Scope — not legal advice: This is an operating control for B2B teams, not a legal opinion or a promise that a campaign is lawful. It covers the EU baseline and uses Germany as a national example. The answer changes with the country, channel, relationship, audience, source, and message. Have qualified counsel or your privacy function approve the actual campaign. The official sources linked below were checked on August 8, 2026 and should be checked again before launch.
A contact record is not “GDPR-compliant.” A specific organisation processes specific data for a specific purpose, then chooses a communication channel governed by its own rules. The useful decision is therefore not Can sales use this list? It is What evidence allows this defined campaign to proceed, and what would stop it?
This guide turns that question into a campaign gate with three outcomes:
- PASS: the required evidence exists, the responsible reviewer has approved it, and no blocking condition remains;
- REVIEW: a fact or legal interpretation is unresolved, so the record or campaign cannot activate yet;
- BLOCK: a mandatory condition fails. More enrichment or a different sales message does not cure it.
Start with two legal questions, not one compliance label
For most EU outbound work, the team has to map two distinct layers.
- Personal-data processing: Why may the organisation collect, select, enrich, store, disclose, and otherwise use information about an identifiable person? The GDPR governs this layer, including purpose limitation, data minimisation, accuracy, storage limitation, lawful basis, transparency, security, and individual rights.
- The communication channel: May the organisation use email, a phone call, an automated calling system, a social-network message, or another channel for this marketing communication? Article 13 of the ePrivacy Directive sets an EU framework for unsolicited communications, but Member States implement and supplement it through national law.
A legitimate-interest assessment is not permission to send an email. Equally, consent or a national channel exception does not remove every obligation around source transparency, data quality, rights, security, or retention.
The relationship between the two layers is not always a simple double test. In its November 2025 judgment in Inteligo Media, C-654/23, the Court of Justice held that processing within the specific existing-customer exception in Article 13(2) of the ePrivacy Directive did not require a second Article 6 GDPR assessment for the same processing. That was a fact-specific ruling about the scope of the ePrivacy exception and Article 95 GDPR. It is not a general exemption for cold prospecting. Record which rule applies and have counsel resolve the interaction rather than assuming either “two bases are always required” or “ePrivacy replaces the GDPR.”
Turn one uncontrolled prospect file into a reviewable gate
The commercial problem usually appears before anyone debates a sending tool: Revenue Operations has a CSV or workbook with mixed sources, missing dates, uncertain countries, several possible channels, and no named reviewer. A “do not contact” note may sit in another system. The same row can look sales-ready while still being legally unresolved.
Leadbase can turn that file into a shared working record for pre-activation review. Import the CSV, XLSX, or XLSM through the Assistant, inspect the proposed structure and a sample of values, then model the decision with typed Sheet columns. A useful minimum is:
This is where Leadbase’s documented product controls matter:
- Evidence stays attached to the decision. Add focused enrichment columns using only the context fields the research needs. Review the concise summary, confidence, and source links before accepting a result. Incomplete inputs or uncertain research can end with no usable result instead of a fabricated value.
- Human approval stays visible. Use the Assistant’s Ask for approval mode when research or edits affect unfamiliar or broad row sets. Sheet roles separate viewing, editing, management, and ownership; they do not replace the legal review role named in the campaign record.
- The working record has recoverable history. Sheet history is immutable, important revisions can be named, and managers or owners can restore a prior version. Name the version that privacy or legal reviewed before changing inputs or preparing a handoff.
- Handoff remains an explicit event. Export a CSV only after the designated reviewer has confirmed the campaign state and destination. A CSV does not inherit later permission changes, so the receiving CRM, sequencer, or calling system must re-check suppression and enforce every block.
The result is not a “compliant lead list.” It is a reviewable evidence trail that shows what is known, what is unresolved, who decided, and which rows must not move. Leadbase does not make PASS true; it makes the evidence and decision boundary inspectable before activation.
If an existing prospect file is already circulating without that boundary, book a Leadbase working session to turn one real file into a pre-activation campaign gate. The session should end with a reviewable field model, a sample containing both source-backed results and rows where research produces no usable result, named approval points, and a controlled handoff design—not a legal conclusion or sending permission.
Legitimate interest is a test, not a sales default
Work contact details can still be personal data when they identify or relate to a person in a professional role. Every processing operation needs an applicable basis unless a more specific rule displaces that requirement for the same matter.
Teams often consider Article 6(1)(f), legitimate interests, for B2B research. Recital 47 says direct marketing may be regarded as a legitimate interest. It does not say that every database, enrichment, audience, or campaign passes automatically. In KNLTB, C-621/22, the Court of Justice restated three cumulative conditions:
- the controller or a third party pursues a lawful, legitimate interest;
- the processing is necessary for that interest, including whether a less intrusive means would work as effectively; and
- the person's interests, rights, and freedoms do not override it.
A usable legitimate-interest assessment, often called an LIA, should therefore record:
- the precise commercial purpose and who benefits;
- each data operation covered, not only the final send;
- why every field and operation is necessary;
- the person's reasonable expectations given the source and existing relationship;
- likely impact, message frequency, scale, profiling, and use of inferred data;
- less intrusive alternatives considered;
- safeguards such as narrow targeting, review before contact lookup, easy objection, short retention, and access controls; and
- the owner, approval date, evidence reviewed, and trigger for reassessment.
If the audience criteria use health, political views, religion, trade-union membership, sexual orientation, or another special category under Article 9, set BLOCK until specialist review identifies a valid exception and the processing design satisfies it. “Publicly visible” and “professionally relevant” are not general Article 9 exceptions. High-risk profiling, large-scale monitoring, or novel combinations of data may also require a data protection impact assessment rather than an ordinary campaign review.
Create a country-by-channel matrix before activation
EU rules are not a single B2B cold-outreach licence. Build the matrix for every destination country and every intended channel. Germany illustrates why.
For German B2B email, a published work address, an address returned by a provider, or an inferred email pattern is not by itself prior express consent. For a German B2B call, account fit alone does not establish presumed consent. For another Member State, replace the German column with that country's current implementation, regulator guidance, and case law.
Do not let records silently move between channels. An email BLOCK does not become a phone PASS because the team has a number. The new channel needs its own decision.
Provenance is required evidence, not decorative metadata
Indirect collection is common in B2B prospecting. A reviewer should be able to reconstruct where each relevant personal field came from and what happened to it later.
At minimum, retain:
- the source type, exact source or provider, source URL where applicable, and retrieval date;
- whether the source was public, supplied by the person, created in a customer relationship, inferred, or supplied by another controller;
- the original value, any inferred or enriched value, confidence or verification state, and last check;
- the purpose for which the field was collected and every approved downstream use;
- the recipient systems or exports; and
- corrections, objections, deletion decisions, and the systems to which they propagated.
A provider's “verified” label is not proof that your organisation may collect or use the field. Obtain the provider's source description, role analysis, privacy information, correction route, subprocessor list, and transfer documentation. Then test the actual output: can a reviewer find the source, date, uncertainty, and record history after export?
Design Article 14 transparency into the first contact
When data was not obtained from the person, Article 14 GDPR normally requires the controller to provide specified information no later than one month after obtaining it. If the data is used to communicate with the person, the deadline is no later than the first communication; if disclosure comes first, it is no later than that first disclosure. The EDPB's guide to individual rights explains these timing rules and notes that the “disproportionate effort” exception has a high threshold.
The notice has to reflect the actual processing. It should cover, as applicable:
- controller identity and contact details, and the data-protection contact;
- purpose and lawful basis, including the legitimate interests pursued when Article 6(1)(f) is used;
- categories of personal data and the source, including whether it was publicly accessible;
- recipients or recipient categories, transfers outside the EEA, and relevant safeguards;
- retention period or the criteria used to determine it;
- rights, the direct-marketing objection, complaint route, and how to exercise them; and
- relevant automated decision-making or profiling information.
A privacy-policy link can support layered information, but it does not rescue a misleading sender identity, an irrelevant generic notice, or a message that hides why the person was selected. Put the identity, commercial reason, and objection route where the person can understand them without an investigation.
Use PASS, REVIEW, and BLOCK as real system states
The states must control activation, not merely colour a spreadsheet.
Define transitions explicitly. Only the designated review role can move REVIEW to PASS. A source refresh, new country, new channel, changed offer, changed vendor, expired retention period, or objection should automatically reopen or block the decision.
The campaign evidence record
Keep one short campaign record and row-level evidence for exceptions. The campaign record should contain:
- campaign ID, owner, reviewer, version, and decision date;
- one-sentence purpose and measurable audience definition, including exclusions;
- countries, channels, sender identity, offer, frequency, and planned volume;
- personal-data fields, source classes, provenance fields, and freshness limits;
- lawful basis by operation and the LIA, consent proof, or other supporting record;
- country-by-channel rule, official authority, interpretation owner, and review date;
- Article 13/14 notice version and delivery point;
- global and channel-specific suppression inputs, last test, and downstream destinations;
- controller, joint-controller, and processor roles; contracts, subprocessors, and transfer mechanism;
- retention or review date, access model, rights owner, and incident route; and
- final PASS, REVIEW, or BLOCK decision with reasons.
Here is a deliberately blocked, fictional record. It shows why account relevance cannot substitute for channel permission.
Pre-send means pre-export
Run the gate before personal data leaves the controlled research workspace, not after a sequence is populated.
- Freeze the campaign version, audience query, exclusion rules, countries, channels, and message template.
- Sample accepted, rejected, and borderline rows. Confirm that source links, dates, role evidence, and uncertainty survive.
- Minimise fields before contact lookup. Do not acquire a mobile number, personal email, or inferred attribute merely because a provider can return it.
- Check global and channel-specific suppression immediately before activation, then confirm that exports and integrations preserve the block.
- Verify sender identity, the Article 14 delivery point, the objection route, and the mailbox or team that handles rights requests.
- Confirm vendor roles, contracts, transfer safeguards, access permissions, and deletion/correction paths.
- Record counts, reviewer, decision time, exceptions, and the exact rows exported.
If any mandatory check cannot produce evidence, use REVIEW or BLOCK. “The campaign launches today” is not an exception state.
Objections, rights, retention, and incidents are part of the campaign
Under Article 21(2) and (3) GDPR, a person may object at any time to processing for direct marketing, including related profiling, and the data must no longer be processed for that purpose. Article 21(4) requires the right to be brought explicitly to the person's attention no later than the first communication. The German Federal Data Protection Commissioner gives the same operational reading in its Article 21 guidance.
Treat “stop,” “not interested—do not contact,” an unsubscribe, and equivalent language as inputs to one owned process. Record the time, source, scope, and propagation result. Stop queued and future marketing actions across the CRM, sequencer, call tasks, exports, enrichment refreshes, and re-imports. Under a counsel-approved policy, retain only the minimum restricted identifier needed to prevent renewed contact, with a documented basis and retention rule; do not use a suppression record for targeting.
The same operating model must locate data for access, correction, restriction, and erasure requests. Verify identity proportionately and route doubtful cases to the privacy owner rather than either disclosing data casually or demanding excessive identification. Corrections and valid deletion decisions must reach downstream recipients where required.
Set retention from the defined purpose, data freshness, objection state, and legal duties. “Until the CRM is cleaned” is not a retention period. At the deadline, delete, anonymise, or conduct the documented review before any renewed use.
Finally, define an incident path. A suppression failure, accidental export, wrong recipient, exposed list, or vendor notification should pause the affected motion, preserve logs, identify systems and records, and reach privacy and security owners immediately. Article 33 can require a controller to notify the competent authority within 72 hours of becoming aware of a personal-data breach unless it is unlikely to risk individuals; processors must notify the controller without undue delay. The EDPB's breach guide explains the assessment and documentation steps. The campaign team should escalate facts, not decide alone that an incident is harmless.
Resolve vendor roles before relying on a contract label
A data provider, research service, CRM, sequencer, and your organisation do not all become processors because a standard agreement says “processor.” Role follows who actually determines purposes and essential means. The EDPB's controller and processor guide summarises the responsibilities and Article 28 contract requirements.
For each vendor and data flow, record:
- the functional role for collection, matching, enrichment, storage, disclosure, and suppression;
- the controller-to-controller or controller-to-processor basis and contract;
- subprocessor approval and change process;
- storage and support locations and any Chapter V transfer mechanism;
- security, access, return/deletion, correction, audit, and incident obligations; and
- what happens when the campaign is blocked or the person exercises a right.
A data-processing agreement is not a lawful-basis assessment, and standard contractual clauses are not permission to market. They solve different parts of the system.
Where the Leadbase operating gate stops
Leadbase publishes this article and sells B2B discovery and enrichment software. Its role here is deliberately operational: structure the working file, keep research evidence and uncertainty close to each decision, record the designated review, preserve a recoverable version, and prepare a deliberate handoff.
Leadbase does not supply consent, establish presumed consent, choose a lawful basis, approve an LIA, interpret national marketing law, run the organisation’s suppression system of record, or make a campaign lawful. A Leadbase field labelled PASS is not a legal conclusion and cannot override the controls in a CRM, sequencer, dialler, or another sending system. Keep consent, suppression, channel permission, and sending enforcement in their designated systems, and test that every block survives export and integration.
What remains for local legal review
Before activation, counsel or the responsible privacy function still needs to decide:
- the applicable Member State laws and competent authorities;
- the exact classification of email, phone, social, postal, and automated messages;
- the lawful basis and interaction with specific ePrivacy rules;
- whether consent or a national exception is valid and adequately evidenced;
- the LIA, any Article 9 condition, and whether a DPIA is required;
- controller, joint-controller, processor, and international-transfer positions;
- notice language, objection scope, suppression design, retention, and rights handling; and
- the breach and regulator-escalation path.
An executable gate cannot guarantee legality. It does something more useful than a generic checklist: it makes the facts, authority, owner, uncertainty, and stopping decision visible before a campaign creates harm.
If the gap is the operating design rather than the legal opinion, schedule a Leadbase review of the campaign gate and handoff workflow. We can inspect whether the working Sheet preserves provenance, unresolved rows, named decisions, version history, and the suppression reference before export. This review cannot provide consent, choose a lawful basis, establish presumed consent, control the suppression system, or grant permission to send; those decisions remain with the responsible legal or privacy function and the designated systems.








