GDPR applies to B2B data whenever a record identifies a person, and a named work email does. This page covers what applies, what does not, and where LeadOcean's filters fit. It is not legal advice. Ask a lawyer about your market.
Key takeaways
- A work email such as jane.doe@acme.com is personal data. GDPR does not stop at the office door.
- You need a legal basis to process it. For B2B outreach that is usually legitimate interests, which you must weigh and write down.
- Email marketing has a second rulebook (ePrivacy law, PECR in the UK). It varies by country and by who you email.
- LeadOcean gives you filters for
country,emailTypeandemailStatus. It does not choose your legal basis for you.
What it is
GDPR is the EU regulation that governs how anyone processes personal data, and it covers business contact details whenever they relate to an identifiable person.
The test is in Article 4(1) of the regulation. Personal data is "any information relating to an identified or identifiable natural person" (GDPR, Article 4, September 2026).
A name, a job title and a work email all qualify. A generic address such as info@acme.com usually does not, because no one is identified.
GDPR also reaches outside the EU. Article 3 covers companies established in the Union. It also covers companies elsewhere that offer goods or services to people in the Union or monitor their behaviour there.
How it works
Take a fictional case. Acme, a payroll vendor, wants to email Jane Doe, a finance director at a German company. Here is what GDPR asks of Acme.
- Confirm it is personal data. Jane's name and work email identify her. The record is in scope.
- Pick a legal basis. Article 6(1)(f) allows processing for the legitimate interests of the controller, unless the person's rights override them. Recital 47 says direct marketing may be regarded as a legitimate interest.
- Weigh it and write it down. Ask whether a finance director would expect a payroll pitch. Record the answer. Recital 47 calls for careful assessment of reasonable expectations.
- Tell her. If you got her data from a third party, Article 14 says to tell her. That is within one month at the latest, or at the first message if you use the data to contact her.
- Stop when she objects. Article 21(2) gives her the right to object to direct marketing at any time. Article 21(3) says the data must then no longer be processed for that purpose.
- Check the email rule separately. Whether Acme may send the message at all is a different question, covered next.
Legitimate interests is not the only basis, and it is not automatic. It is the one most B2B teams reach for, so it is the one you must be able to defend.
GDPR vs email marketing law
People treat GDPR as the single law for cold email. It is not. It governs data processing. A second set of rules governs sending the message.
| GDPR | ePrivacy rules (PECR in the UK) | |
|---|---|---|
| What it governs | Collecting, storing and using personal data | Sending electronic marketing messages |
| Source | Regulation (EU) 2016/679 | Directive 2002/58/EC, then national law |
| Applies to | Any person you can identify, including at work | Rules differ for individuals and for companies |
| Typical basis | Legitimate interests or consent | Often consent for individuals, looser for companies |
| Right to object | Yes, Article 21 | Sender identity and an opt-out in each message (UK) |
| Set by | One EU text | Each country, so it varies |
The ePrivacy Directive leaves much of the company case to member states. Article 13(5) says they must ensure the legitimate interests of subscribers other than natural persons are sufficiently protected (Directive 2002/58/EC, September 2026).
In the UK, the ICO says you can email any corporate body, such as a company or an LLP. Sole traders and some partnerships count as individuals. You need their consent, or a past purchase of a similar product where they were offered an opt-out (ICO, September 2026). The ICO notes this guidance is under review after the Data (Use and Access) Act.
When it matters
Cold email to EU contacts
This is where both rulebooks meet. You need a defensible basis for holding the record and a country-specific answer on whether you may send. Rules differ by country, so check each market you send to.
Personal addresses at work
An address like jane.doe@acme.com names a person, and the ICO flags data protection questions for employee addresses of this kind. A personal Gmail address on a business record is harder still. Filter by email type and treat the two groups differently.
Sole traders and small firms
These sit on the "individual" side of email law in the UK. A one-person consultancy is not treated like a limited company. Exclude them from sends or get consent.
Buying or enriching data from a provider
You hold the data now, so you decide why you use it. Article 14 duties apply because you did not collect it from the person yourself. Keep a note of where each list came from and when.
How LeadOcean handles it
LeadOcean does not decide your legal basis, and nothing on this page claims any dataset is compliant with anything. What it gives you is control over who ends up in a list and how fresh each record is.
The filters that map to the points above:
country: pick the countries you have checked. Send only to those.emailType: separateworkaddresses frompersonalones.emailStatus: keep to sendable statuses and droprisky,roleandspam_trapaddresses.fetched_at: every record carries the date it was last fetched. The dataset is refreshed monthly.
On 2026-09-30, a LeadOcean count of mailable people located in Europe returned 52.7M. That filter is the whole continent, so it includes countries outside the EU and EEA, such as the UK. It is a size check, not a lawful audience.
Size a segment for free before you pull any rows. Send count=true as a query parameter with limit 1. meta.total is capped at 100,000.
curl -X POST "https://api.leadocean.io/v1/people/search?count=true" \
-H "x-api-key: $LEADOCEAN_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"country": ["DE"],
"jobFunction": ["Finance & Accounting"],
"jobLevel": ["Director"],
"emailType": ["work"],
"emailStatus": ["verified", "catch_all_valid", "catch_all"],
"limit": 1
}'The response has an empty data array and meta.countOnly set to true. Remove count=true to pull rows. Each person returned counts one record.
Free gives 1,000 records, one-off, no card. Pro is $499 a month, flat, on /pricing. For a market-by-market view of how providers handle these questions, see the GDPR-focused provider comparison. For UK buyers, see B2B data providers in the UK. For the wider field, see best B2B databases.
FAQ
Does GDPR apply to B2B data?
Yes, when a record relates to an identifiable person. A named work email, job title and employer all count. Company-level facts such as revenue or headcount are not personal data on their own.
Do I need consent to cold email a business contact?
GDPR itself does not require consent for processing. Legitimate interests can be a basis. The email rules are separate, and some countries require consent for individuals. Check the law for each country you send to.
Is a role address like info@acme.com covered?
Usually not, because it does not identify one person. If a person reads it and the address names or points to them, treat it as personal data. LeadOcean marks the role addresses it detects with the role status.
What do I do when someone objects?
Stop using their data for direct marketing and add them to a suppression list. Article 21(3) says the data may no longer be processed for that purpose. Screen every new list against your suppression list.
Does LeadOcean tell me which country's rules apply?
No. It gives you the country field and filter so you can limit a list to the markets you have reviewed. The legal call is yours. This is not legal advice.
Build a country-filtered list and count it free
Free to start. No credit card. 1,000 records to spend whenever you like.
Get your free API key →