GDPR in B2B Sales: The Practical Guide
A GDPR guide for B2B sales — what's allowed, what isn't, and how to implement cold email, CRM data, and enrichment in a data-protection-compliant way.
GDPR and B2B: what you really need to know
GDPR is not a ban on B2B sales. It’s a set of rules for the responsible handling of personal data. The short version:
Allowed: using business contact data for B2B sales when a legitimate interest exists.
Prohibited: processing private data without consent, ignoring opt-outs, hoarding data without a purpose.
The 6 legal bases — and which one counts for B2B
GDPR only permits data processing under one of the 6 legal bases in Art. 6(1):
| Legal basis | Relevant for B2B sales? |
|---|---|
| a) Consent | Only for newsletters, marketing emails to existing customers |
| b) Contract performance | Only for existing customers |
| c) Legal obligation | Not relevant |
| d) Vital interests | Not relevant |
| e) Public interest | Not relevant |
| f) Legitimate interest | The legal basis for B2B cold outreach |
Legitimate interest: the three-step test
-
Does a legitimate interest exist? → Yes: new customer acquisition is a recognized legitimate interest (Recital 47 GDPR explicitly names direct marketing).
-
Is the processing necessary? → Yes: to contact potential customers, you have to process their business data.
-
Do the data subject’s interests override it? → Balancing test: business contact data in a professional context = a lower level of protection than private data. If your offer fits the recipient’s line of business and you act appropriately: no, their interests don’t override yours.
GDPR checklist for B2B sales
When collecting data
- Business data only: business email, company phone, professional LinkedIn profile
- Data minimization: only collect what you actually need (name, email, company, job title — not date of birth or hobbies)
- Document the source: where does the data come from? (LinkedIn, Apollo, Clay, website, event)
- Document the legal basis: legitimate interest + balancing-of-interests test
When making contact
- Privacy notice: a link to your privacy policy in the email signature
- Opt-out option: an unsubscribe link or notice in every email
- Identification: sender name, company, and contact data clearly recognizable
- Factual connection: your offer fits the recipient’s line of business
In the CRM
- Record of processing: cold outreach documented as a processing activity
- Maintain a suppression list: never contact again anyone who has objected
- Deletion periods: automatic reminder for contacts with no interaction after 6-12 months
- Access restriction: only authorized employees have access
Concrete everyday scenarios
Scenario 1: Clay enrichment for outreach
Question: Am I allowed to use data from Clay (Apollo, Cognism, Hunter) for cold emails?
Answer: Yes, if:
- You only enrich business contact data
- Legitimate interest exists (factual connection)
- You name the data sources in your record of processing activities
- Recipients can unsubscribe
- Verified emails = fewer bounces = lower data-protection risk
Scenario 2: Using LinkedIn profile data
Question: Am I allowed to use data from LinkedIn profiles for cold outreach?
Answer: Conditionally. LinkedIn profile data is publicly accessible — but that alone isn’t a GDPR legal basis. You need legitimate interest and must inform the person. In practice: if you use the LinkedIn URL as an enrichment anchor and then find a business email, that’s defensible.
Scenario 3: Transferring CRM data to an outreach tool
Question: Am I allowed to export HubSpot contacts to Instantly or Lemlist?
Answer: Yes, if:
- Both tools are listed in your record of processing activities
- A data processing agreement (DPA) exists with both providers (HubSpot and Instantly offer DPAs)
- The data is processed in the EU/EEA or in a country with an adequacy decision (or standard contractual clauses are in place)
- The purpose of use stays the same
Scenario 4: A contact says “delete my data”
Question: What do I have to do?
Action:
- Delete the data from the CRM (or anonymize it)
- Delete the data from the outreach tool
- Add the email address to an internal suppression list (so you don’t contact them again)
- Send confirmation to the person: “Your data has been deleted”
- Deadline: without undue delay, a maximum of 1 month
Tool-specific GDPR notes
| Tool | DPA available? | Server location | Note |
|---|---|---|---|
| HubSpot | Yes | EU (Frankfurt) possible | Enable GDPR features in settings |
| Clay | Yes | USA (SCCs) | Only enrich business data |
| Apollo.io | Yes | USA (SCCs) | Maintain a do-not-email list |
| Instantly | Yes | USA (SCCs) | Automatic unsubscribe link |
| Cognism | Yes | EU | GDPR-by-design, strongest EU focus |
| n8n (self-hosted) | N/A | Your server | Full control, no DPA needed |
| n8n (Cloud) | Yes | EU (Germany) | GDPR-compliant |
Documentation: what you need to have ready
1. Record of processing activities (Art. 30 GDPR)
Document for your B2B sales activities:
| Field | Example |
|---|---|
| Processing activity | B2B cold outreach (email + LinkedIn) |
| Controller | [Your company] |
| Purpose | New customer acquisition in the B2B segment |
| Legal basis | Art. 6(1)(f) GDPR (legitimate interest) |
| Data subjects | Business contacts at target companies |
| Data categories | Name, business email, job title, company, LinkedIn URL |
| Recipients | HubSpot (CRM), Instantly (email), Clay (enrichment) |
| Deletion period | 12 months after the last interaction with no business relationship |
| TOMs | Access restriction, encryption, DPAs with all processors |
2. Balancing-of-interests test
Record in writing why the legitimate interest in B2B outreach overrides the data subject’s interest:
- Your interest: new customer acquisition
- The data subject’s interest: not being contacted unwantedly
- Balancing test: business data, relevant offer, opt-out available at any time → the controller’s interest overrides
3. Privacy policy
Your website’s privacy policy must include a section on cold outreach/direct marketing — link to it from the email.
Common questions
Does GDPR also apply to B2B contact data?
Yes. GDPR protects the personal data of natural persons — regardless of whether it's processed in a B2B context. The name, email, and phone number of a managing director or sales lead are personal data. Exception: purely corporate data with no personal reference (e.g. company revenue, industry) doesn't fall under GDPR.
Which legal basis applies to B2B cold outreach?
Art. 6(1)(f) GDPR — legitimate interest. Your legitimate interest: new customer acquisition. Precondition: the interests of the data subject do not override it. In practice that means: business contact data, a factual connection, a reasonable frequency, an opt-out option.
Do I have to include a privacy notice with B2B cold emails?
Yes. Under Art. 13/14 GDPR, you must inform the data subject on first contact: who you are, why you're processing the data, and what rights exist (access, deletion, objection). In practice: a link to your privacy policy in the email signature is enough — a multi-page disclaimer in the email itself isn't necessary.
How long am I allowed to store B2B contact data?
GDPR doesn't specify a fixed period. The principle of storage limitation applies: as long as necessary for the processing purpose. Recommendation: contacts who haven't responded after 6 months → check whether legitimate interest still exists. Contacts who have explicitly objected → delete immediately (email) or add to a suppression list.