What is GDPR and why does it matter for B2B companies?
The General Data Protection Regulation (GDPR) is the EU's comprehensive data privacy framework, and for any B2B team that touches European contacts, it is the foundational compliance reference point. This GDPR compliance guide covers what the regulation requires, who it applies to, and how to build a programme that holds up in practice.
The GDPR replaced the EU's Data Protection Directive (DPD). A "directive" allows EU member countries to choose whether or not to enact similar laws that they can customise. A "regulation" requires all members to enact the law in full. The GDPR replaced the DPD for three reasons:
The GDPR granted citizens more control over their personal data and required data controllers and processors to protect it.
The Data Protection Directive was enacted in the internet's infancy and no longer addressed the full scope of modern data collection.
There were clear benefits to an EU-wide law rather than divergent national versions.
The official GDPR regulation document runs to 88 pages, 99 articles, and over 50,000 words. Understanding its scope and structure is the first step toward building a defensible compliance programme.
Note: The UK has its own framework known as the UK GDPR. While the GDPR stopped being directly applicable when the UK exited the EU in December 2020, the Data Protection Act of 2018 retained GDPR requirements in domestic UK law and supplements the UK GDPR by providing exceptions to the law.
Why GDPR was created: the evolution of data privacy law
The GDPR stems from concerns over how individuals' personal data is collected, stored, and used. Almost all modern businesses collect and analyse personal data. As technology advances, digital footprints continue to expand, and the volume of data created each day is growing at a pace that decades-old legislation was never designed to address.
Regulations that once protected names, addresses, and images were no longer sufficient to cover IP addresses, behavioural tracking, biometric data, and the cross-border movement of personal information at scale. GDPR was introduced to bring regulation up to speed with the current state of technology.
GDPR is widely regarded as the strictest data privacy law in the world and directly influenced subsequent regulations including the California Consumer Privacy Act (CCPA), making it the foundational framework for any multi-jurisdiction privacy programme. For B2B marketing and sales teams operating across geographies, understanding GDPR is not optional: it is the baseline from which all other privacy obligations flow.
Note: The UK GDPR framework, described above, continues to apply to UK-based data subjects following Brexit.
What counts as personal data under GDPR?
GDPR protects any personal data that could be used to identify an individual. This includes physical addresses, phone numbers, job information, and education status, as well as other types of data like IP addresses and biometric data (fingerprints, facial recognition data, etc.). Its official definition of personal data reads as follows:
"Any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
Who does GDPR apply to, including US companies?
GDPR applies to any company, inside or outside the EU, that processes personal data regarding any EU individuals where the processing relates to the offering of goods or services to those individuals or to the monitoring of data subjects' behaviour within the EU. This means that companies located around the globe that operate in the EU must have a solid plan for GDPR compliance or risk the penalties.
A financial transaction does not need to take place for GDPR regulations to apply. Even if a prospective EU customer never purchases a product or service from your organisation, if your organisation is subject to GDPR then you are required to adhere to its requirements when processing that prospective customer's data.
Does GDPR apply to US companies?
Yes. GDPR's extraterritorial scope is defined in Article 3, and it applies to US companies based on two criteria, not on where the company is headquartered. The practical self-test is straightforward: Do you offer goods or services to EU residents? Do you monitor the behaviour of EU residents? If the answer to either question is yes, GDPR applies to your organisation regardless of where it is based.
US companies subject to GDPR must also comply with Article 27, which requires appointing an EU representative, a person or entity established in the EU who can act as a point of contact for supervisory authorities and data subjects. This is a concrete operational requirement, not a formality.
The most common misconception is that GDPR only applies once a commercial relationship exists. It does not. Collecting an EU resident's email address through a web form, tracking their behaviour on your website, or including them in a prospecting database are all processing activities that trigger GDPR obligations.
The 7 GDPR data protection principles every B2B team must know
All GDPR compliance obligations flow from seven core data protection principles defined in Article 5 of the regulation. These principles are not aspirational guidelines; they are legally binding requirements that underpin every processing activity your organisation undertakes. The compliance checklist in the next section maps directly to these principles.
Lawfulness, fairness and transparency (Article 5(1)(a)): Personal data must be processed on a valid legal basis, in a way that is fair to the individual, and with clear disclosure of how data is used. For B2B marketing teams, this means identifying and documenting a lawful basis (such as legitimate interests or consent) for every contact in your database before you reach out.
Purpose limitation (Article 5(1)(b)): Data collected for one specified purpose cannot be repurposed for something incompatible with that original purpose. If you collected a contact's email address for a product demo request, you cannot later use it for an unrelated marketing campaign without a separate lawful basis.
Data minimisation (Article 5(1)(c)): You should collect only the data that is adequate, relevant, and limited to what is necessary for the stated purpose. For B2B marketers, this means resisting the temptation to collect every available field on a web form, collect what you need, not what might be useful someday.
Accuracy (Article 5(1)(d)): Personal data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or corrected without delay. For B2B teams, this creates a direct operational requirement to refresh contact records regularly, stale data is not just a campaign performance problem, it is a compliance risk.
Storage limitation (Article 5(1)(e)): Data should not be retained for longer than is necessary for the purposes for which it was collected. B2B marketing teams should define and enforce retention schedules for contact records, suppression lists, and campaign data, and delete records that no longer serve an active purpose.
Integrity and confidentiality (Article 5(1)(f)): Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage. This principle covers your data storage, access controls, and vendor security requirements.
Accountability (Article 5(2)): The data controller is responsible for, and must be able to demonstrate compliance with, all of the above principles. Accountability is the principle that makes the others enforceable: you must not only comply but be able to prove it through documentation, policies, and records of processing activities.
These seven principles form the architecture of GDPR compliance. The checklist below translates them into concrete operational steps.
GDPR compliance checklist: 10 steps to build your programme
This GDPR compliance checklist maps the seven principles and key GDPR articles to the specific actions your organisation needs to take. Use it as a programme-building framework, not a one-time audit. For a deeper reference, the sections above in this GDPR compliance guide cover each area in detail.
Map your data processing activities (Article 30, Records of Processing Activities): Document every category of personal data you process, the purpose, the lawful basis, and the retention period. Owner: DPO/Legal. This is the foundation of your programme, you cannot manage what you have not mapped.
Identify and document your lawful basis for each processing activity (Article 6): For each processing activity in your records, confirm and document which of the six lawful bases applies (consent, contract, legal obligation, vital interests, public task, or legitimate interests). Owner: Legal/Marketing. B2B marketing teams most commonly rely on legitimate interests or consent.
Update privacy notices to meet transparency requirements (Articles 13-14): Ensure your privacy notices tell individuals who you are, what data you collect, why you collect it, how long you retain it, and what rights they have. Owner: Legal/Marketing. Notices must be written in plain language and be easily accessible.
Build a data subject rights request process with a 30-day response window (Articles 15-22): Implement a documented workflow for receiving, verifying, and responding to requests to access, rectify, erase, or port personal data. Owner: Legal/IT. Organisations must respond within 30 days, extendable to three months for complex requests.
Review and update consent mechanisms where consent is the lawful basis (Article 7): Audit every point where you collect consent, web forms, email sign-ups, event registrations, and ensure consent is freely given, specific, informed, and unambiguous. Owner: Marketing. Pre-ticked boxes and bundled consent do not meet the GDPR standard.
Conduct Data Protection Impact Assessments for high-risk processing (Article 35): For any new processing activity that is likely to result in a high risk to individuals, such as large-scale profiling, systematic monitoring, or processing special category data, complete a DPIA before the processing begins. Owner: DPO/IT.
Appoint a Data Protection Officer if required (Articles 37-39): Determine whether your organisation is required to appoint a DPO (required for public authorities, organisations carrying out large-scale systematic monitoring, or those processing special category data at scale). Owner: HR/Legal. Even if not required, many organisations appoint a DPO voluntarily as a governance signal.
Establish a data breach notification procedure with a 72-hour window (Article 33): Document your incident response process so that if a personal data breach occurs, your team can assess, contain, and notify the relevant supervisory authority within 72 hours. Owner: IT/Legal. Notification to affected individuals may also be required under Article 34.
Review third-party data processor agreements and ensure GDPR-compliant DPAs are in place (Article 28): Every vendor or service provider that processes personal data on your behalf must have a signed Data Processing Agreement that meets GDPR requirements. Owner: Legal/Procurement. This includes email service providers, CRM platforms, analytics tools, and enrichment vendors.
Implement data protection by design and by default (Article 25): Build privacy into your systems and processes from the outset, not as an afterthought. Default settings should process only the minimum personal data necessary. Owner: IT/Product. This principle applies to new product features, campaign tools, and data infrastructure decisions.
GDPR key terminology: controllers, processors, and data subjects
Understanding the key roles and terms in GDPR is essential for any B2B team assessing its compliance obligations. The table below covers the most important terms, their definitions, and the relevant GDPR articles.
Term | Definition | GDPR Article |
|---|---|---|
Data Subject | A natural person who can be identified, directly or indirectly, by personal data. In a B2B context, this includes your contacts, prospects, and customers as individuals. | Article 4(1) |
Personal Data | Any information relating to an identified or identifiable natural person. Includes names, email addresses, phone numbers, IP addresses, and job titles. | Article 4(1) |
Data Controller | A natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of processing personal data. The controller bears primary liability for GDPR compliance. | Article 4(7) |
Data Processor | A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the data controller. Importantly, data processors can be directly liable under GDPR, not just controllers. Examples include email service providers and cloud storage providers. | Article 4(8) |
Supervisory Authority | An independent public authority established by an EU member state to monitor and enforce the application of GDPR. In the UK, this is the Information Commissioner's Office (ICO). | Article 4(21) |
Lawful Basis | One of six legal grounds that must exist before personal data can be processed: consent, contract, legal obligation, vital interests, public task, or legitimate interests. | Article 6 |
Data Protection Officer (DPO) | A designated individual responsible for overseeing an organisation's data protection strategy and compliance. Mandatory for certain organisations; advisable for all. | Article 37 |
Special Category Data | A defined set of sensitive personal data categories that receive heightened protection under GDPR: racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sex life, and sexual orientation. | Article 9 |
Being a data controller carries serious legal responsibilities. If you are unsure whether GDPR regulations apply to you as an individual or to your company as a whole, consult a legal adviser familiar with local laws.
Data subject rights under GDPR: what your contacts can demand
EU data subjects have eight fundamental rights under GDPR, defined in Articles 15 through 22. Organisations must respond to data subject requests (DSRs) within 30 days, extendable to three months for complex or high-volume requests. Some rights can be restricted under national law, which adds a layer of jurisdiction-specific complexity for organisations operating across multiple EU member states.
The right to be informed (Article 13-14): Organisations must be transparent in how they use personal data. For B2B marketers, this means your privacy notices must clearly explain what data you collect, why, and how long you retain it.
The right of access (Article 15): Individuals have the right to know what information is held about them and how it is processed. Your team must be able to retrieve and provide a complete record of a contact's data within the 30-day window.
The right of rectification (Article 16): Individuals are entitled to have personal data rectified if it is inaccurate or incomplete. For B2B marketing teams, this reinforces the operational case for maintaining accurate, up-to-date contact records.
The right of erasure (Article 17): Also known as "the right to be forgotten," individuals have the right to have their personal data deleted or removed. For B2B marketers, this means maintaining a suppression list of opted-out contacts and ensuring they are excluded from all campaigns and enrichment workflows.
The right to restrict processing (Article 18): Individuals have the right to block or suppress the processing of their personal data in certain circumstances, for example, while a dispute about accuracy is being resolved.
The right to data portability (Article 20): Individuals have the right to receive their personal data in a commonly used, machine-readable format and to transmit that data to another entity. This right applies where processing is based on consent or contract.
The right to object (Article 21): In certain circumstances, individuals are entitled to object to their personal data being used. If your organisation uses personal data for direct marketing purposes, individuals may object at any time, and you must stop processing for that purpose without delay.
The right not to be subject to automated decision-making and profiling (Article 22): GDPR has put in place safeguards to protect individuals against the risk that a potentially damaging decision is made without human intervention. Individuals can choose not to be subject to a decision that has a legal or similarly significant effect and is based solely on automated processing.
GDPR fines and penalties: what non-compliance actually costs
GDPR enforcement operates on a two-tier fine structure, with penalties scaled to the severity of the violation.
Tier 1 (Article 83(4)): Up to €10 million or 2% of global annual turnover, whichever is higher. This tier applies to less severe violations, including failures to maintain records of processing activities, failures to notify a breach within the 72-hour window, and non-compliance with DPA requirements for processors.
Tier 2 (Article 83(5)): Up to €20 million or 4% of global annual turnover, whichever is higher. This tier applies to the most serious violations, including breaches of the core data protection principles, violations of data subject rights, and unlawful international data transfers.
Notable GDPR enforcement actions
According to the GDPR Enforcement Tracker (enforcementtracker.com), the following fines represent some of the most significant enforcement actions to date:
Organisation | Fine | Year | Violation |
|---|---|---|---|
Meta | €1.2 billion | 2023 | Unlawful data transfers to the US |
Amazon | €746 million | 2021 | Advertising targeting without adequate lawful basis |
€225 million | 2021 | Transparency failures in privacy notices | |
€50 million | 2019 | Insufficient consent for personalised advertising |
GDPR fines are prioritised and processed differently from country to country. According to the GDPR Enforcement Tracker (enforcementtracker.com), Luxembourg had the largest sum of fines at €746,267,200 for only 19 fines total, whereas Spain had the most fines at 425, but the sum paid was far less at €55,524,770.


GDPR fines are determined by the following ten criteria:
Gravity and nature: What exactly happened? Why did the infringement occur? How many people were affected? How long did it take to fix? How bad was the damage?
Intention: Was the violation intentional or the result of negligence?
Mitigation: Was there action taken to mitigate the damage?
Degree of responsibility: What level of responsibility is attributable to the organisation? Were appropriate security measures implemented? Were efforts made to implement data protection by design and by default?
History: Does the company or organisation have a history of infringements under or outside the GDPR?
Cooperation: Is the organisation cooperating with data protection regulators?
Data category: What are the specifics of the type of data affected by the violation?
Notification: Was the organisation proactive in reporting the infringement?
Certification: Has the company adhered to approved codes of conduct under Article 40 of the GDPR? Has the company adhered to approved certification mechanisms under Article 42?
Aggravating/mitigating factors: Are there any other aggravating or mitigating factors applicable to the case?
According to the GDPR Enforcement Tracker (enforcementtracker.com), since the inception of GDPR, "non-compliance with general data processing principles" and "insufficient legal basis for data processing" make up over 50% of the total number of fines and over 75% of the total sum paid.
What GDPR compliance means for B2B organisations
For a company to be GDPR compliant it must abide by the seven data protection principles defined in Article 5, which underpin all GDPR obligations:
Data must be processed lawfully, fairly, and in a transparent manner
Data can only be collected for specified, explicit, and legitimate purposes
The scope of the data collected must be adequate, relevant, and limited to what is necessary in order to achieve the purposes for which the data was collected
Data must be accurate and kept up to date
Data can only be held for the time necessary to accomplish the purposes for which the data is collected and processed, and no longer
Data must be processed in a manner that ensures appropriate security of the personal data
The data controller is responsible for, and must be able to demonstrate compliance with, all of the above principles (Accountability, Article 5(2))
If your business falls under GDPR, we recommend that you explore compliance solutions, training, and legal expertise to gain the tools you need to protect yourself and your customers.
For B2B marketing teams, GDPR compliance is not just a legal obligation, it is a data quality imperative. Stale, inaccurate contact data creates compliance risk: if you cannot serve notice to individuals or honour erasure requests because your records are out of date, you are exposed.
2025 GDPR updates: what B2B teams need to know now
The GDPR regulatory environment is not static. Two significant developments in 2025 have direct implications for B2B organisations operating across the EU.
GDPR Enforcement Rules Regulation (December 2025)
In December 2025, the EU introduced the GDPR Enforcement Rules Regulation, which reforms how cross-border enforcement cases are handled under the one-stop-shop mechanism. The one-stop-shop mechanism allows organisations with an EU establishment to deal primarily with the supervisory authority in the member state where their main establishment is located. In practice, this mechanism had been criticised for producing inconsistent outcomes and significant procedural delays across national authorities.
The new regulation addresses those procedural gaps. For organisations operating across multiple EU member states, this means more consistent and faster case resolution. Compliance teams should treat this as a signal that cross-border enforcement is becoming more efficient, not less, the window for relying on procedural complexity as a buffer is narrowing.
EU Digital Omnibus proposal
The EU Digital Omnibus proposal, if adopted, could reduce certain compliance burdens for smaller organisations. The proposal aims to simplify obligations for SMEs across several EU digital regulations. Compliance teams should monitor its progress and assess implications for their programmes, but should not defer current compliance work pending its outcome. The proposal is not yet law, and its final scope remains subject to the legislative process.
What to do now
These developments point to two concrete near-term actions. First, review your cross-border data transfer mechanisms, Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions, and confirm they are current and properly documented. Second, audit your Data Processing Agreements with third-party processors. Article 28 DPAs are a frequent enforcement focus, and ensuring they reflect current processing activities is one of the most defensible steps your compliance programme can take.
Is ZoomInfo GDPR compliant?
ZoomInfo, an all-in-one AI GTM Platform, works to comply with all applicable privacy regulations, including the GDPR.
As an all-in-one AI GTM Platform, ZoomInfo's compliance posture is built on three foundations that matter directly to B2B marketing and sales teams. Its data layer, 500M contacts verified by 300+ human researchers, is built with accuracy and privacy compliance as foundational requirements, not afterthoughts. The GTM Context Graph processes 1.5B+ data points daily, fusing verified contact data with behavioral signals in ways that require rigorous data governance to maintain. And through Universal Access lanes including APIs and GTM Workspace, ZoomInfo ensures that privacy controls, suppression lists, opt-out enforcement, notice-provided dates, propagate consistently across every surface where customer data is accessed.
Certification & Validation: ZoomInfo's privacy practices and posture have been independently assessed by multiple third parties. Our attestations include:
ISO 27701 Certification
TRUSTe GDPR Practices Validation
TRUSTe CCPA Practices Validation
TRUSTe Enterprise Privacy & Data Governance Certification
Data Accuracy: Data accuracy and completeness are core requirements of data protection laws like the GDPR. More accurate data helps your team ensure compliance, including the ability to effectively serve notice to individuals when required by law, or determine what laws may or may not apply given an individual's location.
Understanding that data accuracy is paramount to a robust and effective compliance programme, ZoomInfo maintains up to 95% accuracy on first-party data. To aid in this, we employ an in-house research team of 300+ human researchers to gather, review, and verify the information we provide on our platform.
Transparency: ZoomInfo provides a privacy notice, direct by email, to all addressable contacts regardless of where they are located geographically. The notice establishes transparency in our processing and provides easy mechanisms for individuals to control their information. In particular, this notice tells the individual who we are, what types of data we collect, and informs them that their information may be accessed by our customers for their sales, marketing, and recruiting purposes.
Managing Preferences: Enabling individuals to control their data is essential to maintaining compliance with established privacy laws. In addition to the standard privacy@zoominfo.com email address, we maintain a full self-service ZoomInfo Privacy Center where individuals can directly manage their data, including removing their information from our systems. Our full-time privacy fulfillment staff manage these requests, ensuring we process requests in a timely manner.
To see how ZoomInfo's compliance infrastructure supports your B2B marketing programmes, request a demo.
How ZoomInfo helps B2B teams stay GDPR compliant
For B2B marketing teams running campaigns that touch EU prospects, GDPR compliance is an operational challenge as much as a legal one. Stale contact data, missing suppression lists, and inconsistent opt-out enforcement are the most common sources of compliance exposure. ZoomInfo's platform includes several features designed to address these operational risks directly.
There are a number of ways in which ZoomInfo supports and encourages customers to achieve compliance. Here's what you can expect:
Options included with all ZoomInfo subscriptions
ZoomInfo's Opt-Out List: All individuals are afforded the right to opt-out of ZoomInfo's processing of their data via an opt-out list within the platform. We also require our customers to regularly review the list and remove any contacts they have obtained from ZoomInfo unless they have an independent lawful basis to process such information.
Master Suppression: The Admin user on your account is able to manage a Master Suppression list within the ZoomInfo platform. By uploading your opt-out lists, unsubscribe lists, or internal blacklists into this tool, your opted-out individuals will be scrubbed from your instance of ZoomInfo.
Do Not Call Toggle: The Admin user can turn on this feature, which will hide phone numbers found in various global Do Not Call registries from your instance of ZoomInfo. Our coverage for this feature is ever evolving, but currently includes the USA, UK (both the TPS and the Corporate TPS), France, Germany, Ireland, Australia, New Zealand, and Canada.
Admin-Defined Dataset: Admin users can upload a list of accounts, limiting what their reps are able to access within the ZoomInfo platform to information related to the uploaded list of accounts.
Notice Provided Date: Each contact record contains an associated "Notice Provided Date" to indicate when ZoomInfo has provided the individual with our Privacy Notice.
Options included with ZoomInfo's Global Data Passport
Hide EU Contact Details: If your ZoomInfo subscription contains access to contacts located in the EU/UK, this feature allows you to redact email and phone from these records while still allowing access to important information like office location, title, web-references, org charts, and employment/education history.
For more information about ZoomInfo's privacy compliance practices, check out our ZoomInfo Privacy Center to learn more.
Please note that the above is for informational purposes only. ZoomInfo is not qualified to provide legal advice of any kind and is not an authority on the interpretation of U.S. or international laws, rules, or regulations. To understand how the GDPR, marketing laws, or any other laws impact you or your business, you should seek independent advice from qualified legal counsel.
Frequently asked questions about GDPR compliance
Does GDPR apply to B2B contact data?
Yes. GDPR applies to any personal data that can identify an individual, including business email addresses, direct phone numbers, and job titles. The fact that data is collected in a professional context does not exempt it from GDPR. B2B marketers must have a lawful basis for processing contact data of EU-based individuals.
Is GDPR compliance mandatory in the USA?
GDPR is not a US law, but US companies that offer goods or services to EU residents, or that monitor the behaviour of EU residents, must comply with GDPR regardless of where they are headquartered. Non-compliance can result in fines of up to 4% of global annual turnover or €20 million, whichever is higher. US companies subject to GDPR must also appoint an EU representative under Article 27.
What are the 7 principles of GDPR compliance?
The 7 GDPR data protection principles, defined in Article 5, are: (1) Lawfulness, fairness and transparency; (2) Purpose limitation; (3) Data minimisation; (4) Accuracy; (5) Storage limitation; (6) Integrity and confidentiality; (7) Accountability. All GDPR compliance obligations flow from these principles. See the full breakdown in the article above.
What is the difference between a data controller and a data processor under GDPR?
A data controller determines the purposes and means of processing personal data and bears primary liability for GDPR compliance. A data processor processes data on behalf of the controller. Importantly, data processors can also be directly liable under GDPR, not just controllers. Examples of processors include email service providers and cloud storage providers. Controllers must ensure their processors are GDPR compliant through Data Processing Agreements (Article 28).
Is ZoomInfo GDPR compliant?
Yes. ZoomInfo, an all-in-one AI GTM Platform, works to comply with all applicable privacy regulations including GDPR. ZoomInfo holds ISO 27701 Certification, TRUSTe GDPR Practices Validation, and TRUSTe Enterprise Privacy & Data Governance Certification. ZoomInfo provides privacy notices directly to all addressable contacts and maintains a self-service ZoomInfo Privacy Center where individuals can manage their data. See the full compliance section above for details on ZoomInfo's opt-out, suppression, and data management features.
What happens if my company violates GDPR?
GDPR violations can result in fines of up to €10 million or 2% of global annual turnover (Tier 1 violations) or up to €20 million or 4% of global annual turnover (Tier 2 violations, the most serious breaches). Beyond fines, organisations face reputational damage, mandatory breach notifications, and potential suspension of data processing activities. The most common violation categories are non-compliance with general data processing principles and insufficient legal basis for data processing, which together account for over 50% of all GDPR fines by count.

