Does GDPR affect your sales team?
Ask yourself:
- Do you rely on purchased leads to fill your pipeline?
- Do you add business card contact details to a mailing list without asking first?
- Do you ask existing customers for referrals?-
If you answered yes to any of these, GDPR affects how you do it. And it doesn't matter whether your business is based in the EU - if you hold data on even one EU citizen, GDPR applies to you.
What counts as personal data?
Names, emails, phone numbers, and interests are the obvious ones - the kind of information sales reps store in a CRM every day. But personal data also covers things like IP addresses, social media activity, and financial or medical details, so it's worth being deliberate about what you collect and why.
How prospecting works under GDPR
Collecting data and informing people
When you collect someone's data - through a web form, a follow-up email, or any other channel - they have the right to know what you're collecting, why, and for how long you'll keep it. If you didn't get explicit consent at the point of collection, you should inform them promptly that you're storing their data and why.
If someone asks you to delete their data after that, you need to comply - unless you have a genuine legal reason to retain it, in which case your Data Protection Officer should be able to explain that reason to them.


Processing the data
Once you have permission to store a prospect's data, you still can't use it however you like. Just because you have someone's email address doesn't mean you can add them to every mailing list you run — they need to actively opt in to each type of communication. Subscription management tools make this manageable at scale.


7 ways to prospect compliantly
1. Email outreach
Automated cold outreach without prior contact or consent isn't compliant. You can still send genuinely one-to-one cold emails to an individual (not a bulk list) if you include a link to your privacy statement and can point to a legitimate interest in reaching out.


2. Social selling
GDPR doesn't prevent you from finding and connecting with prospects on LinkedIn or similar platforms. Once someone accepts a connection, you can reach out with the aim of establishing consent to take the conversation further - but a connection request isn't consent to be added to a marketing list.


3. Purchased lead lists
If you buy leads from a third party, you need documented proof that those contacts consented to their data being shared with partners like you — and you still need to give them an easy way to opt out.
4. Cold calling
Cold calling itself isn't restricted by GDPR the way email marketing is. Ask for consent to send follow-up materials during the call, and send a short summary email afterward - that email doubles as your documentation of what was agreed.


5. Networking
You can still collect and store business cards. What you can't do is add that email address to a marketing list without consent. One-to-one follow-up emails based on a legitimate interest from the interaction are fine.
6. Referrals
Referrals from existing customers remain a valid way to reach new prospects. Having the referring customer make an email introduction — rather than you cold-contacting the referral out of nowhere - gives you a documented, legitimate basis for the first contact.


7. Website forms
Only ask for the data you actually need. Be specific and transparent about what each form submission subscribes someone to — ticking one box (like a webinar signup) shouldn't quietly opt someone into every list you have.


The upside
Handled well, GDPR-compliant prospecting isn't just a compliance box to tick - it pushes your team toward higher-quality leads who actually want to hear from you, rather than a larger pool of disengaged contacts. That usually means better conversion rates and less time wasted chasing people who were never going to buy.
Related reading
- What is GDPR and how does SuperOffice CRM support compliance?
- Setting up consent, privacy lists & subscriptions in SuperOffice CRM
- Full documentation: docs.superoffice.com — Privacy & GDPR
Disclaimer: The content in this article is provided for informational purposes only and should not be considered legal advice.