GDPR & sales prospecting: how to find new customers without breaking the law

Published by Kirsti Aakerholt, 5 Jul 2026. Updated 7 Aug 2026

Prospecting is business-critical, but under GDPR, how you find, contact, and store prospect data comes with rules - worth knowing whether you're new to sales or a veteran.

Does GDPR affect your sales team?

Ask yourself:

  • Do you rely on purchased leads to fill your pipeline?
  • Do you add business card contact details to a mailing list without asking first?
  • Do you ask existing customers for referrals?-

If you answered yes to any of these, GDPR affects how you do it. And it doesn't matter whether your business is based in the EU - if you hold data on even one EU citizen, GDPR applies to you.

What counts as personal data?

Names, emails, phone numbers, and interests are the obvious ones - the kind of information sales reps store in a CRM every day. But personal data also covers things like IP addresses, social media activity, and financial or medical details, so it's worth being deliberate about what you collect and why.

How prospecting works under GDPR

Collecting data and informing people

When you collect someone's data - through a web form, a follow-up email, or any other channel - they have the right to know what you're collecting, why, and for how long you'll keep it. If you didn't get explicit consent at the point of collection, you should inform them promptly that you're storing their data and why.

If someone asks you to delete their data after that, you need to comply - unless you have a genuine legal reason to retain it, in which case your Data Protection Officer should be able to explain that reason to them.

Example consent notification email

![Example consent notification email](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/consent-notification-email.png)

Processing the data

Once you have permission to store a prospect's data, you still can't use it however you like. Just because you have someone's email address doesn't mean you can add them to every mailing list you run — they need to actively opt in to each type of communication. Subscription management tools make this manageable at scale.

Subscription management settings

![Subscription management settings](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/subscription-management-settings.png)

7 ways to prospect compliantly

1. Email outreach

Automated cold outreach without prior contact or consent isn't compliant. You can still send genuinely one-to-one cold emails to an individual (not a bulk list) if you include a link to your privacy statement and can point to a legitimate interest in reaching out.

Example of a non-compliant cold sales email

![Example of a non-compliant cold sales email](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/cold-sales-email.png)

2. Social selling

GDPR doesn't prevent you from finding and connecting with prospects on LinkedIn or similar platforms. Once someone accepts a connection, you can reach out with the aim of establishing consent to take the conversation further - but a connection request isn't consent to be added to a marketing list.

Example LinkedIn outreach template

![Example LinkedIn outreach template](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/linkedin-outreach-template.png)

3. Purchased lead lists

If you buy leads from a third party, you need documented proof that those contacts consented to their data being shared with partners like you — and you still need to give them an easy way to opt out.

4. Cold calling

Cold calling itself isn't restricted by GDPR the way email marketing is. Ask for consent to send follow-up materials during the call, and send a short summary email afterward - that email doubles as your documentation of what was agreed.

Example cold call follow-up email template

![Example cold call follow-up email template](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/cold-call-follow-up-email-template.png)

5. Networking

You can still collect and store business cards. What you can't do is add that email address to a marketing list without consent. One-to-one follow-up emails based on a legitimate interest from the interaction are fine.

6. Referrals

Referrals from existing customers remain a valid way to reach new prospects. Having the referring customer make an email introduction — rather than you cold-contacting the referral out of nowhere - gives you a documented, legitimate basis for the first contact.

Example customer introduction email template

![Example customer introduction email template](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/introducton-email-template.png)

7. Website forms

Only ask for the data you actually need. Be specific and transparent about what each form submission subscribes someone to — ticking one box (like a webinar signup) shouldn't quietly opt someone into every list you have.

Example of a GDPR-compliant web form

![Example of a GDPR-compliant web form](https://community.superoffice.com/globalassets/user--admin/learning/best-practices--tips/gdpr/gdpr-compliant-web-forms.png)

The upside

Handled well, GDPR-compliant prospecting isn't just a compliance box to tick - it pushes your team toward higher-quality leads who actually want to hear from you, rather than a larger pool of disengaged contacts. That usually means better conversion rates and less time wasted chasing people who were never going to buy.

Related reading

Disclaimer: The content in this article is provided for informational purposes only and should not be considered legal advice.