All guides
DACH & Compliance 6 min read

GDPR in B2B Sales: The Practical Guide

A GDPR guide for B2B sales — what's allowed, what isn't, and how to implement cold email, CRM data, and enrichment in a data-protection-compliant way.

CT
CegTec Team
9 April 2026

GDPR and B2B: what you really need to know

GDPR is not a ban on B2B sales. It’s a set of rules for the responsible handling of personal data. The short version:

Allowed: using business contact data for B2B sales when a legitimate interest exists.

Prohibited: processing private data without consent, ignoring opt-outs, hoarding data without a purpose.

GDPR only permits data processing under one of the 6 legal bases in Art. 6(1):

Legal basisRelevant for B2B sales?
a) ConsentOnly for newsletters, marketing emails to existing customers
b) Contract performanceOnly for existing customers
c) Legal obligationNot relevant
d) Vital interestsNot relevant
e) Public interestNot relevant
f) Legitimate interestThe legal basis for B2B cold outreach

Legitimate interest: the three-step test

  1. Does a legitimate interest exist? → Yes: new customer acquisition is a recognized legitimate interest (Recital 47 GDPR explicitly names direct marketing).

  2. Is the processing necessary? → Yes: to contact potential customers, you have to process their business data.

  3. Do the data subject’s interests override it? → Balancing test: business contact data in a professional context = a lower level of protection than private data. If your offer fits the recipient’s line of business and you act appropriately: no, their interests don’t override yours.

GDPR checklist for B2B sales

When collecting data

  • Business data only: business email, company phone, professional LinkedIn profile
  • Data minimization: only collect what you actually need (name, email, company, job title — not date of birth or hobbies)
  • Document the source: where does the data come from? (LinkedIn, Apollo, Clay, website, event)
  • Document the legal basis: legitimate interest + balancing-of-interests test

When making contact

  • Privacy notice: a link to your privacy policy in the email signature
  • Opt-out option: an unsubscribe link or notice in every email
  • Identification: sender name, company, and contact data clearly recognizable
  • Factual connection: your offer fits the recipient’s line of business

In the CRM

  • Record of processing: cold outreach documented as a processing activity
  • Maintain a suppression list: never contact again anyone who has objected
  • Deletion periods: automatic reminder for contacts with no interaction after 6-12 months
  • Access restriction: only authorized employees have access

Concrete everyday scenarios

Scenario 1: Clay enrichment for outreach

Question: Am I allowed to use data from Clay (Apollo, Cognism, Hunter) for cold emails?

Answer: Yes, if:

  • You only enrich business contact data
  • Legitimate interest exists (factual connection)
  • You name the data sources in your record of processing activities
  • Recipients can unsubscribe
  • Verified emails = fewer bounces = lower data-protection risk

Scenario 2: Using LinkedIn profile data

Question: Am I allowed to use data from LinkedIn profiles for cold outreach?

Answer: Conditionally. LinkedIn profile data is publicly accessible — but that alone isn’t a GDPR legal basis. You need legitimate interest and must inform the person. In practice: if you use the LinkedIn URL as an enrichment anchor and then find a business email, that’s defensible.

Scenario 3: Transferring CRM data to an outreach tool

Question: Am I allowed to export HubSpot contacts to Instantly or Lemlist?

Answer: Yes, if:

  • Both tools are listed in your record of processing activities
  • A data processing agreement (DPA) exists with both providers (HubSpot and Instantly offer DPAs)
  • The data is processed in the EU/EEA or in a country with an adequacy decision (or standard contractual clauses are in place)
  • The purpose of use stays the same

Scenario 4: A contact says “delete my data”

Question: What do I have to do?

Action:

  1. Delete the data from the CRM (or anonymize it)
  2. Delete the data from the outreach tool
  3. Add the email address to an internal suppression list (so you don’t contact them again)
  4. Send confirmation to the person: “Your data has been deleted”
  5. Deadline: without undue delay, a maximum of 1 month

Tool-specific GDPR notes

ToolDPA available?Server locationNote
HubSpotYesEU (Frankfurt) possibleEnable GDPR features in settings
ClayYesUSA (SCCs)Only enrich business data
Apollo.ioYesUSA (SCCs)Maintain a do-not-email list
InstantlyYesUSA (SCCs)Automatic unsubscribe link
CognismYesEUGDPR-by-design, strongest EU focus
n8n (self-hosted)N/AYour serverFull control, no DPA needed
n8n (Cloud)YesEU (Germany)GDPR-compliant

Documentation: what you need to have ready

1. Record of processing activities (Art. 30 GDPR)

Document for your B2B sales activities:

FieldExample
Processing activityB2B cold outreach (email + LinkedIn)
Controller[Your company]
PurposeNew customer acquisition in the B2B segment
Legal basisArt. 6(1)(f) GDPR (legitimate interest)
Data subjectsBusiness contacts at target companies
Data categoriesName, business email, job title, company, LinkedIn URL
RecipientsHubSpot (CRM), Instantly (email), Clay (enrichment)
Deletion period12 months after the last interaction with no business relationship
TOMsAccess restriction, encryption, DPAs with all processors

2. Balancing-of-interests test

Record in writing why the legitimate interest in B2B outreach overrides the data subject’s interest:

  • Your interest: new customer acquisition
  • The data subject’s interest: not being contacted unwantedly
  • Balancing test: business data, relevant offer, opt-out available at any time → the controller’s interest overrides

3. Privacy policy

Your website’s privacy policy must include a section on cold outreach/direct marketing — link to it from the email.

GDPRB2B ComplianceData ProtectionCold EmailCRMSales

Common questions

Does GDPR also apply to B2B contact data?

Yes. GDPR protects the personal data of natural persons — regardless of whether it's processed in a B2B context. The name, email, and phone number of a managing director or sales lead are personal data. Exception: purely corporate data with no personal reference (e.g. company revenue, industry) doesn't fall under GDPR.

Which legal basis applies to B2B cold outreach?

Art. 6(1)(f) GDPR — legitimate interest. Your legitimate interest: new customer acquisition. Precondition: the interests of the data subject do not override it. In practice that means: business contact data, a factual connection, a reasonable frequency, an opt-out option.

Do I have to include a privacy notice with B2B cold emails?

Yes. Under Art. 13/14 GDPR, you must inform the data subject on first contact: who you are, why you're processing the data, and what rights exist (access, deletion, objection). In practice: a link to your privacy policy in the email signature is enough — a multi-page disclaimer in the email itself isn't necessary.

How long am I allowed to store B2B contact data?

GDPR doesn't specify a fixed period. The principle of storage limitation applies: as long as necessary for the processing purpose. Recommendation: contacts who haven't responded after 6 months → check whether legitimate interest still exists. Contacts who have explicitly objected → delete immediately (email) or add to a suppression list.

Playbooks für B2B Outbound freischalten

Kostenlos. E-Mail eintragen → Passwort erhalten → Playbooks lesen.