Does GDPR apply to a US company selling to Europe?
Yes. GDPR applies to any organization that processes the personal data of people in the EU and UK, regardless of where the organization is based. A US company sending cold emails to prospects in Germany or France is in scope, and so is the US-hosted CRM behind that outreach. The company has to pick a lawful basis, document it, honor subject rights, and sign DPAs with its processors just like an EU-based competitor.
Is cold email to a B2B prospect legal under GDPR?
Usually yes, provided the outreach is grounded in legitimate interest. That means a documented Legitimate Interest Assessment showing the purpose is real, the processing is necessary, and the prospect's rights are not overridden. The email should go to a work address at a company that plausibly uses products like yours, include transparency about where you got the contact, and offer an easy opt-out. Country-level ePrivacy rules can tighten this further, so a privacy counsel should sign off on the specific program.
What is legitimate interest, and how does it apply to sales?
Legitimate interest is one of the six GDPR lawful bases for processing personal data. It covers processing that is necessary for a legitimate interest of the organization, provided that interest is not overridden by the rights of the person. For B2B sales, it is typically the basis that supports cold outreach to work contacts at companies that could buy the product. It requires a three-part assessment (purpose, necessity, balancing) and must be documented in writing before processing begins.
What rights do data subjects have under GDPR?
Eight rights: to be informed, to access the data held about them, to rectification of inaccurate data, to erasure (the right to be forgotten), to restriction of processing, to data portability, to object to processing, and rights related to automated decision-making and profiling. Most requests must be answered within one month. A sales team cannot refuse these just because the person became a lead through a trade show list or a referral.
What is a DPA, and does my CRM need one?
A Data Processing Agreement is a contract between a controller (you) and a processor (a vendor acting on your behalf) that sets out how personal data will be handled. GDPR requires a DPA with every processor. Your CRM, email platform, enrichment service, phone system, call recorder, and analytics tool are all processors, and each one needs its own signed DPA. Most reputable vendors publish a template DPA that can be executed with a signature.
What are the GDPR breach notification rules?
A personal-data breach that risks the rights or freedoms of individuals must be reported to the relevant supervisory authority within 72 hours of becoming aware. Breaches with high risk also require notifying the affected individuals without undue delay. The 72-hour clock runs on real time, not business hours, so an incident response plan with on-call escalation is a practical necessity. Delayed or missing notifications are a common driver of large fines.
When does a company need a Data Protection Officer?
A DPO is mandatory for public bodies, for organizations whose core activities require large-scale systematic monitoring of individuals, and for organizations that process special-category data (health, biometric, political opinions, and similar) at scale. Many private-sector sales organizations do not strictly need a DPO, but a named internal owner for privacy, with clear authority and budget, is practical even where not required. Some national laws also impose lower thresholds, so check the local regime.
Is GDPR the same as the UK GDPR or CCPA?
No. The UK GDPR is the UK's post-Brexit version of GDPR, nearly identical to the EU text with a UK regulator (the ICO) and some national-law overlays. CCPA (California) is a separate US state law with different mechanics, different definitions, and different enforcement; it focuses more on sales of personal information and consumer opt-outs than on lawful bases. A company selling to EU, UK, and California prospects usually needs to design one program that satisfies all three, rather than treating them as interchangeable.