(mon-fri) 7:00-20:00

GDPR B2B Outreach Compliance Checker

Cold outreach is legal in Europe. Done carelessly, it is also a fast way to draw a complaint. Answer 8 questions and get an honest read, the specific fixes, and a sequenced plan to close your gaps.

Your outbound setup

Answer for how you actually run outbound today, not how you plan to.

B2B outreach in the EU usually relies on legitimate interest, which needs a documented balancing test (an LIA). Consent is rarely the right basis for cold B2B.
Where the data comes from and whether it was collected lawfully. Scraped or bought lists with no provenance are the biggest risk.
Every recipient must be able to object easily, and opt-outs must be honored quickly and permanently across all channels.
A maintained suppression list, checked before every send, stops you contacting people who objected or asked to be removed.
People you contact have a right to know who you are, why you have their data, and where to find your privacy policy.
You should hold only the data you need and delete it on a defined schedule, not keep every contact forever.
GDPR is the baseline, but national rules differ: France (CNIL), Germany (UWG, stricter on email), UK (PECR, CTPS for phone). Phone and email rules are not the same.
Records of processing and data processing agreements (DPAs) with your tools and any agency show accountability if you are ever questioned.

Your compliance read

8 dimensions of GDPR B2B outreach

Answer all 8 questions, then hit check.
We will score your outbound, show the fixes, and sequence them.

-
compliance score

This is a self-assessment guide, not legal advice. For a binding view, consult a data protection professional.

Want outbound that is compliant by default?

We run cold outreach across Europe with clean data sourcing, documented legal basis, and proper opt-out handling built in. Book a call and we will show you how we keep it tight at scale.

Talk to Us

Is B2B cold outreach legal under GDPR?

Yes. Cold email and cold calling to business contacts are legal across the EU and UK. GDPR does not ban outbound. What it requires is that you process personal data lawfully, fairly, and transparently. Most B2B outreach relies on legitimate interest as the legal basis, which is allowed, but it comes with conditions: a balancing test, a clear opt-out, honest transparency about who you are and where you got the data, and clean sourcing.

This checker scores your outbound across the 8 dimensions that decide whether you are on the right side of those conditions. It is a self-assessment, not legal advice, but it tells you fast where your real exposure is, what to do about it, and in what order.

What the checker measures

Each dimension is scored out of 10, for a total out of 80. Three of them can stop you outright: no legal basis, no working opt-out, and contact data you cannot trace to a lawful source. Any one of those overrides your score, because no amount of good practice elsewhere makes up for them.

  • Legal basis. A documented legitimate interest assessment, not a vague assumption that consent covers it.
  • Data sourcing. Where your contacts come from and whether that source was lawful. Scraped lists with no provenance are the most common failure.
  • Opt-out handling. Easy to object, honored quickly, applied across every channel.
  • Suppression list. A do-not-contact list checked before every send.
  • Transparency. Who you are, why you have their data, and a reachable privacy notice.
  • Retention and minimisation. Hold only what you need, delete on a schedule.
  • Country rules. The national layer on top of GDPR, which differs by market and channel.
  • Records and DPAs. Accountability if you are ever questioned.

The total on its own does not decide the verdict. Any single dimension scoring 4 or below caps the result at "Material gaps", however high the average. A 91% score with a broken legal basis is not a pass, and the tool will not tell you it is.

What you get back

Not just a number. For every answer that is not already right, you get the gap in plain terms, the specific fix, and a rough effort estimate. Then the fixes are sequenced into a plan: what to close before you send anything else, what to build over the next fortnight, and what is ongoing hygiene.

The plan is built from your answers, so you only see the items that apply to you. Answer everything correctly and you get no plan at all, because there is nothing to do.

GDPR outbound rules differ by country

Position What to watch
France CNIL guidance on B2B data and consent. Phone prospecting to professional lines is allowed. Data sourcing and opt-out discipline matter.
Germany UWG is strict on unsolicited email. Cold email to business contacts is risky without care. Phone and post have their own rules.
UK PECR sits alongside UK GDPR. Corporate email is more permissive than individual. Phone prospecting should respect the CTPS register.
Benelux and Nordics GDPR baseline with national privacy authorities. Generally pragmatic on B2B, but opt-out and transparency still apply.

How to read your result

The verdict is driven by your weakest dimension first, then by the total. In that order.

Result What it means
High risk A blocker fired: no legal basis, no opt-out, or data you cannot trace. Pause the affected sends and close it before anything else.
Material gaps% No outright breach, but at least one dimension sits at 4 or below. Real exposure regardless of what the total says.
Minor gaps to tidy No critical failure anywhere. Work through the plan before you scale volume.
Solid footing No breaches and no critical gaps. Anything left is a refinement, not a risk.

Frequently asked questions

Do I need consent to cold email a business?

Usually not. Most B2B cold outreach relies on legitimate interest, not consent. But legitimate interest is not a free pass. You need a documented balancing test, a clear opt-out, and honest transparency. Germany is the notable exception where unsolicited email is treated more strictly.

What is a legitimate interest assessment?

A short, documented check that weighs your interest in reaching a prospect against their privacy rights. It records why the outreach is reasonable, relevant to their role, and not intrusive. If a regulator asks why you contacted someone, this is what you point to.

Are bought or scraped lists a problem?

They are the most common cause of trouble, and this checker treats them as a blocker. The issue is not the list itself but whether the data was collected lawfully and whether you can show that. Reputable providers document their sourcing. Scraped lists with no provenance leave you unable to justify how you got the data, unable to complete an honest legitimate interest assessment, and unable to answer someone who asks where you got their details.

My score is high but the tool says material gaps. Why?

Because an average hides the thing that matters. Seven strong dimensions and one broken one still averages well, and it is exactly the broken one that draws the complaint. The verdict looks at your weakest answer before it looks at your total.

Is cold calling allowed in Europe?

B2B phone prospecting to professional lines is generally permitted, with national variations. The UK has the CTPS register to respect, France follows CNIL guidance, and consent and opt-out rules still apply to the data behind the call. Phone rules and email rules are not the same.

How do I make my outbound compliant?

Document your legal basis, source data from providers who can show lawful sourcing, make opt-out easy and honor it everywhere, keep a suppression list, and respect the rules of each market. If you would rather not build all of that, our SDR cost calculators] and Agency Evaluation Scorecard help you weigh running it in-house against an agency that already does.