Back to InspirationData

    GDPR and business contact data in recruitment: what is allowed, what is not

    September 16, 20269 min read
    GDPR and business contact data in recruitment: what is allowed, what is not

    'It is a business email address, so GDPR does not apply' is the most expensive misconception in recruitment. The moment contact data identifies a person — and a name plus work email does exactly that — it is personal data, with all the obligations that brings. The good news: recruitment outreach can be fully compliant if you build it on the right foundations. This article is practical guidance, not legal advice.

    The foundation: legitimate interest, done properly

    Most B2B recruitment outreach rests on legitimate interest. That basis is valid but conditional: you must be able to show why approaching this specific person is relevant to their professional role, that your interest does not override theirs, and that the person could reasonably expect the contact. A recruiter approaching an HR director about staffing passes that test; the same recruiter harvesting private addresses does not.

    Document the reasoning before the campaign, not after the complaint. A short written balancing test per target segment — who we approach, why it is relevant to their role, what data we hold, where it came from — is what regulators ask for first.

    Transparency, sources and retention

    Tell people where you got their data, at first contact at the latest. 'We found your details in the official company register filing for X' is a sentence that builds trust and satisfies the information obligation in one move. Source quality matters here: register-based data comes with provenance you can cite; scraped lists come with questions you cannot answer.

    Keep retention honest. A contact who never responded after a reasonable sequence should be suppressed, not parked forever. Set an explicit period — many firms use twelve months of inactivity — and enforce it. Suppression lists (people who opted out) are themselves kept minimal and used only to honour the opt-out.

    Practical checklist for recruiters

    Before any campaign: written balancing test, verified data source with provenance, and a clear identity in every message. During: honour objections immediately and universally across your systems, keep records of consent or objection, and never mix business contact data with private channels like personal phone numbers unless the basis is watertight.

    When buying data, ask the supplier three questions: where does it come from, when was it verified, and can you show the provenance per record. Drimble's company and officer data is sourced from official registers in the markets we cover — the UK, France, Spain, Ireland, Denmark, Belgium, Canada, Australia, Greenland and India; not the Netherlands — which gives you exactly that paper trail.

    Frequently asked questions

    Can I email a hiring manager without prior consent?

    In most EU and UK scenarios, yes — under legitimate interest — provided the approach is relevant to their professional role, you identify yourself and your source, and you stop immediately on objection. Rules differ per country, so align with your legal counsel for your specific markets.

    Is data from official company registers automatically GDPR-free?

    No. Public availability does not remove GDPR obligations; it strengthens your transparency and provenance position. You still need a valid basis, a purpose, and correct handling of objections and retention.