Every enrichment vendor’s website says “GDPR compliant.” None of them can make you compliant, because the obligation sits with you, not with the tool. You are the controller. The vendor is processing on your instructions, and if a contact object to how their data was appended, the regulator writes to your legal team.
That gap between what the vendor promises and what you actually owe is where most B2B teams sit right now. They have a data enrichment programme running, a provider under contract, and no written record of why any of it is lawful. According to the CMS GDPR Enforcement Tracker Report, which logged 2,685 fines worth roughly EUR 6.11 billion to a 1 March 2026 cut-off, “insufficient legal basis for data processing” is the violation category that has produced the highest number of fines. Not breaches. Not security failures. Missing paperwork on why you were allowed to hold the data at all.
Direct answer — Is B2B data enrichment legal under GDPR?
B2B data enrichment is lawful under the GDPR when you rely on legitimate interests under Article 6(1)(f) and can produce a documented three-part assessment covering purpose, necessity and balancing. Company-level attributes such as headcount, industry or revenue are not personal data. Named work emails and direct dials are. The lawful basis lets you hold and enrich the record. It does not by itself permit the marketing message, which separate ePrivacy rules govern.
Key Takeaways
- Legitimate interest under Article 6(1)(f) is the working legal basis for B2B enrichment. It requires a documented assessment, not a checkbox.
- Two separate permissions are in play: the lawful basis to hold and enrich a record, and the permission to send a message to it. Passing one does not grant the other.
- A named work address like
firstname.lastname@company.comis personal data. A genericinfo@inbox generally is not. - Because enriched data was not collected from the person, Article 14 gives you at most one month to tell them, and no later than your first message.
- The widely quoted three-year retention limit is a French regulator’s recommendation, not a GDPR rule. Cite it accurately or set your own defensible period.
Does GDPR apply to B2B data?
GDPR applies to B2B data whenever that data identifies a living person, and the fact that the person is at work when you contact them changes nothing. There is no business-to-business exemption anywhere in the regulation. What actually decides the question is whether a given field points at a human being or at an organisation.
This distinction does most of the work in practice, and it is the reason a lot of enrichment activity turns out to be less exposed than teams fear. Appending a company’s employee count, funding stage, tech stack or SIC code involves no personal data at all. Appending the mobile number of the person who runs procurement involves a great deal of it.
| Enriched field | Personal data? | Why |
|---|---|---|
| Company headcount, revenue band, industry, funding round | No | Describes an organisation, not an identifiable person |
| Technologies installed on the company domain | No | Attribute of the company estate |
Generic inbox (info@, sales@, hello@) | Usually no | Routes to a function, not to a named individual |
Named work email (firstname.lastname@) | Yes | Identifies one person directly |
| Job title tied to a named contact record | Yes | Identifies a person once combined with employer |
| Direct dial or work mobile | Yes | Reaches one identifiable person |
| LinkedIn profile URL, seniority, tenure | Yes | Attached to a named individual |
| Any field on a sole trader or unincorporated partnership | Yes | The business and the person are the same legal entity |

Named versus generic email addresses
The single most useful line to draw across an enrichment programme runs between named and generic addresses. A named address identifies one person, so every GDPR obligation attaches to it: lawful basis, notice, access, objection, deletion. A generic inbox monitored by whoever is on shift usually identifies nobody, so those obligations do not attach in the same way.
The UK’s Information Commissioner’s Office makes the point directly in its marketing guidance, warning organisations to “consider data protection implications if you are emailing employees at a corporate body who have personal corporate email addresses (eg firstname.lastname@org.co.uk).” That caveat exists precisely because teams assume a work address is somehow less personal than a private one. It is not.
Two edge cases break the rule and both are common in enrichment output. Patterned addresses that are trivially reversible, such as jsmith@ or j.smith@, still identify a person once you hold the company and a name list. And sole traders are treated as individuals in full, so a one-person consultancy gets the same protection as a private citizen no matter how commercial the address looks.
Two gates, not one
The most expensive misunderstanding in B2B enrichment is treating compliance as a single question. There are two gates, they are set by different laws, and clearing the first does not open the second.
Gate one is the lawful basis under GDPR Article 6. It governs whether you may hold, append to and process the record at all. For enrichment this is almost always legitimate interests.
Gate two is the permission to send, governed by ePrivacy rules rather than by GDPR itself. In the UK that is PECR; across the EU it is each member state’s implementation of the ePrivacy Directive. It governs whether you may put a marketing message into that inbox.
The ICO states the relationship plainly: legitimate interests “can apply for direct marketing but only where the Privacy and Electronic Communication Regulations (PECR) don’t require consent.” A perfectly documented legitimate interests assessment does not authorise an email that PECR says needs consent. This is the distinction almost every enrichment guide collapses, and it is the one that decides whether your outbound programme is defensible.
Under the ICO’s electronic mail marketing rules, you may email any corporate body: a company, a limited liability partnership, a Scottish partnership or a government body. But “sole traders and some partnerships are treated as individuals,” which means consent, not opt-out. So the same enrichment job that safely appends a contact at a 400-person manufacturer produces a record you cannot legally email when the target turns out to be a two-person consultancy.

IMPORTANT
This article explains how the rules are structured and what regulators have published. It is not legal advice, and it cannot be. Your lawful basis depends on your specific purpose, your data, and the countries your contacts sit in. Get a qualified data protection lawyer or your DPO to sign off the assessment before you rely on it.
The Article 6(1)(f) three-part test, applied to enrichment
Article 6(1)(f) permits processing that “is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.” Recital 47 confirms that direct marketing “may be regarded as carried out for a legitimate interest,” which is the sentence the entire B2B data industry stands on.
That sentence is permission to make the argument, not permission to skip it. The ICO breaks Article 6(1)(f) into a three-part test, and the European Data Protection Board set out the same structure in its Guidelines 1/2024, adopted on 8 October 2024. Three cumulative conditions: pursue a legitimate interest, show the processing is needed for it, then confirm the person’s rights do not take precedence.
The record of that reasoning is a legitimate interests assessment. Both regulators put it in the same place in the sequence. The ICO says you “should do this test before you start using the personal information,” and the EDPB’s guidelines state that controllers “should carefully assess and document” the three conditions and that this “should be done before carrying out the relevant processing operations.” That rules out the common pattern of running enrichment for a year and writing the justification when a complaint arrives.
| Test | The question | What a defensible enrichment answer looks like |
|---|---|---|
| Purpose | Are you pursuing a legitimate interest? | Named commercial purpose tied to a real offer and a plausible buyer. “Identify operations leads at 200-plus-seat logistics firms who buy routing software” passes. “Grow the database” does not. |
| Necessity | Is the processing necessary for that purpose, with no less intrusive route? | Field-by-field justification. If you segment on headcount and industry, you cannot justify appending personal mobiles because the provider includes them. Every appended field earns its place or gets switched off. |
| Balancing | Do the person’s interests, rights and freedoms override yours? | Assessment of reasonable expectation. A director listed publicly in a professional capacity expects vendor contact. Someone whose personal mobile was inferred by a probabilistic match does not. |
The balancing test is where enrichment programmes actually fail, because reasonable expectation tracks how the data was obtained, not how useful it is. Data taken from a public professional profile sits at one end. Data assembled by probabilistic inference sits at the other, and the further a field travels from something the person knowingly published, the harder the balance is to win. That gradient is worth understanding before you buy: the accuracy claims behind resolved identities vary enormously, and the same measurement questions that govern visitor identification match rates apply to any vendor telling you how confidently it resolved a person.
Workflow · 45 min
How to run a legitimate interests assessment for a B2B enrichment programme
Produces the written record that Article 6(1)(f) requires, covering one enrichment programme and the specific fields it appends.
State the commercial purpose in one sentence
Name the offer, the buying role and the company profile you are targeting. If the sentence needs the word “and” twice, you have more than one purpose and each needs its own assessment.
List every appended field and justify it individually
Write the segmentation or routing decision each field feeds. Switch off any field in your provider’s schema that no decision consumes, and record that you did.
Assess reasonable expectation per data source
Score each source on whether the person knowingly published the data in a professional context. Flag inferred, probabilistic and scraped-personal sources as higher risk and decide whether to keep them.
Record the outcome, the date and a review trigger
Sign and date the assessment, store it with your Article 30 processing record, and set a review for any change of provider, purpose or target market.

What you must tell someone on first contact
Enriched data triggers a notice duty that data collected from your own forms does not. Article 14 covers personal data obtained from anywhere other than the person themselves, which is the definition of enrichment, and it sets a deadline most outbound programmes miss.
You have a reasonable period and at most one month from obtaining the data. If you are going to contact the person, the deadline moves earlier: no later than the first communication. In practice the first email is the notice, and it has to carry more than a footer.
The disclosure has to cover who you are, why you are processing, which lawful basis you rely on and what the legitimate interest is, how long you will keep the data, the rights the person holds including the right to object, the right to complain to a supervisory authority, and the source the data came from. That last item is the one enrichment teams routinely cannot answer, and it is why vendor source disclosure is a contractual issue rather than a curiosity.
Article 21(4) reinforces the point from the other direction: the right to object must be “explicitly brought to the attention of the data subject” at the latest at the time of first communication, and presented separately from other information. A visible objection route in the first message is not a courtesy. It is the rule.
PRO TIP
Write the Article 14 disclosure as a short linked privacy notice built for this purpose, then reference it in the first message with one plain sentence explaining where you got the details. Burying it in a template footer satisfies nobody and reads worse than saying it directly.
Opt-out, objection, and what deletion has to reach
Article 21(2) gives every person an unconditional right to object to processing for direct marketing, at any time. Article 21(3) states that once they object, “the personal data shall no longer be processed for such purposes.”
Read those two provisions against Article 21(1), which covers objections on other grounds and lets a controller continue if it can demonstrate compelling legitimate grounds. The direct marketing provision contains no such escape. There is no balancing to run and no argument to make. The objection is absolute.
What that means operationally is stricter than most suppression setups. Suppressing a send while the enriched profile stays live, keeps refreshing and keeps feeding your scoring model means you are still processing for marketing purposes. An objection has to reach the enrichment layer, not just the sending layer. Three things follow:
- The contact goes on a permanent suppression list that survives every future import, or the same provider will re-append them next quarter and you will start again.
- The enrichment job stops refreshing that record, and any scheduled re-enrichment excludes it.
- Derived fields built from their data, including scores and segment memberships, are cleared rather than left in place.
The suppression list itself is legitimate to keep. You cannot honour an objection you have no record of, so retaining the minimum identifier needed to keep someone suppressed is necessary processing, not a contradiction.
How long you can keep an enriched record
GDPR sets no number. Article 5(1)(e) requires only that personal data be kept in a form permitting identification “no longer than is necessary” for the purpose. The three-year figure that circulates through every enrichment guide is not in the regulation.
It comes from France’s CNIL, which takes the position that prospect data may be kept for three years from the date of collection or the last contact. That is a national regulator’s guidance and a sensible default. It is not a ceiling written into GDPR, and repeating it as though it were is the fastest way to signal that an article was assembled from other articles.
The CNIL’s own enforcement shows why the mechanism matters more than the number. In May 2025 it fined the data broker CALOGA EUR 80,000, and part of the objection was that each time a prospect opened an email, even inadvertently, the company extended the storage period. A retention clock that any passive signal can reset is not a retention policy. It is permanent storage wearing a policy’s clothes.
Set the clock on meaningful engagement, define what counts before you need to defend it, and stage the lifecycle the way CNIL describes: an active base, a restricted intermediate archive where access is exceptional, then deletion or anonymisation. Enrichment complicates this because a refreshed record can look new when the underlying relationship is years cold. Date the acquisition, not the last refresh.

What to ask an enrichment vendor before you sign
Vendor due diligence is where the controller obligation becomes concrete, because you are accountable for a supply chain you did not build. “GDPR compliant” on a pricing page carries no legal weight. The questions below do, and a provider that cannot answer them in writing is telling you something.
- What is the lawful basis for your own collection, and where is it documented? The provider needed a basis to build the dataset before you needed one to use it.
- Can you name the source of each field, per record? Article 14 obliges you to disclose provenance. If the vendor cannot supply it, you cannot comply, and no contract clause fixes that.
- Will you sign a DPA under Article 28, and does it cover sub-processors? Ask for the sub-processor list and the notification terms for changes to it.
- Are you a processor or an independent controller here? Many data providers are controllers of their own database and processors only for the enrichment call. That changes who owes what, and vendors are often vague about it.
- How do you handle a data subject request that reaches you rather than us? Look for a defined route and a response window, not goodwill.
- Where is the data processed, and what covers international transfers? Standard contractual clauses or an adequacy decision, named in the contract.
- Will you accept our suppression list as a permanent exclusion? A provider that cannot suppress at source will keep re-supplying people who objected.
Sequencing multiplies this work rather than dividing it. A waterfall enrichment setup that falls through four providers to fill one field means four sourcing stories behind a single value, and your Article 14 disclosure has to survive whichever one answered. Treat provenance as a selection criterion when you compare data enrichment tools, not as a compliance detail to sort out after procurement.

None of this replaces understanding the mechanics of what you are buying. If the underlying process is unfamiliar, the concepts behind B2B data enrichment explain what gets appended and how the matching works, which is the foundation the necessity test is argued on.
Where this guidance stops
This article is not legal advice and should not be used as a substitute for it. It describes how published regulator guidance and the text of the regulation fit together, which is a starting point for a conversation with someone qualified, not a replacement for one.
Several things sit deliberately outside it. National implementations differ, and the ePrivacy rules that govern sending are set country by country, so an approach that works for UK corporate bodies may not work in Germany or Spain. The UK’s Data (Use and Access) Act has put parts of the ICO’s own marketing guidance under review. US state privacy laws follow different logic entirely and are not covered here. And any programme involving special category data, automated decisions with legal effects, or large-scale profiling raises questions a legitimate interests assessment alone does not settle.
The honest position is that GDPR gives B2B enrichment a workable path and asks you to show your reasoning. Most teams have the reasoning. Very few have written it down.
Frequently Asked Questions
Yes. GDPR contains no B2B exemption. It applies whenever data identifies a living person, including at work. Company-level attributes like headcount or industry fall outside it, but a named work email, direct dial or job title tied to a named contact is personal data and carries the full set of obligations.
A named address such as firstname.lastname@company.com is personal data because it identifies one individual. A generic inbox like info@ or sales@ usually is not, since it routes to a function rather than a person. Patterned addresses that are easily reversible, and anything belonging to a sole trader, count as personal data.
Usually not for the enrichment itself. Legitimate interests under Article 6(1)(f) is the standard basis, provided you document the three-part test. Consent may still be required to send a marketing message, because ePrivacy rules govern sending separately and treat sole traders as individuals rather than as businesses.
GDPR sets no fixed period, only that data be kept no longer than necessary. France’s CNIL recommends three years from collection or last contact for an unresponsive prospect, which is a useful default rather than a legal ceiling. Define what resets the clock, and do not let passive signals like email opens extend it.
GDPR is not US law, but it applies to US companies that process the data of people in the EU or UK when offering goods and services or monitoring behaviour. A US team enriching and emailing European contacts is in scope. Domestic US targeting is governed by state privacy laws instead.






