GDPR doesn’t ban LinkedIn outreach or cold email in a B2B context, but it does set clear rules for how you can do it: you need a documented lawful basis (almost always “legitimate interests” for B2B), you need to collect only the data you actually use, you need an easy and honest way for people to opt out, and you need to be able to show your reasoning if anyone asks. Get those four things right and you can run an active, high-volume outreach programme without exposing your agency or your clients to real risk.


TL;DR:

  • For most B2B outreach, “legitimate interests” is the right lawful basis under UK GDPR — not consent — but you must document a Legitimate Interest Assessment (LIA) to rely on it properly.
  • LinkedIn messages and cold email are governed differently: email also falls under PECR, which is stricter about unsolicited marketing to individuals.
  • Only collect and store the data fields you actually use in your outreach and CRM — data minimisation is a GDPR requirement, not a nice-to-have.
  • Every message needs a clear, low-friction way to opt out, and opt-outs must be honoured promptly and permanently, not just for that campaign.
  • Keeping a simple audit trail (LIA, data source, opt-out log) is what actually protects you if a prospect complains — not the wording of one message.
  • Compliance and reply rates aren’t in tension: tighter targeting and honest opt-outs tend to improve both.

Table of Contents

Why GDPR Matters for LinkedIn Outreach

It’s tempting to treat GDPR as a website cookie banner problem and assume it doesn’t touch outbound prospecting. It does. The moment you pull a prospect’s name, job title, company and LinkedIn profile URL into a spreadsheet or a sequencing tool, you’re processing personal data, and UK GDPR applies whether that person is a director at a 500-person firm or a sole trader.

The good news for agencies and consultants running LinkedIn and email outreach: GDPR was never designed to stop legitimate B2B commercial contact. Regulators have been consistent that reasonable, relevant, well-targeted outreach to business contacts is exactly the kind of activity the “legitimate interests” basis was built for. The risk isn’t outreach itself — it’s outreach done sloppily: scraped lists with no clear source, no targeting logic, no opt-out, and no record of why you thought contacting that person was reasonable in the first place.

Practically, this matters for three reasons. First, complaints happen — a prospect reports your message, and if you have no documented basis you’re immediately on the back foot. Second, clients (especially enterprise and regulated-sector clients) increasingly ask agencies to show their compliance process before signing off on a campaign. Third, LinkedIn and email platforms themselves penalise the same sloppy behaviour that creates GDPR risk — bad list hygiene and irrelevant targeting tank your response rates and get accounts restricted, so tightening this up pays for itself twice over.

GDPR gives you six possible lawful bases for processing personal data, but in practice B2B outreach comes down to a choice between two: consent and legitimate interests.

Consent means the person has actively opted in before you contact them — which is obviously impossible for cold outreach by definition, since the whole point is reaching people who haven’t heard from you yet. Consent is the right basis for your newsletter signup form or a gated whitepaper download, not for a first cold message.

Legitimate interests is the basis almost every B2B outreach programme actually relies on. It allows processing personal data without consent when you have a genuine business reason, the processing is necessary and proportionate, and it doesn’t override the individual’s rights and freedoms. The Information Commissioner’s Office has explicitly acknowledged direct marketing, including B2B prospecting, as a recognised legitimate interest — provided you can show your reasoning.

That last part is the bit most outreach teams skip. “Legitimate interests” isn’t a box you tick and forget; it’s a basis you have to actively justify and document, which is what the next section covers. This article summarises common practice, not legal advice — if you’re unsure how it applies to your specific data sources or sector, it’s worth a short conversation with a data protection professional.

Building a Legitimate Interest Assessment for Outreach

A Legitimate Interest Assessment, or LIA, is a short internal document that records why you believe your outreach is lawful. It doesn’t need to be sent to anyone or published — it needs to exist, be consistent, and be produced if a regulator or a client ever asks. A workable LIA covers three tests:

The purpose test. What’s the genuine business reason for contacting this person? “We sell a relevant service to people in this exact role, at companies of this size, in this sector” is a purpose test that holds up. “We bought a list and messaged everyone on it” is not.

The necessity test. Is messaging this specific person necessary to achieve that purpose, and is there a less intrusive way to do it? Targeted outreach to decision-makers in a defined ICP generally passes; blanket messaging across unrelated job functions and seniority levels is harder to justify.

The balancing test. Would a reasonable person in the prospect’s position be surprised or object to being contacted this way? A relevant, professional message to someone whose job title and public profile suggest they’d want to know about your product usually clears this bar. Repeated messages after no response, personal (non-work) contact details, or targeting based on sensitive inferred characteristics generally don’t.

Write this up once per campaign or ICP segment, date it, and keep it somewhere your team can find it. It takes twenty minutes and it’s the single most useful document you can produce if anything is ever questioned.

What to Include (and Leave Out) of Your First Message

Compliant outreach and effective outreach turn out to want the same things. A first message that clearly states who you are, which company you represent, and why you’re reaching out to this specific person is both more likely to get a reply and easier to defend as legitimate interest in action. Vague, generic openers that could have been sent to anyone are the ones that get reported.

Practical guidelines for the first touch:

Identify yourself and your company by name — no anonymous or vague sender identities. State the specific, relevant reason you’re contacting this person, tied to their role or company, not a generic template. Make the ask small and clear (a short call, a resource, a reply) rather than an immediate hard sell. Include a simple way to say no — “let me know if this isn’t relevant and I won’t follow up” does more compliance work than people expect, and it also filters your pipeline toward people who actually want to talk.

Data Minimisation: What to Collect and Store

Data minimisation means you only hold the personal data you actually need for the purpose you’ve defined — not every field a scraping tool happens to return. For most outreach programmes that’s: name, job title, company, and a business contact method (LinkedIn profile or work email). Personal mobile numbers, home addresses, or inferred personal details (family status, political views, health signals picked up from a profile) have no place in an outreach dataset and create risk with no upside.

This extends to retention. If a prospect never replies and isn’t a target for future campaigns, there’s no legitimate reason to keep their data indefinitely in a sequencing tool or CRM. A simple rule — purge or archive non-responders after a defined period, and always remove anyone who’s opted out — keeps your database smaller, cleaner, and lower-risk, and it tends to improve deliverability and reply rates as a side effect since you’re not repeatedly messaging stale, low-intent contacts.

Handling Opt-Outs and “Do Not Contact” Requests

Under GDPR, an individual can object to processing based on legitimate interests at any time, and for direct marketing specifically, that objection must be honoured — no exceptions, no “compelling legitimate grounds” override available (that override only applies to non-marketing legitimate interest processing). In plain terms: if someone says stop, you stop, permanently, across every channel you have them on.

What good opt-out handling looks like in practice: a single source of truth (usually your CRM) that every tool checks before sending; opt-outs applied within a day or two, not “at the end of the sequence”; suppression that covers LinkedIn, email, and any other channel tied to that contact record, not just the one they replied on; and a light log of who opted out and when, in case it’s ever questioned. Teams running outreach at volume — including agencies managing this for multiple clients — generally find it’s worth building this suppression logic once into the process rather than relying on each rep to remember. This is one of the areas where a done-for-you partner like The Lead Lab earns its keep: consistent suppression-list handling across every client account, rather than depending on individual reps to manage it by hand.

Email vs LinkedIn: Different Rules, Different Risks

GDPR sets the ground rules for both channels, but cold email in the UK also sits under PECR (the Privacy and Electronic Communications Regulations), which specifically governs unsolicited electronic marketing. PECR’s “soft opt-in” exception — which lets you email an existing customer about similar products without fresh consent — doesn’t apply to cold B2B prospecting to a new contact, so cold email relies on the same legitimate interests reasoning as LinkedIn, but with stricter expectations around identifying yourself and providing an unsubscribe mechanism in every message, not just the first.

LinkedIn outreach has a practical advantage here: the platform context itself signals that a message is business-related and the recipient has a public professional profile inviting contact, which supports the legitimate interest and balancing tests more naturally than a cold email to an inbox. That’s not a free pass — the same targeting, relevance, and opt-out standards apply — but it’s part of why many UK agencies lead with LinkedIn and treat email as a secondary channel for warm or partially-engaged contacts rather than pure cold outreach.

Tooling and Process: Keeping Your Stack Compliant

Compliance breaks down most often at the handoff points between tools — a list exported from a scraper into a spreadsheet, then into a sequencing tool, then into a CRM, with the opt-out status not travelling cleanly between them. A few process habits fix most of this:

Keep one master suppression list and sync it into every tool that sends messages, rather than managing opt-outs per platform. Record the source of every list you import (Linkedin Sales Navigator search, a data provider, a conference attendee list) so you can point to it later. Review your ICP and targeting logic periodically, not just once at setup, since a stale ICP definition is often where the “necessity” test starts to look shaky. And build a short compliance check into your campaign launch process — five minutes reviewing the LIA and suppression list before a new sequence goes live catches most issues before they become a message a prospect actually sees.

Common Mistakes That Get Agencies in Trouble

The complaints and compliance issues that actually surface tend to come from a small set of repeat causes. Buying or scraping a broad list with no clear targeting logic and messaging everyone on it. Continuing to message someone after they’ve asked to stop, because the opt-out didn’t sync to every channel. Using personal (non-work) contact details obtained from a source other than the prospect’s own public professional profile. Sending templated messages so generic they read as spam regardless of the legal basis behind them. And treating the LIA as a one-off exercise rather than something reviewed when the ICP or data source changes.

None of these are exotic failure modes — they’re process gaps, which means they’re fixable with process, not with cleverer message copy.

A Simple Compliance Checklist Before You Hit Send

Before launching a new outreach sequence, it’s worth running through a short list: Do you have a written LIA for this segment, dated and specific to this campaign? Is your targeting genuinely narrow enough to pass the necessity test, or is it “everyone with this job title” regardless of relevance? Does the first message identify you and your company clearly? Is there an easy, honest way to opt out, and does that opt-out sync across every channel you’re using? Have you checked the list against your suppression list before importing it? And if a prospect complained tomorrow, could you show your reasoning in under five minutes?

If the answer to all six is yes, you’re in solid shape — and in practice, teams that build this into their process from the start usually find it makes their targeting sharper and their reply rates better, not worse. Compliance and performance point the same direction here far more often than agencies expect going in.

Leave a Reply

Your email address will not be published. Required fields are marked *