GDPR does not prohibit B2B cold email. It regulates it. Under the legitimate interest legal basis, companies can send targeted cold email to business professionals without prior consent - provided the outreach is relevant, documented, and includes an easy opt-out. This guide explains how legitimate interest works, what every cold email must include, what “opt-out” means under GDPR, and how to document your compliance.
Yes - B2B cold email is legal under GDPR under the Legitimate Interest basis.
GDPR Article 6(1)(f) permits processing personal data (including business email addresses) when it is necessary for a legitimate interest that is not overridden by the rights of the data subject. For B2B cold email, this means: the email is relevant to the recipient’s professional role, you have a genuine reason to contact them, and contacting them does not unreasonably override their interests. Prior consent is not required under this basis.
You have a genuine business reason to contact this person.
Email is a necessary and proportionate way to achieve your purpose.
Your legitimate interest does not override the recipient’s rights and freedoms.
Your company name and ideally a physical address. Recipients must know who is contacting them.
A clear way to stop receiving emails. Reply-to opt-out (“Reply STOP to opt out”) or an unsubscribe link both work. The mechanism must actually work.
Unlike CAN-SPAM’s 10-business-day window, GDPR requires prompt processing of opt-out requests. Best practice: remove within 48 hours.
If a recipient asks where you got their data, you must be able to answer. This is a GDPR data subject access right.
B2B cold email under legitimate interest does not require prior consent. Consent is one legal basis - legitimate interest is another.
You do not need to include a GDPR privacy notice in the email itself, but your privacy policy must cover prospect data and be publicly accessible.
GDPR does not require commercial labelling of cold email (unlike some interpretations of CAN-SPAM). Identify yourself, but you do not need to label the email as advertising.
Legitimate interest does not require opt-in confirmation before sending. Opt-in is the consent basis - not required here.
If you receive a complaint or supervisory authority inquiry, you need to demonstrate that you conducted a legitimate interest assessment (LIA) before the campaign. You do not need to submit this proactively - just have it ready. For each contact segment, document:
Sending to invalid or non-existent email addresses undermines your legitimate interest case and creates unnecessary processing. Verify before every campaign. 100 free credits, no card required.
Ayoub built BounceZero's 5-stage validation pipeline, its dedicated BGP-announced IP infrastructure, and the Patroni HA PostgreSQL cluster behind every verification. Previously built high-volume email delivery infrastructure. Trained at 1337 Benguerir (École 42 network, 2019). Open-source: bgp_analyzer.
Deep-dive guides on how email verification and inbox placement work
SMTP check, MX lookup, API - 5 methods ranked by accuracy with code examples
When, how and how often to verify - the full guide
Hard vs soft bounce, SMTP codes, safe thresholds, and how to reduce bounces
What each tool does, how they differ, and how they work together in a workflow
What each does: syntax/MX checks vs SMTP mailbox probe, when to use each, catch-all limits, bounce impact
How to clean an email list in 2026: remove invalid, catch-all, role-based, and disposable addresses
Continue through related topics