Marketing

LinkedIn Data Enrichment and GDPR: What You're Actually Allowed to Do

The legal basis for B2B contact enrichment under GDPR, how CAN-SPAM and CASL compare, what LinkedIn's terms cover, and what you're responsible for as the sender.

By Makeinfo Team
#linkedin-enrichment #gdpr #compliance #can-spam #b2b-data #privacy

Disclaimer: This post is for informational purposes and is not legal advice. Consult a qualified attorney for advice specific to your jurisdiction and situation.


Using a LinkedIn enrichment tool to collect contact data and then sending outreach to those contacts involves at least three overlapping sets of rules: GDPR (if you’re contacting Europeans), CAN-SPAM (US), CASL (Canada), and LinkedIn’s own terms of service. Most people know these rules exist. Fewer people know what they actually say.

Here’s an accurate breakdown of what applies, what it requires, and where the real compliance risk sits.


Why This Matters in 2026

B2B contact enrichment is a well-established practice. Providers like Datagma and LeadMagic operate legally in the jurisdictions where they index data. But the legal responsibility doesn’t end with the data provider.

When you take an enriched contact list and send outreach, you become the data controller under GDPR — the entity responsible for how that personal data is used. Whether your use is lawful depends on what you do, not just what the provider did.


GDPR: The Legitimate Interest Basis

GDPR does not prohibit cold email. It requires a lawful basis for processing personal data. For B2B prospecting, the relevant basis is legitimate interest (Article 6(1)(f)).

Legitimate interest allows processing personal data without consent if:

  1. You have a genuine legitimate interest in the processing
  2. The processing is necessary to achieve that interest
  3. The interests of the data subject don’t override yours (the balancing test)

For cold B2B outreach, this typically works as follows:

Part of the testB2B outreach application
Legitimate interestPromoting your products/services to potential business customers
NecessityContacting them via email is a reasonable way to do this
Balancing testImpact on the individual is low (one email, easy to opt out) vs. genuine business relevance

The balancing test is where most edge cases sit. Emailing someone about a product genuinely relevant to their professional role at their work email address has a low impact on their personal privacy. Emailing a consumer at a personal Gmail about a product they didn’t ask about is a harder case to make.

GDPR also requires that you inform recipients of your legitimate interest basis in the email itself or on a linked privacy notice, and that you provide a clear opt-out mechanism.


What “Publicly Available Data” Means for GDPR

A common misconception: “LinkedIn is public, so enrichment data is fine to use for anything.”

GDPR does not grant blanket permission to use publicly available data for all purposes. The relevant concept is contextual integrity — personal data should flow in ways consistent with the context in which it was originally shared.

A professional’s LinkedIn profile is public in the context of professional networking. Using that profile to find their work email and contact them about a relevant B2B product is arguably consistent with that context — especially for enterprise sales.

Using that same data to contact them about something unrelated to their professional role, or at a personal email address, or in a context they would not reasonably expect, moves away from contextual appropriateness.

The enrichment providers are not responsible for this determination. You are.


What LinkedIn’s Terms Actually Say

LinkedIn’s User Agreement (Section 8.2) restricts automated collection of data from the platform. This restriction is on the data providers — not on users who receive enriched data from those providers.

When you use Datagma or LeadMagic, you’re using data from their database — you’re not scraping LinkedIn yourself. Whether the provider’s data collection practices comply with LinkedIn’s terms is a matter for the provider, not the customer.

That said: LinkedIn has taken legal action against unauthorized scrapers in the past (hiQ Labs v. LinkedIn being the most prominent case). The legal landscape around publicly available data continues to evolve. Using reputable, established providers reduces (but does not eliminate) downstream risk.


CAN-SPAM vs. CASL vs. GDPR: What Each Requires

RequirementCAN-SPAM (US)CASL (Canada)GDPR (EU/EEA)
Opt-in required before sendingNoYes (express or implied consent)No (legitimate interest allowed)
Lawful basis requiredNoConsent (with limited implied consent exceptions)Yes
Opt-out mechanism requiredYesYesYes
Physical address in emailYesYesPrivacy policy link acceptable
Identify as commercial messageYesYesNot explicitly required
Inform of legitimate interest basisNoNoYes
Data subject access rightsNoNoYes (right to erasure, access)

The critical difference: CAN-SPAM is opt-out (you can email until someone says stop). CASL is opt-in (you need a basis to email in the first place). GDPR allows cold email to business contacts under legitimate interest, but with more process requirements than CAN-SPAM.

If you’re emailing Canadian businesses, CASL applies — and it’s stricter than GDPR for cold outreach. “Implied consent” under CASL has specific requirements (the recipient’s email is published and you’re contacting them about a role-relevant offer).


What Every Cold Email Must Include (Minimum Requirements)

Regardless of jurisdiction, these elements reduce compliance risk:

✅ Who you are (your name and company)
✅ Why you're contacting them (specific relevance to their role)
✅ Clear opt-out / unsubscribe mechanism (one-click preferred)
✅ Physical or registered business address
✅ No deceptive subject lines
✅ No deceptive header information (From, Reply-To)

For GDPR specifically, also include:

✅ Brief statement of your legitimate interest basis
   (e.g., "I'm reaching out because your role as [title] at [company]
   is directly relevant to [product]. You can opt out below.")
✅ Link to your privacy policy

Risk Factors to Avoid

PracticeRisk levelReason
Emailing personal (Gmail/Yahoo) addresses found via enrichmentHighNot a work email context; GDPR basis is weaker
Sending to CASL-jurisdiction contacts without an implied consent basisHighCASL requires a consent basis
Sending without opt-out mechanismHighViolates CAN-SPAM, CASL, and GDPR
Using enriched data for non-business purposesHighOutside legitimate interest scope
Re-emailing someone who opted outVery highStatutory violations in all three frameworks
Emailing a single, clearly relevant contact in a professional contextLowCore legitimate interest use case
Sending a single, relevant cold email with opt-out to an EU business contactLow–MediumAcceptable under legitimate interest if handled correctly

Who Is Responsible for What

PartyResponsible for
Datagma / LeadMagicLawful data collection, database accuracy, their own data retention policies
You (the add-on user)How you use the enriched data, your outreach compliance, opt-out management
Makeinfo (add-on developer)Does not receive or process contact data; not in the data call path

The enrichment provider is a data processor with its own obligations. You are the data controller for the purposes of your outreach campaign. This distinction matters if a data subject submits a right-to-erasure request — that request comes to you, not the provider.


Practical Compliance Checklist

Before sending to an enriched LinkedIn list:

[ ] Confirm all contacts are reached at work emails (not personal addresses)
[ ] Confirm the outreach is relevant to each contact's professional role
[ ] Include a working one-click unsubscribe in every email
[ ] Include your physical/registered business address
[ ] For EU contacts: add a brief legitimate interest statement
[ ] For Canadian contacts: confirm you have an implied consent basis (published email + role relevance)
[ ] Maintain a suppression list for opt-outs; never re-email suppressions
[ ] Respond to any data access or erasure requests within the regulatory timeframe (30 days for GDPR)

This post describes the general legal landscape as of early 2026. Laws and enforcement priorities change. Always consult a qualified attorney before launching large-scale contact enrichment campaigns, particularly if you’re reaching European or Canadian contacts.


Enrich responsibly, with full visibility into every result. LinkedIn Profile Enricher for Google Sheets →