EU outbound and GDPR: what SDR operations has to handle
The operational obligations that outbound B2B prospecting creates under GDPR — lawful basis, objections, retention, call recording and data residency — and the controls that make them routine rather than heroic.
Not legal advice. This describes operational controls, not a legal position. GDPR interacts with national implementing law and sector rules, and the detail differs by member state. Take advice for your own jurisdictions and market.
Outbound prospecting in the EU is lawful and routine. What it is not is unregulated, and most of the obligations land squarely on operations rather than on legal — because they are about what your system does by default, every day, without anyone deciding to be careful.
Personal data, even in B2B
The first thing teams get wrong is assuming B2B contact data is exempt. It is not. A named individual at a company — their work email, their direct line, their job title — is personal data about an identifiable person. GDPR applies.
What B2B context does change is which lawful basis is realistically available, and how a data subject’s rights get exercised in practice.
Lawful basis, briefly
For cold outbound, most B2B prospecting in the EU runs on legitimate interests rather than consent. That is a recognised basis, but it is conditional: it requires that you have actually weighed your interest against the individual’s rights and can show your reasoning, and it is defeated when their interests outweigh yours.
Three operational consequences:
- Document the assessment. A legitimate-interests assessment that exists as a document is a defence. One that exists as a belief is not.
- Relevance is part of the basis. Contacting someone whose role has nothing to do with what you sell weakens the argument considerably. Targeting quality is a compliance input, not just a performance one.
- Channel rules differ. Electronic marketing, automated calling and SMS are governed additionally by ePrivacy and national rules, which vary meaningfully between member states. Telephone marketing in particular has national opt-out registers in some countries that you are obliged to screen against.
The obligation that bites hardest: objections
An individual can object to processing for direct marketing, and that objection is absolute — there is no balancing test. Once made, you stop.
Operationally this means an objection has to propagate to a suppression that is enforced automatically, before any rep sees the record. The failure mode is familiar: someone says “take me off your list”, a rep notes it in a CRM field, the list is re-imported from the original source three months later, and the same person gets called again. That second call is the breach, and the cause is architectural, not individual.
What the system needs to do:
- Capture the objection against the person, not just the row in the current list
- Enforce suppression at import, filtering before the data reaches a rep
- Keep suppression per client, because your clients’ lists are separate processing contexts
- Survive re-import — a suppression that a fresh CSV overwrites is not a suppression
Retention: delete on a schedule, not on a clear-out
GDPR requires that personal data not be kept longer than necessary. “Necessary” is yours to define, but it must be defined, documented and actually applied.
The practical shape is a written retention policy per data category — prospect records, activity history, call recordings, transcripts — with an automated process that enforces it. A policy nobody has implemented is an aggravating factor rather than a defence. Note that suppression records are a deliberate exception worth keeping: you need to retain enough to keep honouring an objection, which is a legitimate reason to hold a minimal record indefinitely.
Right to erasure, and why it is harder than it sounds
A deletion request has to reach everywhere the data went. In an SDR operation that is more places than people expect: the prospect record, the activity timeline, call recordings, transcripts, any CRM you pushed the booking into, calendar entries, and derived aggregates.
Two things make this tractable. First, know your data map — have it written down before the first request arrives. Second, be clear about what you are not deleting and why: aggregate performance figures that no longer identify anyone, and the minimal suppression record, generally survive. Being able to explain that distinction calmly is most of handling a request well.
Call recording
Recording calls adds obligations on top. Broadly you need a basis for the recording itself, you need to tell people it is happening, and in some jurisdictions you need consent from all parties rather than one. The rules genuinely differ by country, so a multi-country operation cannot assume one policy covers it.
Treat recordings as high-sensitivity personal data: tighter access, a shorter retention clock than ordinary activity data, and automated archival and deletion. Transcripts are personal data too — generating one does not launder the recording.
Data residency
Not strictly a GDPR requirement — transfers outside the EEA are permitted with appropriate safeguards — but keeping processing inside the EU removes a whole category of question, and it is frequently a procurement requirement regardless of the law.
For reference, Dialbrew runs in AWS eu-central-1 (Frankfurt), with product analytics on EU cloud and anonymous profiling disabled, and error monitoring in the EU region. Retention and right-to-be-forgotten procedures are documented alongside the implementation. We do not hold a SOC 2 or ISO 27001 certification and will not imply otherwise.
The operational checklist
| Obligation | What has to be true in the system |
|---|---|
| Lawful basis | A documented legitimate-interests assessment; targeting relevant to what you sell |
| National channel rules | Screening against applicable opt-out registers per country |
| Objections | Captured against the person and enforced at import, surviving re-import |
| Retention | Defined per data category and automatically applied |
| Erasure | A known data map covering CRM pushes, recordings and transcripts |
| Call recording | Notification, a lawful basis, country-aware policy, short retention |
| Access control | Reps see only the clients they are rostered on, by permission |
| Processor terms | A DPA with every sub-processor in the chain |
The point
None of this requires heroics. It requires that the default path through your system is the compliant one — suppression enforced before a rep sees a record, retention running on a schedule, access scoped by permission. Compliance achieved by people remembering to be careful is compliance that fails on a busy Thursday.