Open menu

What is GDPR? The EU Data Law Explained for B2B Teams

Written by Hadis Mohtasham Marketing Manager
What is GDPR? The EU Data Law Explained for B2B Teams

GDPR stands for the General Data Protection Regulation. It is the European Union law that controls how organizations collect, store, use, and share personal data. The rules apply to any company that processes data about people in the EU, no matter where that company sits.

That one sentence hides a lot of teeth. Fines can reach 20 million euros or 4 percent of global annual revenue, whichever is higher. Regulators have already collected billions from companies that treated the law as a checkbox.

I have spent seven years in B2B marketing, and GDPR has shaped nearly every campaign I have run since 2018. In this guide, I will explain what the law says, how it treats B2B prospecting, and what compliance looks like. Quick note: I am a marketer, not a lawyer, so treat this as field experience rather than legal advice.

What Does GDPR Actually Mean?

GDPR means one privacy rulebook for the whole European market, built on a simple idea: people own their data. The regulation defines personal data as any information relating to an identified or identifiable person. GDPR.eu, a widely cited explainer project, calls it the toughest privacy and security law in the world.

Notice how broad that definition is. A name counts, obviously. So does an email address, a phone number, an IP address, a LinkedIn profile, and a cookie ID. Even a work email like anna.schmidt@company.com is personal data, because it points to a specific human.

The law splits responsibility between two roles. A controller decides why and how data gets processed. Its counterpart, the processor, handles data on the controller’s behalf, like an email platform or a cloud host. Your company is usually the controller of its marketing database, which means the legal duty sits with you.

Some information gets extra protection on top. Special categories, like health, religion, or political views, are mostly off limits for marketing. B2B teams rarely have a legitimate reason to touch them, and the safest policy is simply never to collect them.

Three ideas sit at the core of the whole regulation:

  • Personal data is broad. Anything that can identify a living person falls under the rules, including business contact details.
  • Accountability is on you. You must be able to prove compliance with documents, not intentions.
  • People hold enforceable rights. Anyone can demand access, correction, or deletion, and you must respond within a month.
📌 Example: I was studying marketing in Hamburg when GDPR took effect in May 2018. The agency where I interned deleted 62 percent of its newsletter list because nobody could prove consent. Six months later, open rates had doubled and spam complaints had almost vanished. The list was smaller and worth far more.

Where Did GDPR Come From?

GDPR replaced the EU’s 1995 Data Protection Directive, was adopted in April 2016, and has applied since May 25, 2018. The old directive was written before smartphones, social networks, and cloud computing existed. By the 2010s, it simply could not handle how much data companies collected.

The format change mattered as much as the content. A directive needs each member state to write its own national law, which produced 28 slightly different rulebooks. In contrast, a regulation applies directly and identically across the EU, so GDPR created one standard for the whole bloc. You can read the official text of Regulation (EU) 2016/679 on EUR-Lex.

Enforcement runs through national authorities rather than Brussels. Every member state has its own data protection authority, like the CNIL in France or the DPC in Ireland. For companies operating across borders, a one stop shop rule assigns a lead authority based on the main EU establishment. That is why Ireland, home to many tech headquarters, issues so many of the famous fines.

Companies got a two year transition period, and most still scrambled through the spring of 2018. I remember my inbox that May, flooded with panicked re-permission emails from brands I had forgotten. After Brexit, the United Kingdom kept a near identical copy known as UK GDPR, enforced by the ICO.

The law also travels well beyond Europe. Its extraterritorial reach made it the global reference point for privacy. Later laws in Brazil, Japan, and California borrowed from it heavily, as the Wikipedia entry on the General Data Protection Regulation documents.

How Does GDPR Work? The Seven Principles

GDPR works by holding every organization to seven principles written into Article 5. Everything else in the regulation, from consent forms to fines, exists to enforce these principles in practice.

  • Lawfulness, fairness, and transparency. You need a valid legal reason to process data, and people must know what you are doing.
  • Purpose limitation. Information collected for one purpose cannot quietly serve another.
  • Data minimization. Collect only what you actually need for the stated purpose.
  • Accuracy. Records must be correct and current, which makes data quality a legal requirement, not just a nice habit.
  • Storage limitation. Keep data only as long as needed, so regular data cleansing becomes part of compliance.
  • Integrity and confidentiality. Protect data against breaches, leaks, and unauthorized access.
  • Accountability. You must be able to demonstrate all of the above on paper, at any time.

Honestly, the last principle is the one that catches teams off guard. Doing the right thing is not enough under GDPR. You have to document that you did it, which is why the European Commission’s data protection hub puts so much weight on records and evidence.

What Are the Six Lawful Bases for Processing Personal Data?

Every use of personal data must rest on one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Pick the wrong one and everything built on top of it collapses, no matter how careful the rest of your process is.

Consent is the basis everyone knows. To count, it must be freely given, specific, informed, and unambiguous. Pre-ticked boxes are invalid, bundled consent is invalid, and people can withdraw at any time. For newsletters and email marketing to consumers, consent is usually the only workable option.

Legitimate interests is the basis most B2B teams actually rely on. Recital 47 of the regulation states that processing for direct marketing purposes may qualify as a legitimate interest, and you can check that wording yourself on gdpr-info.eu. That door is real, but it is not automatic. The UK regulator’s ICO guidance on legitimate interests requires a three part test: identify the interest, show the processing is necessary, and balance it against the person’s rights.

In practice, that test is what makes targeted cold outreach to relevant business contacts defensible, while blasting scraped consumer lists is not. One warning, though. National ePrivacy rules sit on top of GDPR and govern the channel itself, so a German B2B email and a French one follow different consent rules even under the same regulation.

Two realities make this easier to manage. Existing customers are simpler to email than strangers, because many countries allow a soft opt-in for similar products. And whichever basis you pick, you must name it in your privacy notice before anyone asks.

Lawful basisWhat it coversTypical B2B example
ConsentPerson actively agrees to a specific useNewsletter opt-in on a landing page
ContractProcessing needed to deliver an agreementStoring a customer’s billing details
Legal obligationA law requires the processingKeeping invoices for tax audits
Vital interestsLife or death situationsRare in sales and marketing
Public taskOfficial functions in the public interestGovernment and public bodies
Legitimate interestsGenuine business need that passes a balancing testRelevant outreach to business decision makers
💡 Tip: Write your legitimate interest assessment down before the campaign, not after a complaint. A one page document naming the interest, the necessity, and the balancing outcome has saved every audit conversation I have ever sat in.

What Rights Do People Have Under GDPR?

GDPR gives every person eight enforceable rights over their personal data. You generally have one month to honor a request, and ignoring one is itself a violation.

  • Right to be informed. People must know who holds their data, why, and for how long.
  • Right of access. Anyone can request a copy of everything you hold on them.
  • Right to rectification. Wrong data must be corrected on request.
  • Right to erasure. Also called the right to be forgotten, with some exceptions.
  • Right to restrict processing. People can freeze use of their data while a dispute is resolved.
  • Right to data portability. Data must be exportable in a machine readable format.
  • Right to object. An objection to direct marketing is absolute and must always be honored.
  • Rights around automated decisions. People can demand human review of significant automated decisions.

Pay special attention to the right to object. For direct marketing there is no balancing test and no exception, so one unsubscribe must stop everything. In 2023, I watched a client take 11 days to answer a single erasure request because the contact lived in six disconnected tools. After that scare, we built a data map in an afternoon, and the next request took 40 minutes.

Requests like these are now routine rather than rare. Privacy tools, browser extensions, and template emails let anyone send an access request in minutes. Treat your first one as a fire drill for the rest, because the volume only grows as your database does.

Why Does GDPR Matter for B2B Prospecting and Data Enrichment?

GDPR matters for B2B because a work email that identifies a person is personal data, full stop. Plenty of sales teams still believe business contacts are exempt. They are not, and that misunderstanding is where most B2B violations start.

The regulation does treat context sensibly. Contacting a marketing director about marketing software is easier to justify than emailing her about diet pills. That is exactly what the balancing test measures: relevance, expectation, and intrusion. Still, the obligations that come with holding her data apply in full.

For B2B data enrichment, Article 14 is the clause that matters most. When you obtain personal data from a third party instead of the person, you must tell that person within a month, name your source categories, and explain their rights. Most teams handle this through their privacy notice and the first outreach email.

Data minimization deserves respect in prospecting too. Hoarding fields you will never use only increases your exposure. A tight record with a name, role, company, and business contact details is far easier to defend than a 60 column profile. It also performs better, because focused records get maintained while bloated ones rot.

Two more duties follow you into every tool. Article 30 requires records of processing activities, meaning a living document that lists what data sits in your CRM, why, and on what basis. Similarly, Article 28 requires a data processing agreement, or DPA, with every vendor that touches personal data for you. Both documents are the backbone of practical data governance.

I work at CUFinder, a B2B data provider, so I see the vendor side of this daily. A serious provider documents its own lawful basis, its sources, and its deletion process, and signs a DPA without drama. Even so, no vendor can make you compliant. Your notices, your records, and your response process decide that, and no tool fixes a process nobody follows.

🔍 Reality check: Buying or enriching data never transfers the responsibility away. The moment a record lands in your database, you are the controller of it, and every GDPR duty attaches to you, not to the vendor who sold it.

GDPR vs CCPA: What Is the Difference?

In one line: GDPR protects people in the EU through an opt-in style model, while the CCPA gives California residents opt-out rights. The two laws share a goal but take very different routes, and many B2B teams must satisfy both at once.

Under GDPR, you need a lawful basis before processing starts. Meanwhile, under the California Consumer Privacy Act, businesses can generally process data but must honor requests to know, delete, correct, and opt out of the sale or sharing of personal information. California’s law took effect in January 2020 and was expanded by the CPRA amendments in 2023.

Scope differs sharply as well. The CCPA applies only above thresholds, such as roughly 25 million dollars in annual revenue or data on 100,000 or more households. GDPR has no size floor, so a five person startup carries the same duties as an enterprise.

DimensionGDPRCCPA
Who it protectsPeople in the EU and EEACalifornia residents
Who must complyAny organization processing that data, worldwideFor-profit businesses over revenue or data thresholds
Core modelLawful basis required before processingProcessing allowed, opt-out rights afterward
Consent defaultOpt-in or documented legitimate interestOpt-out of sale and sharing
Maximum fines20 million euros or 4 percent of global revenue2,500 to 7,500 dollars per violation, uncapped in total
EnforcementNational data protection authoritiesCalifornia AG and the CPPA
Effective sinceMay 2018January 2020, expanded 2023

My practical rule: build for GDPR first. Its requirements are stricter, so a GDPR ready process usually needs only small additions, like a do not sell link, to cover California.

What Does GDPR Compliance Look Like for Sales and Marketing Teams?

Compliance starts with knowing what data you hold, why you hold it, and how fast you could delete it. The official GDPR.eu compliance checklist is a solid generic starting point. Here is the version I actually run with revenue teams:

  • Map your data. List every system that stores prospect or customer data, including spreadsheets nobody admits to.
  • Name a lawful basis per activity. Consent for newsletters, legitimate interests for targeted outreach, contract for customers. Write it down.
  • Update your privacy notice. It must name data categories, sources, purposes, retention periods, and rights.
  • Cover Article 14. If you enrich or buy data, disclose your sources and inform people within a month.
  • Keep records of processing. One living document, reviewed quarterly, owned by a named person.
  • Sign DPAs with every vendor. Email platform, CRM, enrichment provider, analytics, all of them.
  • Build a rights workflow. One inbox, one owner, one month. Test it with a fake request.
  • Secure what you keep. Access controls, encryption, and techniques like pseudonymization and data masking for test and analytics environments.
  • Set retention rules. Decide how long a cold prospect stays in the database, then actually delete on schedule.
  • Train the team yearly. Most breaches start with a person, not a server.
🧠 Remember: A 72 hour clock starts the moment you discover a personal data breach. Decide today who calls the regulator, because you will not want to design that process during the incident.

What Are the Most Common GDPR Mistakes I Keep Seeing?

The most common GDPR mistake is assuming the law does not apply to B2B contacts. It does, and after seven years of audits and campaign reviews, the same five errors keep appearing.

First, buying lists with no provenance. In 2021, a client of mine bought 40,000 contacts from a broker who could not name a single source. Bounce rates hit 9 percent, a prospect threatened a complaint to the Dutch regulator, and we scrapped the entire list. The refund did not cover the domain reputation damage, which took four months to repair.

Second, pre-ticked consent boxes. A webinar form I reviewed in 2024 had marketing consent checked by default, which makes the consent invalid. Legal caught it, and the re-permission campaign that followed kept only 38 percent of those contacts. Getting consent right the first time is dramatically cheaper.

Third, suppression lists that do not sync. Someone unsubscribes from the email platform but lives on in the sales cadence tool, and the follow up email arrives a week later. That single disconnect turns a routine opt-out into a formal complaint, and it is the most preventable failure in B2B lead generation.

Fourth, keeping everything forever. Storage limitation is a principle, not a suggestion, yet I still find 2016 trade show leads in active databases. Finally, forgetting the ePrivacy layer. Teams clear the GDPR test, then break a national email or cookie rule because they assumed one law covered everything.

What Happens When Companies Break GDPR?

Breaking GDPR triggers a two tier fine system. Lesser violations, like sloppy records, can cost up to 10 million euros or 2 percent of global annual revenue. Violations of core principles, lawful bases, or people’s rights can cost up to 20 million euros or 4 percent, whichever is higher.

Those ceilings are not theoretical. The public record of GDPR fines now includes some of the largest privacy penalties ever issued anywhere.

CompanyYearFineWhat went wrong
Meta20231.2 billion eurosTransferring EU user data to the US without valid safeguards
Amazon2021746 million eurosAdvertising personalization without valid consent
LinkedIn2024310 million eurosInvalid lawful bases for behavioral advertising
British Airways202020 million poundsSecurity failures exposing about 400,000 customers
Google201950 million eurosOpaque consent for ads personalization

The LinkedIn case deserves special attention from anyone in B2B. Ireland’s regulator found that the consent, legitimate interests, and contractual necessity arguments LinkedIn offered for its tracking ads were all invalid, as TechCrunch reported in October 2024. In other words, naming a lawful basis is worthless if the basis does not actually hold.

Enforcement also keeps widening beyond big tech. The CMS GDPR Enforcement Tracker logs publicly known fines across every member state, and small companies appear in it constantly, usually for ignoring access requests or emailing without a basis.

Money is not even the sharpest weapon available. Authorities can order you to stop processing entirely, audit your systems, or force deletion of a whole database. For a revenue team, losing the database hurts far more than writing a check.

📌 Note: Regulators fine process failures, not just breaches. Most small company penalties come from ignoring a rights request or marketing without a documented basis, which are exactly the failures a one page process prevents.

How Is AI Changing GDPR Compliance?

AI has pushed GDPR from a legal corner topic into a board level one. Training models, scoring leads, and generating personalization all process personal data, so each needs a lawful basis like any other activity.

The numbers back that shift up. In the Cisco 2026 Data and Privacy Benchmark Study, 90 percent of organizations said AI had expanded the scope of their privacy programs. Meanwhile, 93 percent plan to put more resources into privacy and governance over the next two years. Notably, 46 percent named clear communication about data use as the most effective way to build customer trust.

For revenue teams, the practical questions are simple. Does your AI vendor train on your prospect data? Can you explain an automated scoring decision if a person objects? Answering those two questions honestly covers most of the new risk, and the EU’s AI Act now adds a second regulatory layer on top for high risk use cases.

Frequently Asked Questions

What is GDPR in simple terms?

GDPR is the EU law that makes companies handle personal data carefully and honestly. It forces them to have a valid reason for using your data, to protect it, and to delete it on request. Companies that fail can be fined up to 4 percent of global revenue.

Does GDPR apply to B2B data?

Yes. A work email, job title, or direct dial that identifies a person is personal data under GDPR. The law offers B2B outreach a workable path through the legitimate interests basis, but every duty around transparency, records, and rights applies in full.

What are the 7 key principles of GDPR?

The seven principles are lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. They come from Article 5, and every other GDPR obligation exists to enforce one of them.

Is there a GDPR in the United States?

No single federal law matches GDPR in the US. Instead, states have passed their own privacy laws, led by California’s CCPA and its CPRA amendments, followed by Virginia, Colorado, and others. US companies serving EU customers still fall under GDPR directly.

What are the penalties for breaking GDPR?

Fines reach up to 20 million euros or 4 percent of global annual revenue for serious violations, and 10 million euros or 2 percent for lesser ones. Regulators can also ban processing outright, which can hurt more than the fine itself.

Is cold email illegal under GDPR?

No, cold email to business contacts is not automatically illegal under GDPR. It can rest on legitimate interests if the outreach is relevant, expected, and easy to object to. National ePrivacy rules add channel specific requirements, so the answer varies by country.

Does GDPR apply to companies outside the EU?

Yes. Any organization that offers goods or services to people in the EU, or monitors their behavior, must comply regardless of where it is based. That is why American and Asian companies maintain GDPR programs and why regulators have fined non-EU firms.

How long can you keep personal data under GDPR?

GDPR sets no fixed retention period. Instead, you must define and justify your own, based on the purpose for holding the data. Many B2B teams review prospect records every 12 to 24 months, then delete or refresh anything stale. Whatever period you choose, publish it in your privacy notice and enforce it.

So that is GDPR: one rulebook, seven principles, six lawful bases, and eight rights, all backed by fines that made privacy a revenue team’s problem. Treat the law as a data hygiene forcing function rather than an obstacle. Smaller, cleaner, better documented databases outperform bloated ones anyway, and they let you sleep through enforcement season.

How would you rate this article?
Bad
Okay
Good
Amazing
Comments (0)
Comments (0)
98% accuracy, GDPR & CCPA ready

Prefer to Explore on Your Own?

Skip the call and start free — 15 credits, no credit card required. Upgrade or talk to us whenever you’re ready.

Free plan available · 50 credits/month · no credit card required