Skip to content

GDPR and UK GDPR for B2B marketing: legitimate interest explained

Legitimate interest can cover a lot of B2B marketing, but only if you can show your working. Here's what the test involves.

BootSoc team

A compliance review of marketing data on a laptop

B2B marketers often hear two opposite claims about the GDPR. One says you need consent for everything. The other says business contacts aren't personal data, so the rules don't apply. Both are wrong. A named person's work email, job title and phone number are personal data under the GDPR and the UK GDPR, so you need a lawful basis to use them. But consent is only one of six lawful bases, and for a lot of B2B marketing the more practical one is legitimate interest.

This guide explains what legitimate interest means, how to show it applies, where electronic marketing rules add extra requirements, and the mistakes that cause problems. It is general information, not legal advice. Check your specific programs with counsel.

What legitimate interest is

Article 6(1)(f) of the GDPR allows processing that is necessary for the legitimate interests of the organisation or a third party, unless those interests are overridden by the interests, rights and freedoms of the person whose data it is. Recital 47 says that processing personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. The UK GDPR contains the same basis, and the UK's Data (Use and Access) Act 2025 now names direct marketing in the legislation itself as an example of processing that may be a legitimate interest.

The key word is “may”. Neither law says direct marketing is automatically allowed. You still have to show that your use passes a balancing test and you have to be able to demonstrate it if a regulator or the individual asks.

The three-part test

Regulators, including the UK Information Commissioner's Office, describe legitimate interest as a three-part test. Record your answers in a legitimate interests assessment, or LIA, before you start processing.

  • Purpose: is there a legitimate interest? Telling businesses about relevant products and services is a recognised commercial interest. Be specific about what you will send and why.
  • Necessity: is the processing necessary for that purpose? Collect and keep only the data you need, and consider whether a less intrusive approach would work just as well.
  • Balancing: do the person's interests override yours? Consider their reasonable expectations, the relationship, the sensitivity of the data and how easily they can object.

The balancing test is where most B2B programs succeed or fail. A procurement director at a software company would reasonably expect to hear from vendors about relevant procurement tools at their work address. The same person would not expect a stream of unrelated offers, contact on a personal phone, or their details sold on repeatedly without being told.

Transparency: telling people what you're doing

Legitimate interest doesn't remove the duty to be transparent. If you collect data directly from someone, you must give them privacy information at the time. If you obtain it from another source, such as a data provider or a public profile, Article 14 generally requires you to tell them within a reasonable period, and at the latest within one month, or at your first communication with them if that's sooner. That notice should say who you are, where the data came from, what you'll use it for, the lawful basis and how to object.

The right to object is absolute for direct marketing

Under Article 21, a person can object to the use of their data for direct marketing at any time, and you must stop. Unlike some other objections, there is no balancing test here: the objection wins. In practice that means every message needs an easy way to opt out, and opt-outs need to reach a suppression list that every campaign checks, including campaigns run by partners on your behalf.

Where PECR adds extra rules in the UK

The GDPR decides whether you can use personal data at all. In the UK, the Privacy and Electronic Communications Regulations (PECR) add specific rules for marketing by email, text, phone and fax. For B2B email, PECR draws an important line between two kinds of recipient.

  • Corporate subscribers, such as limited companies, LLPs and government bodies: you can send unsolicited marketing email to their employees' work addresses without prior consent, as long as you identify yourself and give a simple way to opt out. GDPR rules, including legitimate interest and transparency, still apply to the personal data.
  • Individual subscribers, including sole traders and some partnerships: you need prior consent, or the “soft opt-in” for existing customers who bought or negotiated to buy something similar from you and were given a chance to opt out.
  • Marketing calls: you must screen numbers against the Telephone Preference Service and Corporate Telephone Preference Service unless the person has specifically consented to your calls.

The EU applies the ePrivacy Directive through national laws that differ by country, and several member states require consent for B2B email in more cases than the UK does. If you send into the EU, check the rules in each country you target.

Penalties are rising

UK GDPR fines can reach £17.5 million or 4% of worldwide annual turnover, whichever is higher. The Data (Use and Access) Act 2025 raises the maximum PECR fines to the same level as its provisions come into force, so electronic marketing breaches now carry the same top-end risk as other data protection failures.

Legitimate interest or consent: which to use

Consent is not a stronger basis, just a different one. It must be freely given, specific, informed and as easy to withdraw as to give, and once you rely on it you can't switch to legitimate interest if it is withdrawn. Consent suits situations where the person has a real choice and you want an explicit record of it, such as a content download that shares their details with a named sponsor, or marketing to sole traders by email. Legitimate interest suits ongoing, expected contact with business decision makers about relevant products, where you can show a clear balance in your favour and an easy way out. Many B2B programs use both: consent at the point of collection, and legitimate interest for related follow-up that the notice made clear.

Common mistakes

  • Treating legitimate interest as a default rather than a decision, with no written assessment.
  • Relying on legitimate interest for sole traders' email, where PECR requires consent or the soft opt-in.
  • Buying a list without checking how the data was collected and what people were told.
  • Keeping opt-outs in one tool while other campaigns, partners or vendors keep emailing.
  • Using data for a new purpose, such as sharing it with partners, that people wouldn't expect from the original notice.
  • Keeping records indefinitely instead of setting and applying a retention period.

A practical checklist

  • Write an LIA for each type of B2B marketing you do and review it when the program changes.
  • Separate corporate subscribers from sole traders and partnerships in your data.
  • Give privacy information at collection, or within a month when data comes from elsewhere.
  • Include your identity and a working opt-out in every message.
  • Run one global suppression list and apply it to every campaign and vendor.
  • Screen calling lists against TPS and CTPS.
  • Ask lead vendors for the lawful basis, notice wording and consent record attached to each contact.
Legitimate interest isn't a loophole. It's a decision you have to be able to explain, record and stand behind.

Used properly, legitimate interest lets B2B companies reach relevant buyers at work without asking for consent first, while still respecting people's choices. The organisations that get into trouble are the ones that skip the assessment, ignore the notice duty or let opt-outs slip through the cracks.

BootSoc records the lawful basis, the notice wording and a timestamp with every lead, applies separate playbooks for US, UK and Canadian law, and honours opt-outs across every client through a global suppression list. Our data and trust center explains how.

Let's plan next quarter's pipeline.

A 30-minute call with a strategist. You leave with a target spec, audience size and a program plan, whether or not we work together.

Privacy choices

Choose which optional cookies we may use. You can change this any time from “Your privacy choices” in the footer.