73% lower cost per meeting · live in 7 days · 50+ companies, 5 markets Get your free GTM analysis →
← All plays
gdprcold email

Legitimate Interest for Cold Email in Europe: When It Applies and How to Document It

March 4, 2026 · 5 min read · by Ahmet Faruk Yilmaz, Founder of Asphia

Legitimate Interest for Cold Email in Europe: When It Applies and How to Document It

TL;DR

B2B cold email can rely on GDPR legitimate interest when you have a genuine business purpose, process minimal data, target professionals in relevant roles, and document a balancing test showing your interest outweighs recipient privacy expectations. Consent is not required, but accountability is.

B2B cold email is legal under GDPR when you can point to a clear lawful basis. For most outbound sales, that basis is legitimate interest (Article 6(1)(f)). It does not require consent, but it does require documentation, a genuine business purpose, and respect for the recipient’s reasonable privacy expectations.

What Legitimate Interest Actually Means

Legitimate interest is not a free pass. It is a structured argument that your reason for processing personal data (sending the email) is real, proportionate, and does not unfairly override the rights of the person receiving it.

The European Data Protection Board has confirmed that commercial prospecting can qualify, provided:

  • You have an actual business interest (finding customers, offering a relevant service).
  • Cold email is a necessary and appropriate way to pursue it.
  • The people you contact would not be surprised or harmed by the contact.

A professional in a relevant role receiving a business pitch about a tool their company might use is a very different situation from a consumer receiving unsolicited marketing. That distinction matters under GDPR.

Drake meme: rejecting consent, approving legitimate interest documentation No consent forms. Just a 30-minute LIA that keeps your outbound clean and your lawyers happy.

The Three-Part Test You Must Pass

Before relying on legitimate interest, run the balancing test. Document it in writing.

1. Purpose test. Can you articulate a specific, genuine reason? “We want to sell more software” is not enough. “We are offering a B2B lead generation service to heads of sales at SaaS companies with more than 50 employees, because their role involves solving outbound pipeline challenges” is specific enough.

2. Necessity test. Is cold email a reasonable way to achieve that purpose? If you could achieve the same outcome with no personal data processing, legitimate interest fails. Cold email as a channel for B2B prospecting generally passes this test, because there is no realistic alternative that reaches the same decision-makers at scale.

3. Balancing test. Would recipients reasonably expect this contact? A VP of Sales receiving a relevant pitch to a work inbox is within the range of what someone in that role can expect. A private individual receiving the same email to a personal address is not. The nature of the data (business email vs. personal), the relevance of the pitch, and the safeguards you provide (clear opt-out, no deceptive framing) all feed into this balance.

If all three pass, you have a defensible basis. If any part fails, you need a different approach, not a faster send.

What to Document and Where to Keep It

Run a Legitimate Interest Assessment (LIA) before each campaign type, not after a complaint. Your LIA does not need to be lengthy, but it needs to exist.

Cover these points in plain language:

  • The processing activity (cold email prospecting).
  • The personal data involved (first name, last name, work email, job title, company).
  • Your specific business purpose.
  • Why this channel is necessary.
  • Who you are targeting and why their role makes them a reasonable audience.
  • Your safeguards: one-click unsubscribe, suppression list, no deceptive sender identity, retention limits.
  • Your conclusion: interest outweighs privacy risk because [specific reasons].

Store the LIA alongside your campaign records. If a supervisory authority or a recipient requests your lawful basis, you produce it immediately.

For a practical guide on building an outbound system that handles this by design, see GDPR-compliant cold email agency or explore how done-for-you cold email operations structure compliance from the start.

What Recipients Must Always Receive

Even with a valid legitimate interest basis, you have obligations on every send:

  • Identify yourself clearly (real sender name, real company, real domain).
  • Explain why you are contacting this person specifically (a brief, honest reason, not a generic claim).
  • Provide a simple way to opt out, and honor it within a short window.
  • Never contact someone again after they opt out. A suppression list is not optional.

The transparency requirement under Article 13/14 also means that if a recipient asks for your privacy notice, you need to have one that references legitimate interest as your lawful basis and gives them information about their rights (including the right to object).

Country-Level Nuances in Europe

GDPR sets the floor. National ePrivacy laws can add requirements on top.

In Germany, the Telecommunications and Telemedia Data Protection Act (TTDSG) generally aligns with GDPR for B2B email to corporate addresses. In the Netherlands, Article 11.7 of the Telecommunications Act applies a soft opt-in regime for electronic marketing but includes B2B exemptions for existing business relationships. In the UK post-Brexit, the UK GDPR and PECR apply: B2B cold email to corporate addresses is broadly permitted with a legitimate interest basis, but sole traders and some partnerships are treated as individuals under PECR.

If you are running campaigns across multiple EU markets, a single LIA may cover the GDPR layer, but check whether any target country has stricter national ePrivacy rules that require separate analysis.

For agencies targeting specific markets, outbound lead generation Germany and b2b lead generation agency Europe cover the practical setup in more detail.

How Asphia Handles This

The outbound system Asphia builds runs GDPR compliance as a technical constraint, not an afterthought. Contact data is limited to what is strictly necessary. Every campaign includes a working unsubscribe mechanism. Suppression lists are maintained across sends. A human approves every outreach before it goes out, which means the relevance check (does this contact actually match the LIA we wrote?) happens at the individual level, not just the list level.

That is what GDPR legitimate interest requires in practice: not legal boilerplate, but an actual process where someone is accountable for each send.

If you are building this in your own stack, the done-with-you outbound model covers how to structure a compliant system you own. If you want it run for you, B2B appointment setting service outlines what a managed GDPR-native setup looks like.

The European Data Protection Board’s guidance on legitimate interest is available at gdpr.eu for the formal legal text.

Free resource

Get the signal tier list in your inbox.

We rank signals from S to D to decide who gets a cold email and who does not. You get the list once. No follow-up emails.

FAQ

Is cold email legal under GDPR in Europe?

Yes, B2B cold email can be legal under GDPR when you rely on legitimate interest as your lawful basis. You must process only relevant business contact data, target recipients whose role makes outreach reasonably expected, offer a clear opt-out, and document the balancing test.

What is the legitimate interest balancing test for cold email?

The test has three parts: purpose (you have a real business reason), necessity (cold email is a reasonable way to achieve it), and balancing (your interest does not override the recipient's privacy rights). Document each part before your campaign runs, not after a complaint arrives.

Do I need consent to send cold B2B emails in Europe?

Generally no, for genuine B2B outreach to professional email addresses. GDPR allows legitimate interest as an alternative to consent. However, ePrivacy rules in some EU countries add a layer, so check national law, especially for emails to personal inboxes or sole traders.

What data can I store about prospects under legitimate interest?

Only what is necessary: name, job title, company, work email, and the signal that made the contact relevant. Avoid storing sensitive personal data, personal social profiles, or behavioral tracking data unless you have a separate basis. The necessity principle applies strictly.

How long can I keep prospect data under legitimate interest?

There is no fixed limit in GDPR, but the data must not be kept longer than necessary for the purpose. A common practice is to delete or suppress records after the outreach cycle ends (typically 6 to 12 months) unless the person becomes a customer or actively engages.

What should I include in a legitimate interest assessment (LIA)?

Your LIA should cover: the specific business purpose, why cold email is necessary to achieve it, the type and volume of personal data processed, an honest assessment of recipient expectations, your safeguards (opt-out, suppression list, minimal data), and the conclusion of the balance.

Ahmet Faruk Yilmaz, founder of Asphia

Ahmet Faruk Yilmaz

Founder of Asphia. He builds and runs signal-based B2B outbound engines for lean teams, and has booked meetings with teams at companies across five markets. Writes about cold email, Clay, deliverability, and GTM engineering.

Want this run for you?

Get a free GTM analysis. We show you the exact engine we would build.

Get your free GTM analysis →
Keep reading