Cold email under the GDPR: legitimate interest, the balancing test, and ePrivacy
GDPR doesn't ban B2B cold email. Here's the legitimate-interest basis senders actually rely on, what the balancing test requires, and how ePrivacy layers on top.
By Gabriel Lara, Developer Relations, Norbelys
Founder-reviewed ·How we research and correct articles
If you send B2B cold email to contacts in the EU, you’ve probably heard two contradictory things: that GDPR makes cold email illegal, and that it doesn’t apply to work email addresses at all. Neither is right. GDPR regulates the processing of personal data — a business email address tied to a named individual counts — but it also names direct marketing as a legitimate reason to process that data, provided you can show your work.
The legal basis question comes first
Every processing of personal data under GDPR needs a lawful basis under Article 6. For cold email, senders typically reach for one of two:
- Consent — the recipient affirmatively opted in before you emailed them. This is the strongest basis but obviously incompatible with cold outreach: if you already had consent, it wouldn’t be cold.
- Legitimate interest (Article 6(1)(f)) — you can process the data without consent if your interest in doing so isn’t overridden by the individual’s rights and expectations.
GDPR’s own recitals point straight at legitimate interest for this case. Recital 47 states plainly that “the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.” That’s the sentence every B2B sales and marketing team building a GDPR-compliant outreach program eventually cites — and it’s also the sentence that gets misquoted as a blanket permission slip. It isn’t one. The same recital requires that the individual’s rights and reasonable expectations aren’t overridden, and that’s where the actual test lives.
What the balancing test actually requires
Legitimate interest isn’t “we have a reason, so we’re covered.” It’s a three-part, documented assessment — commonly called a Legitimate Interest Assessment (LIA) — that the EDPB’s guidance on Article 6(1)(f) structures around three questions:
- Purpose test — is there a genuine, specific, and lawful interest behind the processing? “We want more customers” is a business goal, not a documented purpose; “we’re contacting people whose role plausibly involves evaluating tools like ours” is closer to what a defensible purpose looks like.
- Necessity test — is processing this data actually necessary to achieve that purpose, or is there a less invasive way to do it? If you could achieve the same goal without holding or emailing personal data, the necessity leg is weaker.
- Balancing test — do the individual’s rights, freedoms, and reasonable expectations outweigh your interest? This is where context matters most: a marketing director at a software company receiving a relevant pitch about developer tooling, at their published work address, is a very different balance than a junior employee at an unrelated company receiving mass-blasted, irrelevant outreach at a personal-looking address.
The balancing test is also where volume and precision cut against each other. A regulator looking at ten thousand identical emails sent in an hour is going to ask how you performed an individualized balancing assessment for each recipient — and “we didn’t, we just ran a list” is not a good answer. Segmentation, relevance to the recipient’s actual role, and a working, honored opt-out are the practical ingredients that make a legitimate interest claim defensible instead of theoretical.
Recipients don’t lose their rights when you rely on legitimate interest
Legitimate interest doesn’t mean the recipient has no say. GDPR gives every data subject a standing right to object to processing carried out for direct marketing under legitimate interest (Article 21), and that objection has to be honored, no balancing test negotiation required — once someone objects to marketing, the processing for that purpose stops. That’s a structurally different mechanism from consent withdrawal, but the practical effect for a cold-email program is the same: an unsubscribe or reply asking to stop has to actually stop things, immediately and permanently, not “once we get around to updating the list.”
This is also where GDPR intersects with a topic covered in more depth elsewhere: if a contact asks you to delete their data rather than just stop emailing them, that’s the erasure right, and it comes with its own separate mechanics and exceptions — see GDPR right to erasure for cold email for how that actually works in a sending platform.
Where ePrivacy comes in — and why it’s a different law
Here’s the part that trips people up: GDPR governs data processing. It does not, by itself, set the specific rule for “can I email this person without asking first.” That rule comes from a separate piece of legislation, the ePrivacy Directive (2002/58/EC), Article 13 of which requires prior opt-in consent for unsolicited commercial email — with an exception, commonly called the “soft opt-in,” when the recipient’s details were collected in the context of an existing sale or service relationship.
Two things worth knowing about that layer:
- It’s implemented per member state, not as one uniform EU-wide rule. Each country transposed the Directive into its own national law, and the soft-opt-in exception in particular is not applied identically everywhere — some national laws read it more narrowly for B2B contexts than others. Don’t assume the rule in one EU country automatically matches another.
- It’s still a Directive, not a Regulation, as of this writing. The European Commission had proposed a new ePrivacy Regulation to replace the 2002 Directive with one directly-binding EU-wide text, but withdrew that proposal in its 2025 work programme after failing to reach consensus, according to the European Parliament’s own legislative tracker. The 2002 Directive — and each country’s national transposition of it — remains the operative law. Check current status before assuming otherwise; EU digital legislation moves.
The practical upshot for a B2B sender: GDPR’s legitimate-interest analysis tells you whether you’re allowed to hold and use the contact’s data at all. ePrivacy’s national implementation tells you whether you’re allowed to send that specific unsolicited email. You generally need both to line up — a solid legitimate-interest case doesn’t override a stricter national email-marketing rule, and vice versa.
What this looks like in practice
Put together, a defensible GDPR-era B2B cold-email program tends to share a few traits:
- Relevance is doing real legal work, not just improving reply rates. Targeting people whose role plausibly involves the thing you’re pitching, at a business address tied to that role, is part of what makes the balancing test defensible — not just good targeting practice.
- The assessment is written down, per campaign type or audience segment, not reconstructed after the fact if a regulator asks.
- Every message identifies the sender clearly and gives a working way to object or opt out, honored immediately.
- Authentication and unsubscribe hygiene stay disciplined for the same reason they matter everywhere — see how Norbelys enforces U.S. anti-spam law for the deliverability-side rules that run in parallel with data-protection law, and DMARC monitoring for keeping your sending domain’s authentication honest.
- Data retention has an end date. Contacts who never respond and were never customers don’t get held indefinitely “just in case” — legitimate interest for direct marketing weakens the longer you hold data without activity.
If you’re also sending into the U.S. or Canada, the legal basis changes shape entirely — CAN-SPAM is opt-out by default, and CASL is opt-in with its own separate B2B carve-outs. For the side-by-side comparison, see CAN-SPAM vs. GDPR vs. CASL compared and, for the Canadian specifics, cold email rules: Canada’s CASL. The UK deserves its own read too, since UK GDPR started as a copy of this same regulation and has since diverged in specific, documented ways — see cold email rules: the UK post-Brexit.
Frequently asked questions
Is cold email illegal under GDPR?
No. GDPR does not ban B2B cold email outright. It requires a lawful basis for processing the recipient's personal data, and direct marketing is explicitly named in Recital 47 as a use case that can qualify for the legitimate-interest basis, provided a documented balancing test supports it and the recipient's right to object is honored.
What is the legitimate interest balancing test?
It is a three-part assessment commonly structured as purpose, necessity, and balancing: whether there is a genuine specific interest behind the processing, whether processing the data is actually necessary to achieve it, and whether the individual's rights and reasonable expectations are outweighed by that interest. Regulators expect this assessed and documented per campaign or audience type, not asserted after the fact.
Does GDPR or ePrivacy govern whether I can email someone without asking first?
That specific rule comes from the ePrivacy Directive (2002/58/EC), implemented differently in each EU member state, not from GDPR directly. GDPR governs whether you have a lawful basis to process the recipient's personal data at all. In practice a compliant program needs to satisfy both frameworks together.
Does a work email address get GDPR protection?
Yes, if it identifies or is reasonably linkable to a natural person. A named individual's business email address is personal data under GDPR regardless of whether it is used for work purposes.