GDPR and Cold Email: Which Data You May Actually Use
The most common question in EU prospecting: is cold email even allowed? The answer is yes, with conditions — and they come from two separate sets of rules that people routinely confuse.
This is not legal advice. It's an explanation of how to build a process with as little risk as possible. When in doubt, talk to a lawyer.
Two independent regimes
1. GDPR — may you process the data
GDPR protects personal data of individuals. The key distinction:
contact@salonaga.com— a generic company address, usually not personal data,anna.kowalska@salonaga.com— identifies a specific person, is personal data,- sole traders — company and personal data often overlap; treat carefully.
For generic addresses, the usual lawful basis is legitimate interest (Art. 6(1)(f) GDPR) — direct marketing is explicitly named in Recital 47 as an example of such an interest.
2. ePrivacy — may you send the message
This is a separate matter and it's stricter. Rules on unsolicited commercial communication by electronic means generally require consent — but in practice what matters is whether the address is a generic business one and whether the message concerns that business's activity.
A safe practical rule:
You write to a business, at a generic business address, about something directly related to its commercial activity, as a first contact to establish whether there's interest.
What to do — a checklist
- Send to generic addresses.
contact@,office@,info@— not to named ones unless you must. - Relevance over volume. The message has to make sense for that specific business. That's not just ethics — it's also the argument that you're acting on legitimate interest rather than spamming.
- Identify yourself clearly. Company name, registration number, address, who's writing. No hidden sender.
- Make "no" easy. One line: "If this isn't for you, reply with one word and I won't write again." Honour it immediately.
- Keep a suppression list. Anyone who says no never gets another message. It must be a durable record, not a note.
- Have your privacy information ready. If someone asks where you got their data, answer straight away: source (public Google listing), purpose, basis, right to object.
- Minimise data. Collect only what you need to assess the lead. Don't build profiles of individuals.
- Don't resell the list. Data gathered under your legitimate interest serves you, not a data-broking business.
What to avoid
- Mass sending with undifferentiated content.
- Named addresses guessed from a pattern (
first.last@). - Ignoring objections — the fastest route to a complaint.
- Hiding who you are.
- Collecting data "just in case", with no purpose.
Why quality is also legal protection
The more a message is tailored to a specific business, the stronger the argument that it's direct marketing under legitimate interest rather than bulk spam. The incentives line up: precise targeting raises reply rates and lowers risk at the same time.
That's why it's worth contacting only businesses where there's a concrete reason. Lead Radary detects that reason automatically — it works exclusively on public company data from Google Maps and shows you why a given business is a sensible recipient.
For the sending side — which countries allow B2B cold email and which do not — see is cold email legal in Europe.
Summary
- GDPR and electronic-communication rules are two different things.
- Generic business addresses + activity-related content = the safest scenario.
- Always: clear identification, easy opt-out, durable suppression list.
- Relevance protects you more than any footer disclaimer.
