โ Blog ยท September 24, 2026
GDPR and LinkedIn outreach: what B2B teams are actually responsible for
Two rulebooks, and only one of them belongs to LinkedIn
Start by separating them, because every confused conversation about this collapses the two. LinkedIn's User Agreement is a contract between you and a private company: it governs automation, scraping, account sharing and what happens to your account if you break it. The consequence of breaching it is enforcement by LinkedIn โ a restriction, a ban, a legal letter. The GDPR is public law: it governs how you handle information about identifiable people, and the consequence of breaching it is a regulator or a complainant, entirely independently of what LinkedIn does or notices.
That distinction matters practically. You can run outreach that LinkedIn is perfectly relaxed about and still have a data-protection problem, because the problem lives in your CRM rather than on the platform. And you can be diligent about data protection while still breaching platform rules. Passing one review does not pass the other. This article deals with the second rulebook; it is a working map for a commercial team, not legal advice, and anything consequential should go past your own counsel or DPO.
Is cold LinkedIn outreach lawful under the GDPR?
It generally can be, and the usual route is legitimate interest rather than consent. Article 6(1)(f) allows processing necessary for your legitimate interests where those are not overridden by the individual's rights and freedoms. Regulators have long accepted that direct marketing can be a legitimate interest; recital 47 of the GDPR says so in terms. What regulators do not accept is treating that as a formality.
The test has three parts and you are expected to have written down your answers before you send, not after someone complains.
- Purpose: what is the interest? "Contacting people whose job is to buy or evaluate this category of product" is an interest. "Growing our list" is not.
- Necessity: is direct contact a reasonable way to achieve it, or would something less intrusive do the same job?
- Balance: would this person reasonably expect a message like this, in this role, about this subject? A named procurement lead at a company that buys your category would. A junior employee contacted at a personal address about something unrelated to their work would not.
Write that up once as a legitimate interests assessment for each campaign type and keep it. It is a short document, and it is the single thing most likely to be asked for if a complaint arrives. Relevance beats volume here: the tighter your targeting, the easier the balancing test is to pass, which is one reason disciplined B2B targeting is a compliance argument as well as a performance one.
One caveat worth flagging to counsel: rules on unsolicited electronic marketing, such as the ePrivacy regime in the EU and PECR in the UK, sit alongside the GDPR and apply to email and SMS. Whether and how they bite on messages sent inside a platform is a question your legal adviser should answer for your specific setup rather than one to settle from a blog post. The GDPR obligations described here apply either way.
The moment it becomes your problem: export
Looking at a profile on LinkedIn is not the event that creates your obligations. Copying it out is. The moment a name, job title, employer and profile URL land in your spreadsheet, CRM or sequencing tool, you are holding personal data as a controller, and a stack of duties attaches to it โ including several that people are surprised by.
- Transparency about indirect collection. Article 14 covers data you did not get from the person themselves, which is exactly what a prospect list is. In broad terms you have to tell them who you are, what you are doing with their data and where you got it โ at the latest when you first contact them. A line in your first message pointing at your privacy notice is the practical way this is usually done.
- The right to object. Where you rely on legitimate interest for direct marketing, an objection is absolute. There is no balancing exercise left to do and no cooling-off period. "Take me off your list" has to mean deletion or suppression, applied across every tool you use, not just the one they replied in.
- Retention. A prospect record that has sat untouched for years is hard to justify. Set a retention period per record type and actually run it.
- Accuracy and minimisation. Keep what the outreach needs โ role, company, contact route, the conversation. Enriched personal detail that never influences a message is data you are holding without a reason.
- A record of processing. Your prospecting database should appear in your Article 30 record alongside everything else, with its lawful basis named.
Note what is not on that list: consent. You do not need a prospect's prior consent to rely on legitimate interest, and a vendor who tells you that every B2B contact must first opt in has misread the regime. What you do need is the documentation and the reflexes above.
What your outreach provider is, in the law's language
If an agency runs sequences against your list, they are processing personal data on your instructions. In GDPR terms that usually makes you the controller and them a processor, and Article 28 requires a written contract between you. This is the paperwork gap we see most often โ a signed commercial proposal with no data terms attached to it at all.
| Ask the provider for | Why it matters |
|---|---|
| A data processing agreement with Article 28 terms | Without it the arrangement is non-compliant on its face, regardless of how carefully anyone behaves |
| A named list of sub-processors | Their sequencing tool, CRM and enrichment vendors are all handling your prospects' data |
| Where the data is stored and who can access it | International transfers need a lawful mechanism; a team outside the EEA or UK is a transfer |
| Deletion or return at the end of the engagement | The default should be that your list does not stay on their systems after you leave |
| How opt-outs are executed and how fast | An objection handled in their inbox but not reflected in your CRM leaves you exposed |
| Security basics: access control, device policy, offboarding | Processors are required to have appropriate measures, and you are required to check |
There is a sharper version of the question for lead sourcing. If a provider brings you a list they built themselves, ask on what lawful basis it was collected and what the people on it have been told. A list with no answer to that question is a liability you are importing into your own systems. When we run outreach for a client, the underlying list is the client's to define and the client's to keep, and the data terms sit alongside the commercial ones.
Where account rental complicates the picture
If outreach runs from a rented profile, the conversations sit inside an account you do not own, and the prospect data flows through a third party's hands. Two things follow. First, the processing agreement needs to cover that provider explicitly, including what happens to message history and any exported contacts when the arrangement ends. Second, your own export discipline becomes the thing that makes deletion and subject-access requests answerable at all โ you cannot honour a deletion request across data you cannot see.
The platform-rules question sits on top of this and does not go away: LinkedIn's User Agreement asks members not to share their account, and accounts can be restricted. A managed arrangement reduces that through human-paced activity, no bulk automation, a dedicated network per profile and a written agreement with a consenting owner. It does not make the arrangement something LinkedIn endorses. Treat the two rulebooks separately when you brief your counsel, and see our honest assessment of whether rental is worth it for the commercial side of the same decision.
A checklist you can hand to a legal reviewer
- Name the lawful basis for prospect data in writing โ for most B2B outreach, legitimate interest โ and file a short assessment for each campaign type.
- Add prospecting to your record of processing activities with its retention period.
- Publish a privacy notice that covers prospect data specifically, and reference it in first contact so Article 14 is satisfied.
- Build one suppression list that every tool reads, and make objections propagate to it the same day.
- Sign an Article 28 data processing agreement with every provider, tool and freelancer that touches the list, with a sub-processor list attached.
- Check where the data sits and who can reach it, and document the transfer mechanism if that is outside the EEA or UK.
- Set a review date. A legitimate interests assessment written for last year's campaign does not cover this year's targeting.
Most teams find this takes a day of work and then almost none. The teams that struggle are the ones that built a list first and went looking for a basis afterwards. If you want to talk through how a provider should be contracted before you sign anything, get in touch and bring your counsel's questions with you.
Key takeaways
- LinkedIn's User Agreement and the GDPR are separate exposures โ passing one review does not pass the other.
- Legitimate interest, not consent, is the usual lawful basis for B2B outreach, but it requires a written balancing assessment.
- Prospect data becomes your responsibility on export, which triggers transparency, objection and retention duties.
- An objection to direct marketing is absolute โ suppress across every tool the same day, not just where they replied.
- Any provider touching your list needs an Article 28 processing agreement with a named sub-processor list.
Frequently asked questions
Do I need someone's consent before sending them a LinkedIn connection request or message?
Under the GDPR, generally no โ B2B direct marketing is usually run on legitimate interest rather than consent, provided your targeting is relevant to the person's professional role and you have documented the balancing test. Separate rules on unsolicited electronic marketing apply to channels like email and SMS, and how they apply to in-platform messages is a question for your own legal adviser.
Is exporting contacts from Sales Navigator into my CRM a GDPR issue?
Yes, in the sense that it is the moment you become a controller of that personal data with the full set of duties attached โ lawful basis, transparency, retention, objection handling and a record of the processing. It is a separate question from whether the export complies with LinkedIn's own terms, which is a platform matter. Treat both as live and answer them independently.
Does GDPR apply if my company is based in the US?
It can. The regulation applies where you offer goods or services to people in the EU or monitor their behaviour, so a US company running outreach into European markets is generally in scope for that activity. The UK operates an equivalent regime. If you sell into Europe, assume you are in scope and have counsel confirm the detail for your setup.
What should happen to my prospect list when I stop working with an outreach agency?
The default in your contract should be that the agency returns or deletes your data at the end of the engagement, with a short window for anything they must retain for legal reasons. Ask specifically about copies inside sequencing tools, shared inboxes and enrichment platforms, because those are where lists tend to survive a formal deletion. Get confirmation in writing when it is done.
Want results like these on your LinkedIn?
We run done-for-you outreach + lead generation. Book a free strategy call.
Book a Free Call โ