Intent Data and GDPR: What European B2B SaaS Companies Can Legally Track

TL;DR: GDPR treats most intent data, IP addresses, device identifiers, browsing behavior tied to an identifiable person, as personal data, which means it can't be collected or used without a valid legal basis under Article 6. For B2B marketing specifically, legitimate interest is the most commonly relied-upon basis, but it requires a documented balancing test and doesn't override the separate consent requirements for cookies and tracking technologies under the ePrivacy rules most EU member states have implemented. This is general information, not legal advice; any specific intent data program should be reviewed by a qualified data protection lawyer or your company's DPO before launch.

Intent data tools built for the US market often assume a permissive default: track broadly, refine later, worry about consent if someone complains. That assumption doesn't transfer cleanly to a European B2B SaaS company operating under GDPR, where several of the data points a typical intent data platform collects are treated as personal data from the outset, regardless of whether the person is contacted directly or the outreach happens to be business-related.

Why "it's B2B, not B2C" doesn't exempt intent data from GDPR

A common and incorrect assumption is that GDPR primarily concerns consumer data, and that B2B activity, targeting companies rather than individual consumers, sits outside its scope. GDPR protects personal data regardless of the context it's processed in, and an IP address, a device identifier, or browsing behavior tied to a specific person at a specific company is still personal data even when the ultimate business purpose is B2B sales and marketing. The company being targeted might be a business, but the actual data points being collected, an individual's device activity, browsing session, or identifiable behavior, belong to a person, not an abstract corporate entity.

What GDPR actually classifies as personal data in a typical intent data stack

‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍
Data pointPersonal data under GDPR?Why
IP addressYes, generallyCan identify or help identify a specific individual or device, even indirectly
Company-level firmographic dataGenerally no, on its ownData about a legal entity alone, without tying it to an identifiable individual, typically falls outside personal data
Named contact plus browsing or engagement historyYesDirectly identifiable individual with behavioral data attached
Cookie-based tracking identifiersYesTreated as personal data and separately subject to consent requirements under ePrivacy rules

Why legitimate interest is the basis most B2B companies rely on, and what it actually requires

Article 6 of GDPR requires a valid legal basis for processing personal data, and consent isn't the only option. Legitimate interest, Article 6(1)(f), is commonly used for B2B direct marketing specifically because it doesn't require the same explicit opt-in mechanism consent does. Relying on legitimate interest isn't a free pass; it requires a documented balancing test showing the company's interest in the processing doesn't override the individual's rights and reasonable expectations, and it requires that the processing be genuinely necessary for that interest, not just convenient. A company relying on legitimate interest without having actually documented that balancing test is exposed if the basis is ever challenged, even if the underlying use case would likely have satisfied the test had it been properly recorded.

Why cookie-based tracking has a separate consent requirement that legitimate interest doesn't cover

A specific and commonly missed point: even where legitimate interest might justify collecting and using certain intent data, the ePrivacy rules implemented across EU member states separately require consent for placing non-essential cookies or similar tracking technologies on a device. This means a company can have a valid legitimate interest basis for the underlying data processing and still be non-compliant if the cookie or tracking technology used to collect that data was deployed without proper consent first. These are two separate legal requirements, and satisfying one doesn't automatically satisfy the other.

Why company-level intent data sits in a comparatively safer position

Aggregate, company-level intent signals, a specific company's overall increase in research activity around a category, without tying that activity to an identifiable individual, generally sit outside GDPR's personal data definition, since GDPR protects individuals, not legal entities. This is one reason many intent data vendors serving the European market have shifted emphasis toward company-level signal rather than individual-level tracking, since it reduces, though doesn't necessarily eliminate, the compliance burden compared to intent data tied to a specific, identifiable person.

Why international data transfer rules add another layer for US-built intent tools

Many popular intent data platforms are US-headquartered, which raises a second compliance question distinct from the legal basis question: whether personal data about EU individuals can be legally transferred to and processed by a US-based vendor at all. This generally requires either an adequacy mechanism recognized by the European Commission or appropriate safeguards such as Standard Contractual Clauses built into the vendor agreement. A European B2B SaaS company evaluating a US intent data provider should confirm what specific transfer mechanism the vendor relies on, since relying on a vendor's general assurance of compliance without confirming the specific legal mechanism is a real, documented risk.

How this connects to how intent data actually gets used once collected

Even where the collection itself is compliant, how the data gets used afterward matters separately. purple path's guide to integrating intent data into CRM and automation covers the technical side of wiring intent signals into a sales and marketing workflow; from a compliance perspective, every additional use of that data, feeding it into an automated outreach sequence, sharing it with a third-party enrichment tool, retaining it longer than necessary, needs to trace back to the same documented legal basis established at collection, not be treated as automatically covered once the initial collection was justified.

What GDPR non-compliance actually risks

GDPR enforcement carries meaningful financial exposure: fines can reach up to €20 million or 4% of a company's total worldwide annual turnover for the preceding financial year, whichever amount is higher, for the most serious categories of infringement. Beyond the direct fine, a documented enforcement action or a public complaint about improper data practices carries reputational cost that can affect enterprise sales cycles specifically, since larger B2B buyers increasingly conduct their own vendor due diligence around data handling practices before signing a contract.

A practical starting checklist before launching an intent data program

Before adopting any intent data tool, confirm which specific data points it collects and whether each one constitutes personal data under the framework above. Document a legitimate interest balancing test if that's the basis being relied upon, rather than assuming it applies without writing down the reasoning. Confirm the cookie or tracking consent mechanism used to collect any browser-based signals is properly implemented and not simply assumed to be covered by the underlying legitimate interest basis. And confirm, in writing, what international transfer mechanism a non-EU vendor relies on if personal data about EU individuals will be processed outside the EU.

Why data minimization and retention limits matter beyond the initial legal basis

Establishing a valid legal basis for collecting intent data is the starting point, not the entirety of GDPR's requirements. The data minimization principle means a company should only collect what's genuinely necessary for the stated purpose, not every data point a tool happens to make available simply because it's technically possible to capture. Storage limitation similarly requires that personal data isn't retained indefinitely once it's no longer needed for the original purpose. A company that establishes a solid legitimate interest basis at collection but then retains detailed intent signal data on every prospect indefinitely, long after any active sales engagement has ended, is exposed on this separate requirement even if the original collection was properly justified.

Why a Records of Processing Activities document is worth maintaining even for a smaller company

GDPR requires many organizations to maintain a Records of Processing Activities document, an internal record describing what personal data is processed, for what purpose, under what legal basis, and for how long it's retained. Even for a smaller Series A company that may fall under certain exemptions based on size, maintaining this kind of documentation voluntarily is good practice, since it's the exact record a data protection authority or a data subject exercising their rights would expect to see, and building it as intent data programs are first implemented is considerably easier than reconstructing it retroactively after a specific data source or use case is already in question.

Frequently Asked Questions

Does GDPR apply if my company is based outside the EU but sells to European buyers?

Generally yes, GDPR has extraterritorial reach and applies to processing of personal data belonging to individuals in the EU, regardless of where the company processing that data is based, when the processing relates to offering goods or services to those individuals.

Is legitimate interest a safer basis than consent for B2B intent data?

Neither is universally safer; each has different requirements and risks. Legitimate interest avoids the friction of an opt-in mechanism but requires a properly documented balancing test and remains challengeable, while consent requires more upfront friction but, if properly obtained, is generally more defensible.

Can a company simply avoid GDPR complexity by only using company-level, not individual-level, intent data?

This does reduce compliance complexity meaningfully, since aggregate company-level signal without an identifiable individual typically falls outside GDPR's personal data scope, though the specific implementation still needs review, since some "company-level" tools may still process individual-level data behind the scenes to construct that aggregate view.

Does this article cover every requirement my company needs to comply with?

No. This is general educational information about the landscape, not a complete compliance guide or legal advice, and GDPR compliance depends heavily on the specific tools, data flows, and use cases involved. A qualified data protection lawyer or your company's data protection officer should review any specific intent data program before launch.

How often should an intent data compliance review be revisited?

At minimum whenever a new tool or data source is added to the stack, and as a general practice, on an annual basis, since guidance from data protection authorities and enforcement patterns continue to evolve.

Getting the legal basis right before launching an intent data program is worth the upfront review, not a detail to sort out after a complaint arrives. Talk to purple path about building an intent data approach designed with European compliance in mind, and confirm the specifics with a qualified data protection lawyer before implementation.

David Miller

Dave leads purple path's content team, getting clients' inbound, outbound, thought leadership, social, and video content running fast, and making sure it actually works. In an AI-saturated content landscape, he's focused on the thing that still wins: content that engages and delivers real value.He's spent his career shaping content marketing strategy for SaaS companies globally, and previously as Head of Content at Minit Process Mining and Senior Copywriter at Exponea. He also built and exited his own company, Elite Language Center, over nearly nine years as CEO. His work has been featured in Forbes, and he's increasingly focused on LLM visibility, making sure content shows up where AI-driven search is heading next (GEO/AEO).