GDPR has acquired a reputation among outbound teams as a wall. It is not a wall. It is a set of conditions, and the conditions are mostly things a reasonable business would do anyway.

What follows is the working version: what to do, what to write down, and what actually gets people into trouble. It is not legal advice, and for anything unusual you should get some.

First, the split that decides everything

GDPR governs personal data, which means information relating to an identified or identifiable person.

ContactPersonal data?Practical treatment
info@acme.comGenerally notOutside GDPR, though ePrivacy rules may still apply
sarah.jones@acme.comYesFull GDPR obligations
sarah@sarahjonesplumbing.com (sole trader)Yes, and treated as an individual in several member statesStricter: consent frequently required
sarah.jones@gmail.comYes, and clearly an individualConsent required

The second row is the normal case for B2B outreach, and it is workable. The third and fourth rows are where teams get into difficulty, usually by treating a sole trader as if they were a company.

Note also that GDPR is not the only regime in play. ePrivacy rules, implemented nationally as PECR in the UK and equivalents elsewhere, govern electronic marketing specifically, and their treatment of corporate versus individual subscribers varies by country. Germany is materially stricter than the UK. If a market matters to you, check that market.

Legitimate interests, properly

For relevant B2B outreach, legitimate interests is the standard lawful basis. It is legitimate, it is widely used, and it is not a loophole. It comes with work attached.

The work is a three-part assessment, written down:

1. Purpose. What is the interest? "Contacting businesses that plausibly need our service, to offer it." That is a legitimate commercial interest. State it plainly.

2. Necessity. Is direct contact necessary to pursue it, or could you achieve the same through less intrusive means? For reaching a specific business with a specific proposition, direct contact is generally necessary. Say why.

3. Balancing. Do the recipient's interests and rights override yours? The factors that matter:

  • Is the contact relevant to their professional role? (Strongly in your favour if yes.)
  • Would they reasonably expect to be contacted this way in this context? (B2B: usually yes.)
  • Is the data already published for business contact? (Strongly in your favour.)
  • Is the volume proportionate, or is this a mass send? (Volume weakens your position.)
  • Is any of the data sensitive? (If so, stop: legitimate interests is not appropriate.)
  • Can they object easily and effectively? (Must be yes.)

Write two paragraphs. Save it. Review it once a year. That is the entire obligation, and it is the document you will be asked for if anyone ever asks.

Transparency: the part most senders skip

Because you did not collect the data from the person directly, they have a right to know certain things: who you are, what you are doing with their data, on what basis, where you got it, how long you will keep it, and how to object.

In practice this means two things.

A reachable privacy notice. Not buried. Linked from your site and, ideally, from your emails.

An honest answer when asked. "Where did you get my details?" is a question you should be able to answer specifically: "your address is published on your company's contact page, and we contacted you because you operate a dental practice in an area we serve." If you cannot answer that question, the real problem is not GDPR, it is that you do not know how you built your list.

Which leads to the single most practical habit in this whole article.

Record the source at collection

For every contact: where it came from and when.

This costs nothing at the point of collection and is impossible to reconstruct afterwards. It is your evidence for transparency obligations, your evidence for a lawful basis, and, in Canada, your legal burden of proof under CASL.

Any tool that captures source and date automatically on harvest, import or capture is doing meaningful compliance work for you, quietly, in a way that manual list building never will.

Objections and suppression

Two rules that matter more than anything else in this article.

Objections to direct marketing are absolute. There is no balancing test, no assessment, no discretion. Someone objects, you stop. Without delay.

Suppress, do not delete. This one is counterintuitive and people get it backwards constantly.

If someone asks not to be contacted and you delete their record entirely, you have no way of knowing not to contact them next time you source that market. Three months later they reappear in a harvest, get emailed again, and now you have a much bigger problem than the first email caused.

The correct behaviour is a suppression list: retain the minimum information needed to ensure they are never contacted again, use it for nothing else, and apply it across the whole workspace rather than per campaign. Workspace-wide suppression that survives new imports is what makes this reliable rather than aspirational.

If someone separately requests erasure of all their data, that is a different request, and you should keep a minimal suppression record while deleting the rest, explaining why.

Data subject requests

You may receive requests for access, rectification, erasure, restriction, portability or objection. The mechanics:

  • One month to respond, extendable by two months for complex or numerous requests if you tell them within the first month.
  • Verify identity proportionately, and do not use what you collect for verification for anything else.
  • Free, unless a request is manifestly unfounded or excessive.
  • Objections to marketing: immediately. Do not wait a month.

For a small outbound team these are rare and straightforward. Have a note of who handles them so the first one does not sit in a shared inbox for three weeks.

Retention

Do not keep contact data forever on the theory that it might be useful. Set a period, apply it, and document it.

A defensible policy for B2B outreach:

DataRetention
Contacted, no response12 to 24 months, then delete or refresh
Engaged, no deal24 months from last contact
CustomerDuration of relationship plus legal requirements
Suppression recordIndefinite, because that is the point of it

The commercial argument aligns with the legal one here: business contact data decays at roughly 25% a year, so a four-year-old record is mostly wrong anyway.

Your processor obligations

If you use a platform to store and send, that platform is processing personal data on your behalf. You are the controller; they are the processor. That relationship must be governed by a written agreement covering security, sub-processors, breach notification, deletion and international transfers.

Practically: check the vendor publishes a data processing addendum and a list of sub-processors, and that the DPA is in force without a signature chase. A vendor that cannot produce either is a vendor whose paperwork becomes your problem.

The short version

  1. Contact businesses, and treat sole traders as individuals.
  2. Write down a legitimate interests assessment. Two paragraphs.
  3. Record source and date for every contact.
  4. Publish a privacy notice and be able to say where you got someone's details.
  5. Honour objections immediately, and suppress rather than delete.
  6. Set a retention period and apply it.
  7. Use a processor with a real DPA.

Seven things. Six of them are one-off tasks and the seventh is automatic if your tooling is sensible. That is what GDPR actually asks of an outbound team, and it is a long way from a wall.