2026-09-28 · 6 min read
GDPR-aware B2B prospecting comes down to six habits: rely on legitimate interest only after you have written down and balanced it, tell people where you got their details within a month (Article 14), make opting out easy and permanent, delete data you no longer need on a fixed schedule, keep a suppression list that every tool checks, and treat information about named people differently from information about companies. If you can show each of these on request, you are in a far stronger position than most outbound teams.
The checklist below turns each habit into concrete steps. It reflects how we think about our own data work at Syntora Ai.
This post is general information, not legal advice. Rules differ between countries, and national electronic marketing laws sit alongside the GDPR. Speak to a qualified adviser about your specific situation.
Does GDPR apply to B2B prospecting?
Yes, whenever you process personal data about people in the EU, and the UK has its own version of the same rules. A work email such as firstname.lastname@company.com identifies a person, so it is personal data even though it is a business address. Information purely about a company, such as its registered name, legal status and registered address, is generally not personal data. Sole traders are an exception, because the business and the person are the same.
This distinction is the foundation of everything else, so start there.
1. Have you separated business data from personal data?
- Keep company facts (name, register number, status, website, general inbox, switchboard number) apart from data about named individuals.
- Tag each field so you know which category it is in.
- Apply stricter rules, shorter retention and tighter access to the personal fields.
- Prefer company-level channels, such as a general inbox published on the company's own website, where they serve your purpose.
This is how we structure SyntoraData: company records built from registers and companies' own websites, with every fact carrying its source and the date it was seen.
2. Can you justify legitimate interest in writing?
Most B2B prospecting relies on legitimate interest as its lawful basis. That only works if you can show you did the thinking. Write a legitimate interests assessment that covers three tests:
- Purpose. What is your interest? For example, offering a product relevant to the person's professional role.
- Necessity. Do you need this person's data to achieve it, or would a company-level contact do?
- Balance. Would this person reasonably expect to hear from you, given their role and how you found them? What is the impact on them?
Narrow targeting makes the balance easier. Contacting the head of finance at a manufacturer about accounting software is easier to justify than emailing every employee at every company in a country. Keep the assessment, date it, and review it when your campaign changes.
3. Do you send an Article 14 notice?
When you collect personal data from somewhere other than the person, Article 14 requires you to tell them. The deadline is within a reasonable period and at the latest one month after you obtain it, or at your first contact with them if that comes sooner.
The notice should cover, in plain language:
- Who you are and how to contact you
- What data you hold and where you got it
- Your purpose and lawful basis, including the legitimate interest you rely on
- How long you will keep it
- Their rights, including to object, access, correct and erase
- Their right to complain to a supervisory authority
In practice many teams put a short version in the first email with a link to a full privacy notice. Being specific about the source is much easier when your data records the source for every field. Our post on B2B data provenance explains why that matters.
4. Is opting out easy and permanent?
- Include a clear, one-step way to opt out in every message.
- Honour an objection to direct marketing immediately and without argument. Under the GDPR this right is absolute.
- Do not ask people to log in, fill in a long form or give a reason.
- Confirm the opt-out has been processed if they ask.
- Make sure the opt-out reaches every tool and every team member who might contact them.
5. Do you have a retention schedule?
Prospect data should not live forever. Set retention periods by category and enforce them automatically:
- Prospects you never contacted: delete after a defined period.
- Prospects who did not reply: delete after a shorter period following last contact.
- Raw imports and enrichment staging files: delete quickly once processed.
The exact periods are your decision, and they should match what your assessment says. What matters is that they are written down, applied by a scheduled job, and logged. A retention policy that only exists in a document does not protect anyone.
6. Does every tool check one suppression list?
A suppression list holds people who must not be contacted: those who opted out, objected, asked for erasure, or should be excluded for another reason.
- Store a minimal identifier, such as a hashed email address, so you can block someone without keeping their full profile.
- Check the list before every import, every enrichment run and every send.
- Keep it in one place that all your tools read from.
- Never delete someone from the suppression list as part of retention, or they may come back in the next import.
7. Do you know where your data came from?
- Record the source of every personal data field and the date you obtained it.
- Check that your supplier's licence allows your use.
- Avoid sources that collected data in ways you would not be comfortable explaining to the person, such as scraping behind logins.
- Verify email addresses before use to avoid contacting the wrong person. Our guide to verifying an email without sending one covers how.
8. Can you handle a data subject request?
When someone asks what you hold about them, you generally have one month to respond. Prepare before the first request arrives:
- A way to find every record about a person across your tools
- A template response listing the data, its sources and your purpose
- A process for erasure that also adds them to the suppression list
- A log of requests and when they were answered
9. Have you checked electronic marketing rules?
The GDPR is not the only law involved. Many countries have separate rules on unsolicited electronic marketing, and some treat emails to corporate addresses differently from emails to individuals. Check the rules for each country you send into, not only your own.
Working with Syntora Ai
Syntora Ai builds data pipelines with source tracking, retention jobs, suppression checks and request handling built in, through our growth and data practice. We apply the same approach to SyntoraData. If you want your prospecting stack set up this way, write to hello@syntorahq.ai or use the contact page.