Data protection in B2B sales: no exemption
Many sales departments still assume that B2B is largely unregulated, since negotiations happen between companies. That view falls short. Under Article 4(1) of the GDPR, personal data means any information relating to an identified or identifiable natural person. As soon as business contact details such as a name, a direct line or a personalised email address are processed, personal data is generally involved.
- A common assumption: B2B contact data falls outside the regulation. In fact its principles apply as soon as a person is identifiable.
- A common assumption: publicly available data may be stored without limit. In fact purpose limitation and transparency duties remain in place.
- A common assumption: systematic market observation is legally impossible. In fact it is possible where purpose, legal basis and limits are properly defined.
For sales leadership this does not spell the end of market observation. It means setting it up deliberately. Understanding and documenting the basics produces a durable prospecting approach rather than reliance on grey areas.
Legitimate interest as the legal basis
Because explicit consent rarely exists before the first piece of research, B2B market observation usually relies on Article 6(1)(f) of the GDPR. This basis permits processing to pursue the legitimate interests of the controller, provided the interests or fundamental rights of the data subject do not override them. Recital 47 explicitly names processing for direct marketing purposes as a legitimate interest that may be considered.
- 1Legitimate interest: the processing company sets out a concrete, lawful commercial interest, for example initiating business in its own core market.
- 2Necessity: the processing has to be necessary to achieve that aim. Where a less intrusive but equally effective means exists, it takes precedence.
- 3Balancing test: the protected interests of the data subject are weighed against it and the outcome is documented.
A central element of the balancing test is the substantive connection. A mechanical engineering firm has a plausible interest in knowing who holds procurement responsibility at a manufacturing site. Where that connection is missing, or where private information is collected, the balance can tip towards the data subject. A documented rationale is therefore the core of any sound market observation.
Public sources and how to use them properly
Sound market observation relies primarily on publicly accessible sources. Official registers and publication portals offer high data quality, because their content is intended precisely for legal and commercial dealings. Under section 9 of the German Commercial Code, anyone is permitted to inspect the commercial register and the documents filed there for information purposes. The task is to process that data transparently and for a defined purpose.
| Source | Typical content | Value for sales | What to watch |
|---|---|---|---|
| Commercial register | Managing directors, authorised signatories, powers of representation | Identifying responsibilities after a change | Keep processing tied to the business purpose |
| Federal Gazette | Annual accounts, management reports | Assessing how a company is developing | Do not capture private contact details |
| Insolvency notices | Status of proceedings, administrators and custodians | Early risk management and repositioning | Delete once the occasion has lapsed |
| Procurement portals | Tenders, deadlines, contracting authorities | Participation in procedures in your core business | Use strictly per project and procedure |
The fact that data is publicly visible does not release you from the general principles of the regulation. Processing stays tied to the original purpose. In addition, the information duties under Article 14 apply where data was not collected from the data subject directly.
Data minimisation instead of stockpiling
The principle of data minimisation under Article 5(1)(c) requires personal data to be adequate and limited to what is necessary for the purpose. Building large, unfiltered contact databases therefore leads sales into a difficult position quickly. A targeted, occasion-driven approach to collection is the sounder route.
- Limit collection: capture only what is needed to initiate business.
- No sensitive extras: leave out private numbers, dates of birth or personal preferences.
- Store on occasion: bring data into the system once a concrete occasion exists, not before.
- Clean regularly: remove records without business contact and without a recognisable occasion.
Technically this can be handled through pre-filtering. A curated feed takes over the pre-selection of relevant market and sector signals, so only records with an actual occasion reach the CRM. Noise never gets stored in the first place, which markedly reduces the effort of cleaning up later.
Where competition law begins
A frequent misunderstanding arises at the intersection of data protection and competition law. While the GDPR governs collection and storage, section 7 of the German Act against Unfair Competition sets the limits for actively reaching out, by declaring advertising that unreasonably harasses a market participant to be unlawful. Research that is permissible under data protection law is therefore not automatically a licence to make contact.
| Area of law | Activity covered | Standard applied |
|---|---|---|
| Data protection law | Collection, storage and enrichment | Legitimate interest and substantive connection |
| Competition law, electronic mail | Direct outreach by email | As a rule, prior express consent |
| Competition law, telephone | Advertising calls to other market participants | At least presumed consent |
| Competition law, post | Postal mailings | Permissible as long as no objection has been raised |
A two-stage setup therefore makes sense: first the documented market observation using public sources, then the choice of a channel that is permissible for the specific situation. How that assessment turns out in an individual case should be clarified with your own legal advisors.
Documentation and deletion in the CRM
Once an occasion has been identified, the focus shifts to internal administration. Article 30 of the GDPR obliges controllers to maintain a record of processing activities, which also has to describe prospecting and market observation. On top of that you need processes that implement data subject rights reliably.
- Maintain the record of processing: document purpose, data categories, legal basis and recipients.
- Keep a suppression list: record objections centrally so that renewed outreach is reliably prevented.
- Meet the deadlines: under Article 12(3), the data subject has to be informed about the action taken on a request without undue delay and, as a rule, within one month of receipt.
- Define deletion routines: review and remove records without an occasion and without business contact after defined periods.
Clean CRM hygiene matters particularly when monitoring distress signals. The storage limitation principle under Article 5(1)(e) requires personal data to be kept in identifiable form only for as long as is necessary for the purpose. Once proceedings have concluded or the occasion has lapsed, the data belongs out of the operational system.
A systematic setup reduces risk
Manual research, where individuals gather contact details and collect them in their own spreadsheets, leads to patchy documentation in practice. A consistent setup reduces that risk noticeably, because provenance, purpose and retention period stay traceable in one place.
- Manual research: unclear provenance, missing deletion routines, spreadsheets scattered across the team.
- A systematic feed: pre-filtered signals from public sources with clear categories and traceable provenance.
- Regulate processing on behalf: where a provider is involved, Article 28(3) requires a contract setting out the subject matter, duration, nature and purpose of processing as well as the obligations and rights of the controller.
- Standardised handover: secure transfer into the CRM including central management of objections.
Cernavio watches public sources such as tenders, insolvency notices, commercial register changes and company news, and turns them into a curated feed of sales occasions. Cernavio does not sell contact data and does not promise outcomes. Assessing your own prospecting processes legally remains the responsibility of your company.
Yes, as soon as data relating to an identifiable person is processed. A business email address containing a first and last name falls within scope. B2B is therefore not exempt, but it does not necessarily require express consent, because legitimate interest can serve as the legal basis.
Data from public registers may be used subject to the general principles. The use has to stay tied to its purpose. The fact that information is publicly accessible does not release you from data minimisation and transparency duties.
Data protection law governs collection and storage, competition law governs the act of reaching out. Under section 7 of the German Act against Unfair Competition, advertising that unreasonably harasses a market participant is unlawful, even where the prior collection of data was permissible.
Usually legitimate interest under Article 6(1)(f). The three-step assessment covering interest, necessity and balancing should be documented so the decision remains traceable later on.
If a contact objects to the processing, the data belongs out of the active system and onto an internal suppression list. The person has to be informed about the action taken without undue delay, as a rule within one month of receipt of the request.
