/

Results appear as you type. Use the up and down arrow keys to move through them and Enter to open one.

Your lawful basis for contacting businesses

Legitimate interests is the usual basis for B2B prospecting, but it is not automatic. What to record, and why “the EU” is twenty-seven different regimes for email.


Not legal advice — see the note at the end. This is the shape of the problem and what the product gives you to work with.

The basis is usually legitimate interests

For B2B prospecting in the EU and UK the usual lawful basis is legitimate interests, GDPR Article 6(1)(f). Direct marketing is named in Recital 47 as capable of being a legitimate interest, which helps.

It is not automatic. You have to run and record a three-part balancing test:

  1. Purpose. Is the interest legitimate? ("Selling scheduling software to dental clinics" — yes.)
  2. Necessity. Is the processing necessary for it, or would something less intrusive do?
  3. Balance. Does it override the rights and reasonable expectations of the individual? A named person at a business, contacted at a published work address, about something plausibly relevant to their job, generally does not.

Write it down once per campaign type and keep it. A supervisory authority asks to see the assessment, not the intention.

A published address is not consent

Publishing a contact address does not mean consenting to marketing. Do not rely on consent you do not have — rely on legitimate interests, properly assessed, and give a working opt-out.

Email is governed separately, and it varies by country

This is where most people get it wrong. GDPR gives you a lawful basis for processing; the ePrivacy Directive governs the sending. ePrivacy requires prior consent for unsolicited email to natural persons and leaves B2B to national law — so the rules genuinely differ across the single market.

  • Several states — Ireland, the Netherlands, the Nordics — permit unsolicited email to a corporate address provided there is a working opt-out.
  • Germany's UWG effectively requires prior consent for email even B2B. Italy has taken a restrictive line too.

Treat "the EU" as twenty-seven regimes, not one, and check the country before the campaign rather than after it. The country column is in every export precisely so you can segment by it.

Outside the EU, briefly

  • United States. CAN-SPAM permits cold commercial email with accurate headers, a physical postal address, clear identification and a working unsubscribe honoured within ten business days. State law can add to it.
  • California. CCPA/CPRA covers business contacts too. A "Do Not Sell or Share" request has to be honoured, and you need a privacy notice describing what you collect.
  • United Kingdom. PECR plus UK GDPR. Corporate subscribers are treated more permissively than individuals; sole traders and partnerships are not corporate subscribers.
  • Canada. CASL is a consent regime with narrow implied-consent routes, and it is strict. Check before sending.

What good practice looks like, wherever you send

  • Identify yourself and your company in the first line.
  • Say why you are writing to them specifically.
  • Say where you got their details — the Link column, and the per-address sources list inside All emails make this a fact rather than a guess.
  • Offer a one-click opt-out and honour it permanently, across every list you own.
  • Keep a suppression list of your own. An opt-out that only applies to one campaign is not an opt-out.

Not legal advice

We are a data vendor, not your counsel. This describes the general shape of the rules and what our data gives you to comply with them. Take advice for your jurisdiction and your campaign, particularly before sending at volume into Germany, Italy or Canada.

See also acceptable use and how we handle business contact data.

Updated on:

Was this article helpful?

Related articles