Guide

Does GDPR Apply to B2B Data and Business Contacts?

A common assumption is that GDPR only covers consumer data. It doesn't, a work email address and job title are personal data too. Here's what actually changes, and doesn't, for B2B processing.

Published September 2, 2026·Last updated September 2, 2026

A common assumption among B2B companies is that GDPR is fundamentally a consumer-protection law and therefore doesn’t really apply to business contact data, sales leads, vendor contacts, colleague email addresses exchanged at a conference. That assumption is wrong in an important way: GDPR protects individuals, not consumers specifically, and a business contact is still an identifiable natural person.

Why B2B data isn’t exempt

GDPR’s definition of personal data, covered in more depth in our personal data guide, doesn’t distinguish between “a person shopping as a consumer” and “a person acting in a professional capacity.” A work email like jane.smith@company.com identifies Jane Smith just as clearly as a personal Gmail address would, and her job title, direct phone number, and LinkedIn profile URL are all personal data about her, collected in a B2B context or not.

There’s no blanket “B2B exemption” in GDPR the way some people assume, though a handful of specific carve-outs exist in some EU member states’ national implementations for certain limited scenarios (these vary and shouldn’t be relied on without local legal advice).

What actually changes in practice for B2B processing

The data being “personal data” doesn’t mean B2B processing is treated identically to consumer processing in every respect, the practical requirements shift because the lawful basis available is often different:

  • Legitimate interests is more often available for B2B outreach than it would be for equivalent consumer marketing. Reaching out to a business contact about a product genuinely relevant to their role is more likely to satisfy GDPR’s legitimate interest balancing test than the same kind of unsolicited outreach to a consumer would, since a business contact might reasonably expect relevant industry outreach. This isn’t unlimited, it still requires a documented balancing test and an easy opt-out. See our lawful basis overview for the full picture.
  • PECR/ePrivacy email marketing rules still apply, separately from GDPR, and most EU countries’ implementations have narrower B2B exceptions for unsolicited email than for consumer email. We cover the email-specific rules in our email marketing and PECR guide.
  • Individual rights still apply. A business contact can still submit a Data Subject Access Request, ask you to correct their job title, or ask you to delete their record from your CRM, the same rights a consumer has. See our DSAR guide.

Common B2B scenarios and how they’re typically treated

Scenario Typical basis Notes
Cold outreach to a relevant business contact about your product Legitimate interests Requires balancing test, easy opt-out, and compliance with ePrivacy email rules
Storing contacts from a signed customer’s team in your CRM Contract / legitimate interests Tied to servicing the existing business relationship
Sharing a prospect’s contact info with a partner without telling them Likely no valid basis Undisclosed third-party sharing is a common enforcement issue regardless of B2B context
Employee data processed by your own HR function Contract / legal obligation A separate but related area, generally the employer is the controller
Our recommendation

Enzuzo

A CRM full of B2B contacts is still a database of personal data under GDPR, complete with the same access, correction, and deletion rights a consumer database carries. Enzuzo bundles consent, policy, and data-request handling in one dashboard, useful for smaller B2B teams without a dedicated privacy function.

Try Enzuzo

What to actually do

  1. Stop treating B2B data as automatically exempt. Apply the same personal-data lens to CRM, lead-gen, and sales outreach data that you’d apply to consumer data.
  2. Document your basis for B2B marketing outreach, usually legitimate interests, with an actual recorded balancing test, not just an assumption.
  3. Check your country-specific email marketing rules for B2B, since ePrivacy implementations vary by EU member state on this point specifically.
  4. Be ready to honor access, correction, and deletion requests from business contacts, not just consumers.

This guide is educational and not legal advice. B2B-specific exceptions vary by EU member state and by the specifics of your outreach; consult a privacy attorney for your jurisdictions.