GDPR Article 6, § 25 TDDDG, the AI Act's Article 50 disclosure and the UWG rules on cold contact are not obstacles to outbound. Treated as design constraints, they make it defensible.
Compliance is a design input, not a disclaimer
Teams that treat EU rules as a legal afterthought build workflows they later have to dismantle. Teams that treat them as design inputs build outbound that survives a data protection enquiry and a competitor complaint alike. This is a practitioner's map, not legal advice, and the specifics of your programme deserve counsel. The structure below is how we think about it.
GDPR Article 6: name your legal basis first
Every processing activity in a B2B intelligence workflow needs a lawful basis before it starts, not after. For most company research the workable basis is legitimate interest under Article 6(1)(f), which obliges you to run and document a balancing test weighing your interest against the individual's rights.
Two disciplines make that basis hold. Process business-context data about companies and professional roles rather than profiles of private life, and keep your transparency posture ready so a contacted person can understand and object with one reply. Caicle limits person research to professional roles by system rule, and generates a GDPR Article 14 notice on every dossier, precisely so this basis stays defensible.
§ 25 TDDDG (formerly TTDSG): keep research off the endpoint
Germany's TDDDG, formerly the TTDSG, implements the ePrivacy rules and governs storing or reading information on a user's device. Section 25 requires consent for that access outside narrow exceptions. The clean way to stay on the right side of it is to never touch the prospect's device in the first place.
Research from public records does exactly that. Reading a commercial register, a legal notice, a public job board or the global legal-entity register means querying published records about a company, not planting or reading anything in a person's browser. The endpoint is never in scope. On our own website, the same section is why only necessary cookies are set until you say otherwise.
The safest device to read from is the one you never touch. Register-based research sidesteps an entire category of ePrivacy risk by design.
EU AI Act Article 50: disclose the machine
The AI Act's Article 50 sets transparency obligations for certain AI interactions and AI-generated content. For an outbound programme that means being honest that AI assisted the work where a reasonable person would expect to know, and never disguising an automated system as a human in a way that misleads.
In practice this is a light lift and a trust win. Strategy Room output is marked AI-generated until a person approves it, the approval is logged, and reports carry a disclosure. The agency can meet the obligation and use it as a credibility signal rather than a confession.
UWG: cold contact done lawfully
Germany's UWG treats unsolicited advertising strictly. Cold B2B email generally requires the recipient's prior express consent, with only a narrow existing-customer exception, and unlawful contact is an unfair commercial practice competitors can act on. Relevance does not create a legal basis by itself.
The compliant path is deliberate: a genuine business justification for contact, clear sender identification, a working and honoured opt-out, and jurisdiction-aware sending rather than a single global template. The Strategy Room's compliance review per jurisdiction is a starting point. The agency still owns the decision to contact, and that decision has to satisfy the UWG on its own terms.
The defensible posture
Put together, an EU-first programme looks like this: public, business-context facts only, no device access, a documented legal basis, honest AI disclosure, a human deciding each send against local rules, and the platform itself hosted in EU data centres with a DPA on every plan. None of it slows a good team down. What it does is make the programme one you can explain, out loud, to a regulator or a client's counsel without flinching.