Back to Blog
Strategy

Is Public Data Prospecting Legal? GDPR and B2B Outreach

Public does not mean unregulated. How GDPR applies to B2B prospect lists built from public sources, and what legitimate interests actually requires.

Kuration Team· Kuration AI
12 min read
Is Public Data Prospecting Legal? GDPR and B2B Outreach

Every team that builds prospect lists from public sources eventually hits the same question, usually from someone in legal, and usually the week before a campaign launches. If the information is published on a website, in a registry or on a job board, are we allowed to use it for outreach?

The short answer is that public data prospecting is normal, widespread and lawful in most cases, and that being public is not by itself the reason it is lawful. Data protection law cares far less about where you found information than about why you are processing it, whether the person would expect it, and what you do when they ask you to stop.

This article is a practical orientation, not legal advice. It sets out the questions a revenue team should be able to answer, so the conversation with your own counsel starts from something useful.

Public Does Not Mean Unregulated

The most common misreading is that publishing information removes its protection. It does not. A work email address on a company contact page is still personal data if it identifies a person, and processing it still needs a lawful basis.

What being public does change is the balancing exercise. Information a professional has deliberately published in a business context, on a company website or a professional profile, carries a different expectation than something scraped from a private setting. That difference matters, but it is an input to the analysis rather than a replacement for it.

What Counts as Personal Data in a Prospect List

This is worth being precise about, because most prospect databases mix two very different kinds of record.

  • Company level facts, such as the legal entity, sector, headcount, addresses, filings, certifications and job postings, are generally not personal data
  • Anything that identifies an individual is, including their name, job title tied to a name, professional email, direct phone, and their profile URL
  • A generic company inbox is a grey area that depends on whether it identifies a person in practice

The practical consequence is that the company layer of your database and the contact layer sit under different obligations. Teams that treat the whole list as one undifferentiated thing tend to over restrict the company research and under protect the contacts.

The Question Is Not Whether You May Collect It. It Is Why.

Data protection frameworks are built around purpose. You need a lawful basis to process personal data, and for most B2B outbound the basis relied on is legitimate interests rather than consent.

That choice comes with a cost. Legitimate interests is not a box to tick, it is an assessment you are expected to have actually carried out and to be able to show. It also gives the person a right to object that you have to honour.

Legitimate Interests, in Plain Terms

The assessment is usually described in three parts. None of them require a lawyer to understand, though your final position should be reviewed by one.

The purpose test

Is there a real business interest here? For B2B outbound the answer is normally yes. Contacting a company that plausibly needs what you sell is a recognised commercial activity, and direct marketing is commonly cited as capable of being a legitimate interest.

The necessity test

Is processing this particular data necessary for that purpose? This is where over collection becomes a liability. If you do not need a personal mobile number to send a business email, holding one is harder to justify. Collect the fields the campaign actually uses.

The balancing test

Does your interest override the person's rights and reasonable expectations? A named buyer at a company you sell to, contacted at work, about something relevant to their role, is a very different balance from a private individual contacted about something unrelated to their job.

The output of these three questions should be written down before a campaign, not reconstructed afterwards.

The three part legitimate interests assessment shown as a sequence, a purpose test asking whether there is a real business interest, a necessity test asking whether this specific data is needed, and a balancing test weighing the interest against the persons reasonable expectations
Three questions, answered in writing before the campaign rather than after a complaint.

Relevance Is a Compliance Feature, Not Only a Performance One

There is a useful overlap between what makes outbound work and what makes it defensible. Tightly targeted outreach to people whose role genuinely relates to what you sell scores better on the balancing test than a large untargeted send, and it also gets better replies.

This is the strongest practical argument for building smaller, better researched lists. A list where every company is on it for a reason is easier to justify, easier to personalise and less likely to generate complaints.

Where Prospecting Teams Actually Get Into Trouble

In practice, problems cluster in a few predictable places rather than in the act of using public sources.

  • Collecting far more personal data than the campaign needs, because the enrichment was available
  • Having no record of where a field came from, so a question about provenance cannot be answered
  • Ignoring or slow walking objections and opt outs, which is the fastest route to a complaint
  • No privacy notice that a contacted person could actually find and read
  • Keeping records indefinitely with no retention rule and no review
  • Sending to individuals in jurisdictions with stricter rules using a list and a template built for a looser one

Transparency Is the Part Most Teams Skip

When you collect someone's data from a source other than the person, you are generally expected to tell them, and to make available information about what you hold, why, and how to object.

In practice this usually means a reachable privacy notice covering prospect data, and a first message that does not pretend the relationship is something it is not. A short honest line about why you are reaching out does more for your position than a paragraph of legal text nobody reads.

The Right to Object Has Real Teeth in Marketing

If someone tells you to stop contacting them for marketing purposes, that is not a negotiation. It is not a request to be routed through a nurture sequence, and it is not satisfied by removing them from one campaign while another still holds their record.

Operationally this means a suppression list that sits above every campaign and every tool, is checked before every send, and is never overwritten by the next import. Most teams discover their suppression handling is broken only when someone who objected receives another email.

Email Rules Are a Separate Layer

One of the most common confusions is treating data protection and electronic marketing rules as the same thing. They are separate, and both can apply to the same email.

Data protection law governs whether you may hold and process the person's details at all. Electronic marketing rules govern whether you may send an unsolicited message to that address. The second set differs meaningfully between countries, and several treat messages to a corporate subscriber differently from messages to an individual or a sole trader.

This is why a campaign that is entirely fine in one market can be a problem in another using exactly the same list. Segment by jurisdiction before you segment by persona.

Two stacked layers, a data protection layer covering whether you may hold and process a contact record, and an electronic marketing layer covering whether you may send an unsolicited message to that address, with a note that the second layer varies by country
Two separate questions. Passing the first one does not answer the second.

What Good Practice Looks Like in a Prospect Database

Most of what compliance asks for is simply a well built database, which is why the teams with the cleanest data usually have the easiest conversations with legal.

  • Every record carries its source and the date it was collected
  • Company facts and personal fields are distinguishable rather than merged into one blob
  • Only fields the campaign uses are collected and kept
  • A suppression list sits above every tool and is checked before every send
  • Records have a retention rule and something actually enforces it
  • The reason a company is on the list is recorded, so relevance can be evidenced

None of this is exotic. It is the same discipline that stops a list going stale, and it happens to be what you would want to show if anybody asked.

Questions to Ask Before a Campaign

A short internal checklist catches most issues while they are still cheap to fix.

  • Which jurisdictions are in this send, and do the rules differ across them?
  • What personal fields are we using, and does the campaign need all of them?
  • Can we say where every field came from?
  • Is our suppression list applied at the point of send, not at the point of import?
  • Can a recipient find our privacy notice and object in one step?
  • Would this person be surprised to hear from us about this?

That last question is not a legal test, but it is a good proxy for one. If the honest answer is yes, the targeting is usually the thing to fix.

How Long Should a Prospect Record Live?

Retention is the obligation teams most often have no answer for. Data should not be kept longer than is necessary for the purpose it was collected for, and prospecting rarely has an honest justification for keeping a contact record forever.

The practical approach is to set a review period rather than a deletion date, because the right answer differs by record. A contact who replied and became an opportunity belongs in the CRM under a different purpose. A contact who never engaged across two campaigns and eighteen months is dead weight that carries risk and costs you nothing to remove.

A workable default

Review prospect records that have had no engagement after a set period, delete the personal fields, and keep the company level research if it is still useful. That preserves the expensive part of the work, which is the company discovery, while dropping the part that carries the obligation.

Whatever you choose, write it down and have something enforce it. A retention rule nobody runs is worse than no rule, because it documents an intention you did not meet.

If a Vendor Collected It, It Is Still Yours to Answer For

Buying a list or using an enrichment provider does not move responsibility onto them. If you decide why and how the data is used, the obligations sit with you, and questions about where a record came from arrive at your door rather than the vendor's.

Two practical consequences follow. Ask providers where their data originates and what basis they rely on, and be sceptical of any answer that stops at the word public. Then keep the provenance yourself, in your own database, so you are not dependent on a supplier's records to answer a question about your own campaign.

How Kuration AI Fits

Kuration AI is built around company discovery first. It finds and enriches organisations from public and specialised sources, records the source of every field, and keeps the company layer and the contact layer distinct rather than merged.

That structure supports the practical side of this article. You can show where a field came from, keep only the fields a campaign uses, and build lists where every company has a documented reason for being there.

Frequently Asked Questions

Is it legal to build a B2B prospect list from public data?

In most cases yes, but not simply because the data was public. You still need a lawful basis for any personal data in the list, which for B2B outbound is usually legitimate interests, and you still owe the person transparency and the ability to object.

Does GDPR apply to business contact details?

It applies to information that identifies a person, and a named individual's work email or direct line generally does. Purely company level information such as a registered address or a filing usually does not.

Do I need consent to send B2B cold email?

Not necessarily for the data protection question, where legitimate interests is commonly relied on. Whether you may send the message is a separate electronic marketing question that varies by country, and some jurisdictions are stricter for individuals and sole traders than for corporate subscribers.

What is a legitimate interests assessment?

A short documented analysis covering whether there is a genuine business purpose, whether the specific data is necessary for it, and whether that interest is outweighed by the person's rights and reasonable expectations. It should exist before the campaign runs.

What happens if someone asks to be removed?

Honour it promptly and permanently, across every tool rather than one campaign. Keep the minimum record needed to make sure they are not re added by a later import.

Does scraping make prospecting unlawful?

Collection method is a separate question from data protection, and can involve contract and site terms as well. The safer position is to use sources you are permitted to use, keep a record of them, and avoid collecting fields your campaign does not need.

Build the List You Could Explain

The useful test is not whether a source was public. It is whether you could explain, to the person who received your email, why you have their details, where they came from, and how they can make it stop. A team that can answer those three questions comfortably is usually in reasonable shape.

That standard also happens to describe a better prospect list. Fewer records, each with a reason and a source, targeted at people whose role relates to what you sell. Compliance and quality are pulling in the same direction here, which is rarer than it sounds.

None of the above is legal advice, and the rules differ by country and by circumstance. Use it to prepare the conversation with your own counsel, not to replace it.


Build Prospect Data You Can Account For

Kuration AI discovers companies from public registries, certifications, job boards, trade shows and company websites, records the source of every field it collects, and keeps company data separate from contact data. Build smaller, better targeted lists where every company has a documented reason for being there.

Kuration Team

Kuration Team

Kuration AI

Get started

Build your data edge in 90 seconds

Extract prospects from events, maps, PDFs, and directories, enriched with verified decision maker contacts. No credit card required.

Encrypted in transit & at restGDPR readyNo credit card requiredAuto-refresh, never stale