Is Cold Emailing GDPR Compliant? The Definitive B2B Sales Guide

Yes, cold emailing is GDPR compliant, but only under specific conditions. The GDPR law does not ban cold email outright; it essentially regulates the personal data processing behind it. For B2B outreach, the legal basis is legitimate interest under Article 6(1)(f), reinforced by Recital 47, which includes direct marketing as an example of a legitimate interest. That basis holds only if you pass a three-part test (a genuine purpose, a necessity for using email specifically, and a balance that doesn’t override the data subject’s privacy rights), disclose where you got their contact details, and give them a working way to opt out.

If you skip any of those, the same email that was compliant before becomes a liability the moment someone complains to a regulator. It’s also important to note that GDPR isn’t the only law in play; a separate rule set, the ePrivacy Directive, governs the send itself and varies by country, which is where a lot of otherwise compliant campaigns still run into trouble. This article covers all this in detail.

Table of Contents

What Legal Basis Allows GDPR-Compliant Cold Emailing?

The legal basis is legitimate interest, under Article 6(1)(f) of the GDPR. It’s the only one of GDPR’s six lawful bases that actually fits how B2B outreach works, and it’s the one nearly every compliant cold email program in Europe runs on.

Why Consent Doesn’t Work for Cold Outreach

Most people’s first instinct is that GDPR requires consent for everything. It doesn’t, and for cold email, consent is not only impractical, but it’s also a logical dead end.

Consent under GDPR has to be freely given, specific, informed, and unambiguous, and it has to be obtained before you process someone’s data. Cold email is, by definition, the first contact. You can’t ask a prospect to agree to be emailed in the same email that’s asking them to agree to be emailed. There’s no prior relationship to get consent through, and no form for them to fill out, because they don’t know you exist yet.

That’s exactly the gap Article 6(1)(f) was built to cover. Consent is the right basis for someone who fills out a demo request or subscribes to a newsletter — not for a sales rep reaching out cold.

Legitimate Interest Under Article 6(1)(f), Explained

Article 6(1)(f) allows you to process personal data without consent when you have a genuine business reason, the processing is necessary to achieve it, and that reason isn’t outweighed by the person’s right to privacy. This is not left for interpretation, either, as Recital 47 names direct marketing directly, stating that processing personal data for direct marketing purposes “may be regarded as carried out for a legitimate interest.”

That’s about as close as GDPR gets to endorsing cold email outright. But it’s not a blank check. Legitimate interest only holds up if you can actually demonstrate it — and that’s where the three-part test comes in.

The Three-Part Test: Purpose, Necessity, Balancing

Regulators and courts assess legitimate interest using three questions. If your outreach can’t answer all three honestly, the legal basis doesn’t hold, no matter how well-intentioned the email is.

Purpose test. Is there a real, specific business reason for contacting this person? Data regulators want to see something concrete, like reaching out to a company’s IT director because your product addresses a security gap their industry is currently dealing with. If you can’t articulate the reason beyond “they might buy,” you don’t have one.

Necessity test. Is email the right way to pursue that purpose, and is there a less invasive option that would do the job just as well? For most B2B outreach, this is straightforward — email is a normal, expected channel for professional contact, and it’s less intrusive than a cold call.

Balancing test. Does your interest in contacting them outweigh their interest in not being contacted? This is where role and context matter. A CFO at a company that just raised a funding round expects vendors to reach out — that’s a reasonable professional expectation. A private individual who’s never had a business relationship with you, contacted at a personal address about something irrelevant to their work, tips the balance the other way.

When you pass all three, legitimate interest holds. But when you fail any one, this basis doesn’t hold — regardless of how the email is written or how polite the opt-out is.

How to Document a Legitimate Interest Assessment (LIA) for Cold Email

Passing the three-part test isn’t enough on its own. If a prospect complains, or a regulator comes asking questions, thinking it through in your head carries no weight unless you can show your work. That’s what a Legitimate Interest Assessment is for — a short, written record proving you actually ran the test before you hit send, not after someone objected.

A LIA isn’t a GDPR requirement in name — the regulation never uses the term. But without one, you lose the legitimate interest argument by default the moment it’s challenged. The UK’s ICO publishes a free template, and most European data protection authorities expect to see something equivalent even where they don’t formally name it.

What an LIA Needs to Include

A usable LIA doesn’t need to be long. It needs to answer the same three questions the legal test asks, in writing, tied to a specific campaign, not a vague, one-time company policy.

Purpose. State the actual business reason for the campaign, and make it specific rather than generic. Instead of a broad goal like growing pipeline, describe something concrete like — you’re contacting operations managers at logistics companies because your software addresses a compliance requirement that recently changed for their sector.

Necessity. Explain why email is the right channel, and why you couldn’t achieve the same purpose with a less intrusive method. This is usually a short paragraph — email is standard, expected, and low-friction for professional outreach.

Balancing. This is the part people skip, and the part regulators look at hardest. Note the recipient’s likely expectations, whether the contact details came from a public professional source, and what safeguards are in place — an opt-out, limited frequency, no automated profiling beyond basic role-matching.

Alongside those three, keep a record of where the contact data came from and when it was collected. If a prospect asks how you got their email, you need an answer with a timestamp attached, not a guess.

Good practice is to write a fresh LIA per campaign, not per company. Targeting criteria change, industries change, and a LIA from eighteen months ago covering a different audience won’t hold up for a new list.

Why “We Assumed It Was Fine” Doesn’t Survive a Complaint

Here’s the part most teams get wrong: they run the reasoning in their head, decide it’s fine, and never write it down. That works right up until someone files a complaint, at which point the absence of a document becomes the finding against them.

Regulators don’t take a company’s word that it considered the balancing test. They ask for evidence. No LIA on file typically reads as no assessment having taken place at all, regardless of how reasonable the campaign actually was. It’s the difference between a five-minute conversation with an investigator and a formal inquiry that drags on for months.

This is also why relying on the fact that a company has always sent cold emails this way without a problem isn’t a defense — it just means no one’s complained yet. The first complaint is usually the first time anyone checks whether the paperwork exists.

The next question is what happens once GDPR’s own test is satisfied — because in Europe, GDPR is not the only hurdle. There’s a second law that governs the email itself, and passing one doesn’t mean you’ve cleared the other.

GDPR vs. ePrivacy: Which Law Actually Governs Cold Email?

Everything so far has been about GDPR, and it’s easy to walk away thinking a solid legitimate interest assessment is the finish line. It isn’t. Once you’ve cleared GDPR, there’s a second law waiting — one that governs the email itself, not just the data behind it.

How GDPR and the ePrivacy Directive Interact (Article 95, Recital 173)

The ePrivacy Directive is the older of the two laws, dating back to 2002, and it deals specifically with privacy in electronic communications — things like cookies, call metadata, and unsolicited marketing messages. GDPR arrived later and covers personal data processing broadly, across every context, not just electronic ones.

Where they overlap, GDPR doesn’t take priority by default. As per Article 95, GDPR shouldn’t impose extra obligations on top of rules that already exist under the ePrivacy Directive for the same objective. Recital 173 backs that up, framed the same way. Lawyers call this relationship lex specialis — the more specific law governs, and the general law steps back.

For cold email, that means the ePrivacy Directive is the one setting the actual rules for sending an unsolicited marketing message, while GDPR governs everything upstream of the send: how you collected the contact’s data, what you’re allowed to do with it, and what rights they have over it once you’re in touch. Both laws are in play at once, just answering different questions.

Why Passing the GDPR Test Doesn’t Mean You’re Cleared to Send

This is where a lot of cold email programs quietly go wrong. A team runs a proper legitimate interest assessment, documents the three-part test, and treats the campaign as compliant — without ever checking what the ePrivacy Directive says about actually sending the message.

As we mentioned, the two laws don’t ask the same question. GDPR asks whether you had a lawful reason to process this person’s data in the first place. The ePrivacy Directive asks a narrower, blunter question: are you even allowed to send them a marketing email without their prior consent? And the answer to that second question depends heavily on who the recipient is and which country’s implementation of the directive applies to them.

This is also why country-by-country variation exists at all. The ePrivacy Directive is a directive, not a regulation, which means that each EU member state transposes it into national law separately, and they haven’t done it identically. Germany’s implementation reads very differently from France’s. The UK, post-Brexit, runs its own version through PECR. A campaign that’s fully defensible under GDPR’s legitimate interest test can still be illegal to send in a specific country, because that country’s ePrivacy rules set a stricter bar for direct marketing than GDPR does on its own.

Do Cold Email Rules Differ by Country in the EU and UK?

Yes, significantly — and this is the part of GDPR compliance that trips up more sales teams than the regulation itself. Because the ePrivacy Directive is implemented country by country rather than applied uniformly, the same cold email that’s low-risk in Paris can be a legal problem in Berlin. There’s no single European standard for cold email; there are 27 national ones, loosely related. Here are the top four:

France — Legitimate Interest Applied More Permissively

France is one of the more workable markets for B2B cold outreach in Europe. Its implementation of the ePrivacy Directive allows unsolicited commercial email without prior consent when the message is sent to a professional address and is relevant to that person’s role, which lines up closely with how GDPR’s legitimate interest basis already works.

That doesn’t mean France is a free pass. CNIL, the French data protection authority, has been one of the most active regulators in Europe on marketing and prospecting complaints, and it expects the same fundamentals as anywhere else, including a working opt-out, honest sender identification, and outreach that’s actually tied to the recipient’s professional function rather than a generic mass list. Remember that permissive doesn’t mean unmonitored.

Germany — Stricter Consent Standards and Court-Enforced Damages

Germany runs the opposite way. Its national law, the UWG (Gesetz gegen den unlauteren Wettbewerb, or Act Against Unfair Competition), treats unsolicited commercial email as presumptively unwanted, and German courts have taken a narrow view of what counts as legitimate interest for marketing outreach — narrower than what CNIL or the ICO tolerate.

What makes Germany distinct isn’t just the stricter standard; it’s the enforcement mechanism. Unlike most of the EU, where cold email complaints usually route through the data protection authority, Germany allows individual recipients and competitors to bring civil claims directly through the courts over unsolicited email, and German courts have awarded damages in these cases. That’s a meaningfully different risk profile, as it’s not just regulatory exposure; it’s private litigation exposure, and it moves faster than a DPA investigation typically does. If Germany is a real market for you, treat it as its own compliance track, not a variation on your general EU approach.

UK PECR — The Corporate Subscriber Exemption

The UK sits outside GDPR’s EU framework post-Brexit but runs its own near-identical version, alongside PECR (the Privacy and Electronic Communications Regulations), which is the UK’s implementation of the old ePrivacy Directive.

PECR’s most useful feature for B2B outreach is the corporate subscriber exemption. Consent requirements for unsolicited marketing under PECR apply to individual subscribers — essentially, people contacted in a personal capacity. Emails sent to a corporate subscriber, meaning a limited company, LLP, or Scottish partnership, generally fall outside that consent requirement. In practice, that means cold-emailing a role-based or named contact at a UK limited company is on much firmer ground than emailing a sole trader or an individual using a personal address, even where the outreach is professional in nature.

That exemption doesn’t erase UK GDPR obligations underneath it, though. You still need a legitimate interest basis for processing the contact’s data, a clear sender identity, and a working opt-out — PECR just removes the extra consent hurdle specifically for corporate recipients.

Netherlands — Strict Opt-In Requirements

The Netherlands sits at the stricter end, closer to Germany than to France or the UK. Dutch implementation of the ePrivacy Directive generally requires prior consent for unsolicited commercial electronic messages, with limited carve-outs, and Dutch regulators have not extended the same permissive reading of legitimate interest to B2B cold email that France applies.

For teams prospecting into the Netherlands, that means the safer approach looks less like classic cold outreach and more like building consent through a lower-friction first step — a content offer, a webinar signup, something the recipient actively opts into — before moving into direct sales contact. Treating Dutch contacts the same way you’d treat a French or UK list is one of the more common country-level mistakes in EU outreach campaigns.

What Must a GDPR-Compliant Cold Email Include?

Getting the legal basis right is only half the job. Regulators and courts also look at the email itself, and there are three concrete elements that show up in almost every enforcement case involving cold outreach. When you miss one of these, even a well-documented legitimate interest assessment won’t save you.

1. Sender Identity and Physical Address

Every marketing email needs to make it obvious who’s sending it. That means a real company name, not just a brand or product name the recipient has never heard of, and it means including a genuine physical business address somewhere in the email, usually in the footer.

This requirement traces back to the ePrivacy rules on unsolicited communications, and it exists for a simple reason. A recipient has to be able to identify who’s contacting them and where that company is actually based. Emails sent from a generic address with no company details, no address, and a sender name that doesn’t match the actual business are one of the clearest signals investigators look for when assessing whether a campaign was run in bad faith.

2. Disclosing Where You Got the Recipient’s Data

If someone replies asking how you got their email address, you need a real answer, and ideally you’re providing that answer proactively rather than waiting to be asked. This obligation comes directly from GDPR’s transparency requirements under Articles 13 and 14, which require you to tell people where their data came from when you didn’t collect it directly from them.

In practice, this is usually a short line in the email itself. Something like noting that you found their contact information through their company website, a professional networking platform, or a public conference speaker list. It doesn’t need to be elaborate. It needs to be true, specific, and something you can actually document if pressed. Vague language like “we found your details online” tends to raise more suspicion than it resolves, because it reads as something written after the fact rather than something tracked at the point of collection.

3. A Working Opt-Out, Honored Promptly

Every cold email needs a clear, functioning way for the recipient to say no to further contact, and once they use it, that request has to be respected. This isn’t optional or a courtesy. It’s a direct expression of the right to object under Article 21, and GDPR treats that right as close to absolute for direct marketing. There’s no balancing test the recipient has to pass. If they object, you stop.

A working opt-out means more than a line that says “reply STOP.” It means the request actually gets processed, the person is removed from future sends within a reasonable timeframe, and that removal is tracked somewhere so the same contact doesn’t end up back on a list a few months later through a different campaign or a different rep. This is one of the most common failure points in practice. Teams honour the opt-out on the list they sent from, then re-add the same contact from a fresh data pull without checking suppression records first. That pattern is usually seen as a compliance failure in its own right, not a technical oversight.

Where Can You Legally Source B2B Prospect Data?

The safest sources are the ones a business made public itself for a professional purpose. That includes:

  • Company websites, staff pages, and press contacts;
  • Business registries like Companies House in the UK or equivalent national registers across the EU;
  • Conference and event listings that name speakers and their employers;
  • Industry directories and trade association member lists;
  • And a person’s own LinkedIn profile, viewed and recorded manually rather than pulled through scraping tools.

In each case, the data was published by the business or the individual for a professional reason, and using it for related B2B outreach is a reasonably defensible extension of that purpose.

Where it gets risky is in how that data is collected and compiled, not just where it originates.

Publicly Available Business Contacts vs. Scraped Personal Profiles

There’s a common assumption in sales that if data is visible online, it’s fair game to collect however you like. That’s not how GDPR sees it. Public visibility and lawful processing are two separate questions, and confusing them is one of the more expensive mistakes a company can make.

Manually noting a director’s name and general contact email from a company website, or pulling a speaker’s name and employer from a conference agenda, is about as clean as B2B data sourcing gets. The information was published by the business itself, it’s limited to what’s relevant to that role, and the volume involved is small and targeted.

Scraping personal profiles at scale is a different situation entirely, even when each profile is technically public. Pulling names, job titles, and inferred emails from thousands of individual social profiles, building a searchable database out of it, and reselling or using that data for cold outreach involves a much bigger footprint of personal data than any one person agreed to when they made their profile visible. Regulators have been explicit that public does not mean unrestricted. The Dutch data protection authority has described large-scale scraping of personal data as almost always a violation, and that view has shaped enforcement across several EU regulators, not just the Netherlands.

The Risk of Purchased Lists and LinkedIn Scraping

Buying a list doesn’t transfer someone else’s compliance work to you. If the vendor’s data was collected unlawfully, and you use it, you’re processing that data too, and you inherit the same exposure the original collector had. Article 14 requires you to be transparent with data subjects about where you got their information even when you weren’t the one who originally collected it. You need an answer, and “we bought it from a vendor” is rarely a complete one if you can’t say how that vendor sourced it lawfully in the first place.

LinkedIn scraping specifically carries two separate layers of risk that are worth pulling apart. The first is contractual. LinkedIn’s user agreement prohibits automated scraping outright, and LinkedIn has actively pursued legal action against companies doing it at scale, including a 2025 lawsuit against Proxycurl, whose LinkedIn data API shut down entirely as a result. That’s a breach of contract issue, separate from privacy law, but it’s still a real business risk if your data supply chain depends on it.

The second layer is GDPR itself, and this is where the real regulatory teeth are. In December 2024, France’s CNIL fined the contact enrichment company Kaspr €240,000 over how it built its contact database, largely from scraped professional profiles. The fine itself was relatively modest by GDPR standards, but the operational orders alongside it were the real consequence. CNIL required Kaspr to stop collecting data from profiles where visibility had been restricted, stop automatically extending how long it retained data, and properly respond to access requests with full disclosure of where the data came from. For a company whose entire product is a contact database, being ordered to delete large portions of it and change how it collects data going forward is a far bigger hit than the fine.

The practical takeaway for anyone building outbound lists is to treat data provenance as a due diligence question, not an afterthought. If you’re buying from a vendor, ask directly how they source their data and whether they can demonstrate a lawful basis for it. If the answer is vague, or the vendor can’t explain where a contact’s email actually came from, that uncertainty becomes yours the moment you send the first email.

What Happens When a Recipient Objects? (Article 21)

Sooner or later, someone on your list is going to reply and ask to be left alone. How a company handles that single moment tends to say more about its actual compliance posture than any policy document sitting in a drawer somewhere.

Why the Right to Object Overrides Legitimate Interest

Article 21 gives people an unconditional right to object to their personal data being used for direct marketing. The word unconditional is doing real work there. Legitimate interest was a balancing act, weighing your business reason against the recipient’s privacy expectations, and in most cases that balance favoured reasonable, well-targeted outreach. Article 21 removes that balancing act entirely once someone objects. There’s no test to pass at that point, no argument about how relevant the outreach was or how carefully it was targeted. The objection itself ends the legal basis for using that person’s data in marketing, full stop.

This is actually one of the cleaner parts of GDPR, because it removes ambiguity rather than adding it. Companies don’t get to decide whether an objection was reasonable. They don’t get to argue that their legitimate interest was strong enough to override it. Once the objection comes in, continuing to process that person’s data for marketing purposes is a violation, regardless of how solid the original legitimate interest assessment was.

It’s worth being clear on what this doesn’t cover, too. An objection to marketing doesn’t erase every other relationship a company might have with that person’s data. If they’re also a customer with an active contract, or their information is retained for a legitimate legal or financial reason, those bases aren’t automatically wiped out by a marketing objection. What Article 21 kills is the marketing use specifically.

Response Timelines in Practice

GDPR doesn’t hand out a fixed number of days for processing an objection to marketing the way it does for some other data subject requests, but regulators consistently expect it to be fast and without unnecessary friction. The practical standard that has emerged across enforcement guidance is that removal should happen as soon as reasonably possible, and definitely before the next scheduled send touches that contact again.

In real operational terms, that means an unsubscribe or objection can’t sit in an inbox for two weeks while a rep gets around to it manually. It needs to flow into a suppression list automatically, or close to it, so the person isn’t accidentally re-added by a different campaign, a different tool, or a colleague pulling from an older version of the same contact list. This is where a lot of otherwise compliant teams slip. The objection gets honoured on paper, in the sense that someone marks the contact as unsubscribed in one system, but the same email address resurfaces a few months later from a fresh list pull that never checked the suppression record first.

Documenting how objections are handled matters almost as much as handling them promptly. If a regulator or a complainant later asks whether a request was honoured and when, having a timestamped record showing the contact was suppressed shortly after the objection came in is the difference between a quick resolution and a drawn-out investigation. Treat every unsubscribe the same way you’d treat a legal deadline, because functionally, that’s close to what it is.

GDPR Cold Email Compliance Checklist

Everything covered so far comes together into a fairly short list of concrete checks. This is the version worth keeping open on a second monitor before a campaign goes out, or printing and pinning above a desk. It won’t replace a proper legitimate interest assessment, but if any of these items is missing, that’s a strong signal the campaign isn’t ready to send.

Before you build the list

  • You can name the specific, genuine business reason for contacting each segment of this list, beyond simply wanting more leads
  • You’ve confirmed email is a necessary and appropriate channel for this outreach, not just the easiest one
  • You know exactly where each contact’s data came from, and that source is documented with a date
  • The data wasn’t scraped at scale from personal profiles or purchased from a vendor who can’t explain their own sourcing

Before you write the legitimate interest assessment

  • A written LIA exists for this specific campaign, not a general company policy from months or years ago
  • The purpose, necessity, and balancing sections are all filled in with real detail, not boilerplate language
  • Someone has actually considered whether the recipient’s role and context make this outreach reasonably expected

Before you check which laws apply

  • You’ve identified which country each recipient is based in, and checked whether that country’s ePrivacy implementation adds stricter requirements than GDPR alone
  • If any recipients are in Germany, you’ve treated that list as a separate, higher risk track rather than folding it into general EU outreach
  • If any recipients are in the Netherlands, you’ve considered whether a lower friction opt-in step should come before direct cold outreach
  • UK recipients have been checked against the PECR corporate subscriber exemption, and you’re not relying on it for sole traders or personal addresses

Before you send

  • The email clearly states your real company name and includes a genuine physical business address
  • The email discloses, specifically and truthfully, where you got the recipient’s contact details
  • There’s a working opt-out mechanism, not just a reply instruction that nobody is actually monitoring

After you send

  • Objections and unsubscribes are processed quickly, ideally through an automated suppression list rather than manual tracking
  • Suppressed contacts are checked against new list pulls before future campaigns, so people who objected don’t resurface under a different list
  • You’re keeping a timestamped record of when objections were received and honoured, in case it’s ever questioned later

Frequently Asked Questions

Is cold emailing illegal under GDPR?

No, cold emailing is not illegal under GDPR on its own. GDPR regulates how you process personal data, not whether you’re allowed to send an email at all. B2B cold outreach is generally lawful when it’s based on legitimate interest under Article 6(1)(f), the data was sourced transparently, and the recipient has a clear way to opt out. What makes cold email illegal isn’t the act of sending it; it’s doing so without a valid legal basis, ignoring disclosure obligations, or continuing to contact someone after they’ve objected.

Can I cold email without consent?

Yes, in most B2B contexts. GDPR doesn’t require consent for every type of processing, and legitimate interest is a separate, equally valid legal basis that fits cold outreach far better than consent does, since consent has to be obtained before first contact, which isn’t possible with cold email by definition. That said, consent isn’t off the table everywhere. Some countries, Germany and the Netherlands in particular, apply stricter national rules under their ePrivacy implementations that lean more heavily toward requiring consent, so the answer shifts depending on which country your recipient is in.

What if a prospect asks how I got their email?

You need to be able to give them a real, specific answer, not a vague one. GDPR’s transparency rules under Articles 13 and 14 already require you to disclose the source of someone’s data when you didn’t collect it directly from them, so ideally this information is included in the email itself rather than something you’re scrambling to answer after the fact. A good answer names the actual source, whether that’s the company website, a professional networking platform, or a public event listing, and matches whatever record you kept when the data was first collected. If you can’t answer this question with specifics, that’s usually a sign the data sourcing wasn’t documented properly in the first place.

Does GDPR apply to role-based inboxes like info@ or sales@?

Generally, no, because GDPR only protects personal data, and a generic address like info@company.com or sales@company.com typically doesn’t identify a specific individual on its own. That makes these addresses a lower risk option for outreach compared to a named inbox like jane.smith@company.com, which clearly identifies a person and is treated as personal data.

There’s a real exception worth knowing, though. If a role-based inbox is effectively used by, and identifiable as belonging to, one specific person, whether that’s common knowledge internally or something you could reasonably work out, it can still count as personal data in practice. This comes up most with small businesses and sole traders, where an address like hello@janedoe.com looks generic but clearly points to one identifiable person. When in doubt, it’s safer to treat the address as personal data and apply the same standards you would to a named contact.

Does GDPR apply if my company is outside the EU?

Yes. GDPR applies based on whose data you’re processing, not where your company is based. If you’re sending cold emails to someone located in the EU or UK, GDPR and the relevant ePrivacy rules apply to that outreach regardless of whether your business operates from Kenya, the US, or anywhere else outside Europe. This is often called GDPR’s extraterritorial reach, and it’s one of the most commonly underestimated parts of the regulation among sales teams operating from outside the EU. Targeting European prospects means European rules apply, full stop, and geography on your end doesn’t change that.

Conclusion

Cold emailing under GDPR comes down to a few fundamentals, done consistently. A genuine legitimate interest, documented before you send. A working knowledge of which country’s ePrivacy rules apply on top of GDPR. Clear sender identity, honest disclosure of your data source, and an opt-out that actually works when someone uses it. None of it is complicated on its own, and none of it requires abandoning cold outreach as a channel. It just requires treating compliance as part of how the campaign is built, not something to sort out after a complaint lands.

Leave a Comment

X