GDPR-compliant B2B lead generation — to many sales teams, that sounds like a contradiction. It is not: researching public company data for new customer acquisition is fundamentally possible under the GDPR (the EU General Data Protection Regulation, known in Germany as the DSGVO), usually on the basis of legitimate interest under Art. 6(1)(f) GDPR. The prerequisites are a documented balancing of interests, fulfilled information duties under Art. 14 GDPR, working processes for data subject rights, and the right outreach channel under § 7 UWG (a provision of the German Act Against Unfair Competition). This guide explains all four building blocks — and what is expressly off-limits. It is not legal advice.
Does the GDPR apply to B2B lead generation?
Yes, the GDPR also applies to B2B lead generation — but only to personal data, meaning information about identified or identifiable natural persons (Art. 4 No. 1 GDPR). Data about companies as legal entities is not covered. In practice, however, this line blurs quickly:
- Data about legal entities (GmbH, AG, registered merchants with multiple shareholders) does not fall directly under the GDPR
- For sole traders, freelancers, and partners in a GbR (a German civil-law partnership), company data and personal data are identical — here the GDPR applies in full. For skilled-trade businesses, medical practices, or law firms, this is the norm, not the exception
- Data about individuals as representatives of a company (such as "Max Mustermann, Managing Director") is personal data and subject to the GDPR
- Generic role addresses like info@firma.de are, in practice, considered less sensitive than personalized addresses — but as soon as they can be attributed to a person (sole proprietorships), they too are personal data
Personal data means any information relating to an identified or identifiable natural person — in the B2B context, that includes a contact's name, personalized email address, direct dial number, or LinkedIn profile. Anyone building a lead list should therefore assume that a substantial share of the records is subject to the GDPR, and design the process accordingly from the start.
Company data or personal data — where is the line?
The line does not run between "B2B" and "B2C", but between data with and without a link to a natural person. The same piece of information can fall under the GDPR or not, depending on the company's legal form. The following overview shows the most important cases:
| Type of data | Personal reference | GDPR applicable? |
|---|---|---|
| Company name, address, switchboard number of a GmbH | No | No — but the UWG applies to outreach |
| info@firma.de of a GmbH | Usually no | Only if the address can be attributed to a person |
| Name and email of a managing director or employee | Yes | Yes, in full |
| All data of a sole trader or freelancer | Yes | Yes, in full |
| Handelsregister entry with managing directors' names | Partially | Yes, for the personal-data portions |
The practical consequence: you do not need two separate processes. If you set up your lead research so that it holds up for personal data, you are automatically on the safe side with pure company data as well — the reverse is not true.
Which legal basis permits B2B lead generation?
The central legal basis for researching and storing B2B contact data is legitimate interest under Art. 6(1)(f) GDPR. Recital 47 of the GDPR expressly names direct marketing as a form of processing that can serve a legitimate interest. The German supervisory authorities acknowledge this as well: the guidance of the Datenschutzkonferenz (the conference of German data protection authorities) on direct marketing (February 2022) confirms that marketing-related data processing can be based on Art. 6(1)(f) GDPR — but stresses at the same time that the value judgments of the UWG feed into the balancing of interests.
Legitimate interest is not a free pass but a three-stage balancing exercise that you should document:
- Name the legitimate interest: New customer acquisition in B2B is a recognized economic interest
- Check necessity: Are you processing only the data needed for the purpose (company name, business contact data, industry) — or more?
- Balance the interests: Do the interests of the data subject prevail? For business contact data from public sources, processed in a professional context, they usually do not — for private data or unexpected uses, they do
Important: "the data is public" is not a blank check on its own. You always need the documented balancing, and the processing must stay within what the data subject can reasonably expect. A managing director who publishes their contact details in the company's Impressum (Germany's mandatory site notice) must expect business contact — but not that their record will be resold to third parties.
Which data sources are suitable?
Suitable sources are those that the company itself makes publicly accessible and whose origin you can prove for each record:
- Listings on Google Maps / Google Business Profile
- Impressum details on company websites
- Contact emails on public websites (info@, kontakt@)
- Public LinkedIn profiles of managing directors
- Handelsregister entries (the German commercial register)
How to retrieve this public data in a technically clean way and within Google's terms of service via the Google Places API is explained in our article on Google Maps scraping and the legal API alternative.
Which information duties apply under Art. 14 GDPR?
Anyone who collects personal data not from the person themselves — the normal case in lead research — must actively inform the data subject under Art. 14 GDPR: within a reasonable period, at the latest within one month of collection, and in any case at the latest at the time of first contact. This duty is the one most frequently overlooked in practice.
The mandatory disclosures include in particular:
- The identity and contact details of your company (and, where applicable, of the data protection officer)
- The purpose and legal basis of the processing — for Art. 6(1)(f) GDPR, also the specific legitimate interest
- The categories of data processed and their source (e.g. "public directory listing", "Impressum of the company website")
- The storage period or the criteria for determining it
- Data subject rights, in particular the right to object under Art. 21 GDPR, and the right to lodge a complaint with a supervisory authority
In practice, you solve this with a brief transparency note in the first outreach ("I obtained your contact details from your public company profile") plus a link to a complete privacy notice. The exemption in Art. 14(5)(b) GDPR — no duty where the effort would be disproportionate — is to be interpreted narrowly and regularly does not apply to targeted individual outreach to leads: if you can contact a person, you can also inform them.
The outreach channel decides: What does § 7 UWG allow?
The GDPR only governs data processing — for promotional outreach, § 7 UWG applies in addition, and in the view of the data protection authorities its value judgments feed directly into the balancing of interests. The rules differ significantly by channel:
- Email: Under § 7 Abs. 2 Nr. 2 UWG, marketing emails require prior express consent — even in B2B. There is no such thing as "presumed consent" for email. The only exception: existing customers under the narrow conditions of § 7 Abs. 3 UWG. Cold emails to researched addresses without consent are anticompetitive and can trigger an Abmahnung (a formal cease-and-desist warning under German law)
- Phone (B2B): permissible with presumed consent (§ 7 Abs. 2 Nr. 1 UWG) — the circumstances must indicate a concrete, substantive interest of the person called in the offering; mere membership in an industry is not enough
- Postal mail: Direct mail to business addresses is generally permissible on the basis of legitimate interest, as long as no objection has been raised
Researched email addresses are therefore primarily research and verification data (who is the right contact, what is the domain) — not a mailing list for cold outreach. The details of email outreach are explained in our article on B2B cold email outreach in Germany, and the rules for calls in the guide to B2B telephone prospecting.
Which data subject rights do you have to implement?
Every person in your lead database has enforceable rights for which you need working processes — no matter how small the list is. The four most important ones:
- Access (Art. 15 GDPR): On request, you must disclose within one month which data you store, where it came from, and what you use it for
- Rectification (Art. 16 GDPR): Incorrect data must be corrected without undue delay
- Erasure (Art. 17 GDPR): If the purpose no longer applies or an objection takes effect, the data must be deleted — leads with no response should be deleted after a reasonable time anyway
- Objection (Art. 21 GDPR): The objection to direct marketing is absolute — it must be implemented immediately, without any balancing. Maintain a suppression list so that contacts who objected do not end up in the database again during the next research run
A verified case shows that supervisory authorities take this seriously: in 2019, the Berlin Commissioner for Data Protection and Freedom of Information imposed fines totaling 195,407 euros on Delivery Hero Germany GmbH — among other reasons, because one person received 15 further marketing emails despite an express objection to advertising, and old accounts were not deleted.
What is not allowed in B2B lead generation?
Prohibited or highly risky are above all these practices — they appear again and again in Abmahnung proceedings and fine cases:
- Sending marketing emails without prior express consent (§ 7 Abs. 2 Nr. 2 UWG — also in B2B)
- Using private email addresses or private social media profiles for prospecting
- Using data of persons who have objected
- Buying address lists from unclear or illegal sources — without a demonstrable legal basis for the original collection, you are liable for the further processing
- Harvesting data behind logins or from closed areas
- Storing more data than necessary for the outreach (a violation of data minimization, Art. 5(1)(c) GDPR)
Practical guide: How to reduce the risk of your lead generation
- Document your balancing of interests — legitimate interest only holds if it is reasoned and recorded in writing
- Choose the right channel — phone (B2B, with presumed consent) and postal mail are defensible; email only with consent or in an existing customer relationship
- Use public data sources with proof of origin — Google Places and company websites are more traceable than purchased databases of unclear provenance
- Fulfill the information duty — inform about the data source, purpose, and right to object at the latest at first contact; keep your privacy notice up to date
- Process data in Europe — US tools mean additional review effort (third-country transfer)
- React immediately to objections — anyone who opts out must be removed from all lists at once and blocked from being re-added
How does anilead.io support a privacy-oriented process?
anilead.io is a B2B lead generation software for the DACH market that finds companies via Google Places, extracts email addresses, and scores every lead with Claude AI. Three properties are relevant for data protection practice: only publicly accessible company data is processed (Google Places API, company websites), the source of origin is stored per record — which makes access requests under Art. 15 and source disclosure under Art. 14 easier — and data processing runs on EU servers in Frankfurt. This considerably reduces the review effort compared to US-based databases, but does not replace your own responsibility: anilead.io is deliberately not an email sending tool, and the legally compliant design of the outreach — channel choice, consents, information duties — rests with you as the user. Why data provenance makes the difference when choosing a tool is shown in our comparison of Apollo.io alternatives for DACH.
Frequently asked questions about the GDPR in B2B lead generation
Do I need consent to research B2B leads?
No, for researching and storing business contact data from public sources, legitimate interest under Art. 6(1)(f) GDPR with a documented balancing of interests is usually sufficient. You only need consent for certain outreach channels: under § 7 Abs. 2 Nr. 2 UWG, marketing emails require prior express consent — even in B2B.
May I use Impressum data for prospecting?
Yes, Impressum data is publicly accessible company information and may be researched and stored on the basis of legitimate interest. But "public" is not a blank check: the balancing of interests must be documented, the information duty under Art. 14 GDPR still applies, and outreach is subject to the channel rules of § 7 UWG.
Do I have to actively inform every researched lead?
In principle, yes: Art. 14 GDPR requires information within one month of collection, at the latest at first contact. A practicable approach is a source note in the first outreach plus a link to the privacy notice. The exemption for disproportionate effort (Art. 14(5)(b) GDPR) regularly does not apply to targeted individual outreach.
What are the consequences of violations?
Three risks in parallel: fines from the data protection authorities under Art. 83 GDPR (in the 2019 Delivery Hero case: 195,407 euros), competition-law Abmahnungen with cease-and-desist declarations and contractual penalties for impermissible promotional contact (§ 7 UWG), and damages claims by affected persons under Art. 82 GDPR. Clean processes are considerably cheaper than the first legal dispute.
Is a US tool for lead generation automatically impermissible?
No, but it increases the review effort: you must secure the third-country transfer (for example via the EU-US Data Privacy Framework or standard contractual clauses), assess the legal basis of the underlying contact database, and fulfill the information duties. EU hosting and traceable public data sources simplify this review considerably.
Conclusion
B2B lead generation and the GDPR are not mutually exclusive. What matters is a documented legal basis (Art. 6(1)(f) GDPR), fulfilled information duties (Art. 14 GDPR), data subject rights that are actually honored (in particular the absolute objection to direct marketing under Art. 21 GDPR), and the right outreach channel under § 7 UWG. If you observe all this, you reduce the risk of Abmahnungen and fines to a minimum — but there is never a guarantee in data protection law. This article is not legal advice; for an assessment of your specific process, qualified legal counsel is the right choice.


