Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

Sales Team: What You Need to Know About the GDPR

The European Union will introduce new laws on data protection — GDPR (General Data Protection Regulations) — on 25 May 2018. These new rules will impact every business operating with the EU, or dealing with clients who are EU citizens. In this blog post, here’s what you need to know about GDPR for sales teams. The new regulations are not a step change either. They represent quite radically different ways of working compared to the processes in place since 1995, when the last data protection laws were passed. One function within business that will be highly affected is that of sales and marketing. If you work within this department, here’s what you need to know about the GDPR.

GDPR for sales teams: What you need to know

A move to campaigns that have ‘data protection by design’

Typically, sales and marketing work together to conceive and execute a marketing strategy, then deal with the holding of data as and when it needs to be managed. In the wake of new policies, teams are urged to approach campaign building from a ‘data protection by design’ perspective. You’ll need to consider how campaign ideas will require the use of client or customer data; if you don’t have the audiences’ explicit consent to contact them on this topic, you won’t be able to run the campaign. Designing for added privacy from the start will allow you to identify any obstacles, in light of the GDPR, and innovate in line with them. If you’re still confused by the definitions of ‘consent’ or what is (and isn’t) permissible under new legislation, then Sage’s guide on the GDPR has further information.

Innovations such as beacons and geotagging just got more complicated

The last few years have seen some exciting new sales tools come to the fore; for example, beacon technology and using mobile phone data to send geo-specific sales promotions to customers. Unfortunately, these innovations will be derailed if you’re not able to attain consent from the audience. Indeed, having received consent previously will not be enough. To comply with GDPR rules, you’ll need to reattain freely given consent and be able to demonstrate how you received this, in order to engage with your customers in a way that requires data such as a cell number, email address or location.

You’ll need to revisit your email campaign mail list

Even the humble sales email — or initial contact with prospective clients through LinkedIn – must be reviewed. You’ll need to design a means of allowing your subscribers to opt-in for correspondence, without having to actually email them as this would be in breach of the GDPR. LinkedIn is suggesting you act now to expand your direct network on the social site, to minimize the fall out come May. Nevertheless, LinkedIn Premium members will still be able to InMail second and third-degree connections.

Cold-calling hasn’t been outlawed just yet

In an unexpected outcome, the method of direct sales calls — or cold-calling — hasn’t been barred by the changes in GDPR. Certainly, processes around this sales method will need to evolve, but the behavior will still be legal.

GDPR for Sales teams: start planning now

With such interruption expected within sales and marketing functions, it’s advised that you start planning sooner rather than later for the introduction of GDPR. Failure to do so could lose you custom and profit.

Related reading

The short version: GDPR compliance isn’t optional for sales teams, it affects how you collect leads, store contact data, and communicate with prospects across Europe. Your sales process needs explicit consent, clear privacy notices, and the ability to honor data subject rights or you’ll face serious fines.

What Happens When a Prospect Says “Where Did You Get My Data?” During a Sales Call

This is the scenario nobody writes about in GDPR guides, yet it happens to sales teams every single week. A prospect picks up the phone, listens to your opening line, and then flatly asks: “How did you get my number?” Most sales reps freeze at this point because their training covered objection handling for pricing and competitors, not data provenance. The honest answer is that you need to know, with specificity, before you dial. “We got it from LinkedIn” is not sufficient. You need to know when you collected it, what legitimate interest assessment or consent mechanism covered that collection, and whether the individual was informed at the point of collection that their data might be used for direct marketing.

In practice, this means every lead entering your CRM should carry a source tag that maps directly to a documented lawful basis. When I audited a client’s HubSpot pipeline in 2022, roughly 40% of their existing leads had source fields that said things like “imported” or “conference” with nothing else attached. That is a compliance problem sitting in plain sight. The ICO has made clear that “legitimate interests” as a lawful basis for B2B prospecting does not give you a blank cheque. You must have conducted a legitimate interests assessment, documented it, and the processing must pass a three-part test: purpose, necessity, and a balancing test weighing your interests against the individual’s rights.

Here is a simple internal process that works for sales teams rather than just legal teams:

  • Assign one person in sales operations to own a “lead source dictionary” that maps every source to a specific lawful basis document.
  • Add a mandatory CRM field called “Lawful Basis Reference” before any lead can be moved to the “contacted” stage.
  • Create a one-page script response for reps to use on the spot when asked about data sourcing, written in plain English, not legal language.
  • Set a six-month review date on every legitimate interests assessment, because the circumstances that justified it can change.
  • Log the date and method of every verbal or written data subject request, even informal ones during calls.

The part that catches sales managers off guard is the Subject Access Request clock. If that prospect on the phone says “I want to know everything you hold on me,” the 30-day response window starts immediately, not from when you get around to forwarding it to whoever handles GDPR in your office. Sales reps need a direct, tested escalation route to whoever fulfils SARs, and that route needs to work on a Friday afternoon just as well as a Tuesday morning.

One more thing worth saying plainly: suppression lists are not just a nice-to-have. If someone has previously objected to your direct marketing and their details are not on a suppression list that is checked before every campaign or call batch, you are not just risking a fine. You are damaging the trust of someone who had already given you a clear signal. The ICO has issued reprimands and fines specifically for this failure, and the affected individuals remember being contacted twice after they said no far longer than you will remember sending the campaign.

Frequently asked questions

Do I need GDPR compliance if my company isn’t based in Europe?

Yes. GDPR applies to any organization processing personal data of EU residents, regardless of where your business is located. If you’re selling to European customers or prospects, you’re subject to the regulation.

What counts as explicit consent under GDPR?

Explicit consent means getting clear, affirmative action from the person, like a checked box or signed agreement, before you collect or use their data. Pre-checked boxes don’t count. You must be transparent about what you’ll do with their information.

Can my sales team still use purchased email lists?

Not without documented consent from those individuals. Buying or using email lists without prior permission from each person violates GDPR. You need to build your prospect list through opt-in methods or confirmed double opt-in processes.

What happens if we don’t comply?

Fines can reach 4 percent of global annual revenue or 20 million euros, whichever is higher. Beyond the financial penalty, non-compliance damages your reputation and can result in legal action from affected individuals.

Related: How to Get a Free Business Telephone Number (That Makes You Look Professional)

Related reading: How to Use LinkedIn to Find Legitimate Transcription Jobs (Without Wasti.

Related reading: What Does a Legal Transcription Job Involve? A Realistic Look Inside the.

Related reading: Which AI Tools Are GDPR Compliant for UK Businesses (And Which Just Say .

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.