Skip to content
Leadsfinder
GDPRCold outreachCompliance

Cold B2B outreach and GDPR: how to do it legally in Sweden

By the Leadsfinder team · · 3 min read

The most common question we get from Swedish sales teams is simple: are we really allowed to call and email companies we've never spoken to? The short answer is yes — B2B prospecting is fully permitted in Sweden, but it rests on a legal basis and comes with obligations. This guide walks through what applies in practice.

Quick answer: Yes — you may call and email Swedish companies without prior consent. Cold B2B outreach rests on legitimate interest (GDPR Article 6.1 f), not consent — provided you run a balancing test, respect the marketing opt-out (reklamspärr), and always offer an easy way to decline.

Legal basis: legitimate interest

GDPR requires a legal basis to process personal data — and a contact person at a company (name, work email, direct number) is personal data. For cold B2B outreach the relevant basis is legitimate interest (Article 6.1 f), not consent. So you don't need to ask permission in advance, provided your interest in marketing a relevant product outweighs the recipient's privacy interest.

The balancing test is what matters. Outreach that is relevant to the recipient's role, aimed at the company rather than the individual, and easy to decline usually tips in your favour. Irrelevant mass mailing does not.

The marketing opt-out and suppression registers

Before you call, you must respect opt-outs. Companies and sole traders can register a marketing block (reklamspärr), and you're obliged not to contact anyone who has actively said no. A sound process checks suppression lists before every send or call round — not after the fact.

  • Respect the marketing block and any industry-specific opt-outs before contact.
  • Keep your own do-not-contact list and maintain it per account.
  • Remove a recipient immediately when they ask — across every channel.

Your duties at every contact

Whatever the channel, the recipient should easily understand who you are and be able to say no. In an email that means a clear sender and a working unsubscribe link. On a call it means introducing yourself and your company and respecting a no straight away. You should also be able to say where the data came from if asked.

  • Be transparent about who you are and why you're reaching out.
  • Always offer an easy way to opt out.
  • Be able to disclose the source of the data (e.g. public registers).
  • Only process the data you actually need — no more.

Keeping it manageable

What makes cold outreach legal in practice is not a one-off judgement but a routine: document your legitimate-interest assessment, keep sources traceable, respect opt-outs automatically, and make unsubscribing trivial. A tool built on open registers with suppression handling built in removes much of the manual risk — but responsibility for the balancing test always stays with you.

This text is general information about how Swedish sales teams tend to work, not legal advice. Review your own process with the Swedish Authority for Privacy Protection (IMY) and, where needed, a legal adviser.

Frequently asked questions

Is consent required for cold B2B outreach?

No. The legal basis is legitimate interest (Article 6.1 f), not consent — as long as you run a balancing test and the contact is relevant to the recipient's professional role. Marketing to private individuals, by contrast, normally does require consent.

Do I have to show where the data came from?

Yes. If asked, you must be able to disclose the source. For Leadsfinder that's public registers — Bolagsverket and SCB — complemented with data from the open web.

Sources