If information can be linked to a specific person, it is personal data, and a work email like jane.doe@company.com counts.
Key points
- The GDPR defines personal data in Article 4(1) as any information relating to an identified or identifiable natural person [1].
- A person is identifiable directly or indirectly, for example through a name, an identification number, location data or an online identifier [1][2].
- Business contact details are personal data when they identify an individual, so B2B Cold Email to a named person is covered [3].
- Generic addresses such as info@ or sales@ are usually not personal data on their own, although a Role-Based Email Address used by one person can be [3].
- Data about companies themselves, such as Firmographics or Technographics, is not personal data unless it relates to an identifiable person [2].
- California's CCPA / CPRA uses a broader term, personal information, which includes data that could reasonably be linked to a consumer or household [4].
What counts as personal data
The test is whether information relates to a person who can be identified, directly or indirectly [1]. A name plus an employer, a work email address, a phone extension, an IP address or a cookie ID can all qualify. Recital 26 explains that identifiability depends on the means reasonably likely to be used, so pseudonymized data remains personal data if it can be linked back, while truly anonymous data is out of scope [5]. Opinions and inferences about a person, such as a Lead Scoring result or notes in a CRM (Customer Relationship Management), are personal data too. Special categories, such as health or political opinions, get extra protection. For most outbound work, the key point is simple: a named contact record is personal data, whatever the context.
Personal data in B2B sales
Many teams assume B2B data is exempt. It is not. The ICO explains that an email address like firstname.lastname@company.com identifies an individual and is personal data, even though it is a work address [3]. The European Commission gives similar examples, including a work email and a name combined with an employer [2]. Company-level information is different: a company's size, industry and funding stage are not personal data, which is why Firmographics carry less risk than contact details. This distinction shapes a sensible workflow. Research and qualify at the company level first, then collect only the contact details you need for a relevant message, in line with Data Minimization. Keep records accurate, because outdated contact data from Data Decay is still personal data you are responsible for.
Obligations that follow
Once you hold personal data, the rules attach. Under the GDPR you need a lawful basis, such as Legitimate Interest or Consent, and must tell people how their data is used [1]. People can ask to see their data, correct it or request the Right to Erasure, and they can object to direct marketing. If a vendor processes the data for you, a Data Processing Agreement (DPA) is required. In California, the CCPA / CPRA gives similar rights over personal information, and its definition covers data linked to households as well as individuals [4]. Even information you found in public can be personal data, as explained under Publicly Available Data, and that includes contact details gathered by Web Scraping. A practical rule: treat every contact record as personal data and design your process to respect those rights.
Related terms
Outreach without the busywork.
PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.
Start free with 100 credits →