“It’s B2B, so GDPR doesn’t apply” is wrong twice. GDPR applies to a work email address that identifies a person, and GDPR is not the only statute governing whether you may send to it. The rule that stops you is usually not in the regulation everyone has read.
The basis most senders rely on
Article 6(1)(f) permits processing necessary for a legitimate interest, balanced against the rights of the person whose data it is. Recital 47 says in as many words that direct marketing may be a legitimate interest. For a message that is genuinely relevant to somebody’s job, that is a defensible basis, and it is the one most European B2B outbound runs on.
Relying on it means three things are true at once:
- The message relates to the recipient's professional role, not to them as a private person.
- You identify yourself and say plainly where the address came from.
- Every message carries a working opt-out, and the opt-out is honoured across every campaign, not just the one it came from.
Where the basis stops helping
The ePrivacy Directive governs unsolicited electronic communication, and each member state implements it in its own law. Where both apply, the national ePrivacy rule is the more specific one and it governs. Your legitimate-interest assessment can be immaculate and still be beside the point.
Two implementations change the answer:
| Country | Instrument | What it requires |
|---|---|---|
| Germany | UWG §7(2) | Prior express consent for commercial email. No general B2B exemption. |
| Austria | §174 TKG 2021 | Opt-in for direct-marketing email. Successor to §107 TKG 2003, so the older case law still reads across. |
Germany’s rule sits in competition law rather than data-protection law, which is why it surprises people: the exposure is an Abmahnungfrom a competitor or a trade association, not only a supervisory-authority complaint. Austria’s sits in telecoms law and derives from Article 13 of the same directive.
The paperwork that has to exist first
A legitimate interest assessment is three short sections: the interest, why the processing is necessary to pursue it, and the balance against the recipient’s reasonable expectations. It takes an afternoon.
Its value is entirely in its date. An assessment written before the campaign is evidence of a considered decision. The same document written the week a complaint arrives is evidence of something else, and everyone reading it will know which one they have.
The assessment is not the artefact that protects you. The date on it is.
What the recipient can ask for
Two requests arrive more often than any other, and both have short deadlines. Article 15 gives a right of access — including, in practice, “where did you get my address?” Article 21 gives an absolute right to object to direct marketing, with no balancing test to apply: once someone objects, processing for that purpose stops.
Answering the first one requires that you recorded the source at the time of collection. If your list came from an aggregator that will not tell you where a row originated, you cannot answer, and the inability to answer is itself the finding.
What we do about it
This is the reasoning behind a constraint we publish on the evidence standard: every company is researched from public sources at the moment of the request, and each claim carries the page it was read from and the date it was read. Not because it is a nicer story, but because it is the only version of the answer that survives an access request.
It is also why we do not resolve visitor IP addresses to company names, and why we wrote separately about why that trick fails on both the legal and the accuracy axis.