GDPR compliance in email outreach starts before the email is written. It begins with the personal data you collect, where it came from, why you are using it and which rules apply to the people you want to contact.
That makes a GDPR email checklist more useful than a single “compliant” template. An unsubscribe line cannot fix a list collected without a valid basis, just as a legitimate interest assessment cannot excuse irrelevant targeting or keeping prospect data indefinitely.
This checklist focuses on the practical questions B2B sales and marketing teams should review before processing personal data for outreach. It is general information, not legal advice. GDPR, ePrivacy rules and national electronic marketing laws can interact differently depending on the country, recipient and campaign, so get qualified legal advice when your setup needs a definitive answer.
GDPR and email marketing: start with the right legal question
GDPR governs the processing of personal data. Email marketing also sits under rules covering electronic communications, including national laws implementing the ePrivacy Directive. Those two layers overlap, but they do not answer exactly the same question.
| Question | Main legal layer |
| Can we collect, store and use this person’s information? | GDPR and other applicable data protection rules |
| What lawful basis supports the processing? | GDPR |
| Can we send this type of electronic marketing message to this recipient? | National electronic marketing and ePrivacy rules, alongside GDPR |
| What information must we provide about the processing? | GDPR transparency requirements |
| What happens when the person objects to direct marketing? | GDPR right to object, plus any relevant local requirements |
This distinction matters because “GDPR allows legitimate interests” does not automatically mean every cold email is permitted in every European country. The channel, local law and type of recipient still need to be checked.
Woodpecker’s broader GDPR practical guide for email senders explains the regulation’s main principles in an outreach context.
Does GDPR apply to a business email address?
Often, yes. GDPR protects personal data about identifiable people, including information connected with their professional activity. A work email such as [email protected], a named business phone number or a job title linked to a specific employee can therefore be personal data.
Pure information about a legal entity is different. A company registration number or a generic mailbox that does not identify a natural person may fall outside GDPR’s definition of personal data, although other communication and marketing rules can still apply.
| Data | Likely GDPR relevance |
| [email protected] | Can identify a natural person and may be personal data |
| Maria Smith, VP Sales at Company | Personal data |
| Maria’s direct business phone number | Personal data |
| Company Ltd, 250 employees | Information about a legal entity rather than an individual |
| [email protected] | May not identify an individual, but electronic marketing rules still need checking |
12-point GDPR email compliance checklist
Treat the checklist as a workflow rather than twelve boxes to tick after a campaign has already been built. Several later decisions, including the email copy and retention period, depend on choices made near the beginning.
1. Define exactly why you are processing the data
Start with the purpose rather than the list. “Marketing” is broad. A more useful description might be prospecting for finance leaders at European SaaS companies, sending a customer newsletter, inviting existing clients to an event or following up on a product enquiry.
A clear purpose helps you decide which personal data is necessary, what lawful basis may apply and how long the information needs to be retained. If several unrelated campaigns use the same database, document the purpose for each rather than assuming that data collected for one activity can automatically be reused for another.
2. Identify the people, countries and channels involved
Before relying on a general statement about B2B marketing, map the actual campaign. Note where the recipients are located, what type of contact they are, which communication channels you plan to use and where your organization operates.
This is where country-specific electronic marketing rules need to enter the review. Rules for an employee at a company, a sole trader and an individual consumer may not be identical. Email, LinkedIn messages and phone calls may also be treated differently under local law.
3. Document a lawful basis for processing
GDPR provides several lawful bases for processing personal data. Consent and legitimate interests are two that often appear in marketing discussions, but neither should be treated as a default label added after the list has already been collected.
If you rely on consent, it needs to meet GDPR standards for a freely given, specific, informed and unambiguous indication of the person’s wishes. Silence, inactivity and pre-ticked boxes do not create valid consent.
Legitimate interests can sometimes support direct marketing processing, but it needs an assessment rather than an assumption. A practical legitimate interests review should consider three things:
| Test | Question to document |
| Purpose | What legitimate, specific interest are we pursuing? |
| Necessity | Is processing this personal data genuinely necessary for that purpose? |
| Balancing | Do the person’s rights, interests and reasonable expectations outweigh our interest? |
A narrow campaign to people whose professional responsibilities closely relate to the problem you solve can be easier to justify than emailing an entire company directory. Relevance helps, but it is only part of the legal analysis.
4. Check the electronic marketing rules separately
A lawful basis under GDPR answers the data-processing question. You still need to determine whether the communication itself is allowed under the electronic marketing rules that apply to the recipient.
That is one reason blanket claims such as “B2B cold email is legal under GDPR” are too broad. Your answer may change with the country, recipient category, existing relationship and communication channel.
5. Know where every contact came from
Publicly available does not mean unrestricted. If you obtain a person’s work email from LinkedIn, a company website, an event list, a data provider or another third party, record the source and make sure you can explain how and why the data entered your system.
When personal data was not collected directly from the individual, GDPR Article 14 creates additional transparency obligations. If you intend to use that data to communicate with the person, the required information generally needs to be provided no later than the first communication, unless a valid exception applies.
For purchased or outsourced prospect data, review the provider rather than assuming they carry the compliance responsibility for you. Ask how the data was sourced, when it was updated, which notices were given and what use the provider says is permitted.
6. Collect less data, not more
Data minimization means processing personal data that is adequate, relevant and limited to what the purpose requires. A cold email campaign to sales leaders might reasonably need a name, role, company, business email and a small amount of professional context. That does not mean every public fact about the person belongs in your CRM.
| Often relevant for B2B prospecting | Needs a much stronger reason |
| Name | Private phone number |
| Professional role | Personal social media activity unrelated to work |
| Company | Family or relationship information |
| Work email | Health, political or other sensitive personal information |
| Relevant business trigger | Detailed personal history unrelated to the campaign |
This also improves outreach quality. Woodpecker’s guide to B2B buying signals focuses on business context that can make outreach more relevant without requiring invasive personal research.
7. Keep the information accurate
People change companies, roles and email addresses. GDPR’s accuracy principle means personal data should be accurate and, where necessary, kept up to date for the purpose in which it is processed.
For outreach, stale data creates two problems at once. You may process information about the wrong person and you may increase bounce rates. Check priority accounts manually and use verification before sending rather than treating an old export as permanently reliable.
8. Make the first email transparent
A cold email should make it easy to understand who is contacting the recipient and why. When Article 14 applies, the transparency obligation covers considerably more than the sentence in the email itself, including the purpose and legal basis for processing, categories of data, relevant recipients, retention information, rights and the source of the data.
You do not need to turn the email body into several paragraphs of legal text. A concise message can identify the sender and reason for contact while directing the recipient to an accessible privacy notice containing the required information.
Before a sequence is launched, Woodpecker’s email preview tool can help you check that the sender identity, privacy information and opt-out wording remain readable instead of disappearing inside a long signature.
9. Give the recipient a simple way to object
The right to object is especially important in direct marketing. If someone objects to the processing of their personal data for direct marketing purposes, you must stop processing it for that purpose.
The mechanism does not have to look identical in every type of email. A newsletter will commonly use an unsubscribe link. A one-to-one cold email may use a clear opt-out instruction or an unsubscribe mechanism supported by the sending platform. What matters is that the recipient can exercise the right easily and without having to defend the decision.
Woodpecker’s guide to cold email opt-outs discusses different ways to make that option clear without turning a short B2B message into legal fine print.
10. Keep suppression and deletion processes separate
An opt-out creates an operational problem that simple deletion does not always solve. If every trace of a contact disappears, the same address can later be imported from another list and contacted again.
Build a suppression process that prevents future marketing while retaining only the minimum information required for that purpose. The correct implementation depends on your systems and legal basis, so document how suppression, erasure and other data subject requests interact rather than treating them as one button.
Woodpecker has a GDPR encryption feature designed around this problem. It can obscure prospect information while preserving the ability to prevent an encrypted prospect from accidentally entering another campaign.
11. Set a real retention rule
GDPR does not prescribe a universal number of days for keeping cold prospect data. The storage limitation principle says personal data should not be kept longer than necessary for the purpose in which it is processed.
Woodpecker has historically recommended a 30-day rule for certain non-responsive EU prospects, but that is a Woodpecker operational recommendation, not a retention period written into GDPR. Your organization should define and document a period that fits its lawful purpose, legal obligations and outreach process, then review or delete the data when that period ends.
Useful retention rules can distinguish between active opportunities, inactive prospects, subscribers, customers, suppression records and old campaign exports instead of applying one deletion period to everything.
12. Review vendors, access and security
A prospecting workflow can pass data through a database provider, enrichment tool, CRM, automation platform and email service before the first message is sent. Map that chain. Identify which providers process personal data on your behalf, what they receive, where the data is stored and which contractual safeguards apply.
Access should also be limited internally. A salesperson who needs a work email and company role does not automatically need access to every field in the CRM. Use appropriate permissions, authentication and security controls for the sensitivity and volume of data involved.
If you use Woodpecker as a processor for prospect data, review the company’s Data Processing Addendum alongside your own controller responsibilities.
What should a GDPR-aware B2B cold email look like?
The copy itself is only one part of compliance, but it should reflect the decisions made earlier. A good B2B message identifies the sender, has a credible professional reason for contacting that particular recipient, avoids unnecessary personal details and makes it easy to stop future outreach.
For example:
Subject: Outbound workflow at [Company]
Hi Maya,
I came across your role while researching sales teams expanding into new European markets. I’m reaching out because Woodpecker helps outbound teams manage personalized cold email and LinkedIn outreach while keeping sending and reply workflows together.
Is outbound infrastructure something you are reviewing as the team expands?
You can see how we handle personal data in our privacy information here: [privacy link]. If you would rather not hear from me again, just reply and I will stop the outreach.
Best,
Sam
This example is intentionally plain. It does not claim that inserting those two final lines makes an otherwise unlawful campaign compliant. The list source, lawful basis, local marketing rules and internal data handling still matter.
Cold email GDPR checklist before launch
For day-to-day campaign review, the longer checklist can be reduced to ten practical questions. If the team cannot answer one of them, pause the campaign and resolve it before sending.
- Purpose: Can we explain why we are processing these contacts?
- Scope: Do we know which countries and recipient types are in the campaign?
- Lawful basis: Have we documented the basis we rely on rather than assuming it?
- Channel rules: Have we checked the electronic marketing rules that apply in those markets?
- Source: Do we know where every contact came from?
- Relevance: Does the person’s professional role have a credible connection to the offer?
- Minimization: Are we storing only the personal data needed for the purpose?
- Transparency: Can the recipient understand who is processing their data, why and where to find the required information?
- Opt-out: Can they object easily, and will the request stop future direct marketing?
- Retention: Do we know when inactive data will be reviewed or removed?
GDPR compliance does not end when the campaign starts
The team needs a process for what happens after the first email. Replies may correct inaccurate data, opt-outs need to update suppression records and an active opportunity may create a new reason to retain information. The processing lifecycle changes as the relationship changes.
Automation should respect those changes. Woodpecker’s guide to outbound sales automation is useful when defining how sequences respond to replies, opt-outs and other campaign events instead of continuing blindly.
Prepare for requests from individuals
People can exercise GDPR rights over their personal data, including access, rectification, erasure in applicable circumstances and objection. Your sales team does not need to become a legal department, but it should know where requests are routed and who owns the response.
Document the workflow before a request arrives. Otherwise, a simple reply asking where the data came from can bounce between sales, marketing and operations while nobody knows who is responsible.
Have a data breach process
Not every security incident creates the same notification duty, but the team needs a way to identify and escalate a personal data breach quickly. Where a breach is likely to create a risk to people’s rights and freedoms, GDPR can require notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
That is why breach ownership, vendor contacts and incident procedures belong in the compliance process before anything goes wrong.
Keep legal compliance and email performance separate
A strong reply rate does not prove that a campaign is compliant, and a compliant campaign can still perform badly. Treat legal review and campaign optimization as separate layers.
Once the legal and data-processing questions are resolved, Woodpecker’s cold email benchmarks can help put reply performance into context. Benchmark performance should never be used to justify collecting more personal data or ignoring an opt-out.
The same applies to testing. If you compare subject lines or message angles, keep the required transparency and opt-out process intact. For campaigns with enough volume, the cold email A/B test calculator can help determine whether a performance difference is statistically meaningful.
Plan infrastructure after you know what you are allowed to send
Technical capacity is not a legal basis. Buying more domains and mailboxes does not answer the compliance questions above. Once your campaign scope has been reviewed, however, the sending setup still needs to support the intended volume responsibly.
Woodpecker’s cold email infrastructure calculator can estimate the domains and sending accounts required for a planned outreach program.
How Woodpecker fits into a GDPR-aware outreach process
Woodpecker provides tools that can support parts of a GDPR-aware outbound workflow, including opt-out handling and GDPR encryption for prospect records. It also publishes a separate GDPR compliance statement describing its own data protection commitments.
Using a GDPR-conscious tool does not transfer the controller’s legal decisions to the software vendor. Your organization still decides which prospects to upload, which data fields to process, why the campaign exists and how long the information should be retained.
GDPR email compliance mistakes to avoid
| Mistake | Why it is risky |
| “It is B2B, so GDPR does not apply.” | Professional contact information can still identify a natural person. |
| “The address was public, so we can use it however we want.” | Public availability does not remove transparency, purpose and lawful-basis requirements. |
| “Direct marketing is a legitimate interest, so the campaign is automatically fine.” | Legitimate interests requires a case-specific assessment and does not override separate electronic marketing rules. |
| “We have an unsubscribe link, so the campaign is GDPR compliant.” | Opt-out is one part of a much wider processing lifecycle. |
| “The data provider collected it, so they are responsible.” | Using third-party data creates responsibilities for the organization that processes it too. |
| “We can keep every prospect forever in case they become useful later.” | Storage limitation requires a purpose-based retention policy. |
| “Delete every opt-out and forget about it.” | Without a controlled suppression mechanism, the person may accidentally be imported and contacted again. |
GDPR email FAQ
Is cold email legal under GDPR?
GDPR does not create a blanket ban on cold email, but neither does it provide automatic permission for every B2B campaign. You need an appropriate lawful basis for processing personal data, transparency, respect for individual rights and compliance with the electronic marketing rules that apply to the recipient and country.
Do you always need consent for B2B cold email?
Not necessarily under GDPR. Legitimate interests can sometimes support direct marketing processing, provided the required assessment is satisfied. However, separate ePrivacy and national electronic marketing laws may impose consent or other requirements, so the answer depends on the market and recipient.
Is a work email address personal data?
A business email address that identifies a person, such as [email protected], can be personal data under GDPR. Information purely about a legal entity is treated differently.
Does GDPR require an unsubscribe link?
GDPR gives people the right to object to direct marketing and requires that this right be brought clearly to their attention. It does not prescribe one universal interface called an “unsubscribe link.” Email marketing and national electronic communications rules may add their own requirements, and an unsubscribe link is commonly used because it provides a simple mechanism.
What happens when someone objects to direct marketing?
The organization must stop processing that person’s personal data for direct marketing purposes. Your systems should also prevent the person from being accidentally added back into a future marketing campaign.
How long can you keep cold prospect data?
GDPR does not specify one retention period for cold outreach. Keep personal data only as long as necessary for the documented purpose and set review or deletion periods that fit the campaign, relationship and applicable legal requirements.
Can you use personal data from LinkedIn or a company website?
Public availability does not automatically make every use lawful. You still need to consider the lawful basis, purpose, relevance, transparency obligations and applicable marketing rules. When the information was not obtained directly from the individual, Article 14 can require additional information about the processing and source.
What are the maximum GDPR fines?
For certain infringements, GDPR allows supervisory authorities to impose fines of up to €20 million or 4% of a company’s total worldwide annual turnover, whichever framework applies to the infringement. Authorities consider the circumstances of each case rather than applying the maximum automatically.
Build privacy into the outreach process, not the email footer
A compliant outreach process is easier to maintain when privacy decisions are made before contacts enter the campaign. Know why you need the data, collect only what supports that purpose, document where it came from and give people a straightforward way to understand and control its use.
The final email should reflect those decisions, but it cannot replace them. GDPR compliance is a data-processing discipline that runs from prospect research and list building through sending, opt-out handling, retention and eventual deletion. Treat it that way and the checklist becomes part of normal campaign operations rather than a legal paragraph added five minutes before launch.