Same Sample

Buying B2B Contact Data in the EU: What the Law Actually Says

By Cuong Tran · Published 2026-08-31 · Last updated 2026-08-31

Affiliate disclosure: Same Sample may earn a commission from some links on this page. The commercial relationship is stated next to each product, and products we have no approved affiliate relationship with carry ordinary links. Affiliate status and commission rates are not inputs to the scoring model.

Whether a purchased B2B contact list can lawfully be used for cold email depends on the country, not on the vendor. In France it is workable under conditions. In Germany, Denmark and the Netherlands prior consent is required even for business recipients, which a bought list by definition does not carry.

TL;DR

There is no B2B exemption in the GDPR for a named person at a company. [email protected] is personal data; [email protected] is not.

The ePrivacy Directive harmonised consumer marketing email and expressly left business recipients to national law, which is why the answer changes at every border.

Buying a list starts a one-month clock under Article 14. You must tell each person you hold their data, why, and which vendor you bought it from, at the latest with your first message.

The largest fines in this area landed on the sellers, but one landed on a buyer: CNIL held that a supplier's contractual warranty was not verification.

None of this makes contact data tools unusable. It changes what they are useful for, which is enrichment, verification and warm workflows, rather than cold blasts into Germany.

Is a work email address personal data under the GDPR?

Yes, when it identifies a person. GDPR Article 4(1) defines personal data as any information relating to an identified or identifiable natural person, and [email protected] identifies one on its face. A generic address such as [email protected] relates to the company instead and falls outside.

The belief that business contact data sits outside the GDPR comes from Recital 14, which says the Regulation does not cover processing that concerns legal persons. That carve-out is real but narrow. It exempts data about the company, not data about a human being who happens to work there. There is no business-to-business exemption in the GDPR for named individuals.

France's regulator, the CNIL, draws the same line explicitly, stating that generic addresses of the info@ or contact@ type concern legal persons and are not subject to the principles that govern prospecting. Everything with a person's name in it is.

This matters commercially because it decides which of the two regimes below you are in. A vendor selling you 5,000 named contacts at European companies is selling you 5,000 records of personal data, and the obligations that come with them land on you the moment you take delivery.

Sources GDPR consolidated text, EUR-Lex read 2026-08-31 · CNIL, prospection commerciale par courrier électronique read 2026-08-31

Can you cold-email a purchased B2B list in Germany, the Netherlands, Denmark or France?

France yes, under conditions. Germany, Denmark and the Netherlands no. All three require prior consent from the recipient before a marketing email is sent, and their rules make no exception for business addresses, so a purchased list cannot satisfy the requirement.

The reason there is no single European answer sits in the ePrivacy Directive itself. Article 13(1) requires prior consent for marketing email. Article 13(5) then applies that requirement to subscribers who are natural persons, and tells Member States only to ensure that the legitimate interests of other subscribers are sufficiently protected. Business recipients were handed to national law, and national law diverged.

The soft opt-in in Article 13(2) is worth understanding because it is the exception people reach for, and it can never apply to a bought list. It permits contacting someone whose details you obtained in the course of selling them something, about your own similar products. A purchased list fails both halves: there was no prior sale, and you are not the entity that collected the address.

MarketCold marketing email to a business addressRuleRegulator
GermanyPrior express consent requiredUWG § 7(1) and (2) no. 2Bundesnetzagentur
DenmarkPrior consent required, all recipient typesMarkedsføringsloven § 10Forbrugerombudsmanden
NetherlandsPrior consent required, existing-customer exception onlyTelecommunicatiewet art. 11.7ACM
FrancePermitted on legitimate interest, if job-related, with prior information and an easy free opt-outePrivacy transposition plus GDPRCNIL

Read this as a table of what the regulator says, not as legal advice. Rules are summarised, and the sub-paragraph numbering of UWG § 7 changed in 2021.

Germany deserves a closer look because the drafting is deliberate. UWG § 7(2) no. 1 governs marketing phone calls and distinguishes between a consumer, who must give express consent, and another market participant, from whom presumed consent suffices. The paragraph on email draws no such distinction. The legislature made the business carve-out for one channel and declined to make it for the other. The Bundesnetzagentur states the resulting rule in terms of the addressee, with no consumer qualifier attached.

Germany also has a second enforcement layer that has nothing to do with data protection fines. Unfair competition law is privately enforced there, so a competitor or an industry association can send an Abmahnung and seek an injunction with costs. That risk arrives faster than a regulator ever would.

Denmark says the same thing more plainly than anyone. The Consumer Ombudsman's guidance on the spam ban states that it applies to all recipients, whether the message goes to a consumer, a company or a public authority.

France is the outlier in the permissive direction, and even there the permission is conditional. The CNIL accepts legitimate interest rather than consent for business prospecting, provided the message relates to the recipient's job, and provided the person was informed and can object easily and free of charge. Read that second condition again: it is Article 14 wearing different clothes. France removes the consent requirement. It does not remove the duty to tell people you hold their data.

Sources ePrivacy Directive 2002/58/EC, EUR-Lex read 2026-08-31 · Bundesnetzagentur on fax and email spam read 2026-08-31 · Forbrugerombudsmanden, Vejledning om spamforbuddet 2021 read 2026-08-31 · ACM, Spam voorkomen in uw reclame read 2026-08-31 · CNIL, prospection commerciale par courrier électronique read 2026-08-31

What does Article 14 require when you buy a contact list?

Article 14 applies whenever personal data is obtained from someone other than the person themselves, which is exactly what buying a list is. You must inform each person within a reasonable period and at the latest within one month, or at the latest with your first message to them, whichever comes first.

The trigger is acquisition, not first contact. This is the single most misread point in the whole area. A buyer who imports 5,000 records in January, gets busy, and starts emailing in June has been in breach since February. The clock does not wait for the campaign.

Article 14(1) requires your identity, your purposes and your legal basis, the categories of data you hold, the recipients, and any transfer outside the EU. Article 14(2) then adds retention period, the person's rights, the right to complain to a supervisory authority, and two items that hurt a bought list specifically.

The exemption everyone reaches for is Article 14(5)(b), which lifts the duty where providing the information proves impossible or would involve a disproportionate effort. Read the provision and it is anchored to archiving in the public interest, scientific or historical research, and statistical purposes. Commercial prospecting is none of the three, and the regulators have said so: the transparency guidelines endorsed by the EDPB state at paragraph 61 that this exception should not be routinely relied upon by controllers who are not processing for those purposes.

There is also a structural trap in the exemption that is worth stating plainly. Cost is not the test, and holding the contact details defeats the claim. If you own a working email address, emailing a notice to it costs approximately nothing. The very asset you bought is the proof that notification is not disproportionate. That is the reasoning that decided the Bisnode case below.

One further detail from the KASPR decision, which matters if you are selling into several European markets at once: CNIL held that sending the Article 14 notice in English only was not transparent and comprehensible information for French data subjects. A multilingual prospecting operation needs multilingual notices.

Sources GDPR Article 14, EUR-Lex read 2026-08-31 · WP29 Guidelines on Transparency, WP260 rev.01, endorsed by the EDPB read 2026-08-31

Does legitimate interest cover buying and using a contact list?

Sometimes, and never automatically. Recital 47 says direct marketing may be regarded as a legitimate interest. May is doing the work in that sentence: it grants permission to run the three-part test, not permission to skip it.

The EDPB's guidelines on legitimate interest, adopted in October 2024, set out three cumulative conditions. There must be a legitimate interest pursued by the controller or a third party, the processing must be necessary for it, and the interests or fundamental rights of the people concerned must not take precedence. All three, not two.

Two paragraphs of those guidelines close off the arguments buyers usually make. Paragraph 53 states that merely providing the required information does not by itself establish that the processing was within the person's reasonable expectations, which kills the idea that sending a privacy notice retroactively legitimises the processing. And the guidelines separate reasonable expectations from common sector practice, so everybody in sales does this is not a defence.

the disclosure, for consideration, of personal data ... may be regarded as necessary for the purposes of the legitimate interests pursued by that controller ... only on condition that that processing is strictly necessary for the purposes of the legitimate interest in question and that, in the light of all the relevant circumstances, the interests or fundamental rights and freedoms of those members do not override that legitimate interest

CJEU, Case C-621/22, KNLTB v Autoriteit Persoonsgegevens, 4 October 2024, read 2026-08-31

That ruling is the closest thing to a decision on this business model. It concerned a body disclosing its members' personal data for money to commercial parties, and the Court did not hold that selling contact data is unlawful. It held that the interest must be lawful, that the processing must be strictly necessary, and that the balancing test is real and losable. That is a considerably higher bar than the one implied by a vendor page saying it is GDPR compliant.

Notice the recursion between this section and the country table above. The Court required the interest to be lawful and not contrary to law. If the outreach you plan breaches German or Danish or Dutch rules on unsolicited email, then the interest you are asserting is contrary to law, and the legal basis fails at the first of the three conditions rather than at the balancing stage.

One right has no balancing test at all. Article 21(2) and 21(3) give an absolute right to object to processing for direct marketing, and once someone objects, the data must no longer be processed for that purpose. There is no exception and no weighing exercise. An opt-out is final and immediate, which is why a suppression list is infrastructure and not paperwork.

Sources EDPB Guidelines 1/2024 on legitimate interest read 2026-08-31 · CJEU Case C-621/22, EUR-Lex read 2026-08-31

Has anyone actually been fined over bought contact data?

Yes, repeatedly, and the enforcement is recent rather than theoretical. The decisions below were issued between 2019 and 2025 by the Polish, French and Dutch authorities, and they cover both the sellers of contact databases and one company that bought and used the data.

CaseAuthorityDateFineWhat it turned on
BisnodeUODO, Poland15 Mar 2019PLN 943,470, about EUR 220,000Article 14. Claimed postal notification was disproportionate at PLN 33.7m; held that owning 6.49m postal addresses defeats the claim. Upheld on final appeal in 2023.
KASPRCNIL, France5 Dec 2024EUR 240,000A LinkedIn-scraping contact database of about 160m records. No valid legal basis, informed people four years late, notices in English only, answered source requests with only 'publicly accessible sources'.
SOLOCAL MARKETING SERVICESCNIL, France15 May 2025EUR 900,000The buyer's case. Consent collected through partner forms was invalid, and the user of the data had to verify that itself. Contractual warranties from the supplier were held manifestly insufficient.
TAGADAMEDIACNIL, France29 Dec 2023EUR 75,000, reduced to EUR 50,000 on appealConsent not free or unambiguous on sweepstake forms, plus an Article 30 record that did not say which entity was the controller.
CompaneoOPTA, now ACM, Netherlands2 Oct 2012EUR 100,000About 15 million unsolicited commercial emails sent to businesses. Evidence that the Dutch ban is enforced against business-to-business senders, not only consumer ones.

Fines and dates are taken from each authority's own published decision or press release. Where a decision was appealed, the outcome is noted.

Two of these deserve emphasis for anyone choosing a vendor. Bisnode was working with data from public company registers, which is about the most defensible source there is, and the disproportionate-effort defence still failed. KASPR is the closest analogue to the tools compared on this site: the same business model, the same category of data, and a regulator ruling that publicly available is not by itself an answer to where did you get this.

SOLOCAL is the one to read if you are a buyer rather than a seller. The company had contractual assurances from its supplier and had asked the supplier about verification. CNIL held that was manifestly insufficient, and that the user of the data had to satisfy itself that valid consent existed. Buying from a large, well-known vendor does not transfer the obligation. That is the practical meaning of controller.

Sources UODO decision ZSPR.421.3.2018 (Bisnode) read 2026-08-31 · CNIL, KASPR fined EUR 240,000 read 2026-08-31 · CNIL, SOLOCAL MARKETING SERVICES fined EUR 900,000 read 2026-08-31 · CNIL, TAGADAMEDIA fined EUR 75,000 read 2026-08-31 · ACM, OPTA fines business spam EUR 100,000 (Companeo) read 2026-08-31

What does the buyer have to do that the vendor cannot do for you?

Seven things, and none of them transfer with the invoice. From the moment you take delivery of a list you are a controller in your own right, which means the lawful basis, the notification, the record and the suppression list are yours.

The practical consequence for anyone selling into Europe is that the shape of the operation changes rather than the tooling. Contact data tools remain useful for enrichment of inbound leads, for verifying addresses you already hold, for research before a warm introduction, and for outbound in markets where the rules allow it. What does not survive contact with German or Danish or Dutch law is buying a list and blasting it.

This page is a summary of published regulation, regulator guidance and decisions, with each claim linked to its source. It is not legal advice, and I am not a lawyer. Where a decision turns on the specifics of your business, take advice from someone qualified in the relevant jurisdiction.

Sources GDPR Articles 5, 14, 21, 28, 30, EUR-Lex read 2026-08-31 · CNIL, using a suppression list to respect objections read 2026-08-31

Which contact data vendors make European compliance easier?

Only two of the five tools we track offer a European buyer anything structural: Hunter.io hosts in Belgium by default, and Lusha offers a contractual Europe Service under which it undertakes not to process personal data in a third country. The other three store in the United States with no EU residency option.

Two separate questions get confused here. Where your account data and your uploaded lists are stored is a transfer question, answered by hosting location, the data processing agreement and the transfer mechanism. Whether the vendor's own database was lawfully built is a source question, answered by how they collected it and whether they will tell you. A vendor can be strong on the first and weak on the second.

The source question is where the sharper differences sit. Two of the five build part of their database from their own customers' mailboxes, through a community programme that takes email headers and signature blocks from connected Google or Microsoft accounts. That is a harder legitimate-interest argument in Europe than crawling published web pages, and it is the kind of detail that decides an Article 15 source request. The full breakdown, with each vendor's own wording and the terms it comes from, sits on the comparison page.

Frequently asked questions

Is B2B data exempt from the GDPR?
No. Recital 14 excludes data about legal persons, which covers a company and a generic address such as [email protected]. A named individual's work address relates to that individual and is personal data, so a list of named contacts at European companies is a list of personal data.
Can I cold-email a German business address if I bought the list legitimately?
No. UWG § 7 requires prior express consent from the addressee before a marketing email, and it makes no exception for business recipients, unlike the paragraph on phone calls. Buying the list lawfully does not create the consent, because consent has to come from the person.
How long do I have to tell people I bought their data?
One month from acquisition, or the moment you first contact them, whichever comes first. Article 14(3) sets both deadlines and the earlier one applies, so emailing someone in week one means the notice is due with that first email.
Does the disproportionate effort exemption in Article 14(5)(b) cover a large list?
Rarely. The transparency guidelines endorsed by the EDPB say at paragraph 61 that it should not be routinely relied on outside archiving, research and statistics. Bisnode also shows that holding the contact details is itself evidence that notifying is not disproportionate.
If the vendor says it is GDPR compliant, am I covered?
No. CNIL fined SOLOCAL MARKETING SERVICES EUR 900,000 in May 2025 partly because it relied on its supplier's contractual warranties, which the authority held to be manifestly insufficient. As the user of the data you are a controller and must verify for yourself.
Which European market is the most permissive for cold B2B email?
France. CNIL accepts legitimate interest rather than consent for business prospecting, provided the message relates to the recipient's job and the person was informed and can object easily and free of charge. That second condition is the Article 14 duty restated.