Why "Legitimate Interest" Isn't a Blanket Pass
Agencies expanding new-business outreach into EU-based prospects run into GDPR fast, and legitimate interest under Article 6(1)(f) is usually the legal basis they reach for, since obtaining explicit prior opt-in from every cold prospect defeats the point of cold outreach entirely. What gets missed is that legitimate interest isn't a blanket exemption for B2B email. It's a specific legal basis that has to be earned through a documented test, applied to the actual outreach in question, not assumed because the recipient happens to be a business.
It's also a different framework from the one most US agencies already know. CAN-SPAM, covered in the companion guide, is built around an opt-out model: send first, honor unsubscribes within 10 business days, keep a physical address on the email, per sender.net. GDPR's legitimate-interest basis puts the burden earlier in the process, before the send, requiring the three-part test below to justify the outreach in the first place. An agency running one compliant process for its US list and assuming the same process covers EU contacts is working from the wrong model.
The Three-Part Test, Specifically
Per salesforceeurope.com, three conditions have to be met, in order. Purpose: is there a genuine business objective behind the outreach, not a vague or pretextual one. Necessity: is email actually a proportionate method for achieving that purpose, not just the cheapest or easiest channel available. Balancing: does the recipient's privacy interest fail to outweigh the sender's business interest, meaning the outreach has to survive a real weighing test, not just clear a low bar. All three have to hold. A cold-email program that passes purpose and necessity but fails the balancing test still doesn't have a valid legal basis.
The Named Example of What Fails This Test
salesforceeurope.com gives a specific, concrete example of non-compliance worth internalizing exactly as written: "a marketing agency buys a list of 5,000 generic 'info@company.com' addresses and sends a flyer about social media management." That fails the balancing test and is classified as spam. Notice what's doing the work in that example. It isn't that the recipients are businesses, or that the email was commercial. It's the combination of a purchased, generic list and an untargeted, one-size-fits-all pitch, exactly the shape of outreach a fast-scaling agency BD program is tempted to run.
What This Means for How You Actually Build a List
The practical read of that example is that legitimate interest gets stronger the more specific and researched the outreach is, and weaker the more it looks like a bulk purchase blasted at scale. A named contact, a genuine reason that specific business was selected, and a message tied to something real about their situation sit closer to passing the balancing test than a generic role-based address pulled from a purchased list and a form-letter pitch.
Document the Test, Not Just the Conclusion
salesforceeurope.com recommends recording a Legitimate Interest Assessment (LIA), a documented record showing the three-part test was actually applied to a given outreach program, not just a general belief that the outreach "should be fine under legitimate interest." That documentation matters for the same reason a consent record matters under TCPA, covered in the companion guide: if the legal basis is ever questioned, being able to show the test was run beats asserting that it probably would have passed.
Enforcement and What It's Attached To
Enforcement of GDPR sits with national data protection authorities, CNIL in France and the ICO in the UK among the most active. GDPR's statutory maximum penalty, publicly codified under Article 83(5), runs up to EUR20 million or 4% of global annual turnover, whichever is higher. That figure is well-established EU regulatory text rather than a number this research pass independently re-verified against the current EUR-Lex text, so confirm it against the live regulation before citing the exact figure in outward marketing copy.
A Practical Checklist Before You Target EU Contacts
- Can you articulate a specific, genuine business purpose for reaching this particular contact, not a generic "we sell agency services" rationale?
- Is email actually the proportionate method here, or would a different channel fit the balancing test better?
- Have you documented a Legitimate Interest Assessment for this outreach, rather than assuming legitimate interest applies by default?
- Is your list built from purchased, generic role-based addresses (the failing pattern in salesforceeurope.com's example), or from specific, researched contacts?
- Does your unsubscribe and data-handling process hold up if a recipient exercises their GDPR rights directly?
What this means for you
- Legitimate interest under GDPR Article 6(1)(f) is the standard basis for B2B cold email into the EU, but it requires a documented three-part test, not an assumption.
- The test is purpose, necessity, and balancing, per salesforceeurope.com, and all three have to hold, in that order.
- A named failing example: buying a generic list of "info@company.com" addresses and sending a flyer fails the balancing test and counts as spam.
- Document the test itself with a Legitimate Interest Assessment (LIA), not just a general belief that the outreach should qualify.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
- salesforceeurope.com, What Is Legitimate Interest for GDPR Cold Email? B2B Rules
- sender.net, CAN-SPAM Act Compliance Guide
