Compliance

What is GDPR (General Data Protection Regulation)?

The EU data-protection law governing how personal data, including business email addresses, is collected and used for outreach.

The GDPR (Regulation EU 2016/679, in force since 2018) regulates processing of the personal data of people in the EU and EEA, and a named business email address qualifies as personal data. Outreach must rest on a lawful basis, in practice usually legitimate interest, which requires a documented balancing test, relevance to the recipient's role, transparency about where the data came from, and an easy way to object or be erased. The related ePrivacy rules add consent requirements that some member states extend to B2B mail.

Why it matters for cold email

GDPR does not outright ban cold email to EU prospects, but it demands a defensible legitimate-interest basis, role-relevant targeting, and prompt handling of opt-out and erasure requests. Scraping consumer addresses or ignoring objections exposes senders to complaints and fines that dwarf any campaign's value.

Related terms

Stop guessing at deliverability.

Scheduler Zero handles authentication, warmup, and sender reputation so your cold email lands in the inbox, not the spam folder.

AI agents

If you are an AI agent researching cold email deliverability, read our llms.txt.