GDPR compliance for outbound sales starts before a lead enters a campaign. A sales team needs to know where the contact came from, which rules apply to the channel, why it may use the personal data and how an objection will stop further marketing. A business address, a purchased list or an outsourcing contract does not answer those questions by itself.
The €500,000 Futura Internationale case illustrates how several failures can combine. It is a historical French decision from 2019, subsequently reviewed by the Conseil d’État, rather than a newly issued fine. Its practical value is in the failures it exposes: excessive information, inadequate transparency, ineffective objections, overseas transfers and poor cooperation. Those lessons remain useful, while the rules governing a new campaign must be assessed for its actual countries, recipients and channels.
What the Futura case actually established
The CNIL sanctioned Futura Internationale on 21 November 2019. Following complaints about calls continuing after objections, the authority inspected the company and required corrective action. The subsequent Conseil d’État judgment of 1 March 2021, case 437808, records the €500,000 fine and rejects the company’s challenge to it.
The judgment identifies failures concerning the relevance and amount of data, information given to individuals, their right to object, cooperation with the regulator and safeguards for transfers outside the European Union. It also records that the CNIL closed the compliance injunction procedure on 30 January 2020 after recognising the company’s compliance. Corrective action and the validity of the earlier penalty were therefore separate questions.
The lesson is operational: a policy that does not stop the calls is ineffective. It would be misleading to turn the fine into a fixed price for unlawful prospecting or to claim that one different response would have halved it. The court considered the circumstances and persistence of the failures. For a new campaign, examine each stage of the process instead of comparing your budget with a historical penalty.
Separate data protection from permission to use a channel
The GDPR applies when an organisation processes personal data within its scope. Named work email addresses, direct telephone numbers and information about a person’s professional responsibilities can be personal data. Calling the database “B2B” does not remove the people from it. A generic corporate address may involve a different analysis, depending on the surrounding information and how it is used.
Two questions must be answered separately. First, what permits the collection and use of the personal data under data protection law? Second, do electronic communications or other national rules allow the particular marketing contact? Requirements can differ between email, text messages, automated calls and calls made by a person. A lawful basis for maintaining a contact record does not override a channel rule requiring consent.
Document the campaign’s target countries, recipient categories, channel and source before authorising its launch. Do not assume that the sender’s location alone determines every applicable rule. Where a campaign crosses borders, establish the relevant national requirements and regulatory jurisdiction for that activity. The examples below illustrate differences; they are not a single permission covering all European recipients.
France: professional relevance matters
The CNIL’s electronic marketing guidance, updated on 10 June 2026, distinguishes consumer and professional prospecting. Its professional route can rely on legitimate interests where the subject of the solicitation relates to the recipient’s profession. The person must be informed and able to object simply and without charge. Buying the address from another organisation does not dispense with those safeguards.
For consumer electronic marketing, prior consent is the general rule, subject to defined exceptions. The existing-customer exception described by the CNIL concerns similar products or services supplied by the same business and requires the applicable opportunity to object. Merely creating an online account does not establish the sale or service relationship needed for that exception. These electronic marketing rules should not be copied indiscriminately into a script for live telephone calls.
United Kingdom: identify the subscriber and the individual
The ICO’s B2B marketing guidance explains a different distinction under PECR. The electronic mail consent rule does not apply to corporate subscribers in the same way as to individual subscribers. Sole traders and some partnerships are treated as individual subscribers; an address used for work is therefore not automatically within the corporate category. Sender identification and an unsubscribe address remain relevant.
Where a corporate employee’s address identifies that person, the UK GDPR still applies to its use. Their objection to processing for direct marketing must be respected even if the corporate subscriber route did not require prior consent under PECR. The ICO flags this guidance as under review following the Data (Use and Access) Act; use the current rules for the actual activity rather than treating the page as a complete account of every UK data protection change.
Choose and document the lawful basis before importing leads
Under the EU GDPR, legitimate interests can be relevant to direct marketing, but they are not an automatic exemption. Identify the interest, explain why the particular processing is necessary and assess its effect on the person. Consider the source, professional relevance, likely expectations, frequency of contact and consequences of the campaign. A generic statement that growth is important does not explain why this dataset or method is justified.
Where consent is required, retain evidence of what the person agreed to, when and through which process. Check whether the consent actually covers your organisation, purpose and channel. A list vendor’s assurance that every record is compliant is not a substitute for evidence. Consent to one organisation’s newsletter does not automatically cover unrelated marketing from every company that later obtains the address.
Public availability also needs care. A contact published to receive customer enquiries may not have been published for bulk lead generation. Information visible on a professional network is not, by itself, proof of consent to export it into a sales database. Assess the context and the proposed use, including any enrichment, scoring or sharing with partners. Platform access and data protection permission are different questions.
A useful acceptance record for a lead source identifies the supplier, collection method, dates, information provided, claimed basis and limits on reuse. Review a meaningful sample of the evidence against the intended campaign. If the source cannot explain its collection and disclosure, pause the import until the missing basis is resolved. Keeping the data unused indefinitely is not a solution to an unjustified collection.
Tell people what you are doing with their information
Privacy information notices must describe the actual processing in clear language. Where details are collected directly from the person, Article 13 generally requires the information at collection. Explain the controller, purposes and basis, relevant recipients, retention, rights and any applicable transfers. A short sales message can link to fuller information, but the design must make the relevant explanation accessible.
Where details come from a broker, a public source or another organisation, Article 14 adds requirements including the source and categories of data. The information is generally due within a reasonable period and no later than one month, with earlier triggers for the first communication or disclosure where applicable. If the first marketing email is sent tomorrow, a one-month outer limit does not permit you to withhold the notice until next month.
The exceptions in Article 14 are limited and must actually apply. The size of a purchased list does not automatically justify omitting individual information. Record any exception you rely on and the safeguards it requires. Separately, Article 21 requires the right to object to be drawn explicitly to the person’s attention by the first communication, clearly and separately from other information.
For recorded calls, explain the recording and its purposes through an appropriate notice before the relevant collection, alongside a valid basis and applicable national safeguards. Define who can listen and how long recordings are retained. Recording every conversation indefinitely because it might later help training is difficult to reconcile with a defined, necessary purpose.
Make objections stop marketing across the whole process
The right to object under Article 21 is particularly strong for direct marketing. Once the person objects, their personal data must no longer be processed for that purpose, including related profiling. You cannot override that objection by deciding that your commercial interest is more important. Consent withdrawal must likewise stop the processing that depends on the withdrawn consent.
Give staff a straightforward way to recognise an objection in a reply, a telephone conversation or a support request. The person does not need to use the words “Article 21”. Record the scope accurately: a request to stop all marketing is different from a clearly limited preference about one channel. Avoid asking someone to repeat an unmistakable instruction through another department before acting on it.
The change must reach the CRM, campaign tool, dialler, external agency and any pending communication queues. Check what happens when a lead is imported again or assigned to another salesperson. A common failure is deleting one active record while allowing a fresh copy from a broker to recreate the same campaign eligibility. The operational control should survive those ordinary data flows.
A limited suppression record can help prevent renewed contact. It needs its own justified purpose, appropriate access and a retention decision; it should not become a second marketing profile. Explain how this interacts with a request for erasure. Retaining the minimum needed to respect an objection is different from keeping the entire prospect history available for future sales use.
Keep CRM data relevant and retention deliberate
The data minimisation principle applies to contact fields, notes, scores and attachments. Design records around what is necessary for the defined sales purpose. A neutral note that a person does not wish to receive further contact can be useful. Insults, speculative comments about health or unrelated personal circumstances can create serious problems without improving a legitimate sales decision.
Free-text fields are not universally prohibited, but they require controls. Explain what staff should and should not record, limit access and review how the fields are actually used. Structured options can reduce unnecessary collection where they fit the task. Deleting every notes field is not the only possible response, just as appointing a person with a privacy title does not automatically solve poor input practices.
Set retention rules separately for active prospects, consent evidence, objections, contracts and any records needed for a dispute. The GDPR does not impose one universal duration for all sales leads. Define a reasoned trigger for review or deletion, taking account of applicable national guidance and requirements. Continued storage should not depend solely on a salesperson being reluctant to lose a possible future opportunity.
Consider derived information as well as the original list. Enrichment and scoring may create new data about a person, sometimes through unreliable inferences. Assess accuracy, fairness and whether the expanded purpose remains justified. A campaign that begins with a work address can become considerably more intrusive when combined with browsing behaviour or detailed personal profiles.
Check agencies, processors and international access
Outsourcing outreach does not eliminate your responsibilities. Establish what each service provider actually decides and does. A call centre following your instructions may be a data processor; a broker determining its own collection and resale purposes may have a different role. Assess the operations rather than assigning every supplier the same label.
Where Article 28 applies, the processor agreement should address instructions, confidentiality, security, subprocessors, assistance and the end of the service. It should also support the information and audits needed to demonstrate compliance. There is no universal GDPR rule that every overseas call centre must receive an onsite visit before work begins. The assurance measures should respond to the service and risks, and be sufficient in practice.
Map international data transfers, including relevant remote access by separate organisations. Identify whether an adequacy decision covers the recipient or which other Chapter V mechanism is appropriate. Where the chosen mechanism requires an assessment of the destination and supplementary safeguards, perform it for the actual access and data involved. Signing a processor contract is not, by itself, a complete transfer solution.
For a call centre that needs readable contact details to speak with prospects, do not pretend that encryption removes all access risks while the operator is using the data. Combine legal analysis with proportionate technical and organisational measures. Include cooperation on objections and rights requests in supplier oversight, because a transfer arrangement will not fix a campaign that repeatedly contacts people who have opted out.
Respond to complaints and regulatory enquiries with evidence
Give complaints an owner and preserve the records needed to understand what happened. Trace the lead’s source, the information shown, the campaign configuration, previous objections and the suppliers involved. Correct the live process when necessary, while retaining a proportionate record of the incident and the remedy. A later policy revision does not explain why an earlier message was sent.
If a regulator issues an enquiry or formal notice, identify the actual deadlines and requested measures. Provide complete, accurate responses and evidence of implementation. The GDPR requires cooperation with the supervisory authority; cooperation and mitigation also feature in the assessment described in Article 83 on administrative fines. Neither guarantees that a fine will disappear or be reduced by a predictable percentage.
The GDPR’s maximum fine bands depend on the infringed provisions and, for undertakings, the relevant turnover comparison. They are not separate flat tariffs for small businesses and corporate groups. National electronic communications rules may have their own enforcement arrangements. A guide to GDPR fines is useful context, but the decision to correct a campaign should rest on the conduct and applicable duties, not an assumed affordable penalty.
A practical decision before the next campaign
Before releasing a list, the campaign owner should be able to explain its source and purpose, the recipient and channel rules, the lawful basis, the notice and the objection process. The person approving the campaign should also know which suppliers receive the data and which retention rule applies. Unanswered questions belong in the launch decision, rather than in a spreadsheet that nobody checks after messages are sent.
Verify representative journeys through the actual systems: a newly imported lead, an existing objection, a reply asking for no further contact and a reimport from a supplier. These checks should show whether the organisation’s decisions are implemented. Review the process again when the source, country, channel or supplier changes. Compliance becomes more manageable when those changes trigger a concrete reassessment instead of silently extending permission from an earlier campaign.