This page explains how European data-protection principles may apply to professional-contact data. It is not a promise that every customer use, dataset, or campaign is lawful. Customers remain responsible for their own purpose, lawful basis, notices, recipients, communications rules, and suppression obligations.
Depending on the processing, a controller may consider consent, contract, legal obligation, or legitimate interests. Legitimate interests are not automatic permission for direct marketing. A controller should identify a specific purpose, show the processing is necessary, assess reasonable expectations and impact, document the balancing exercise, and provide required transparency.
A work email address, direct business telephone number, or other information relating to an identifiable professional can be personal data. Public availability does not remove data-protection obligations and does not itself establish consent to a particular message.
People may have a right to object to processing for direct marketing. Senders should identify themselves, provide required notices and a simple opt-out, honor objections promptly, and keep suppression records. Separate electronic-communications and national marketing rules may require consent even where another GDPR basis is considered.
Subject to applicable conditions and exceptions, individuals may have rights of access, correction, erasure, restriction, objection, portability, and withdrawal of consent. Submit a request through our Privacy Choices & Data Requests page.
Review our Acceptable Use Policy and Terms before using data.