Prospecx
Explainers

Is Cold Email Legal in India & the EU? GDPR and DPDP Explained

Cold email is legal in both India and the EU, but only when done correctly. Under India's Digital Personal Data Protection (DPDP) Act 2023 and the EU's GDPR, you can contact B2B prospects without prior consent if you have a legitimate business interest and the contact is reasonable. The key tests: is the person's role relevant to your offer, did you obtain their details lawfully, can they opt out easily, and are you transparent about why you're reaching out? Where most outbound campaigns fail is poor targeting and opaque data sourcing. Prospecting tools that surface leads from public buying signals—like LinkedIn posts expressing a need, new hires in relevant roles, or public company announcements—pass both the legitimate-interest and lawful-basis tests because the data is already public and the relevance is demonstrable. The short answer: yes, cold email is legal in India under GDPR and DPDP principles, provided you target thoughtfully, source data transparently, and respect opt-outs immediately.

What Does the DPDP Act Say About Cold Email?

India's DPDP Act, which came into force in 2023, borrows heavily from GDPR but simplifies enforcement. It requires consent for processing personal data unless an exemption applies. The most relevant exemption for B2B sales is legitimate interest: you can contact someone if the communication serves a lawful business purpose, the person would reasonably expect it given their role, and you provide an easy opt-out.

Crucially, the DPDP Act defines personal data as information that identifies an individual. A work email like [email protected] tied to a job title is personal data. However, contacting a decision-maker at a company that matches your ideal customer profile—especially when that person has publicly signaled interest in your category—meets the legitimate interest standard. The law does not require opt-in consent for every B2B email, but it does require you to stop immediately when someone opts out, and to clearly state who you are and why you're writing.

How Does GDPR Apply to Indian Companies Emailing EU Prospects?

GDPR applies to any organisation that processes the personal data of EU residents, regardless of where that organisation is based. If your sales team in India emails prospects in Germany or France, you must comply with GDPR. The regulation allows cold B2B email under the legitimate interest legal basis, but the bar is higher than many assume.

GDPR's legitimate interest test has three parts: purpose (do you have a genuine business reason?), necessity (is email the least intrusive way to achieve that purpose?), and balancing (does your interest outweigh the individual's privacy rights?). Emailing a procurement head about procurement software passes this test. Emailing a random employee with no decision-making authority does not. The safeguard: you must document your legitimate interest assessment, honour opt-outs within 30 days (in practice, immediately), and never buy scraped lists from providers who cannot prove lawful collection. Public professional data—job titles, company details, and public posts—provides the cleanest legal basis.

What Counts as Lawful Data Collection?

Both DPDP and GDPR require that personal data be collected lawfully and transparently. Purchasing a list from a broker who scraped LinkedIn profiles behind a login, or harvested emails from private databases, creates liability. The data subject never consented to that use, and you cannot prove a legitimate collection basis.

Lawful collection means the data was either made public by the individual (a LinkedIn post, a company directory, a conference speaker list), provided voluntarily in a business context (a webinar signup, a contact form), or enriched from verified public records. Tools that monitor public LinkedIn activity—posts, comments, job changes, follows—collect data that the user has explicitly chosen to share with a professional audience. Enriching that lead with a business email from a verified contact provider (one that sources from public registries and opt-in databases) keeps the chain lawful. The transparency requirement: if asked, you must be able to explain where you got someone's details.

Why Buyer Intent Signals Strengthen Your Legal Position

A common compliance mistake is treating all prospects the same. Emailing 10,000 companies because they exist is weak on legitimate interest. Emailing 200 companies whose executives recently posted about the exact problem you solve is strong. The difference is relevance, and relevance is the core of the balancing test under both GDPR and DPDP.

Buyer intent signals—public indicators that someone is researching, evaluating, or experiencing a need—make your outreach expected rather than intrusive. A founder who posts on LinkedIn asking for CRM recommendations has invited exactly the kind of message you want to send. A company announcing a new sales hire signals expansion and likely software procurement. These signals demonstrate that your email serves the recipient's interest, not just yours. From a legal standpoint, intent-based prospecting documents your legitimate interest clearly: the recipient has publicly indicated relevance. From a practical standpoint, it also improves reply rates and reduces complaints, which is the real enforcement risk.

What Are the Penalties for Getting It Wrong?

Under GDPR, fines can reach up to 4% of global annual turnover or €20 million, whichever is higher. Enforcement is complaint-driven: if prospects mark your emails as spam consistently, or if a data protection authority investigates and finds systemic violations (no opt-out mechanism, undocumented legitimate interest, purchased scraped lists), the penalties are severe. Under India's DPDP Act, fines go up to ₹250 crore per violation, though enforcement mechanisms are still being defined as of mid-2026.

The bigger operational risk is deliverability. Email providers like Google and Microsoft treat spam complaints as a strong negative signal. A campaign with poor targeting and no relevance will land in spam folders quickly, regardless of legal compliance. The overlap between legal compliance and email best practices is nearly total: target tightly, personalise thoughtfully, source data transparently, and honour opt-outs instantly. A tool that filters leads by public buying intent and verified contact quality protects both your sender reputation and your legal standing.

How Prospecx Keeps Your Outbound Compliant

Prospecx monitors public LinkedIn activity—posts, comments, job changes, hiring signals—to surface leads showing real buying intent. Because all signals come from content the user chose to make public, the data collection is lawful under both GDPR and DPDP. The platform ranks leads by intent strength and ideal customer profile fit, so you only contact prospects where relevance is demonstrable.

Contact enrichment pulls business emails and phone numbers from verified sources, not scraped databases. Every lead includes the specific signal that triggered it (a post, a comment, a role change), which documents your legitimate interest if ever questioned. The result: outreach that is not only compliant but genuinely useful to the recipient. When your email references a problem they just posted about, it feels less like cold outreach and more like timely advice. That is the standard both regulators and prospects expect.

Key takeaways
  • Cold email is legal in India and the EU under DPDP and GDPR if you have a legitimate business interest, target relevantly, and honour opt-outs immediately.
  • Lawful data collection means sourcing from public professional information—posts, profiles, directories—not scraped lists from behind logins.
  • Buyer intent signals (public posts, hiring announcements, role changes) strengthen your legitimate interest case and improve targeting quality.
  • Compliance and deliverability overlap: poor targeting leads to spam complaints, which harm both your sender reputation and your legal standing.
  • Tools that surface leads from public signals and enrich with verified contacts keep prospecting both compliant and effective.

Frequently asked questions

Is cold email legal in India under the DPDP Act?

Yes, cold email is legal in India under the DPDP Act if you have a legitimate business interest and the recipient would reasonably expect your message given their role. You must provide a clear opt-out, source contact details lawfully (from public professional sources, not scraped lists), and stop contacting anyone who opts out. Targeting decision-makers with relevant offers based on public buying signals meets the legal standard.

Does GDPR allow cold emailing to EU prospects from India?

Yes, GDPR permits cold B2B email under the legitimate interest legal basis, even if you are based in India. You must demonstrate that your outreach serves a genuine business purpose, that the recipient's role makes the message relevant, and that your interest does not override their privacy rights. You also need to document your legitimate interest assessment, honour opt-outs immediately, and source data lawfully from public professional sources.

What makes data collection lawful under GDPR and DPDP?

Data collection is lawful when the information is publicly available (LinkedIn posts, company directories, conference speaker lists) or provided voluntarily in a business context (webinar signups, contact forms). Purchasing scraped lists from providers who cannot prove consent or public sourcing creates legal risk. Using verified contact enrichment from public registries and monitoring public professional activity both meet the lawful collection standard.

Why do buyer intent signals improve cold email compliance?

Buyer intent signals—like public LinkedIn posts asking for recommendations, new hires, or company announcements—demonstrate that your outreach is relevant and expected. Under GDPR and DPDP, the legitimate interest test requires balancing your business purpose against the recipient's privacy. When someone publicly signals a need you can solve, the balance tips clearly in favour of contact, and your email is less likely to feel intrusive or generate complaints.

What are the penalties for non-compliant cold email in India and the EU?

Under GDPR, fines can reach 4% of global annual turnover or €20 million, whichever is higher. India's DPDP Act allows fines up to ₹250 crore per violation. Enforcement is typically complaint-driven. Beyond fines, poor targeting and spam complaints harm your email deliverability, causing messages to land in spam folders regardless of legal compliance. The safest approach: target tightly using public intent signals, source data transparently, and honour opt-outs immediately.

See buyers who are already showing intent

Prospecx finds B2B leads showing buying intent on LinkedIn, verifies their contacts, and drafts your outreach.

Start free — 3 days, 10 credits
← All articles