Back to insights
Checking Compliance Practices

Can I share someone's email address with GDPR?

Yes — sharing an email address counts as processing under GDPR and needs a documented lawful basis. One wrong handoff drew a €900,000 CNIL fine in 2025....

Can I share someone's email address with GDPR?

Can I share someone's email address with GDPR?

Key Facts

A colleague asks for a contact's email. A partner wants the attendee list from your last event. A vendor needs "just a few addresses" to send a proposal. These feel like small courtesies — but under GDPR, each one is a legal decision with real consequences.

The reason is simple: sharing an email address counts as processing personal data. GDPR treats an email address as personal data because it can identify a person — and that holds true even for business addresses, depending on context. The moment you pass that address to anyone else, the law applies.

Article 6 of the GDPR allows processing only when at least one of six lawful bases applies:

  • Consent — the person has clearly agreed
  • Contract — sharing is necessary to fulfill an agreement
  • Legal obligation — the law requires it
  • Vital interests — protecting someone's life
  • Public task — an official or public function
  • Legitimate interests — the most flexible basis, but never automatic

The UK's Information Commissioner's Office is blunt about timing. Its Data Sharing Code of Practice states: "You must identify at least one lawful basis for sharing data before you start." Not after. Not retroactively. Before. And you must document it — the ICO's lawful basis guidance requires you to determine and record your basis before processing begins.

Regulators have collected €7.1 billion in GDPR fines since May 2018, with €1.2 billion issued in 2025 alone. This is not a dormant rule — enforcement is accelerating.

Consider SOLOCAL Marketing Services. France's CNIL fined the company €900,000 in 2025 for prospecting without consent and — critically for this topic — transferring data to partners without a legal basis. That is precisely the "harmless" act of sharing email addresses with a third party, punished at scale.

Smaller cases draw fines too. An Austrian marketing firm paid €15,000 for emailing addresses scraped from online directories, and Spain's AEPD penalized a company for failing to disclose how it obtained contact details, according to documented enforcement examples.

Before you forward, export, or hand over anyone's email address, ask: which of the six bases covers this, and can I prove it in writing? If you rely on legitimate interests — the usual route for B2B sharing — the ICO requires a documented three-part test covering purpose, necessity, and balancing against the individual's interests.

This is why compliance-conscious partners matter. At Worqd, every outreach program runs on personalized, permission-aware contact practices with documented lawful bases — because a shared email address without one isn't a courtesy. It's a liability waiting for a complaint.

The Six Lawful Bases — and Which Ones Actually Work for Email

Sharing an email address without a lawful basis isn't a gray area — it's a breach of GDPR's very first principle. The ICO's Data Sharing Code of Practice puts it plainly: you must identify at least one lawful basis before you start, and any sharing without one is unlawful.

GDPR Article 6 offers six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. For email addresses in a business or marketing context, only two realistically apply — consent and legitimate interests. Contract, legal obligation, vital interests, and public task almost never fit the reality of sharing a contact's email for outreach or lead generation.

Whichever basis you pick, the bar is high. The ICO's lawful basis guidance requires processing to be "necessary" — more than just useful, more than standard practice. If you can achieve your purpose by less intrusive means, the basis fails.

Legitimate interests is what most B2B operations rely on, and the ICO calls it the most flexible lawful basis — but flexibility comes with conditions. There are no purposes that automatically qualify; you must complete a three-part Legitimate Interest Assessment before processing begins:

  • Purpose — what specific, legitimate interest are you pursuing?
  • Necessity — is sharing this email genuinely necessary for that purpose?
  • Balancing — does your interest outweigh the individual's rights, expectations, and privacy?

That written assessment matters. When CNIL fined SOLOCAL €900,000 in 2025 for prospecting without consent and transferring data to partners without a legal basis, the absence of documentation was central. That's why Worqd documents the basis for every outreach program before any list is used — the assessment is your evidence if a regulator comes knocking.

Email marketing adds another layer. Under the ePrivacy Directive, email marketing is only allowed with the consent of the parties concerned, though countries interpret this differently — Germany and Austria require prior consent even for B2B, while the UK, Ireland, and the Nordics accept B2B soft opt-in.

Two final rules close the loop. Individuals hold an absolute right to object to direct marketing, regardless of your lawful basis — an objection can never be outweighed by your legitimate interest, and processing must stop. And you cannot swap lawful bases after the fact; as the ICO warns, it is inherently unfair to lead people to believe they had a choice if they did not. If consent is withdrawn, sharing stops.

The single most important question in cold email compliance isn't what you say — it's who you're emailing. The line between B2B and B2C outreach determines whether your campaign is a lawful growth tactic or a regulatory liability.

On the B2B side, cold email can be legal without prior consent. According to guidance on GDPR-compliant B2B outreach, legitimate interest under Article 6(1)(f) and Recital 47 provides the lawful basis — but only with a documented three-part Legitimate Interest Assessment covering purpose, necessity, and balancing. The ICO is explicit that no purpose automatically qualifies as a legitimate interest; you must run the test every time and keep the paperwork.

A lawful B2B cold email generally needs to meet all of these conditions:

  • The message is relevant to the recipient's professional role
  • It's sent to a corporate address, not a personal one
  • A documented LIA supports the legitimate interest claim
  • A clear, working opt-out is included in every message

On the B2C side, the picture is stark. Legal analysis of outbound marketing under GDPR confirms that cold emailing consumers without prior consent is illegal — as one industry assessment puts it, legitimate interest is nearly impossible to argue when you're emailing someone's personal Gmail about a consumer product. B2C cold email without consent is effectively dead under GDPR.

Even the B2B safe harbor has borders. The ePrivacy Directive adds a consent layer on top of GDPR, meaning email marketing is formally only allowed with the consent of the parties concerned — and each country implements this differently. Germany and Austria are the strictest markets, typically requiring prior consent even for B2B outreach, while the UK, Ireland, and the Nordics generally accept a B2B "soft opt-in." France, Spain, Italy, and the Netherlands sit in between, accepting legitimate interest with strict documentation.

One more trap: a business email address can still be personal data. Any address that identifies an individual — like [email protected] — falls under GDPR depending on context, so "it's a work email" is not a compliance strategy.

The stakes for getting this wrong are concrete. France's CNIL fined SOLOCAL €900,000 in 2025 for prospecting without consent and transferring data to partners without a legal basis — one of ten commercial prospecting sanctions the CNIL issued that year.

This is why Worqd builds outreach as personalized, permission-aware communication to relevant accounts — segmented by audience type and jurisdiction, with documented lawful bases behind every list. A documented LIA is what separates a normal workday from a six-figure fine. If you're unsure whether your current outreach would survive that scrutiny, a free growth call is a good place to find out where your lead handling stands.

How to Share Email Addresses Safely: A Practical Checklist

Knowing the rules is one thing — putting them into a repeatable process is what actually keeps you safe. Here is a five-step checklist you can run before any email address leaves your hands.

1. Identify and document a lawful basis before you share. The ICO's Data Sharing Code of Practice is blunt: "You must identify at least one lawful basis for sharing data before you start" — and you must be able to show you considered it, not just claim you did. That means picking one of the six bases in Article 6 and writing down why it applies.

2. Complete a written Legitimate Interest Assessment for B2B outreach. Legitimate interests is flexible, but the ICO stresses there are no purposes that automatically qualify — you must pass the three-part test of purpose, necessity, and balancing. This document matters: SOLOCAL Marketing Services was fined €900,000 by the CNIL in 2025 for prospecting without consent and transferring data to partners without a legal basis, according to enforcement tracking.

3. Segment your lists by B2B/B2C and by country. The rules change dramatically depending on who you're emailing and where they live:

  • B2C cold email without prior consent is effectively illegal — treat consumer addresses as consent-only.
  • Germany and Austria are the strictest markets, typically requiring prior consent even for B2B outreach (scrap.io's country breakdown).
  • The UK, Ireland, and the Nordics generally accept a B2B "soft opt-in" under legitimate interest.
  • France, Spain, Italy, and the Netherlands sit in the middle — legitimate interest works, but only with strict documentation.

The cost of getting this wrong is concrete: an Austrian marketing firm paid a €15,000 fine in 2020 for sending unsolicited promotional emails to personal addresses scraped from online directories, per this legal explainer.

4. Always include a clear opt-out — and honor it immediately. People have an absolute right to object to direct marketing whatever lawful basis applies, and that objection always wins. Carrefour Spain learned this the hard way with a €3,050,000 AEPD fine for failing to process unsubscribe requests, one of the cases tracked by industry compliance research. A broken unsubscribe link is not a minor bug — it's a seven-figure liability.

5. Be transparent about data sources. The ICO requires you to clearly explain your legitimate interests in your privacy policy, and a 2022 Spanish AEPD penalty targeted a company that failed to disclose how it obtained contact details at all. If you can't say where an address came from, don't use it.

This is exactly how Worqd runs its B2B outreach — personalized, permission-aware campaigns to relevant accounts, with consent captured explicitly at every intake point. It's the opposite of a template blast, and it's the approach this checklist is designed to protect.

What This Means for Your Lead Generation

Compliance is not the brake on your pipeline — done right, it is the engine. The teams that get fined are not the ones moving fast; they are the ones moving without documentation.

Consider what the rules actually reward. A documented legitimate interest assessment, a clear opt-out in every message, and instant suppression of objections are not bureaucratic overhead. They are the exact mechanics of outreach that converts: relevant, respectful, and fast to back off when someone says no.

The cost of skipping this is concrete. Enforcement data compiled from DPA trackers shows over €7.1 billion in GDPR fines since May 2018, with €1.2 billion issued in 2025 alone. SOLOCAL was fined €900,000 for prospecting without consent and transferring data to partners without a legal basis — a lead-sharing failure, not a sophisticated hack.

Meanwhile, the same research suggests only 24% of email marketers operate in full compliance. That gap is an opportunity: compliant outreach stands out precisely because so little outreach is.

Compliant outreach is not slower outreach. A practical lead-handling path looks like this:

Notice what this list excludes: nothing about speed. You can still respond to every inquiry in under a minute, still follow up around the clock, still book calls while competitors sleep. The documentation happens once; the pipeline runs continuously.

This is the philosophy behind how Worqd approaches lead conversion. Our AI SDR follow-up is built on personalized, permission-aware outreach — the opposite of a template blast. Every inquiry gets qualified and answered fast, every opt-out gets honored instantly, and every contact in your funnel carries the consent context it arrived with. When someone raises a hand, the response is immediate; when someone opts out, the conversation stops. Both happen automatically.

The result is a pipeline that regulators can inspect and buyers actually welcome. Fast follow-up and lawful follow-up are the same workflow, not competing priorities.

If you are not sure whether your current lead-handling path would survive a documentation request — or whether your follow-up is fast enough to convert the leads you already have — that is exactly what a growth call is for. We will review how leads enter your funnel, how consent is captured, and where response time is costing you booked calls. Book a Growth Call and bring your current process; we will find the bottleneck before touching anything else.

Frequently Asked Questions

Is it legal to share someone's email address with a colleague or partner under GDPR?
Yes, but only if you have a lawful basis first. Sharing an email address counts as processing personal data, and the ICO's Data Sharing Code of Practice requires you to identify at least one lawful basis — like consent or legitimate interests — before you share, not after.
Is a business email address still personal data under GDPR?
Yes. Any address that identifies an individual — like [email protected] — can fall under GDPR depending on context. "It's a work email" is not a compliance strategy, so the same lawful-basis rules apply to B2B contacts.
Can I rely on legitimate interests to share email addresses for B2B outreach?
Legitimate interests is the most flexible basis, but the ICO stresses no purpose automatically qualifies — you must complete a written three-part assessment covering purpose, necessity, and balancing before processing begins. That documentation is your evidence if a regulator asks.
What happens if I share email addresses without a lawful basis?
It's a GDPR breach, and enforcement is real: over €7.1 billion in GDPR fines have been collected since May 2018. In 2025, France's CNIL fined SOLOCAL €900,000 for prospecting without consent and transferring data to partners without a legal basis — exactly the "harmless" act of sharing addresses.
Is cold emailing a consumer (B2C) without consent legal?
No — B2C cold email without prior consent is effectively illegal under GDPR. Legitimate interest is nearly impossible to argue when emailing someone's personal Gmail about a consumer product, so treat consumer addresses as consent-only.
Do the rules for B2B cold email change by country?
Yes. Germany and Austria typically require prior consent even for B2B outreach, while the UK, Ireland, and Nordics generally accept a B2B soft opt-in, with France, Spain, Italy, and the Netherlands in between. Segment your lists by country and by B2B vs B2C before any sharing or outreach.
What if someone objects to marketing or unsubscribes — can I still use their email?
No. Individuals have an absolute right to object to direct marketing, whatever lawful basis you rely on, and processing must stop immediately. Carrefour Spain was fined €3,050,000 for failing to process unsubscribe requests.

Share Smart: The Checklist That Keeps Your Outreach (and Your Budget) Safe

So, can you share someone's email address under GDPR? Yes — but only with a documented lawful basis identified before you hit forward. That means a written legitimate interest assessment for B2B outreach, strict consent rules for consumer addresses and strict markets like Germany, a working opt-out honored immediately, and transparency about where every contact came from. The stakes are real: regulators have issued €1.2 billion in GDPR fines in 2025 alone, and SOLOCAL's €900,000 penalty came from exactly the kind of casual data-sharing that feels harmless in the moment. The good news? Compliance and conversion are the same workflow — relevant, documented, respectful outreach is what buyers respond to anyway. Your next step: pick one list you're using right now and ask which lawful basis covers it. If you can't answer in writing, that's your bottleneck. Worqd builds outreach this way from day one — if you want a second pair of eyes on your lead handling, book a free growth call and we'll find the gaps before they find you.

Want help putting this into action?

Book a Growth Call

Stay in the Loop