derrick
GDPR B2B 19 min read

GDPR B2B

Account Based Marketing and GDPR: A Tactic-by-Tactic Compliance Map

Account based marketing and GDPR, mapped tactic by tactic: find which law applies, which legal basis holds, and the artefact you must file before launch.

Updated 19 min read

Account based marketing and GDPR sit closer together than most compliance guides admit. An ABM programme narrows its audience to a named list of companies you have a commercial reason to approach, which is exactly the shape of processing that Article 6(1)(f) was written to accommodate. The friction is not the strategy. It is that a single ABM campaign fires four or five different mechanisms at once, each governed by a different rule, and teams tend to pick one legal basis and stretch it across all of them.

The stakes are not theoretical. Cumulative European fines reached 7.1 billion euros according to the DLA Piper GDPR fines survey, the figure we follow in our GDPR enforcement tracker, and the recurring triggers are prospecting and data practices rather than exotic engineering failures.

This guide does the thing the rest of the category skips. Instead of restating the six GDPR principles, it maps each concrete ABM tactic to the law that actually governs it, the basis that holds up, and the artefact you need to be able to produce if a regulator asks. Read it alongside our guide to legal bases for B2B enrichment if you have not yet settled that question for your stack.

Account Based Marketing and GDPR: What Actually Changes

Three properties of ABM change your compliance posture, and only one of them is a constraint.

Your audience is defined before the data is collected. In broad demand generation, you buy reach and work out relevance afterwards. In ABM, you decide that these 180 companies match your ideal customer profile, and only then do you look for people inside them. That order matters legally, because the necessity limb of a legitimate interest test asks whether you could have achieved your purpose with less data. A team that can show a documented account selection step has a far easier answer than a team that ingested a 400,000 row file and filtered later.

Your data volume is small and your justification is specific. Data minimisation stops being an abstract principle when the list is 180 companies and roughly 900 named contacts. You can genuinely state, per field, why it is there. Our note on data minimisation in B2B covers the field level discipline that makes this defensible.

Your personalisation is the exposure. This is the constraint. ABM sells itself on relevance, and relevance means inferring things: seniority, budget authority, current tooling, a hiring pattern, a funding event. Every inference is processing, every inference has to be justified, and some of the inferences that make an ABM deck look impressive are the ones a data protection authority finds most interesting.

Account-Level or Person-Level: The Line That Decides Everything

Almost every ABM compliance mistake traces back to one confusion. GDPR protects natural persons. It does not protect companies.

Revenue, headcount, industry code, headquarters address, registration number, funding history, tech stack: these describe a legal entity, and on their own they are not personal data. You can build, buy, enrich and retain an account-level dataset without touching GDPR at all.

The moment a row identifies a human being, the whole regime applies. A named contact, a work email built on firstname.lastname, a direct dial, a LinkedIn profile URL, a job title tied to an individual: all personal data, all fully in scope, and the B2B context does not create an exemption. It only shifts which legal basis is realistic.

Data in an ABM programmePersonal data?Practical consequence
Company revenue, headcount, sector, registration numberNoOutside GDPR. No basis, no retention clock, no subject rights.
Generic company inbox (contact@, sales@)Usually noTreat as corporate. Becomes personal if it resolves to one identifiable person.
Named contact, work email, direct dial, profile URLYesFull regime: basis, transparency, objection, retention, record.
IP address captured for account de-anonymisationYes, in most casesTreated as personal data. Reverse-IP is not a GDPR-free zone.
Behavioural intent scores attached to a named personYesHighest exposure. Basis plus transparency plus an absolute right to object.

One qualification on the first row, and it matters more in Europe than teams expect. For a sole trader or a single-person company, the so-called company attributes identify a natural person: the trading name is their name, the registered address is often their home, and the registration number points at them. In those cases the account layer is personal data and the full regime applies, which is why the account-level exemption is a property of the entity type, not a blanket rule.

That fourth row is where confident ABM teams get caught. Reverse-IP tools are sold as account identification, and the pitch is that no individual is identified, so privacy law does not bite. The Court of Justice held in Breyer (C-582/14) that a dynamic IP address is personal data in the hands of a party with legal means to identify the subscriber. Whether a given deployment clears that bar is a real analysis. It is not a slogan on a vendor page.

The Tactic-by-Tactic Map: Which Law, Which Basis, What to Record

Here is the part the category leaves out. GDPR is not the only instrument in play. The ePrivacy Directive, as implemented by each member state, governs two things GDPR does not: storing or reading anything on a user's device, and unsolicited electronic communications. An ABM programme touches both. Picking the right instrument per tactic is most of the work.

Free tool

ABM tactic to legal basis mapper

Pick the tactic you are about to run. The output is the instrument that governs it, the basis that realistically holds, and the artefact you need on file before launch.

Which ABM tactic are you running?

Pick a tactic to see which law governs it and what you need on file.

General guidance for EU programmes, not legal advice. National implementations of ePrivacy differ sharply on B2B email, so confirm the rule in each country you send to. The UK regime (UK GDPR and PECR) diverges on several of these points and is not covered here.

The same map in full, so you can read it without touching the tool:

ABM tacticInstrument that governs itWorkable basisKeep on file
Build the target account listOutside GDPR while it stays account-levelNone needed for company attributes aloneThe selection criteria that define the list
Find named contacts inside accountsGDPRLegitimate interest, Article 6(1)(f)The legitimate interest assessment plus the source of each contact
Outbound email to named contactsGDPR for the data, ePrivacy Article 13 for the sendingLegitimate interest, subject to the national B2B ruleProof of the Article 14 notice and a working opt-out in every message
Upload a list as a matched audienceGDPR and ePrivacy, plus the platform's termsConsent is the safe reading: EDPB guidelines 8/2020 treat list-based social targeting as joint controllershipWhat you uploaded, to whom, the arrangement, and the deletion schedule
Retargeting pixel on your own siteePrivacy Article 5(3) first, then GDPRPrior consent for the storage or read on the deviceConsent logs and the tag inventory they cover
Third-party behavioural intent dataGDPRLegitimate interest, the hardest one to defendThe vendor's collection basis, your Article 14 notice, the Article 28 contract
Observed company events (funding, hiring)GDPR only where the event names a personLegitimate interest, on facts the company published itselfThe public source of the event and the field it wrote to

Two readings of that map are worth carrying into your next campaign. First, the instrument changes mid-funnel: the same audience can be lawful to assemble under legitimate interest and unlawful to retarget without consent, because the retargeting step touches a device rather than a database. Second, the artefact column is the one that decides an audit. Regulators rarely argue that legitimate interest was unavailable. They ask to see the assessment, and there isn't one.

Account Based Marketing and GDPR at the List-Building Stage

Start account-level and stay there as long as the work allows. Selecting 180 companies on sector, headcount, geography, funding stage and observable tooling involves no personal data whatsoever, so the entire selection phase of an ABM programme sits outside the regime. Teams routinely give this away by pulling contacts in the same query as the firmographics, then treating the whole file as a compliance problem.

When you do move to people, the question that matters is provenance. Not accuracy, not volume: provenance. A regulator asking about a prospect file starts with where it came from, and a rented list is where most answers fall apart, because the answer is a vendor name and the vendor's own basis, which does not transfer to you. Our guide on consent versus legitimate interest works through why that transfer fails.

Assembling contacts yourself changes the answer from a vendor name to a described step. That property belongs to the method, not to any tool: any route where you perform the steps yourself produces an account of them, and a manual one counts. Tooling only decides how long it takes. Derrick runs from a Google Sheets sidebar rather than a formula language, and the same operations are available through a REST API and an MCP server for teams that would rather drive it from a pipeline or an AI client. Enrich Companies fills the account layer at 1 credit per company, and Import Leads from Target Companies resolves the named contacts inside those accounts at 1 credit per lead. Both run on the free plan of 100 credits per month, and both scale to a list of 20 or 20,000 without changing the workflow. See the full feature catalogue for the rest of the surface.

The field-level discipline is the same one that makes the necessity test easy. Enrich the fields the campaign uses. If your sequence never references company revenue, do not carry a revenue column into the contact table, because you will be asked why it is there and "the tool returned it" is not an answer.

Ads, Pixels and Matched Audiences: This Is ePrivacy, Not GDPR

This is the single most common structural error in ABM compliance, and it is not a subtle one. Teams complete a careful legitimate interest assessment for their prospect database, then deploy an advertising pixel across the site and consider the question settled.

It is not settled, because a different instrument applies. Article 5(3) of the ePrivacy Directive requires prior consent for storing information on, or gaining access to information already stored in, a user's terminal equipment. Two narrow exemptions exist, for storage whose sole purpose is carrying a communication and for what is strictly necessary to deliver a service the user explicitly requested, and an advertising or retargeting pixel falls inside neither. That rule is triggered by the storage or the read itself. It does not care what your GDPR basis is, and legitimate interest is not an available alternative to it. A cookie, a pixel, a local storage write and a device fingerprint all fall inside it.

Matched audiences add a second layer. When you upload a list of named contacts to an advertising platform so it can find those people among its users, you are disclosing personal data to another organisation. You need a basis for that disclosure, the platform's own compliance posture does not cover your side of it, and you should be able to say what you uploaded, when, and when both parties delete it. The convenience of the upload button hides a genuine transfer, and if that platform processes outside the EEA, our guide to international transfers of enriched data covers the layer underneath.

Intent Data in Account Based Marketing: Observed Facts Versus Tracked Behaviour

Intent data is where ABM programmes take on most of their risk, and the category habitually collapses two very different things under one word.

First-party signals are what happens on surfaces you control: pages viewed on your site, content downloaded, emails opened, events attended. You are the controller, you know the collection path, and the device-level part of it needs ePrivacy consent while the profile-building part needs a GDPR basis.

Third-party behavioural intent is bought. Someone else observed reading behaviour across a publisher network and sold you the inference. Two problems follow. The vendor's legal basis covers the vendor's processing, not yours, so you need your own. And Article 14 applies precisely because the data did not come from the individual: you owe them information about your processing, generally within a month or at the first communication, whichever comes first. Most teams buying third-party intent have never sent that notice.

Observed corporate events are a third category that sits far lower on the risk curve, and ABM teams underuse it. A funding round, a job change, a hiring sprint, a visible tooling change: these are facts the company published about itself, they are timing signals rather than inferences about a person's private behaviour, and they are usually stronger buying indicators than an anonymised content-consumption score. The reason to prefer them is a property of the data, not of any tool: when the event is something the company announced, you can point at the public source, which is not true of a purchased behavioural score. If you want them collected automatically, Derrick's Signal watches accounts and leads for job changes, funding rounds, hiring sprees and tech-stack moves and fires an alert when one lands. It is a paid feature, available from the Standard plan at €20 per month, and it costs 1 credit per signal that fires.

What You Must Be Able to Show: The Assessment, the Record, the Clock

Legitimate interest is not a checkbox. It is a documented three-part test, and the document is the point.

Purpose. State the commercial interest plainly. "Contacting decision makers at companies that match our ideal customer profile, to offer a product relevant to their professional role" is a legitimate interest. It does not need to be noble.

Necessity. Show that the processing is needed for that purpose and that a less intrusive route was not available. This is where the ABM shape helps you: a 180-account list is manifestly more targeted than a bulk file, and the narrowing itself is the evidence.

Balancing. Weigh your interest against the reasonable expectations of the person. A named contact whose role is to evaluate the category you sell into can reasonably expect professional approaches. The same person cannot reasonably expect their browsing history across unrelated sites to have been assembled into a score you bought.

One artefact sits underneath all of this and is missing from most ABM files: the Article 28 processing agreement. Every enrichment vendor, sending platform and ad platform that touches your contact data is either a processor or a separate controller, and in the first case you need a written contract with the Article 28 clauses before the data moves. If your record names a recipient you have no agreement with, that is a finding waiting to happen.

Alongside the assessment, three further artefacts finish the file. The Article 30 record listing the ABM programme as a processing activity, with purpose, categories, basis, recipients and retention. The Article 14 notice, since none of this data came from the individual. And a retention clock. GDPR fixes no number: Article 5(1)(e) only says data must not be kept longer than necessary. The reference point most European teams use is the French regulator's, the CNIL, which recommends a maximum of three years from the last meaningful contact for prospect data, after which the record is deleted or anonymised unless a new interaction restarts it. Other supervisory authorities have not harmonised on that figure, so treat it as a defensible default you write down, not as a legal ceiling.

One right deserves separate emphasis because it has no balancing test. Under Article 21(2), objection to processing for direct marketing is absolute. The person says stop, and you stop, immediately and permanently, regardless of how strong your legitimate interest assessment is. In an ABM programme that means the suppression list has to reach every channel, not just the email tool, and our guide to data subject rights in practice covers the operational side.

Account Based Marketing and GDPR: The Five Failures That Get Caught

Enforcement rarely arrives as a philosophical dispute about legitimate interest. It arrives as one of five operational failures, and all five are cheap to prevent before launch.

  • The file with no origin story. A list arrived from an agency, a departing employee, a trade show, or a vendor nobody can name any more. There is no basis to assess because nobody can describe the collection. This is the failure that cannot be repaired retroactively, which is why building the list through steps you performed is a compliance decision and not just an operational one.
  • The notice nobody sent. Article 14 is the most systematically ignored obligation in B2B prospecting. The fix costs one paragraph in the first outbound message and a reachable privacy page.
  • The suppression that only reached one tool. Someone objects by email, the sales platform records it, and the ad platform keeps serving them ads because the audience was uploaded three weeks earlier and never refreshed.
  • The consent banner that does not match the tags. A tag inventory drifts, a new pixel ships, and the banner still describes last quarter's stack. Since this sits under ePrivacy, no GDPR basis rescues it.
  • The database with no clock. Contacts from 2019 sitting in an active sequence. Nobody decided to keep them. Nobody decided anything, which is precisely the problem, because accountability under Article 5(2) means being able to demonstrate a decision.

None of this makes account based marketing harder than broad outbound. It makes it more defensible, provided the paperwork is produced at the same time as the campaign rather than after a letter arrives. A programme that starts account-level, adds people deliberately, documents where each row came from, keeps the ePrivacy layer separate from the GDPR layer, and honours objection everywhere at once is a programme that survives scrutiny. Start with our complete legal guide to GDPR and B2B data enrichment for the layer underneath all of it.

Any questions?

Start enriching your sheet in 30 seconds

Free for 100 credits/month. No credit card.

Is account based marketing compliant with GDPR?

+
Yes, when it is built correctly. ABM restricts processing to a named list of companies you have a documented commercial reason to approach, which strengthens the necessity limb of a legitimate interest assessment under Article 6(1)(f). Compliance depends on the artefacts you can produce, not on the strategy itself.

Which legal basis should you use for ABM in Europe?

+
Legitimate interest, Article 6(1)(f), is the workable basis for B2B prospecting data. Consent is impractical because you have no relationship with the contact before the first approach. Legitimate interest requires a documented three-part test covering purpose, necessity and balancing.

Is firmographic account data covered by GDPR?

+
Usually not. Revenue, headcount, industry code, registration number and headquarters address describe a legal entity, and GDPR protects natural persons only. Two limits matter. The regime applies the moment a row identifies a human being, such as a named contact, a work email, a direct dial or a profile URL. And for a sole trader or a single-person company those attributes identify a natural person anyway, since the trading name is their name and the registered address is often their home, so the full regime applies to the account layer itself.

Do advertising pixels and matched audiences fall under GDPR?

+
Partly, and that is the common trap. Storing or reading anything on a user's device is governed by the ePrivacy Directive, which requires prior consent and does not accept legitimate interest as an alternative. Uploading a contact list to an ad platform is a separate disclosure of personal data that needs its own basis under GDPR.

Can you buy third-party intent data for an ABM programme?

+
You can, but it carries the highest exposure of any ABM input. The vendor's legal basis covers the vendor's processing, not yours, so you need your own. Article 14 also applies because the data did not come from the individual, meaning you owe them information about your processing, generally within a month or at first contact.

How long can you keep B2B prospect data in an ABM programme?

+
GDPR fixes no number: Article 5(1)(e) only requires that data not be kept longer than necessary. The usual reference point is the French regulator, the CNIL, which recommends a maximum of three years from the last meaningful contact for prospect data. Other supervisory authorities have not harmonised on that figure, so treat three years as a defensible default you write into your Article 30 record, not as a legal ceiling.

What happens when a contact objects to an ABM campaign?

+
You stop, immediately and permanently. Under Article 21(2), objection to processing for direct marketing is absolute and has no balancing test against your interest. The practical requirement is that the suppression reaches every channel at once, including uploaded ad audiences, not only the email tool.