Legitimate interest is usually the legal basis
GDPR requires a legal basis for processing personal data, and for B2B prospecting the most common basis is "legitimate interest", not consent. You therefore do not normally need to obtain prior consent before sending a relevant business communication to a professional.
Legitimate interest requires a balancing test: your interest in marketing a relevant product must be weighed against the recipient's privacy. The balance tilts more in your favour when the communication is relevant to the person's job, you are contacting them in a professional role, and you make it easy to opt out. It tilts the other way if you are contacting private individuals, using sensitive data or sending something entirely irrelevant.
The Norwegian Marketing Control Act and electronic communications
Alongside GDPR, the Norwegian Marketing Control Act applies. The main rule under § 15 is that electronic marketing to consumers requires prior consent. For business operators the picture is different: as a general rule you may contact a business at a general business address, and communications addressed to a person in their professional capacity within a company stand in a different position from pure consumer marketing.
In practice this means that a relevant business communication to a professional at a company is generally acceptable — but you must always have a valid legal basis, give the recipient the opportunity to opt out, and respect that immediately. When in doubt about the boundary between consumer and business operator, exercise caution and seek legal clarification.
Your obligations in practice
Regardless of legal basis, you have certain concrete obligations when processing personal data for prospecting. They are not complicated, but they must be in place — and they are part of a balancing test that actually holds.
- Have an informative privacy policy that explains what you collect and why
- Provide a simple way to opt out, and stop communications immediately when someone requests it
- Process only the data you actually need — data minimisation
- Be transparent about where the data comes from if the recipient asks
- Delete or anonymise data you no longer have use for
Choose data sources you can stand behind
Much of the risk lies in where the data comes from. Purchased email lists of unknown origin are problematic both legally and practically — you do not know how they were collected, and the quality is often poor. Public sources such as the Brønnøysund Register, on the other hand, are open precisely to be used, and provide a solid basis for B2B prospecting in Norway.
Vexter is built on Norwegian, publicly available data sources and verifies contact information against Norwegian domains. This gives you both better data quality and a cleaner privacy footprint than random purchased lists — but it does not relieve you of your own obligations as a data controller. The responsibility for using the data correctly always lies with you.
