Skip to content

EU outbound and GDPR: what SDR operations has to handle

The operational obligations that outbound B2B prospecting creates under GDPR — lawful basis, objections, retention, call recording and data residency — and the controls that make them routine rather than heroic.

Updated 1 October 20269 min readTypeExplainer

Not legal advice. This describes operational controls, not a legal position. GDPR interacts with national implementing law and sector rules, and the detail differs by member state. Take advice for your own jurisdictions and market.

Outbound prospecting in the EU is lawful and routine. What it is not is unregulated, and most of the obligations land squarely on operations rather than on legal — because they are about what your system does by default, every day, without anyone deciding to be careful.

Personal data, even in B2B

The first thing teams get wrong is assuming B2B contact data is exempt. It is not. A named individual at a company — their work email, their direct line, their job title — is personal data about an identifiable person. GDPR applies.

What B2B context does change is which lawful basis is realistically available, and how a data subject’s rights get exercised in practice.

Lawful basis, briefly

For cold outbound, most B2B prospecting in the EU runs on legitimate interests rather than consent. That is a recognised basis, but it is conditional: it requires that you have actually weighed your interest against the individual’s rights and can show your reasoning, and it is defeated when their interests outweigh yours.

Three operational consequences:

  1. Document the assessment. A legitimate-interests assessment that exists as a document is a defence. One that exists as a belief is not.
  2. Relevance is part of the basis. Contacting someone whose role has nothing to do with what you sell weakens the argument considerably. Targeting quality is a compliance input, not just a performance one.
  3. Channel rules differ. Electronic marketing, automated calling and SMS are governed additionally by ePrivacy and national rules, which vary meaningfully between member states. Telephone marketing in particular has national opt-out registers in some countries that you are obliged to screen against.

The obligation that bites hardest: objections

An individual can object to processing for direct marketing, and that objection is absolute — there is no balancing test. Once made, you stop.

Operationally this means an objection has to propagate to a suppression that is enforced automatically, before any rep sees the record. The failure mode is familiar: someone says “take me off your list”, a rep notes it in a CRM field, the list is re-imported from the original source three months later, and the same person gets called again. That second call is the breach, and the cause is architectural, not individual.

What the system needs to do:

  • Capture the objection against the person, not just the row in the current list
  • Enforce suppression at import, filtering before the data reaches a rep
  • Keep suppression per client, because your clients’ lists are separate processing contexts
  • Survive re-import — a suppression that a fresh CSV overwrites is not a suppression

Retention: delete on a schedule, not on a clear-out

GDPR requires that personal data not be kept longer than necessary. “Necessary” is yours to define, but it must be defined, documented and actually applied.

The practical shape is a written retention policy per data category — prospect records, activity history, call recordings, transcripts — with an automated process that enforces it. A policy nobody has implemented is an aggravating factor rather than a defence. Note that suppression records are a deliberate exception worth keeping: you need to retain enough to keep honouring an objection, which is a legitimate reason to hold a minimal record indefinitely.

Right to erasure, and why it is harder than it sounds

A deletion request has to reach everywhere the data went. In an SDR operation that is more places than people expect: the prospect record, the activity timeline, call recordings, transcripts, any CRM you pushed the booking into, calendar entries, and derived aggregates.

Two things make this tractable. First, know your data map — have it written down before the first request arrives. Second, be clear about what you are not deleting and why: aggregate performance figures that no longer identify anyone, and the minimal suppression record, generally survive. Being able to explain that distinction calmly is most of handling a request well.

Call recording

Recording calls adds obligations on top. Broadly you need a basis for the recording itself, you need to tell people it is happening, and in some jurisdictions you need consent from all parties rather than one. The rules genuinely differ by country, so a multi-country operation cannot assume one policy covers it.

Treat recordings as high-sensitivity personal data: tighter access, a shorter retention clock than ordinary activity data, and automated archival and deletion. Transcripts are personal data too — generating one does not launder the recording.

Data residency

Not strictly a GDPR requirement — transfers outside the EEA are permitted with appropriate safeguards — but keeping processing inside the EU removes a whole category of question, and it is frequently a procurement requirement regardless of the law.

For reference, Dialbrew runs in AWS eu-central-1 (Frankfurt), with product analytics on EU cloud and anonymous profiling disabled, and error monitoring in the EU region. Retention and right-to-be-forgotten procedures are documented alongside the implementation. We do not hold a SOC 2 or ISO 27001 certification and will not imply otherwise.

The operational checklist

Obligation What has to be true in the system
Lawful basis A documented legitimate-interests assessment; targeting relevant to what you sell
National channel rules Screening against applicable opt-out registers per country
Objections Captured against the person and enforced at import, surviving re-import
Retention Defined per data category and automatically applied
Erasure A known data map covering CRM pushes, recordings and transcripts
Call recording Notification, a lawful basis, country-aware policy, short retention
Access control Reps see only the clients they are rostered on, by permission
Processor terms A DPA with every sub-processor in the chain

The point

None of this requires heroics. It requires that the default path through your system is the compliant one — suppression enforced before a rep sees a record, retention running on a schedule, access scoped by permission. Compliance achieved by people remembering to be careful is compliance that fails on a busy Thursday.

Book a walkthrough

Put every client on one floor

A walkthrough on your own roster, clients and commission model — from an imported list to a sent invoice. Judged on your operation, not a demo dataset.

EU-hosted · eu-central-1 · integrates the CRM, calendar and telephony you already run