All guides
DACH & Compliance 9 min read

B2B Addresses for Cold Outreach: Sourcing Them GDPR-Compliant

Sourcing B2B addresses for cold outreach in a GDPR- and UWG-compliant way: legal sources, legitimate interest, data minimization, and documentation.

CT
CegTec Team
21 June 2026

Cold outreach in the DACH region rarely fails because of the message — it fails because of the data foundation. Anyone sourcing B2B addresses for cold outreach operates between two frameworks: GDPR (may I process this data at all?) and UWG (may I contact this person unsolicited?). Both questions are answered differently, and that’s exactly where the expensive mistakes happen.

This article shows where to get B2B contact data in a GDPR-compliant way, which sources are safe, what you should never do, and how to document your approach so it holds up under scrutiny.

Important: This article is professional orientation and does not replace legal advice. For your specific case, consult a specialized law firm.

The most common thinking error is lumping sourcing and use together. They’re two separate checks.

Level 1 — May I process the data? (GDPR) As soon as you collect and store names, business email addresses, or phone numbers of natural persons, that’s processing of personal data. For pure B2B business data, legitimate interest under Art. 6(1)(f) GDPR is usually the legal basis in question. This requires a balancing of interests: your interest (e.g., acquiring new customers) against the protection interest of the data subject. For business contact data with a clear factual connection, this balance often falls in your favor — but it must actually be carried out and documented.

Level 2 — May I contact this person? (UWG) Even if you legitimately possess the data, Section 7 UWG governs first contact for advertising. For email advertising, the law generally requires the recipient’s prior express consent — even in B2B. For telephone advertising toward businesses (B2C is stricter), presumed consent suffices — that is, a factual reason to assume the call is relevant to the called party’s business.

In concrete terms: a cleanly researched address is the necessary, but not the sufficient, condition. Whether you’re allowed to send a cold email with it is a separate question. More in our guide on the legal status of B2B cold outreach by email and on whether B2B cold outreach is permitted at all.

Legitimate sources for B2B addresses

The safest strategy is always the one where you can prove the origin of every record at any time. The following sources meet that bar.

Source for B2B addressesLegally defensible?SuitabilityNote
Company legal notice / websiteYesHighPublicly published, origin clearly provable
Trade/commercial registerYesMediumOfficial, but rarely specific contact persons
LinkedIn / Xing (public profiles)Yes, with moderationHighOnly publicly visible data, observe platform ToS
Industry & trade-fair directoriesYesHighPublic, often with function/department
Own inbound leads (form, download)YesVery highOften with consent — best foundation
Data providers with source proofConditionalHighOnly if source + legal basis per record are documented
Purchased unvetted mass listsNoLowOrigin not provable, violates accountability obligation
Scraped data (scraping entire platforms)NoLowRegularly violates ToS and GDPR

Your own research from public sources

The backbone of clean address sourcing. Anyone who finds the responsible person in procurement or IT leadership on a target company’s website, and uses the business address given in the legal notice or on the team page, works with data whose origin is crystal clear. This research scales more slowly than buying a list — but every record is defensible.

Public profiles and directories

LinkedIn, Xing, chamber-of-commerce databases, industry portals, and trade-fair attendee lists come with function and responsibility attached. Important: use only publicly visible information, and respect the terms of use of the respective platform. Automated mass scraping of entire profile bases is delicate both under ToS and under data-protection law.

Providers — but only with source proof

Data providers aren’t forbidden per se. What matters is whether the provider discloses the origin and legal basis per record. Reputable European providers document this. Blanket offers of “2 million decision-maker addresses for €199” don’t — stay away.

We give a practical overview of sources and enrichment tools in our article on addresses for cold outreach.

What’s not allowed

Three practices reliably get you into trouble:

  1. Unvetted purchased lists. If you can’t prove where a record came from and on what basis it was collected, you’re violating the accountability obligation (Art. 5(2) GDPR). In a complaint, you’d have no proof. Add to that the miserable quality: high bounce rates ruin your domain reputation before a single reply comes in.

  2. Fully automated scraping of entire platforms. Systematically scraping complete profile or membership bases regularly violates platform ToS and isn’t covered by legitimate interest under data-protection law.

  3. Repurposing. Data collected for a different purpose (e.g., an applicant database or customer data from a completely different context) can’t simply be repurposed for cold outreach. The purpose of collection is binding.

A detailed breakdown of risks and fine amounts is in our guide to GDPR and cold email.

Data minimization: only collect what you need

GDPR requires data minimization (Art. 5(1)(c)) — you may only collect the data you actually need for the specific purpose.

For B2B first contact, that generally means:

  • Usable: first name, last name, function/role, company, business email address, possibly business phone number.
  • Usually unnecessary: private contact data, date of birth, information from social networks beyond the professional role, personal interests.

The less you store, the smaller your risk, and the simpler your balancing of interests. “We collect everything we can get” is the opposite of compliant.

Documentation: the part everyone forgets

The best research is useless if you can’t produce anything when it matters. So keep a record of:

  • Origin & timing: which source the record came from, when it was collected.
  • Legal basis: which basis you rely on for processing (usually legitimate interest).
  • Balancing of interests: a short, traceable justification for why your interest outweighs the person’s protection interest — a documented standard assessment per segment is usually enough.
  • Privacy notices: data subjects must learn that and how you process their data (information obligation, Art. 13/14 GDPR).
  • Opt-out / objection: every recipient must be able to easily object to processing — and the objection must be honored.
  • Deletion periods: data you no longer need should be deleted.

These points aren’t bureaucratic box-checking. They’re exactly what keeps you able to act in a complaint or a regulatory inquiry. Find the full framework in our B2B GDPR guide.

Special cases: functional mailboxes and sole proprietors

Two constellations regularly cause confusion.

Functional mailboxes like info@, sales@, or procurement@ aren’t directly tied to a natural person. The personal-data connection is weaker here, which tends to ease the GDPR assessment. But UWG still applies: advertising to a functional mailbox is still advertising and subject to Section 7 UWG requirements. A generic mailbox isn’t a free pass for unsolicited promotional emails.

Sole proprietors, freelancers, and partnerships are trickier than corporations. Here the line between business and private sphere blurs — a solo self-employed person’s business email is often also their personal one. The requirements for balancing interests and for a factual connection are correspondingly higher in these cases. When in doubt: assess more conservatively.

Practical workflow for clean address sourcing

A proven, defensible approach in five steps:

  1. Define the ICP sharply. The more precise your ideal-customer profile, the clearer the factual connection — the foundation of your balancing of interests. Anyone who targets “everyone” has none.
  2. Research from public sources. Website, legal notice, register, public profiles, industry directories. Note the origin.
  3. Store data minimally. Only the fields you need for outreach.
  4. Verify. Check business email addresses before sending — protects your reputation and shows careful processing.
  5. Document & set up opt-out. Record source, legal basis, privacy notice, and objection route per campaign.

Common mistakes and how to avoid them

The same pitfalls repeat in practice:

  • Buying lists instead of researching. Tempting because it’s fast — but without source proof and with poor quality, it’s a double risk. Rely on your own research or providers with transparent proof of origin.
  • Skipping the UWG level. Many diligently check GDPR and forget that sending itself follows its own rules. A lawfully stored address doesn’t automatically permit the promotional email.
  • No working opt-out. An objection route that isn’t implemented is worse than none — it documents that you knew the requirement and ignored it.
  • Keeping everything. Hoarding records only enlarges your attack surface. Define deletion periods and stick to them.
  • Mixing purposes. Repurposing data from other contexts is convenient but not legally covered. Keep collection purposes cleanly separated.

Anyone who avoids these five points is already ahead of a large part of the market — and builds a more resilient data foundation at the same time.

How we handle this at CegTec

At CegTec, GDPR-compliant address sourcing isn’t an afterthought, it’s part of the system. We source data exclusively from public sources and combine that with human approval before any message goes out — no fully automated sending to unvetted mass lists.

On this foundation, our own outbound has sent over 87,000 emails — consistently with data from public sources and a documented approach. We offer customers exactly this approach via our GTM Goat offering: GDPR-aware outbound from publicly sourced data with human-in-the-loop, transparently priced from €2,500/month.

If you want to know whether this pays off for your sales operation, talk to us.

Conclusion

GDPR-compliant address sourcing for cold outreach isn’t rocket science, but it requires discipline. Cleanly separate data processing (GDPR, usually legitimate interest) from first contact (UWG, often requiring consent). Source data from provable public sources, minimize what you store, and document origin, legal basis, and opt-out. Anyone who does that builds an outbound machine that doesn’t collapse at the first pushback — and delivers better results along the way thanks to better data quality.

This article is professional orientation and does not replace legal advice. For a legal assessment of your specific approach, consult a specialized law firm.

Start your free trial · 4 weeks free, no credit card. Prefer to see it running first? Book a demo.

B2B AddressesCold OutreachGDPRAddress SourcingCompliance

Common questions

Can I just source B2B addresses for cold outreach?

Sourcing business contact data from public sources (legal notice, company website, LinkedIn, industry directories) is in principle permitted under legitimate interest per Art. 6(1)(f) GDPR, provided there's a factual connection between your offer and the recipient. But sourcing is only one side — first contact by email or phone is additionally subject to Section 7 UWG, which generally requires consent for advertising. You must check both levels separately.

Are purchased B2B address lists allowed?

Blanket-purchased, unvetted mass lists are problematic. You typically can't prove the origin and legal basis of individual records, which violates the accountability obligation (Art. 5(2) GDPR). Data quality is also usually poor (high bounce rates). Only your own documented research from traceable public sources, or working with providers who transparently document source and legal basis per record, is legitimate.

Which sources for B2B addresses are legally safe?

The safest are self-researched, publicly accessible data: company legal notices, company websites, the trade/commercial register, LinkedIn profiles, industry and trade-fair directories. Here the origin is always provable. Your own inbound contacts (website forms, content downloads) are also clean, because consent is often already in place.

What do I need to document for B2B addresses?

Document per record or source: where the data came from, when it was collected, which legal basis you rely on (e.g. legitimate interest), and the result of a brief balancing of interests. Add to that your privacy notices, a working opt-out/objection option, and deletion periods. You need this proof to satisfy the accountability obligation.

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.