 10 min read
Read article Read articleOctober 7, 2026 - 11 min read
Read article Read articleOctober 6, 2026 - 8 min read
Read article Read article