Resources
    Guide6 min read

    GDPR and B2B prospecting in Norway

    Many people believe GDPR makes cold B2B prospecting illegal. It does not. The data protection framework sets boundaries, but it does not prohibit contacting companies — it requires that you do so cleanly, with a valid legal basis and respect for individual rights. Here is a practical overview for Norwegian B2B. (This is general information, not legal advice — consult your own lawyer if in doubt.)

    Legitimate interest is usually the legal basis

    GDPR requires a legal basis for processing personal data, and for B2B prospecting the most common basis is "legitimate interest", not consent. You therefore do not normally need to obtain prior consent before sending a relevant business communication to a professional.

    Legitimate interest requires a balancing test: your interest in marketing a relevant product must be weighed against the recipient's privacy. The balance tilts more in your favour when the communication is relevant to the person's job, you are contacting them in a professional role, and you make it easy to opt out. It tilts the other way if you are contacting private individuals, using sensitive data or sending something entirely irrelevant.

    The Norwegian Marketing Control Act and electronic communications

    Alongside GDPR, the Norwegian Marketing Control Act applies. The main rule under § 15 is that electronic marketing to consumers requires prior consent. For business operators the picture is different: as a general rule you may contact a business at a general business address, and communications addressed to a person in their professional capacity within a company stand in a different position from pure consumer marketing.

    In practice this means that a relevant business communication to a professional at a company is generally acceptable — but you must always have a valid legal basis, give the recipient the opportunity to opt out, and respect that immediately. When in doubt about the boundary between consumer and business operator, exercise caution and seek legal clarification.

    Your obligations in practice

    Regardless of legal basis, you have certain concrete obligations when processing personal data for prospecting. They are not complicated, but they must be in place — and they are part of a balancing test that actually holds.

    • Have an informative privacy policy that explains what you collect and why
    • Provide a simple way to opt out, and stop communications immediately when someone requests it
    • Process only the data you actually need — data minimisation
    • Be transparent about where the data comes from if the recipient asks
    • Delete or anonymise data you no longer have use for

    Choose data sources you can stand behind

    Much of the risk lies in where the data comes from. Purchased email lists of unknown origin are problematic both legally and practically — you do not know how they were collected, and the quality is often poor. Public sources such as the Brønnøysund Register, on the other hand, are open precisely to be used, and provide a solid basis for B2B prospecting in Norway.

    Vexter is built on Norwegian, publicly available data sources and verifies contact information against Norwegian domains. This gives you both better data quality and a cleaner privacy footprint than random purchased lists — but it does not relieve you of your own obligations as a data controller. The responsibility for using the data correctly always lies with you.

    Ready to fill your pipeline?

    Get started in minutes, or let our team do the work for you.

    We use cookies

    We use cookies and similar technologies to help improve your experience, serve personalized content, and analyze our traffic. Privacy Policy