Answer

What is GDPR for sales?

This page explains the GDPR mechanics that touch a sales team day to day: the lawful bases, the seven data principles, the subject rights, and the common CRM gotchas. It is a general-purpose explanation, not legal advice. Talk to counsel before building your program.

Short answer

GDPR is the European Union data protection law that took effect in 2018 and governs how any company handles the personal data of people in the EU, including sales prospects. It defines six lawful bases for processing data, grants data subjects rights like access and erasure, and requires documentation, breach notices within 72 hours, and contracts with every vendor that touches the data. For B2B sales teams, legitimate interest is usually the lawful basis for cold outreach.

Key points

What matters most.

Six things every revenue leader should know about GDPR before approving a cold-outreach program, a data import, or a new CRM.

What it is

An EU law with global reach.

The General Data Protection Regulation took effect May 25, 2018 and applies to any organization that processes personal data about people in the EU and UK, regardless of where the company is based. A startup in Austin selling to a prospect in Berlin is in scope. The law replaced a 1995 directive and raised the ceiling on fines dramatically.

The six bases

Every record needs a lawful basis.

Consent, contract, legal obligation, vital interests, public task, and legitimate interest. A sales team cannot process personal data without picking and documenting one of these six. For B2B cold outreach, legitimate interest is usually the right fit; for marketing newsletters and consumer sales, consent is almost always required.

Seven principles

Lawful, fair, transparent, minimal.

GDPR imposes seven data-handling principles: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. Every CRM field, every segment, and every bulk import has to answer to these. Hoarding fields "just in case" is not compliant.

Subject rights

Access, correction, deletion, portability.

People whose data you hold can ask what you have, correct it, delete it, port it to another vendor, restrict how you use it, or object to processing. Most requests must be answered within one month. A sales team cannot ignore these just because the prospect became a lead through a trade show list.

Vendor contracts

A DPA with every processor.

Every tool that touches the data on your behalf (CRM, email platform, enrichment service, phone system, call recorder, analytics) is a processor, and GDPR requires a signed Data Processing Agreement with each one. International transfers out of the EU need an extra layer (Standard Contractual Clauses or an adequacy decision).

Breach timeline

72 hours to notify regulators.

A personal-data breach that risks the rights of individuals must be reported to the supervisory authority within 72 hours of becoming aware. Serious breaches also require notifying affected people. The timer runs on the clock, not the business week, and the fine math punishes slow responders.

The six lawful bases

Pick one, document it, stick to it.

GDPR does not ban holding personal data. It requires that every piece of personal data in your CRM be tied to one of six specific lawful bases, chosen before processing starts and documented in a way you can defend. Switching bases later is messy. For most sales teams, two of the six carry the real weight: consent (for marketing to consumers) and legitimate interest (for B2B outreach). The other four show up in edge cases, but you should know what they are before leaning on them.

Consent

Freely given, specific, informed.

The person actively agreed to the specific processing, with a clear description of what you will do and the ability to withdraw at any time. Pre-ticked boxes do not count. Consent is the standard basis for marketing newsletters, lead magnets, and most B2C sales. It is also the most fragile, because withdrawal must be as easy as giving it.

Contract

Needed to deliver the deal.

Processing is necessary to perform a contract with the person, or to take steps at their request before a contract. Billing addresses on paid customers, shipping details on fulfilled orders, support contacts on an active account. This basis is clean for existing customers and unavailable for cold prospects you have never contracted with.

Legal obligation

The law requires it.

Processing is required to comply with a legal obligation, such as tax records, anti-money-laundering checks, or regulatory reporting. Narrow and specific. A sales team does not get to invoke this to justify a prospect database; it covers compliance-driven records like invoices and KYC data.

Vital interests

Life-or-death processing.

Needed to protect the life of the person or another individual. Used by hospitals, emergency services, and humanitarian organizations. If a sales team is leaning on vital interests to justify an outreach campaign, something has gone very wrong.

Public task

Public-interest processing.

Processing is carried out in the public interest or in the exercise of official authority. Reserved for public bodies and some regulated entities. Not a basis that applies to a private-sector sales motion.

Legitimate interest

The B2B outreach basis.

Processing is necessary for a legitimate interest of the controller or a third party, provided that interest is not overridden by the rights and interests of the person. For B2B cold outreach to a work contact at a company that could plausibly buy your product, this is usually the right basis. It requires a documented Legitimate Interest Assessment (LIA) weighing your interest against the prospect's.

The seven principles

How GDPR expects data to be handled.

Picking a lawful basis is step one. The seven data principles describe how the data has to be treated once it is in the system. Every CRM field, every automated workflow, every segmentation query, every bulk import has to pass these seven tests. The accountability principle at the end is the one most teams underestimate: you must be able to prove compliance, not just claim it.

Lawful, fair, transparent

Nothing hidden from the person.

Processing must have a lawful basis, be fair to the person, and be transparent in a way the person can actually understand. Hidden tracking pixels, data bought from a broker without disclosing the source, and privacy policies written in dense legalese all fail this test. A one-click link from your email to a plain-English notice usually passes.

Purpose limitation

Collect for one job, use for that job.

Data collected for one specific purpose cannot be quietly reused for an unrelated one. The contact who signed up for a product changelog did not consent to being enrolled in a cold-outbound campaign for a different product line. Re-permissioning the list is required before the pivot.

Data minimization

Only what you actually need.

You should collect only the fields that are strictly necessary for the purpose. Hoarding birthday, home address, personal mobile number, and spouse name "in case the rep wants to send a card" is not minimization. The CRM should justify every field it stores against a specific use, not a wish list.

Accuracy

Keep records up to date.

Personal data must be accurate and, where necessary, kept up to date. Stale leads with bounced emails, old phone numbers, and former employers linger in every CRM. The accuracy principle requires an active hygiene process, not a one-time import. Automated bounce handling and quarterly list reviews belong in the program.

Storage limitation

Delete when the purpose ends.

Data must not be kept longer than needed for the stated purpose. A prospect you have not touched in three years, who never became a customer, almost certainly fails this test. Retention policies with concrete timeframes (e.g., 24 months of inactivity triggers deletion) are the operational answer, and the CRM has to be able to enforce them.

Integrity and confidentiality

Protect the data from leaks.

Appropriate technical and organizational security measures: encryption at rest and in transit, role-based access, audit logs, strong authentication, backup discipline, incident response. The breach that puts a company on the regulator's front page almost always traces to a basic control that was never implemented.

Accountability

You must be able to prove it.

The controller is responsible for, and must be able to demonstrate, compliance with the other six principles. That means records of processing activities, documented lawful bases, LIAs, DPIAs where required, retention schedules, DPAs with every processor, and an audit trail your regulator or a prospect's procurement team can inspect.

Cold B2B outreach

How legitimate interest actually works.

The question every sales leader asks about GDPR is some version of: "can we still send cold email in Europe?" The answer is usually yes for B2B, provided the campaign is scoped to legitimate interest and the people on the list have a plausible connection to what you sell. The gotcha is that legitimate interest is not a get-out-of-jail-free card; it has three tests, each of which must pass, and you must document the reasoning before you press send. Note too that country-level ePrivacy rules (the "cookie law" and marketing-communication rules) sit on top of GDPR and vary by member state. Germany, for example, is stricter than the Netherlands.

Purpose test

Is the interest legitimate?

The first test asks whether the processing serves a real, lawful, specific interest. Selling a B2B product to a buyer at a company that could use it clears this bar comfortably. "We want to grow revenue" is a legitimate interest. Random data mining with no concrete purpose is not.

Necessity test

Is the processing necessary?

The second test asks whether the processing is actually needed to serve the interest, or whether a less intrusive route could reach the same goal. If you can find the prospect through a public LinkedIn profile and send one targeted business email, that is more defensible than scraping ten thousand records from a doubtful source.

Balancing test

Do their rights outweigh yours?

The third test weighs your interest against the person's rights, freedoms, and reasonable expectations. A work email at a company website, contacted by one rep with a relevant product and an easy opt-out, usually passes. A personal gmail address scraped off a hobby forum does not. The balancing test is where most sloppy outreach programs lose.

LIA documented

Write the assessment down.

The three tests have to be documented in a Legitimate Interest Assessment (LIA) that an auditor could read in five minutes. The LIA lives in your records of processing. If a regulator asks why you emailed someone, "we did an LIA and here it is" is the answer that holds up; "we assumed it was fine" is not.

Easy opt-out

Every message, every time.

A legitimate-interest cold email must include a clear way to object to further processing. A one-click unsubscribe link in every message, honored immediately, is the baseline. Rights to object are stronger under GDPR than under US spam laws, and ignoring an opt-out is one of the fastest ways to earn a complaint.

B2C is different

Consumer sales need consent.

The legitimate-interest route works for B2B outreach. For marketing to consumers (B2C) or sending marketing newsletters to any audience, country-level ePrivacy rules usually require prior opt-in consent. Treat B2B outreach and B2C marketing as two separate compliance programs that happen to share the CRM.

CRM gotchas

Where sales programs trip over GDPR.

Most GDPR trouble inside a sales team does not come from the strategy. It comes from day-to-day CRM operations: a bulk import nobody vetted, an old list a new rep decided to warm back up, an enrichment vendor plugged into the pipeline without a contract. The pattern repeats across companies. These are the places where a well-intentioned program quietly stops being compliant, and where a quarterly review usually finds the broken piece.

Bulk imports

The list from the old job.

A new rep arrives, exports contacts from their last employer, and imports them into your CRM. Half of those contacts have no relationship to your business and no basis for being processed by you. Imports from unverified sources are one of the most common sources of GDPR exposure. Every import needs a source and a basis before it lands.

Re-permissioning

Old lists do not auto-refresh.

A dormant list collected under old consent terms (or no consent at all) cannot be revived with "we miss you" emails. Legitimate interest might cover a narrow re-engagement for B2B contacts still in a relevant role, but blanket re-mailing of a 10-year-old list is usually indefensible. Prune first, then outreach.

Enrichment vendors

Buying data has a provenance problem.

Enrichment tools that append email addresses, phone numbers, and firmographic data to your CRM are processors, and the data they sell has to have come from somewhere lawful. If the vendor cannot explain their basis, you are importing their risk. DPAs and provenance disclosures from every data vendor are non-negotiable.

Call recording

Phone systems process personal data.

Call recordings capture a voice, which is personal data. The dialer, the recording vendor, and the transcription service are all processors. Many regions also require disclosing the recording at the start of the call. The telephony stack sits inside GDPR scope just as firmly as the CRM.

Subject requests

A rep cannot ignore a DSR.

When a prospect emails "please delete my data," that triggers a formal Data Subject Request with a one-month clock. It does not matter who received it or how casually it was phrased. The CRM has to support a workflow that routes DSRs to the privacy function and completes them end to end, including removal from backups and processors.

International transfer

EU data crossing a US border.

If your CRM, email tool, or data warehouse is hosted in the United States, you are transferring EU personal data out of the EU. Those transfers need a lawful transfer mechanism (Standard Contractual Clauses or a recognized adequacy decision like the EU-US Data Privacy Framework). The right contracts and the right regional hosting are both part of the answer.

Program hygiene

What a defensible sales program looks like.

A sales program that holds up under a GDPR audit does not depend on heroics. It depends on a short list of boring artifacts that get kept current. If you can produce these on request and show that your tooling actually enforces them, you are in a much better position than a team with a slick pitch deck and no records. Again, this is a general-purpose checklist, not legal advice; a privacy counsel should review your specific program.

Data mapping

Know what you hold and why.

A record of processing activities (ROPA) that lists every category of personal data, the lawful basis, the source, the retention period, the processors involved, and the international transfer path. It does not have to be a 200-page document; a well-maintained spreadsheet or a GRC tool is enough. The point is that you can answer "what do you have on me?" in minutes.

DPIA

Impact assessment for risky processing.

A Data Protection Impact Assessment is required when processing is likely to result in high risk to individuals: large-scale profiling, systematic monitoring, special-category data, automated decision-making with legal effect. Sales programs that layer AI scoring on top of a huge contact database often cross the DPIA threshold without noticing.

DPA with every processor

Contracts, not just handshakes.

Signed Data Processing Agreements with every vendor that touches the data on your behalf. CRM, email platform, enrichment service, dialer, recorder, data warehouse, analytics tool, each one needs its own DPA. Keep them in one folder your privacy function can produce without an archaeology project.

Breach plan

A written 72-hour runbook.

A documented incident response plan that defines what counts as a breach, who gets notified internally within an hour, who escalates to the supervisory authority, and how affected individuals are informed when risk warrants it. The 72-hour clock does not pause for business hours. The plan should be rehearsed, not just written.

DPO or privacy lead

A named owner for the program.

A Data Protection Officer is required for public bodies, for organizations doing large-scale systematic monitoring, and for processing of special-category data at scale. Even when a DPO is not mandatory, a named internal owner for privacy is a practical necessity. "The CTO handles it in their spare time" is not a program.

Not legal advice

Talk to counsel for your situation.

The checklist above is a general framework, not legal advice for your specific business, data flows, member states, or industry sector. GDPR enforcement varies by country, by regulator, and by sector-specific overlays. Have a qualified privacy lawyer review your program before launch, and keep that relationship active as the program evolves.

A CRM that supports your compliance work, not around it.

Strkr includes role-based access, audit logs, retention controls, bulk opt-out handling, and a published DPA. Pricing is public and the feature pages show exactly what ships today. Still: talk to privacy counsel before launching an EU program.

People also ask

Related questions.

Does GDPR apply to a US company selling to Europe?

Yes. GDPR applies to any organization that processes the personal data of people in the EU and UK, regardless of where the organization is based. A US company sending cold emails to prospects in Germany or France is in scope, and so is the US-hosted CRM behind that outreach. The company has to pick a lawful basis, document it, honor subject rights, and sign DPAs with its processors just like an EU-based competitor.

Is cold email to a B2B prospect legal under GDPR?

Usually yes, provided the outreach is grounded in legitimate interest. That means a documented Legitimate Interest Assessment showing the purpose is real, the processing is necessary, and the prospect's rights are not overridden. The email should go to a work address at a company that plausibly uses products like yours, include transparency about where you got the contact, and offer an easy opt-out. Country-level ePrivacy rules can tighten this further, so a privacy counsel should sign off on the specific program.

What is legitimate interest, and how does it apply to sales?

Legitimate interest is one of the six GDPR lawful bases for processing personal data. It covers processing that is necessary for a legitimate interest of the organization, provided that interest is not overridden by the rights of the person. For B2B sales, it is typically the basis that supports cold outreach to work contacts at companies that could buy the product. It requires a three-part assessment (purpose, necessity, balancing) and must be documented in writing before processing begins.

What rights do data subjects have under GDPR?

Eight rights: to be informed, to access the data held about them, to rectification of inaccurate data, to erasure (the right to be forgotten), to restriction of processing, to data portability, to object to processing, and rights related to automated decision-making and profiling. Most requests must be answered within one month. A sales team cannot refuse these just because the person became a lead through a trade show list or a referral.

What is a DPA, and does my CRM need one?

A Data Processing Agreement is a contract between a controller (you) and a processor (a vendor acting on your behalf) that sets out how personal data will be handled. GDPR requires a DPA with every processor. Your CRM, email platform, enrichment service, phone system, call recorder, and analytics tool are all processors, and each one needs its own signed DPA. Most reputable vendors publish a template DPA that can be executed with a signature.

What are the GDPR breach notification rules?

A personal-data breach that risks the rights or freedoms of individuals must be reported to the relevant supervisory authority within 72 hours of becoming aware. Breaches with high risk also require notifying the affected individuals without undue delay. The 72-hour clock runs on real time, not business hours, so an incident response plan with on-call escalation is a practical necessity. Delayed or missing notifications are a common driver of large fines.

When does a company need a Data Protection Officer?

A DPO is mandatory for public bodies, for organizations whose core activities require large-scale systematic monitoring of individuals, and for organizations that process special-category data (health, biometric, political opinions, and similar) at scale. Many private-sector sales organizations do not strictly need a DPO, but a named internal owner for privacy, with clear authority and budget, is practical even where not required. Some national laws also impose lower thresholds, so check the local regime.

Is GDPR the same as the UK GDPR or CCPA?

No. The UK GDPR is the UK's post-Brexit version of GDPR, nearly identical to the EU text with a UK regulator (the ICO) and some national-law overlays. CCPA (California) is a separate US state law with different mechanics, different definitions, and different enforcement; it focuses more on sales of personal information and consumer opt-outs than on lawful bases. A company selling to EU, UK, and California prospects usually needs to design one program that satisfies all three, rather than treating them as interchangeable.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.