GDPR cold email scenarios 2026: practical examples and mistakes
Concrete GDPR B2B cold email scenarios in 2026 — what's allowed, what's borderline, what's prohibited. Practical examples and documentation.
On this page
- Base principle: every action is a scenario
- High-acceptance scenarios (low risk)
- Borderline scenarios (medium risk, require documentation)
- High-risk scenarios (generally avoid)
- Concrete documentation to maintain
- Reactions to problematic cases
- Specific jurisdiction differences in Europe
- Most frequent mistakes that draw DVI attention
- Practical pre-campaign checklist
- If you want us to handle this for you
- Next step
In the previous GDPR article we covered the foundation — is cold email lawful (yes, in B2B context) and how the legitimate interest test works. This article is the next layer: concrete practical scenarios that are accepted and prohibited, and how to document them properly.
If the previous article was “how to understand the basics”, this is “what to actually do in your weekly work”.
Disclaimer: This isn’t legal advice. It’s practical experience from 100+ Latvian client projects. For specific situations (regulated industries, sensitive data types), consult a lawyer.
Base principle: every action is a scenario
Most GDPR questions in B2B cold email context arise because the legislator hasn’t specifically addressed it. Instead it’s a general regulation that must be applied to each specific action.
In practice this means: you don’t make “is cold email legal?” decision once and for all time. You make it for each new campaign configuration — different target market, new data source, new segmentation approach.
So below: not one general “allowed/prohibited” list, but 20+ concrete scenarios.
High-acceptance scenarios (low risk)
Scenario 1: B2B SaaS to another B2B SaaS Head of Growth
You send: “Hi [Name], noticed [competitor] recently raised [funding amount]. If budget conversations about marketing automation open up for you too, we do this specifically in the SaaS segment…”
Data source: Apollo (contact publicly registered as “Head of Growth at TechCo”)
GDPR assessment: High acceptability. Personalized, professional context, legitimate B2B interest, proper data source.
Scenario 2: Manufacturing company to another manufacturer’s Purchasing Manager
You send: “Hi [Name], our components are used in [specific industry] and I think it could be of interest given your recently announced product expansion…”
Data source: LinkedIn Sales Navigator + verification
GDPR assessment: High acceptability. Specific industry, professional role, legitimate B2B content.
Scenario 3: Consulting services to Marketing Director
You send: “Hi [Name], your recently published article on [topic] resonated with work we’re doing with [client-similar company]. Would 15 minutes be worth it to discuss a concrete approach?”
Data source: Public articles + company email domain check
GDPR assessment: High acceptability. Context is relevant, shows professional activity, not aggressive.
Borderline scenarios (medium risk, require documentation)
Scenario 4: AI tool offer to B2B SaaS marked as “early stage startup”
Risk: Early stage startups are usually small companies (1-5 employees), where the line between “company email” and “personal email” can be unclear.
How to handle: Verify the email is on a company domain ([email protected]), not personal ([email protected]). If on company — acceptable. If on personal — high risk.
Documentation: Save proof the contact was obtained from professional sources (LinkedIn, company websites, public registries).
Scenario 5: Sales to NACE-classified company where specific role isn’t published
You send: Try to reach “Head of Operations” at a manufacturing company, but don’t know the specific person with that role publicly.
Risk: You send to [email protected] or to [email protected] based on guesswork. In this case you don’t have a clear legitimate connection to a specific person.
How to handle: Send to info@ if possible, with a specific request to forward. Don’t try to “guess” specific people.
Documentation: If you do have a specific name (received from some source), save proof of that source.
Scenario 6: Services to non-professional role (executive assistant, office manager)
Risk: This person’s role typically isn’t decision-making. The GDPR balancing test here is harder — is this person a justifiable communication recipient for this purpose?
How to handle: Send only with a specific request to forward to the proper decision-maker. Don’t position this person as a sales target.
Scenario 7: Multiple contacts in one company
You send: 3-5 people at one company in parallel (CEO, VP Sales, Marketing Director, Head of Growth, COO).
Risk: Complaint probability increases — one person can forward to another and realize you’ve sent to multiple.
How to handle: Send to at most 2 people at a time, with 1-2 week gap between. If you get a reply from one — stop the other contact.
High-risk scenarios (generally avoid)
Scenario 8: Sending to info@, contact@, general@
Risk: These are general company emails usually managed by a receptionist or someone who isn’t the decision-maker. High complaint probability.
Alternative: Identify a specific professional-role person and send directly to them.
Scenario 9: B2B “database” from an untrusted source
Risk: List from “B2B leads EU, 50,000 contacts, €100” — almost certainly contains illegally obtained data. You inherit GDPR liability.
Alternative: Use verified sources (Apollo, Lemlist, LinkedIn Sales Navigator, local registries).
Scenario 10: Multiple sequences to the same person on the same topic
Risk: Complaints about “harassment” with repeat emails on the same topic after the person already ignored.
Alternative: After a 3-4 email sequence, stop this contact’s activity for at least 4-6 months. If one day you want to try again, build a completely different approach, based on a new context source.
Scenario 11: Ignoring high opt-out rate
Risk: Complaint volume above 1-2% of a campaign signals targeting is wrong. Continuing to send under these conditions is continuing GDPR risk.
Alternative: Stop campaign after 1-2% opt-outs. Update ICP and targeting, restart.
Concrete documentation to maintain
GDPR doesn’t require specific forms, but in practice documentation protects you in case of complaint. This is the minimum we maintain for each client:
1. Legitimate interest test for each campaign (1-page document)
Campaign name: [e.g. "Germany B2B SaaS Q3 2026"]
Sending purpose: [e.g. "Apollo SaaS tool offer to VP Sales and Head of Growth in Germany"]
Purpose test: Legitimate B2B commercial activity — service offer to another B2B company in similar or complementary market.
Necessity test: Advertising and exhibition alternatives exceed scalability and cost that a Latvian SME can justify in a first market test. Personalized cold email is the minimum invasive way for this purpose.
Balancing test:
- Data subject: in professional role [VP Sales / Head of Growth]
- Email: obtained from professional sources [Apollo + LinkedIn validation]
- Content: directly related to professional duties
- Opt-out mechanism: clearly visible in each email
- Opt-out respect: 24 hours to opt-out registration
Date: 2026-XX-XX
Responsible: [name]
2. Data processing register
Processing activity: B2B cold email campaign execution
Data categories: name, surname, company email, company name, professional role
Source: Apollo, LinkedIn Sales Navigator
Purpose: B2B service offer matching ICP definition
Basis: GDPR 6(1)(f) legitimate interest
Retention: 2 years or until opt-out
Recipients: internal sales staff, sales automation platform (Smartlead, Lemlist)
Data transfer outside EU: none (or Smartlead server location — verify)
Security measures: 2FA, encrypted databases, permission management
3. Opt-out list
Centralized list of everything ever opted-out — stored indefinitely, used before every next campaign to exclude these contacts.
4. Sender identification
Each cold email footer (or beginning) text:
[Sender name]
[Position] | [Company name]
[Company legal address]
Registration number: [UR number]
Want to opt out of further emails? Reply STOP.
This text is small but critical. Its absence automatically moves your email to the spam category both technically (email clients filter it) and legally (recipient has no way to know who’s sending).
Reactions to problematic cases
Recipient says they’ve complained to DVI
React: Reply within 24 hours. Confirm data will be deleted. Save all campaign materials in case DVI wants to review.
DVI contacts you
React: Reply within specified time (usually 30 days). Submit requested documentation. We recommend consulting a GDPR-specialized lawyer at this point.
Recipient asks why you’re emailing them
React: Reply honestly and in detail. Explain how you got their contact (Apollo, LinkedIn etc.), why you thought this service might interest them, and offer opt-out.
This honest communication usually resolves the situation without DVI involvement.
Specific jurisdiction differences in Europe
Although GDPR is unified, local supervisory authorities differ in interpretation:
Germany (BfDI and state Datenschutzbeauftragte): Strictest on cold outreach. BDSG adds requirements. Specifically — cold outreach to personal emails ([email protected]) is high-risk.
France (CNIL): Actively fines spam, but B2B cold emails with proper identification are accepted.
Italy (Garante): Locally very active on individual complaints. Reacts quickly to opt-out ignoring.
Scandinavia (Datatilsynet, Datainspektionen): Moderate, similar to Latvia. Rarely active in B2B context.
Latvia (DVI): Active but moderate. Mainly reacts to specific complaints, not “patrolling” the market.
Practical conclusion: if your practice matches the strictest (Germany) requirements, you’re protected in all jurisdictions.
Most frequent mistakes that draw DVI attention
After dozens of Latvian and EU SME consultations, the most common reasons:
1. Ignoring opt-outs. Highest category. Once a person opts out and gets more emails — that’s a near-certain path to a DVI complaint.
2. Personal email campaigns. B2B purposes sent to gmail.com, outlook.com etc. — high risk.
3. General, untargeted sending. Sent to everyone, no ICP filtering — high spam suspicion, high complaint rate.
4. Improper data source documentation. “We bought a database from someone” — won’t survive DVI review.
5. Missing sender identification. Email without legal name, address and registration — automatically spam.
Practical pre-campaign checklist
Before clicking “send” on a new cold email campaign, verify:
- Legitimate interest test documented for this specific campaign
- Data processing register updated with this campaign
- All contacts obtained from legitimate sources (Apollo, LinkedIn, local registries)
- Opt-out list cross-checked against this campaign’s contact list
- Sender identification clearly visible in each email
- Opt-out mechanism clearly indicated in each email
- Targeting directly related to professional role and industry
- Sending to company emails, not personal
These steps take 30 minutes for each new campaign. That’s negligible compared to DVI complaint risk.
If you want us to handle this for you
Our Sales Pilot, Market Testing and retainer services include a full GDPR compliance layer:
- Legitimate interest test documented for each campaign
- Data processing register maintained
- Sender identification properly configured
- Opt-out list maintained across different campaign jurisdictions
- DVI response process included (if a recipient asks)
GDPR compliance is like technical infrastructure — once built correctly, it doesn’t require much ongoing management. But building it correctly the first time — that’s where most Latvian SMEs lose.
Next step
Read the foundational article Is cold email legal in Latvia 2026 if you haven’t.
Check the basic GDPR guide GDPR cold email compliance, which provides broader EU context.
Contact us via /en/contact/ if you want consultation on GDPR aspects of your specific campaign or our full service handling.
GDPR in cold email context isn’t about whether you can send — it’s about how you send. A properly configured process protects you from risks and actually increases campaign efficiency by leaving only serious senders in the market.
Related reading
B2B Lead Generation in 2026: The Practitioner's Guide
What works in B2B lead generation in 2026 — ICP, list-building, enrichment, qualification, routing. From production pipelines for clients.
Is cold email legal in Latvia in 2026? GDPR and B2B practice
Is cold email lawful in Latvia in 2026? GDPR 6(1)(f) legitimate interest in B2B context, DVI practice, concrete scenarios for compliant outreach.
Cold Email Outreach in 2026: The Practitioner's Guide
What works in cold email outreach in 2026 — strategy, copy, sequencing, common failure modes. From running outreach for clients at production scale.
GDPR Compliance for Cold Email in 2026: What B2B Teams Need to Know
What GDPR actually requires for B2B cold email in 2026, when legitimate interest applies, and the operational compliance steps teams need to run.
How to Personalize Cold Email at Scale Without Faking It
The three tiers of personalization, when each wins by segment and volume, and the AI-assisted workflow that produces real hooks rather than theater.