GDPR for sales teams: What you need to know
A move to campaigns that have ‘data protection by design’
Typically, sales and marketing work together to conceive and execute a marketing strategy, then deal with the holding of data as and when it needs to be managed. In the wake of new policies, teams are urged to approach campaign building from a ‘data protection by design’ perspective. You’ll need to consider how campaign ideas will require the use of client or customer data; if you don’t have the audiences’ explicit consent to contact them on this topic, you won’t be able to run the campaign. Designing for added privacy from the start will allow you to identify any obstacles, in light of the GDPR, and innovate in line with them. If you’re still confused by the definitions of ‘consent’ or what is (and isn’t) permissible under new legislation, then Sage’s guide on the GDPR has further information.Innovations such as beacons and geotagging just got more complicated
The last few years have seen some exciting new sales tools come to the fore; for example, beacon technology and using mobile phone data to send geo-specific sales promotions to customers. Unfortunately, these innovations will be derailed if you’re not able to attain consent from the audience. Indeed, having received consent previously will not be enough. To comply with GDPR rules, you’ll need to reattain freely given consent and be able to demonstrate how you received this, in order to engage with your customers in a way that requires data such as a cell number, email address or location.You’ll need to revisit your email campaign mail list
Even the humble sales email — or initial contact with prospective clients through LinkedIn – must be reviewed. You’ll need to design a means of allowing your subscribers to opt-in for correspondence, without having to actually email them as this would be in breach of the GDPR. LinkedIn is suggesting you act now to expand your direct network on the social site, to minimize the fall out come May. Nevertheless, LinkedIn Premium members will still be able to InMail second and third-degree connections.Cold-calling hasn’t been outlawed just yet
In an unexpected outcome, the method of direct sales calls — or cold-calling — hasn’t been barred by the changes in GDPR. Certainly, processes around this sales method will need to evolve, but the behavior will still be legal.GDPR for Sales teams: start planning now
With such interruption expected within sales and marketing functions, it’s advised that you start planning sooner rather than later for the introduction of GDPR. Failure to do so could lose you custom and profit.Related reading
- Screening Millennial Employees Social Media Accounts
- How to Track Your Advertising Campaign Success Online
- Why Finding The Right Candidate For Sales Is So Challenging
- How to Create a Personal Brand
- more marketing and business articles
The short version: GDPR compliance isn’t optional for sales teams, it affects how you collect leads, store contact data, and communicate with prospects across Europe. Your sales process needs explicit consent, clear privacy notices, and the ability to honor data subject rights or you’ll face serious fines.
What Happens When a Prospect Says “Where Did You Get My Data?” During a Sales Call
This is the scenario nobody writes about in GDPR guides, yet it happens to sales teams every single week. A prospect picks up the phone, listens to your opening line, and then flatly asks: “How did you get my number?” Most sales reps freeze at this point because their training covered objection handling for pricing and competitors, not data provenance. The honest answer is that you need to know, with specificity, before you dial. “We got it from LinkedIn” is not sufficient. You need to know when you collected it, what legitimate interest assessment or consent mechanism covered that collection, and whether the individual was informed at the point of collection that their data might be used for direct marketing.
In practice, this means every lead entering your CRM should carry a source tag that maps directly to a documented lawful basis. When I audited a client’s HubSpot pipeline in 2022, roughly 40% of their existing leads had source fields that said things like “imported” or “conference” with nothing else attached. That is a compliance problem sitting in plain sight. The ICO has made clear that “legitimate interests” as a lawful basis for B2B prospecting does not give you a blank cheque. You must have conducted a legitimate interests assessment, documented it, and the processing must pass a three-part test: purpose, necessity, and a balancing test weighing your interests against the individual’s rights.
Here is a simple internal process that works for sales teams rather than just legal teams:
- Assign one person in sales operations to own a “lead source dictionary” that maps every source to a specific lawful basis document.
- Add a mandatory CRM field called “Lawful Basis Reference” before any lead can be moved to the “contacted” stage.
- Create a one-page script response for reps to use on the spot when asked about data sourcing, written in plain English, not legal language.
- Set a six-month review date on every legitimate interests assessment, because the circumstances that justified it can change.
- Log the date and method of every verbal or written data subject request, even informal ones during calls.
The part that catches sales managers off guard is the Subject Access Request clock. If that prospect on the phone says “I want to know everything you hold on me,” the 30-day response window starts immediately, not from when you get around to forwarding it to whoever handles GDPR in your office. Sales reps need a direct, tested escalation route to whoever fulfils SARs, and that route needs to work on a Friday afternoon just as well as a Tuesday morning.
One more thing worth saying plainly: suppression lists are not just a nice-to-have. If someone has previously objected to your direct marketing and their details are not on a suppression list that is checked before every campaign or call batch, you are not just risking a fine. You are damaging the trust of someone who had already given you a clear signal. The ICO has issued reprimands and fines specifically for this failure, and the affected individuals remember being contacted twice after they said no far longer than you will remember sending the campaign.
Frequently asked questions
Do I need GDPR compliance if my company isn’t based in Europe?
Yes. GDPR applies to any organization processing personal data of EU residents, regardless of where your business is located. If you’re selling to European customers or prospects, you’re subject to the regulation.
What counts as explicit consent under GDPR?
Explicit consent means getting clear, affirmative action from the person, like a checked box or signed agreement, before you collect or use their data. Pre-checked boxes don’t count. You must be transparent about what you’ll do with their information.
Can my sales team still use purchased email lists?
Not without documented consent from those individuals. Buying or using email lists without prior permission from each person violates GDPR. You need to build your prospect list through opt-in methods or confirmed double opt-in processes.
What happens if we don’t comply?
Fines can reach 4 percent of global annual revenue or 20 million euros, whichever is higher. Beyond the financial penalty, non-compliance damages your reputation and can result in legal action from affected individuals.
Related: How to Get a Free Business Telephone Number (That Makes You Look Professional)
Related reading: How to Use LinkedIn to Find Legitimate Transcription Jobs (Without Wasti.
Related reading: What Does a Legal Transcription Job Involve? A Realistic Look Inside the.
Related reading: Which AI Tools Are GDPR Compliant for UK Businesses (And Which Just Say .