Skip to content

Is Business Contact Data Personal Data? An EU Field Test

Is business contact data personal data? Classify named work details, generic inboxes and business forms, then separate GDPR duties from marketing rules.

An isometric sorting station separates a company building token from contact cards linked to individual people.
By AI Priority Map Editorial

Is business contact data personal data? A spreadsheet labelled “B2B” cannot answer that question. One row may mix a company's registration number, a named buyer's direct email and a general switchboard number. Each field can fall on a different side of the GDPR line, and none of those classifications alone permits a marketing message.

Quick Answer: Business contact data is personal data when a field or its context identifies a natural person, including someone acting at work. A legal entity's own details are outside GDPR as such. Classify each field first, then assess GDPR use controls and the target market's electronic-marketing rules separately.

Last updated: 26 August 2026

A B2B label does not classify the row

The GDPR protects natural persons, not commercial and non-commercial data as two separate categories. Article 4(1) defines personal data by whether information relates to an identified or identifiable natural person 1. A person's working role, employer or professional email domain does not remove that person from the definition.

Recital 14 draws the other boundary. The GDPR does not cover legal persons as such, including a legal person's name, legal form and contact details 1. A company's registered name and central telephone number may therefore sit outside the GDPR, while the named purchasing manager in the next columns remains an identifiable natural person.

That mixed row is normal. A list audit should not ask only whether the customer is a business. It should ask what each field identifies, what contextual data is available to the holder, and what the business plans to do with the result. Those are different questions and they need separate answers.

The popular shortcut, “B2B data is exempt from GDPR”, collapses those questions. There is no business-context exclusion for information about an identified person. What people often half-remember is a narrower electronic-marketing rule in a particular jurisdiction. That rule concerns a use and a channel; it does not rewrite the GDPR definition.

Start with the subject, then inspect the field

Classification begins with the subject of the information. Ask whether the field describes a legal entity as such or whether, alone or with reasonably available context, it identifies a natural person. The European Commission's examples put a named company email on the personal-data side and a generic company inbox on the non-personal side 2.

Contact fieldInitial classificationContext checkNext step
Registered company name and numberUsually legal-entity dataDoes another field connect it to a person?Keep separate from named-contact fields
[email protected]Personal dataConfirm which person the address identifiesApply the GDPR use analysis
Employee's direct work numberPersonal dataCheck whether it is assigned to one personApply the GDPR use analysis
[email protected]Usually not personal on its faceDoes the database or routing identify one recipient?Reclassify if context identifies a person
Main company switchboardUsually legal-entity dataIs the number actually assigned to one individual?Record the contextual result
Name of a natural person trading in businessPersonal data when the record identifies that personDo not treat a business role as a shieldApply the GDPR use analysis

“Usually” in the table is a prompt to inspect context, not a licence to leave the result unresolved. The same string can be generic in one organisation and identifying in another. A shared inbox handled by a rotating team is different from an inbox whose signature, customer relationship record and routing rule all point to one employee.

Classification should also follow the data as it changes. A generic lead can become personal data after enrichment adds a contact name. A direct address can become stale when the employee leaves. The audit record needs a review trigger because classification, accuracy and intended use can change at different times.

Named work details usually identify a person

A named work email is personal data when it identifies its user. The company domain does not turn a natural person into a legal entity, and a work purpose does not make identification disappear. The Commission uses a [email protected]-style address as an example of personal data 2.

Direct telephone numbers, named messaging handles and contact-card records follow the same functional test. If the number or handle singles out an employee, buyer, director or other natural person, the record is about an identifiable individual. Job title, department and employer may also relate to that person when stored with the identifier.

The result is not that every fact visible on a company website may be copied and used freely. Public availability does not answer purpose, lawful basis or transparency. Nor does a sales database become non-personal merely because a supplier calls it “corporate”. The receiving business must make its own evidenced decision about the data it actually holds and the purposes it chooses.

There is an important practical consequence for list purchases. A vendor's assurance that a list is “GDPR compliant” cannot replace field inspection. The buyer determines its own processing purposes and must know what it received, where the data came from, whether it is accurate enough for that purpose and what information the identified people must receive.

Generic inboxes depend on the surrounding record

A generic address such as [email protected] usually identifies a function or organisation rather than a person. On that limited view, it is not personal data. The same is commonly true of a main switchboard or an unassigned role mailbox.

Context can reverse the answer. Suppose a customer relationship system links the inbox to “Marta, owner”, every reply carries Marta's signature and the small company has only one recipient. The holder can identify a natural person through the combined information, so treating the address string in isolation would miss the actual record.

The reverse can also happen over time. A formerly direct mailbox might be converted to a team queue after its user leaves. That does not excuse retention of an inaccurate name or old notes. It does mean that the current classification should be based on current facts, with old personal fields corrected or removed under the list's retention and accuracy controls.

Business forms require a national-law check

Labels such as partnership do not produce one EU-wide answer. National law determines whether a particular business form is a legal person and how that form relates to the people behind it. The CJEU case record in Case C-631/21 illustrates why legal personality and form cannot be flattened into a portable partnership category 4.

Use a two-stage decision, and record both stages:

Decision pointIf yesIf no or unclear
Is the exact business form a legal person under the applicable national law?Its own name, form and contact details are outside GDPR as suchIdentify how national law treats the form before relying on an entity-only classification
Does the field identify a natural person behind or within the business?The field can be personal data even if the entity itself is a legal personKeep the field-level result separate from the entity result
Is the trader in the record a natural person acting commercially?Information identifying that person can be personal dataDo not infer the answer from a translated business-form label
Does available context turn a generic field into an individual identifier?Classify the combined record as personal dataDocument why the field remains organisational

A natural person remains a natural person while trading. A commercial address, invoice contact or order history can therefore be personal data if it identifies that person. By contrast, a limited-liability company that national law treats as a legal person is not itself a data subject merely because its details are useful to a sales team.

The safe EU-level rule is the test, not an example borrowed from one Member State. A list covering several markets may contain similarly translated labels with different legal effects. Where the legal form is unclear, the list should be held from the affected use until the market-specific status is verified.

Personal-data status does not grant permission to use it

Classification answers whether the GDPR applies to a field. It does not answer whether the business may collect, combine, score, retain or contact the person for a particular purpose. Those operations require their own controls.

For personal-data fields, define the purpose before choosing and documenting a lawful basis. Give the required transparency information, especially when contact details came from a third party rather than from the person. Keep only fields necessary for the defined purpose, maintain reasonable accuracy, set a retention trigger and make it possible to honour applicable rights. These duties flow from the GDPR even when the contact is acting entirely in a professional capacity 1.

Legitimate interests may be considered for some business processing, but it is not a synonym for “B2B”. The business must identify the interest, show that the processing is necessary and weigh the effect on the person. Consent is a different basis with different conditions. The suitable basis depends on the purpose and facts; a list category cannot choose it automatically.

If a field is genuinely legal-entity data and does not identify a person, that field is outside the GDPR definition. The conclusion is narrow. It does not validate adjacent personal fields, establish that a marketing channel is permitted, or remove other legal and contractual limits. Record “not personal on current facts”, not “free to use”.

Direct electronic marketing requires a second check after classification. The ePrivacy Directive governs unsolicited communications, including email and certain automated communications, while the GDPR governs processing of personal data. A campaign can therefore engage both regimes, one of them, or neither, depending on the field, recipient and channel.

Article 13 of the ePrivacy Directive establishes rules for direct-marketing communications and separately requires Member States to protect the legitimate interests of subscribers that are not natural persons 3. Because a directive is implemented through national law, the operational result is not one uniform EU-wide B2B exemption. The sending business must check the rule in the recipient market for the chosen channel and subscriber category.

QuestionGDPR analysisePrivacy analysis
What triggers it?Processing information about an identified or identifiable natural personUsing a covered communications channel for direct marketing
What must be classified?The field and its contextThe market, channel, recipient or subscriber category, and any national conditions
What is not enough?A B2B label, public availability or a company domainA GDPR lawful basis or a rule remembered from another Member State
What must be recorded?Purpose, lawful basis, transparency, rights, minimisation, accuracy and retentionThe applicable national route, its conditions and suppression outcome
Can the answer travel across the EU?The core natural-person definition is shared under the GDPRThe operative marketing rule depends on Member-State implementation

This separation prevents two opposite mistakes. The first is treating a named work email as non-personal because a national marketing rule may allow some business outreach. The second is assuming that a lawful basis under the GDPR automatically permits the chosen email, text or automated-call campaign. Neither inference is sound.

Channel matters as much as geography. A conclusion about a postal letter does not automatically govern email, and a rule for live calls does not automatically govern automated calls. The campaign record should therefore name the channel rather than recording only “marketing allowed”. A change of channel triggers a fresh check.

Turn the list into field-level decisions

A useful list audit ends with an action, not a colour-coded theory. Work through a sample first if the list is large, then expand the same fields and decision rules to the full dataset. If the sample exposes inconsistent vendor labels or unexplained enrichment, pause the intended use until the source and classification can be reconstructed.

Audit fieldWhat to recordWhy it matters
Source and collection dateVendor, form, event, public page or existing relationshipSupports transparency, accuracy and provenance checks
Data field and contextExact value type plus linked identifiersPrevents row-level B2B labels from hiding people
Subject classificationLegal entity, identifiable natural person, or unresolved national formEstablishes whether the GDPR branch applies
Purpose and lawful-basis decisionThe specific intended processing and recorded assessmentSeparates personal-data status from permitted use
Transparency statusWhat notice was given, when and by whomIdentifies missing information before use
Accuracy and review dateLast verification and event that triggers reviewReduces stale direct contacts and role errors
Retention triggerDate, relationship end or defined review eventPrevents indefinite list storage
Rights and suppression statusObjection, opt-out, restriction or other relevant statusPrevents a new import from reviving excluded contacts
Marketing rule checkRecipient market, channel, subscriber category and national routeEvidence that ePrivacy was assessed separately
Final actionKeep/use, correct, notify, suppress, route generically, verify or removeTurns the audit into an operational decision

The final action can be more precise than “keep” or “delete”. A valid customer-service contact might be retained for that service purpose but excluded from prospecting. A stale named email may be corrected from reliable information or removed. A record missing transparency may need a notice before further processing. A generic company route may be suitable for an initial non-personal approach, subject to the national marketing check.

Suppression is a control, not a failure to delete. When an identified person objects to direct marketing, a minimal suppression record can be needed to prevent later imports from contacting them again. The record should contain only what is necessary for that protective purpose and should not be reused as a fresh marketing audience.

Unresolved records need their own queue. A partnership-like form with unknown national status, an inbox that may map to one person or a list with no credible source should not be forced into a convenient category. Mark the missing fact, assign an owner and withhold the affected use until the fact is established. If the business cannot classify the field, support the purpose, meet transparency and accuracy needs or verify the applicable marketing route, removal is the defensible endpoint.

The two classification branches lead to different controls

Consider one supplier row containing Northstar SRL, a registration number, [email protected], “Lucia Bianchi, purchasing manager” and [email protected]. The company name and registration number describe the legal entity as such. Lucia's name, title and direct email identify a natural person. The sales inbox begins as organisational, but its classification remains open until context shows whether a team or Lucia alone receives it.

Now add purpose. Retaining Lucia's direct address to administer an existing order requires a GDPR purpose, lawful-basis and transparency analysis for that service activity. Reusing it for a prospecting campaign is another purpose and requires a fresh compatibility or lawful-basis decision. If the campaign uses email, the target Member State's electronic-marketing rule must also be checked. Nothing about the company registration number answers those questions.

The non-personal branch is narrower than it first appears. The business may keep the entity-only fields outside its GDPR record of personal-data processing, while preserving enough classification evidence to explain the boundary. Before marketing to [email protected], it still checks the applicable national ePrivacy route because Member States must protect legal-person subscribers as well as natural-person subscribers 3. “Outside GDPR” has not become “marketing permitted”.

The unresolved inbox should not be guessed into either branch. The auditor can verify its routing, use a genuinely organisational route for a non-marketing service message, or withhold the intended campaign. If the team cannot establish what the address identifies, where it came from or which national marketing rule applies, the defensible action is to exclude it from that use.

A UK answer needs a different marketing branch

The natural-person classification question is broadly recognisable in both EU and UK data-protection regimes, but the electronic-marketing route is not a locale swap. The EU answer must send the reader to the applicable Member-State implementation of Article 13. A UK answer must instead work through PECR and its own subscriber-category structure.

That difference changes an operative branch, not merely a regulator name or acronym. It earns a separate UK article. Importing the UK route into this EU page would imply that one country's categories and permissions travel across the Union; they do not.

Frequently asked questions

Is a named work email address personal data under the GDPR?

Usually yes. An address such as [email protected] points to a natural person even though the employer owns the domain and the message concerns work. The same reasoning normally covers a named employee's direct telephone number. Personal-data status starts the GDPR analysis; it does not by itself authorise collection, enrichment, retention or contact.

Is [email protected] personal data?

Usually not on its face, because it identifies an organisational function rather than a natural person. Context can change the answer. If a contact database, signature, routing rule or other accessible information shows that one identifiable person receives the inbox, the combined record may be personal data. Classify the actual record, not the address in isolation.

Are a limited company's details personal data?

A legal person's own name, legal form, registration number and corporate contact details are outside the GDPR as such. A row about the company can still contain personal data in adjacent fields, such as a named buyer, a direct work email or notes about an identifiable director. Classification therefore belongs at field level, not only at row level.

Are partnership contact details always personal data?

No single EU-wide answer follows from the label partnership. National law determines whether the particular form has legal personality and how it is constituted. Then inspect the field itself: does it describe the entity as such, or identify a natural person behind it? Record both findings instead of applying a portable partnership rule across Member States.

Does GDPR apply to a natural person trading through a business?

It can. A natural person does not stop being a natural person when acting commercially. If the record identifies that person, it can be personal data even when it records a business address, order history or professional role. The lawful basis, transparency information, purpose, rights, accuracy and retention analysis must then fit the intended processing.

Can a business send marketing because a contact is listed as B2B?

Not on that label alone. First decide whether the fields identify a natural person and apply the GDPR where they do. Then check the electronic-marketing rule for the recipient's market, subscriber category and channel. The ePrivacy Directive is implemented through Member-State law, so a route available in one country may not travel to another.

What should a small business record when auditing a B2B list?

Record the field, source, subject identified, classification, purpose, lawful-basis decision where GDPR applies, transparency status, accuracy date, retention trigger and suppression or objection status. For intended electronic marketing, also record the target market, channel and national-rule check. A row-level label such as corporate or B2B is too coarse to evidence those decisions.

Why should the UK marketing answer be kept separate?

The underlying question of whether information identifies a natural person remains familiar, but the marketing branch is jurisdiction-specific. UK outreach is governed by PECR and its subscriber categories; EU outreach depends on the target Member State's implementation of the ePrivacy Directive. Combining those routes would hide a decision point and could suggest permission that does not travel.

Frequently Asked Questions

Is a named work email address personal data under the GDPR?
Usually yes. An address such as [email protected] points to a natural person even though the employer owns the domain and the message concerns work. The same reasoning normally covers a named employee's direct telephone number. Personal-data status starts the GDPR analysis; it does not by itself authorise collection, enrichment, retention or contact.
Is [email protected] personal data?
Usually not on its face, because it identifies an organisational function rather than a natural person. Context can change the answer. If a contact database, signature, routing rule or other accessible information shows that one identifiable person receives the inbox, the combined record may be personal data. Classify the actual record, not the address in isolation.
Are a limited company's details personal data?
A legal person's own name, legal form, registration number and corporate contact details are outside the GDPR as such. A row about the company can still contain personal data in adjacent fields, such as a named buyer, a direct work email or notes about an identifiable director. Classification therefore belongs at field level, not only at row level.
Are partnership contact details always personal data?
No single EU-wide answer follows from the label partnership. National law determines whether the particular form has legal personality and how it is constituted. Then inspect the field itself: does it describe the entity as such, or identify a natural person behind it? Record both findings instead of applying a portable partnership rule across Member States.
Does GDPR apply to a natural person trading through a business?
It can. A natural person does not stop being a natural person when acting commercially. If the record identifies that person, it can be personal data even when it records a business address, order history or professional role. The lawful basis, transparency information, purpose, rights, accuracy and retention analysis must then fit the intended processing.
Can a business send marketing because a contact is listed as B2B?
Not on that label alone. First decide whether the fields identify a natural person and apply the GDPR where they do. Then check the electronic-marketing rule for the recipient's market, subscriber category and channel. The ePrivacy Directive is implemented through Member-State law, so a route available in one country may not travel to another.
What should a small business record when auditing a B2B list?
Record the field, source, subject identified, classification, purpose, lawful-basis decision where GDPR applies, transparency status, accuracy date, retention trigger and suppression or objection status. For intended electronic marketing, also record the target market, channel and national-rule check. A row-level label such as corporate or B2B is too coarse to evidence those decisions.
Why should the UK marketing answer be kept separate?
The underlying question of whether information identifies a natural person remains familiar, but the marketing branch is jurisdiction-specific. UK outreach is governed by PECR and its subscriber categories; EU outreach depends on the target Member State's implementation of the ePrivacy Directive. Combining those routes would hide a decision point and could suggest permission that does not travel.

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex · 2016
  2. 2.European Commission — Application of the GDPREuropean Commission
  3. 3.Directive 2002/58/EC on privacy and electronic communicationsEUR-Lex · 2002
  4. 4.Court of Justice of the European Union — Case C-631/21Court of Justice of the European Union

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.