If you source prospects from Google Maps and want to email them, the legal question is not whether you can scrape a directory — it is whether you have a lawful basis for sending that first message. For most EU B2B outreach, that basis is legitimate interest under GDPR Art. 6(1)(f). This guide explains what that means in practice, what you must do to stay inside it, and where the real edge cases sit.
Key takeaways
- For EU B2B cold email to businesses found on Google Maps, the typical lawful basis is GDPR Art. 6(1)(f) legitimate interest — not consent.
- Legitimate interest requires three things: a genuine commercial purpose, outreach relevant to the recipient's trade, and a clear, easy opt-out honored within 48 hours.
- Only use contact details the business itself made public — a listed phone number or a website email is fair game; a personal Gmail scraped from a social profile is not.
- US outreach is governed by CAN-SPAM and, for some sectors, CCPA — neither requires pre-consent for B2B cold email, but opt-out compliance is still mandatory.
- LeadGrid surfaces only public Google Maps business listings with website-enriched emails, so the underlying data already fits the 'publicly disclosed by the business' requirement.
What is the lawful basis for cold-emailing businesses found on Google Maps?
For EU B2B outreach, the lawful basis is typically legitimate interest under GDPR Art. 6(1)(f): you have a genuine commercial reason to contact the business, the contact details were published by the business itself, the message is relevant to their trade, and you provide a clear opt-out. Consent is not required for B2B email in most EU member states, but legitimate interest is not a blank cheque — you must pass a three-part balancing test.
The three-part test works like this. First, purpose: is your reason for reaching out real and specific, not just 'we want more sales'? Second, necessity: is email the reasonable way to make that contact, given that the business listed its email publicly? Third, balance: would a reasonable business owner expect to receive this kind of message, or would it feel intrusive? A plumber receiving a cold pitch for commercial cleaning supplies passes that test easily. A sole-trader receiving a speculative financial-services pitch probably does not.
One practical safeguard: only use contact details the business itself disclosed publicly — a phone number on their Google Maps listing, or an email address on their own website. LeadGrid's enrichment works exactly this way: it reads the business's own website to find a contact email, never pulling from login-walled sources or social profiles. That is the distinction that matters legally. You can read more about how the data is sourced on our about our data page.
How does legitimate interest under GDPR Art. 6(1)(f) actually work in practice?
Legitimate interest under GDPR Art. 6(1)(f) means you document why you are contacting this category of business, why email is proportionate, and how you will handle opt-outs — before you send, not after a complaint arrives. In practice that means a short written record (a 'legitimate interest assessment' or LIA), a one-click unsubscribe in every message, and a process to suppress opt-outs within 48 hours.
The Recital 47 of the GDPR explicitly names direct marketing as a legitimate interest, which gives B2B cold email a firmer footing than many assume. The key boundaries are: the recipient must be acting in a professional or business capacity (not as a private individual), the subject matter must be relevant to that business, and you must identify yourself clearly — no disguised sender addresses or misleading subject lines.
Member-state law can tighten this. Germany's UWG, for instance, imposes stricter requirements for unsolicited B2B email. If you are targeting specific EU countries at scale, it is worth a quick check with a local counsel — this guide frames the typical position, not a country-by-country legal opinion.
- Write a brief legitimate interest assessment: state your business purpose, why this category of recipient is relevant, and confirm the data source is publicly disclosed.
- Verify that the contact detail came from the business's own public listing or website — not a scraped social profile or purchased list of unknown provenance.
- Draft your outreach so the relevance to their trade is obvious in the first sentence: a generic 'I help businesses grow' opener fails the balancing test.
- Include your full legal name, company name, and a one-click opt-out in every email — this is required under both GDPR and CAN-SPAM.
- Log opt-outs immediately and suppress them within 48 hours; keep that suppression list permanently so you do not accidentally re-contact the same address.
- Review your LIA annually or whenever you change the category of businesses you target.
Does the same lawful basis apply in the US, or is CAN-SPAM different?
US B2B cold email is governed primarily by CAN-SPAM, which does not require prior consent for commercial email — it requires honest headers, a physical postal address, and a working opt-out mechanism honored within 10 business days. GDPR Art. 6(1)(f) is an EU concept and does not apply to US-only outreach, but the practical obligations (identify yourself, stay relevant, honor opt-outs) are similar.
The main US complication is CCPA (California Consumer Privacy Act). For B2B contacts who are sole proprietors or where the contact is also a consumer, CCPA can apply. In practice, if you are emailing a registered business address listed on Google Maps — a dental practice, a law firm, a restaurant — you are almost certainly in B2B territory and CCPA's B2B exemption covers you. If you are reaching out to a freelancer's personal Gmail, that exemption is shakier.
If you are running outreach across both US and EU targets from the same list, apply the stricter GDPR standard uniformly — it is simpler operationally and reduces compliance risk without materially changing what good outreach looks like anyway.
Which lead sources fit the 'publicly disclosed by the business' requirement, and which do not?
A contact detail 'publicly disclosed by the business' means the business itself chose to publish it in a professional context — a Google Maps listing, their own website's contact page, a trade directory they registered with. LinkedIn profiles, personal social accounts, and data harvested from login-walled platforms do not meet this standard, because the individual controls the context of disclosure.
That gap is why email enrichment matters. According to a LeadGrid analysis of 4,066 US local-business listings, half of businesses with a website still do not list an email on Google Maps — but the email often exists on the website's contact page. LeadGrid enriches from the business's own site, so the address is still 'publicly disclosed by the business' and fits the legitimate-interest framing. An email guessed from a name pattern (the Hunter model) sits in a greyer area, because the business never explicitly published that address.
| Data source | Publicly disclosed by the business? | Fits Art. 6(1)(f)? | Notes |
|---|---|---|---|
| Google Maps listing (phone, website) | Yes | Yes | Business registered it voluntarily |
| Business's own website contact page | Yes | Yes | Strongest position |
| Email pattern guessed from name + domain | Partial | Grey area | Business disclosed the domain, not that specific address |
| LinkedIn profile (work email) | No — platform-walled | No | Individual controls context; platform ToS also prohibits scraping |
| Purchased list from unknown broker | Unknown | Risky | Provenance cannot be verified; lawful basis unclear |
LeadGrid sits firmly in the first two rows. Competitors like Apollo or Lusha primarily surface people-level data including work emails derived from LinkedIn signals — useful for enterprise sales, but the lawful basis for that data under GDPR is more contested. That is not a knock on those tools for their intended use case; it is a genuine difference in data posture that matters if you are operating under EU law.
Frequently asked questions about lawful-basis B2B outreach
- Do I need consent to cold email a business in the EU?
- Not typically. GDPR Art. 6(1)(f) legitimate interest is the standard lawful basis for B2B cold email in the EU, provided you use publicly disclosed business contact details, keep the message relevant to their trade, identify yourself clearly, and honor opt-outs promptly. Consent is one of six lawful bases under GDPR — it is not the only one, and it is rarely the right one for B2B outreach.
- What must I include in every cold email to stay compliant?
- At minimum: your real name, your company's legal name and physical address, a subject line that accurately reflects the email's content, and a one-click opt-out mechanism. Under GDPR you should also be prepared to explain your lawful basis if asked. Under CAN-SPAM, opt-outs must be processed within 10 business days.
- Can I email a sole trader or freelancer the same way I email a company?
- With more caution. A sole trader operating under their own name may be treated as an individual rather than a business in some EU jurisdictions, which weakens the legitimate-interest argument and can bring ePrivacy rules into play. If the contact detail is a business address for a registered trade, you are generally fine; if it is a personal email used for freelance work, seek local legal guidance.
- How quickly must I honor an opt-out request?
- LeadGrid's own policy is within 48 hours. GDPR does not specify a fixed window for marketing opt-outs but requires 'without undue delay.' CAN-SPAM gives 10 business days. Operating to a 48-hour standard satisfies both regimes and is the practical benchmark for responsible outreach.
- Does using LeadGrid data mean I am automatically GDPR-compliant?
- No — and any tool that claims otherwise is overselling. LeadGrid surfaces publicly disclosed business data, which supports a legitimate-interest argument, but compliance depends on how you use it: the relevance of your message, your opt-out process, your LIA documentation, and the member-state rules that apply to your targets. Responsibility for lawful outreach stays with you as the sender.
- Is Google Maps data legal to use for lead generation?
- This guide frames the question as lawful basis rather than legality, because that is the operationally useful question. Using publicly listed business information (name, address, phone, website) that a business voluntarily registered on Google Maps for the purpose of being found is the basis on which legitimate-interest arguments rest. What you do with that data — and how you contact people — is where compliance is won or lost.