Lead Radary
BlogPricing
Start free

GDPR and Cold Email: Which Data You May Actually Use

By Max Swillo·Published 2026-08-05·3 min read

The most common question in EU prospecting: is cold email even allowed? The answer is yes, with conditions — and they come from two separate sets of rules that people routinely confuse.

This is not legal advice. It's an explanation of how to build a process with as little risk as possible. When in doubt, talk to a lawyer.

Two independent regimes

1. GDPR — may you process the data

GDPR protects personal data of individuals. The key distinction:

  • contact@salonaga.com — a generic company address, usually not personal data,
  • anna.kowalska@salonaga.com — identifies a specific person, is personal data,
  • sole traders — company and personal data often overlap; treat carefully.

For generic addresses, the usual lawful basis is legitimate interest (Art. 6(1)(f) GDPR) — direct marketing is explicitly named in Recital 47 as an example of such an interest.

2. ePrivacy — may you send the message

This is a separate matter and it's stricter. Rules on unsolicited commercial communication by electronic means generally require consent — but in practice what matters is whether the address is a generic business one and whether the message concerns that business's activity.

A safe practical rule:

You write to a business, at a generic business address, about something directly related to its commercial activity, as a first contact to establish whether there's interest.

What to do — a checklist

  1. Send to generic addresses. contact@, office@, info@ — not to named ones unless you must.
  2. Relevance over volume. The message has to make sense for that specific business. That's not just ethics — it's also the argument that you're acting on legitimate interest rather than spamming.
  3. Identify yourself clearly. Company name, registration number, address, who's writing. No hidden sender.
  4. Make "no" easy. One line: "If this isn't for you, reply with one word and I won't write again." Honour it immediately.
  5. Keep a suppression list. Anyone who says no never gets another message. It must be a durable record, not a note.
  6. Have your privacy information ready. If someone asks where you got their data, answer straight away: source (public Google listing), purpose, basis, right to object.
  7. Minimise data. Collect only what you need to assess the lead. Don't build profiles of individuals.
  8. Don't resell the list. Data gathered under your legitimate interest serves you, not a data-broking business.

What to avoid

  • Mass sending with undifferentiated content.
  • Named addresses guessed from a pattern (first.last@).
  • Ignoring objections — the fastest route to a complaint.
  • Hiding who you are.
  • Collecting data "just in case", with no purpose.

The more a message is tailored to a specific business, the stronger the argument that it's direct marketing under legitimate interest rather than bulk spam. The incentives line up: precise targeting raises reply rates and lowers risk at the same time.

That's why it's worth contacting only businesses where there's a concrete reason. Lead Radary detects that reason automatically — it works exclusively on public company data from Google Maps and shows you why a given business is a sensible recipient.

For the sending side — which countries allow B2B cold email and which do not — see is cold email legal in Europe.

Summary

  • GDPR and electronic-communication rules are two different things.
  • Generic business addresses + activity-related content = the safest scenario.
  • Always: clear identification, easy opt-out, durable suppression list.
  • Relevance protects you more than any footer disclaimer.

Find your first leads today

Lead Radary finds local businesses that need your service — with a reason and a ready message.

Start free