GDPR does not prohibit B2B cold email. It regulates it. Under the legitimate interest legal basis, companies can send targeted cold email to business professionals without prior consent - provided the outreach is relevant, documented, and includes an easy opt-out. This guide explains how legitimate interest works, what every cold email must include, what “opt-out” means under GDPR, and how to document your compliance.
Yes - B2B cold email is legal under GDPR under the Legitimate Interest basis.
GDPR Article 6(1)(f) permits processing personal data (including business email addresses) when it is necessary for a legitimate interest that is not overridden by the rights of the data subject. For B2B cold email, this means: the email is relevant to the recipient’s professional role, you have a genuine reason to contact them, and contacting them does not unreasonably override their interests. Prior consent is not required under this basis.
You have a genuine business reason to contact this person.
Email is a necessary and proportionate way to achieve your purpose.
Your legitimate interest does not override the recipient’s rights and freedoms.
Your company name and ideally a physical address. Recipients must know who is contacting them.
A clear way to stop receiving emails. Reply-to opt-out (“Reply STOP to opt out”) or an unsubscribe link both work. The mechanism must actually work.
Unlike CAN-SPAM’s 10-business-day window, GDPR requires prompt processing of opt-out requests. Best practice: remove within 48 hours.
If a recipient asks where you got their data, you must be able to answer. This is a GDPR data subject access right.
B2B cold email under legitimate interest does not require prior consent. Consent is one legal basis - legitimate interest is another.
You do not need to include a GDPR privacy notice in the email itself, but your privacy policy must cover prospect data and be publicly accessible.
GDPR does not require commercial labelling of cold email (unlike some interpretations of CAN-SPAM). Identify yourself, but you do not need to label the email as advertising.
Legitimate interest does not require opt-in confirmation before sending. Opt-in is the consent basis - not required here.
If you receive a complaint or supervisory authority inquiry, you need to demonstrate that you conducted a legitimate interest assessment (LIA) before the campaign. You do not need to submit this proactively - just have it ready. For each contact segment, document:
Sending to invalid or non-existent email addresses undermines your legitimate interest case and creates unnecessary processing. Verify before every campaign. 100 free credits, no card required.
Ayoub built BounceZero's 5-stage validation pipeline, its dedicated BGP-announced IP infrastructure, and the Patroni HA PostgreSQL cluster behind every verification. Previously built high-volume email delivery infrastructure. Trained at 1337 Benguerir (École 42 network, 2019). Open-source: bgp_analyzer.
Deep-dive guides on how email verification and inbox placement work
272,446-domain census: DMARC gap, provider divide, catch-all rates
10.2M verifications: 12.3% of addresses are dead, and where they hide
826K re-verifications: only 19% of valid addresses survive 90 days
True catch-all is 1.4% - most of what looks catch-all is unprobeable providers
info@ bounces 4.5x more than personal addresses - measured, not guessed
The 3x invalid-rate gap that vanishes when you control for domain size
Explore other topics