Legitimate Interest Assessment for Cold Email, Filled In

Short answer

A completed LIA for one sample B2B campaign, test by test, with the UK email rule that sits next to it and the record to keep before you send.

Artem Smirnov
Artem Smirnov

Last updated · 11 min read

Artem Smirnov in a dark suit against a charcoal studio backdrop, next to the line 'Write down why you emailed them. Before the first send.'

A legitimate interest assessment (LIA) is a short written record showing why you may use someone's personal data without their consent. In B2B cold email, it is how you justify emailing a named person at a company under GDPR's legitimate interests basis.

The UK regulator, the Information Commissioner's Office (ICO), splits it into three tests: purpose (what interest you pursue), necessity (whether you need this data to pursue it) and balancing (whether the person's interests override yours). The same guidance says you should record the LIA and its outcome.

Most pages on this subject describe those three tests and stop there. Below is a complete LIA for one sample campaign, the UK email rule it does not cover, and a list of what to keep on file.

This is not legal advice. Every source below was checked on 28 September 2026.

Why write it before the first send?

Because most of its answers are fixed the moment a list is built. I put the LIA with the foundations: written before the list is loaded and before volume starts, not after somebody asks.

Smirnov Consulting Group is a Prague-based B2B outbound lead generation agency that runs cold email and LinkedIn campaigns for founder-led B2B companies and books qualified sales calls. From that side of the table, the LIA is the working paper you should be able to hand over when a prospect or a regulator asks why you contacted them. It guarantees nothing on its own. What it does is force a written answer to a question every campaign faces anyway: why is it reasonable for this person to hear from you?

What does legitimate interest actually allow?

GDPR lists six lawful bases in Article 6(1). Consent is point (a). Legitimate interests is point (f): the processing has to be necessary for an interest you pursue, and it fails where the person's interests or fundamental rights override yours.

People skip the second half. A business reason alone is not enough: you weigh it against the person's interests, and you need to be able to show why yours still wins.

The ICO notes that UK GDPR names direct marketing as a potential legitimate interest, next to intra-group transfers for admin and network security. "Potential" is the key word. You still run the test.

A work address like jane.smith@company.com belongs to a person. The ICO's email marketing guidance says data protection can apply when you email employees at personal corporate addresses. If your contacts come from a bought list, read what the law says about buying a B2B email list before you run the tests below.

What are the three tests?

TestThe questionWhat the ICO asks you to considerA typical weak answer
PurposeIs there a real, specific interest?Why you want the data, the benefit, who else benefits, the impact if you could not go ahead, the outcome for people, and whether you comply with other laws and industry codesWriting "business growth" instead of naming the offer and the buyer
NecessityDo you need this data, used this way?Whether it actually helps, whether it is proportionate or excessive, whether you could manage with less data, or in a more obvious and less intrusive wayLoading every contact at a company when one role buys
BalancingDo the person's interests override yours?The nature of the data, their reasonable expectations (the ICO calls this an objective test), the likely impact, and safeguards such as an opt-outData from a source that never told people it would be reused

The EU works the same way. The European Data Protection Board (EDPB) adopted its Guidelines 1/2024 on legitimate interest for public consultation at its 9 October 2024 plenary. They describe three cumulative conditions: a legitimate interest, necessity, and a balancing exercise in which the person's rights do not take precedence.

Cumulative means all three. A strong purpose does not rescue a weak balancing test.

What does a completed LIA look like?

The sample below is invented. The sender, the product and every entry are illustrative and belong to no client.

It follows the three ICO tests, answered the way a UK software company might for an ordinary B2B campaign.

The campaign on one page

FieldEntry
ControllerExample Software Ltd, a UK company selling production-planning software (fictional)
ActivityCold email to named Operations Directors at UK manufacturing companies with 50 to 200 employees
Data usedFirst name, last name, job title, work email, company name, company size, industry
Not collectedPersonal email, mobile number, home address, anything from personal social media
SourceCompany websites and one named B2B data provider, recorded per list batch
RecipientsLimited companies and LLPs only; sole traders and ordinary partnerships excluded
RetentionNon-responders deleted after 6 months; opt-outs kept on a suppression list
Owner and dateHead of Sales, 28 September 2026
Next reviewMarch 2027, or earlier if a trigger listed further down applies

Part 1: purpose test

What is the interest? Finding new customers for production-planning software among the people responsible for production scheduling.

Who benefits? We do, through new revenue from a defined market. The recipient gets information about a tool aimed at a problem their role owns: late orders and planning done in spreadsheets.

What happens if we do not do it? We rely on referrals and inbound inquiries, which reach only the companies already looking.

What outcome do we expect for the person? One short email and a brief follow-up sequence, stopped at the first reply or opt-out.

Do we comply with other laws? For the channel, yes: UK email marketing rules allow email to corporate bodies without prior consent, with conditions covered in the next section.

Any ethical issues? None identified. No sensitive topics, and no conclusions drawn about individuals beyond their job role.

Result: pass. The interest is specific and lawful.

Part 2: necessity test

Does emailing this person help the purpose? Yes. At companies of this size, the Operations Director usually owns the scheduling problem the product solves.

Is it proportionate? One role per company. A second contact only if the first role is empty or clearly wrong.

Could we do it with less data? Name, title and company are needed to address and target the email. Size and industry are needed to select the list. Nothing else is stored.

Is there a more obvious or less intrusive route? We use events and content too. Neither reaches named decision-makers at companies that have not started looking. A short email to a work address, about their role, is the least intrusive direct route we found.

Result: pass, on the condition that the list stays at one role per company and the field list stays as written.

Part 3: balancing test

Nature of the data. Professional details only, about people in their work capacity. No special category data, no data about criminal convictions, nothing people would usually treat as private, no children.

Reasonable expectations. There is no existing relationship. The data comes from company websites and a B2B provider. We asked the provider what it tells people about reuse by third parties and saved the answer. Senior operations people get vendor emails at work about their role, so a reasonable person in that job would not be surprised by one. Lists are refreshed every quarter.

Impact. Checked against each harm the ICO lists: no barrier to exercising rights, no barrier to services or opportunities, no physical harm, no financial loss or fraud, no discrimination or reputational damage. Loss of control over further use of the data is the one real risk. The safeguards below answer it.

Safeguards. The real sender name and company in every email. An opt-out line in every email, processed within 2 working days. The suppression list screened before every new send. A privacy notice link in the first email naming the data source and the right to object. Deletion after 6 months. No sharing with third parties.

Points against. No prior relationship. Part of the data comes from a third party. Nobody on the list asked to hear from us. They are recorded on purpose.

Conclusion. Legitimate interests applies to this activity. Our interest is not overridden, given professional-only data, a message about the person's own role, a clear opt-out and short retention. Signed off by the Head of Sales on 28 September 2026.

Which UK email rule sits next to the LIA?

The LIA answers whether you may use the person's data. It does not answer whether you may send marketing email to that address. In the UK, the second question is answered by the Privacy and Electronic Communications Regulations, known as PECR.

QuestionRuleAnswer for the sample
May we use this person's data?UK GDPR lawful basis, here legitimate interestsYes, per the assessment above
May we email this address without consent?PECRYes for companies and LLPs; for sole traders and some partnerships, only with consent or after a similar earlier purchase they did not opt out of
What must every email carry?PECRThe sender's real identity and a valid address to opt out

The ICO's email marketing guidance lets you send marketing email to corporate bodies, which it defines as companies, Scottish partnerships, limited liability partnerships and government bodies. Sole traders and some partnerships get the same treatment as private individuals. For them you need specific consent, or an earlier purchase of a similar product with an opt-out they chose not to use.

That guidance calls a "do not email" list of businesses that object good practice. It also flags that the guidance is under review, since the Data (Use and Access) Act changed the rules. Check it again before you rely on it.

Here is how the two connect. The purpose test asks whether you comply with other relevant laws. PECR is that law for the channel. The PECR answer goes into Part 1, and a failed PECR check stops the campaign no matter how clean the balancing test looks.

Outside the UK the channel rules change by country, which is why selling into several European markets needs a separate check for each one.

What does the necessity test rule out?

The EDPB's announcement of its legitimate interest guidelines puts it plainly: "if there are reasonable, just as effective, but less intrusive alternatives for achieving the interests pursued, the processing may not be considered to be necessary."

In cold email, that sentence lands on the list far more than on the copy.

Common practiceWhy it struggles on necessityA version that can pass
Buying a broad list of "decision-makers" in an industryMost contacts do not own the problem, so you hold data you cannot useA list built for one role at companies that fit your ICP
Emailing several people at one company about the same offerMore people than the purpose needsOne primary contact, a second only when the first is wrong
Collecting mobile numbers and personal emails "for later"Data with no use in this campaignOnly the fields the email needs
Keeping non-responders with no end dateRetention without a purposeA deletion date written into the LIA
Enriching records from personal social mediaMore intrusive than the purpose needs, and less expectedCompany and role data only

Almost all of this gets decided before a single email is written, which is why the list deserves more of your attention than the copy.

What must the first email say?

The LIA's safeguards only count if they reach the person. GDPR puts two of them into the first email.

Article 21 lets the person refuse direct marketing whenever they choose, and after that refusal you must stop processing their data for it. The same article requires you to point this right out no later than your first message, "clearly and separately from any other information."

Article 14 applies when the data came from somewhere other than the person, which describes every cold email list. Among other things, they must be told the legitimate interest you pursue, their right to object and where their details came from. When the purpose is contacting them, that information is owed by the first email at the latest.

In the sample, that means one plain line at the bottom of the first email, separate from the pitch: "Not relevant? Reply 'no' and I will not email you again." Next to it, a link to a privacy notice that names the data provider and the interest.

What should you keep on file, and when do you redo it?

The ICO expects a written record showing what you decided and why legitimate interests fit your outreach. It also wants the LIA looked at again from time to time, and updated whenever something big shifts, like why you email, who you email or how.

Here is what I would keep for a cold email program:

  1. The LIA itself, dated, with the owner's name
  2. The source of every list batch, plus what the provider told people about reuse, which varies a lot between the big data providers
  3. The fields you collect, and the ones you decided not to collect
  4. The first email and its opt-out line, as sent
  5. The suppression list, with the date each objection arrived and was handled
  6. The retention rule, and proof that deletions actually ran
  7. The next review date

Only put numbers in your LIA whose source you can open.

The ICO wording on reviews is general, so here are the triggers I would treat as a significant change: a new data source, a new country, a new buyer role or offer, adding LinkedIn or another channel, and a complaint or a run of opt-outs from one segment.

For a per-contact version of this record, my breakdown of real marketing email fines has a table that ties each field to a fine where it went wrong.

Quick answers on legitimate interest and cold email

Does legitimate interest mean I can skip the opt-out?

No. GDPR Article 21 lets a person refuse direct marketing whenever they want, and you have to stop. The right must be pointed out clearly and separately in the first email at the latest. In the UK, PECR also requires a valid address for opting out.

Do I need a new LIA for every campaign?

Not for every send. Write one per activity, meaning one kind of campaign to one kind of buyer. The ICO says to review it regularly and refresh it when the purpose, nature or context changes significantly. A new country, data source or buyer role is that kind of change.

I use a data provider, not a bought list. Does that change anything?

It changes what you need to ask. One of the ICO's reasonable-expectations questions is what the original source told people about reuse by third parties. Ask the provider, save the answer, and name the source in your privacy notice, as GDPR Article 14 requires.

Want to get more B2B clients for your business?

I help B2B companies book 10 to 100+ qualified sales calls per month with outbound. Let's see if it fits yours.

Artem Smirnov
Artem Smirnov

I help B2B companies book qualified sales calls with cold email and LinkedIn outbound.