Lawful basis, records, and opt-outs: doing B2B follow-up properly
Contacting a business contact needs a lawful basis, a record of why, and a working opt-out. What the main regimes expect, and why B2BLead keeps research and records separate from sending.
B2BLead9 min read
Research and contact are different obligations
Researching a company is not the same act as contacting a person there, and the two attract different obligations. Reading a public website to judge whether a business plausibly needs what you sell is ordinary commercial research. Sending an electronic message to a named individual is regulated, and the rules differ by where that person is.
Keeping the two separate is the single most useful habit in this area. It lets you do as much qualification as you like without incurring any messaging obligation, and it means that by the time you do contact someone, you can articulate why — which is exactly what every regime expects you to be able to do.
This article is general information, not legal advice. The regime that applies depends on where your recipient is, and you should confirm your position with a qualified adviser before running any outreach programme.
The regimes differ more than people assume
There is no single global standard for business-to-business contact, and assuming the most permissive rule applies everywhere is how teams get into trouble. In broad terms:
- EU/UK GDPR — you need a lawful basis for processing personal data. Legitimate interests can apply to business contact, but it requires a balancing assessment you should actually document, plus an honoured right to object
- UK PECR and EU ePrivacy — govern electronic marketing specifically, and sit on top of GDPR. Treatment of corporate versus individual subscribers varies, and national implementations are not uniform
- Germany — notably stricter in practice under unfair-competition rules, with prior express consent generally expected even between businesses
- US CAN-SPAM — an opt-out regime rather than a consent one, but it still mandates accurate headers, honest subject lines, identification, a working opt-out, and a physical postal address
- Canada CASL — consent-based, with express and implied consent narrowly defined and meaningful penalties
- Elsewhere — many jurisdictions have their own rules; check rather than extrapolate
What a defensible record looks like
Most of what regulators and payment providers ask for comes down to whether you can explain your own actions after the fact. That is a record-keeping problem, and it is cheap to solve if you do it as you work rather than reconstructing it later.
For each account you decide to contact, keep the reason and the origin attached to the record:
- Why this company — the specific fit or event that made it relevant to what you sell
- Where the contact detail came from, and when you obtained it
- Which role you contacted and why that role rather than a personal address
- What you sent and when, so frequency is visible
- Any objection, unsubscribe, or do-not-contact request, applied immediately and permanently
Where B2BLead sits, and where it does not
B2BLead is research and workspace software. You describe your product under My Business, Prepare with AI builds a scoring brief, product warm-up ranks directory companies in your chosen countries against it, live AI validation judges specific accounts, and Lead CRM holds the account, your notes, and the history.
It is not a list product. B2BLead does not sell static contact databases or email lists, and does not provide marketing lists or marketing data as a deliverable. Contact reveals are metered per account inside the workspace so you can reach a company you have qualified — not so you can assemble and export a marketing database.
It also does not send on your behalf. Outreach goes through your own mailbox and SMTP settings, which means the lawful basis, the message content, the frequency, and the opt-out handling are yours. That is a deliberate boundary, not a missing feature: the party with the customer relationship is the party who has to justify contacting them.
Practical habits that keep you on the right side
None of this requires a compliance function. It requires a handful of defaults that make the careless version harder than the careful one:
- Contact roles, not people's personal addresses, wherever a role address exists
- Write to a specific reason. If you cannot state why this company, that is a signal not to send
- Keep an easy, honest opt-out in every message and process requests the day they arrive
- Maintain a suppression list that survives re-import, so a past objection is never undone by new research
- Keep frequency low and visible in the account history, so nobody gets contacted repeatedly by accident
- Identify yourself and your company plainly — no disguised sender names or misleading subjects
- Re-check your position per market before entering a new country
Why the careful version is also the effective one
The habits above are usually presented as a compliance tax. In practice they overlap almost exactly with what makes business development work: contacting fewer, better-chosen companies, for a reason you can articulate, at a frequency that does not irritate anyone, with an easy way to say no.
The version that gets teams into difficulty — contacting everyone who matches a profile, with no recorded reason and a hard-to-find opt-out — also performs badly. Doing this properly is not a constraint on results so much as a description of the approach that produces them.
Frequently asked questions
- Does B2BLead sell marketing lists or contact databases?
- No. B2BLead sells recurring software access and metered platform credits. It does not sell static contact databases or email lists, and does not provide marketing lists or marketing data as a deliverable. Contact reveals are metered per account inside the workspace so you can reach a company you have already qualified.
- Does B2BLead send outreach for me?
- No. Outreach is sent through your own mailbox and SMTP settings that you configure. B2BLead provides research, scoring, and CRM records. The lawful basis, message content, frequency, and opt-out handling remain your responsibility.
- Is legitimate interests enough to contact a business contact under GDPR?
- It can be a lawful basis for processing, but it is not automatic and it is not the whole picture. It requires a balancing assessment you should document, and the recipient's right to object must be honoured. Separate electronic-marketing rules under PECR or national ePrivacy implementations also apply on top, and some countries expect prior consent even between businesses. Confirm your position for each market with a qualified adviser.
- What records should I keep about an account I contacted?
- The reason the company was relevant to what you sell, where the contact detail came from and when, which role you contacted, what you sent and when, and any objection or opt-out request with the date it was applied. Keeping this on the account record in your CRM as you work is far easier than reconstructing it later.
- How should opt-outs be handled?
- Immediately and permanently. Every message should carry an honest, easy opt-out, requests should be processed the day they arrive, and the suppression should survive future imports and research so a past objection is never undone by a new list.