Cold calling compliance: what TCPA and GDPR mean for B2B mobile numbers
A practical guide to TCPA and GDPR for B2B cold calling on mobile numbers: what each rule actually restricts, how consent and legitimate interest work, and the daily habits that keep a calling programme clean.
9 min read · Published September 19, 2026
The short answer
The short version.
- The TCPA restricts the technology you use to reach US mobile numbers, not B2B calling itself. Manual or click to dial, no prerecorded voice without consent.
- GDPR does not ban B2B cold outreach. It requires a lawful basis, usually legitimate interest, plus transparency and a fast opt-out.
- The ePrivacy rules sitting next to GDPR decide whether you may call or email at all in each European country, and they differ by country.
- The operating answer is the same everywhere: screen before you dial, identify yourself, honour every opt-out immediately and keep records.
- This is general information, not legal advice. Take advice on your own programme.
Two sets of rules decide most of what a B2B team may do with a mobile number: the TCPA in the United States and the GDPR across Europe. Both are widely misunderstood. Neither bans B2B cold calling, and both punish specific behaviours that are easy to avoid once you know what they are.
This guide explains what each rule actually restricts, how the consent and legitimate interest tests work in practice, and the daily habits that keep a calling programme defensible. It is written for operators, not lawyers, and it is general information rather than legal advice.
What the TCPA actually restricts
The TCPA restricts automated dialing systems, prerecorded voice and artificial voice to US mobile numbers without prior express consent. A human dialling a business contact is not the target of the law.
The Telephone Consumer Protection Act is a 1991 US law aimed at robocalls. Its sharpest teeth apply to three things directed at mobile numbers: automatic telephone dialing systems, prerecorded voice messages and artificial voice. Using any of those to call or text a mobile without prior express consent carries statutory damages per call, which is why class action lawyers watch this space.
Ordinary B2B cold calling, where a rep selects a number and dials it, sits outside the high risk zone. Texting platforms and autodialers are where exposure concentrates. The national do not call registry is aimed at residential consumers, so calls to business lines and business mobiles are generally outside it, but several states run their own rules on calling hours, registration and mini TCPA statutes that cover more technology.
- Dial manually or with click to dial rather than an autodialer when calling US mobiles.
- Never send prerecorded or AI voice messages to a mobile without prior express consent.
- Treat text messages as calls under the TCPA, because the law does.
- Keep an internal do not call list and honour it permanently, across every campaign.
- Check state level rules for the states you dial most, especially Florida and Oklahoma.
How GDPR applies to a business mobile number
GDPR treats a business mobile number as personal data because it identifies a person. Processing it for outreach needs a lawful basis, most often legitimate interest, supported by a balancing test and a fast opt-out.
GDPR does not distinguish between a personal mobile and a mobile someone uses for work. If the number reaches an identifiable person, it is personal data and the regulation applies in full. The same is true of a work email that contains a name.
Most B2B outreach runs on legitimate interest. That is a genuine legal basis, but it is not a formality. You must be able to show three things: a real business reason for the contact, that the processing is necessary for it, and that the person's rights do not override your interest. A relevant offer to a carefully matched professional passes that test far more comfortably than a bulk blast, which is one more reason tight ICP screening matters.
Transparency is the other half. The person is entitled to know where their data came from and why you hold it, and your privacy notice must say so. When someone objects, you stop, and you keep proof that you stopped.
- Document a legitimate interest assessment before a European campaign, and refresh it when targeting changes.
- Only collect fields you actually use. GDPR calls this data minimisation.
- Tell prospects in the first touch where you got their details.
- Action objections immediately and keep the suppression record.
- Keep data current. Holding stale records is itself a compliance weakness.
The ePrivacy layer that decides if you may call at all
Alongside GDPR, each European country has ePrivacy rules that govern unsolicited calls and emails. Some countries allow B2B calls with an opt-out, others expect opt-in for email, and most run do not call registries you must screen against.
GDPR governs how you handle the data. The ePrivacy rules, implemented country by country, govern whether you may make the approach. Germany is the strictest large market: unsolicited B2B email effectively requires prior consent, and cold calls to businesses rely on presumed consent, which courts read narrowly. France allows B2B email on an opt-out basis when the offer matches the recipient's role. Ireland, the Netherlands and the Nordics each run their own blend, and most maintain a do not call register that businesses can join.
The practical routine is to pick the countries you will actually sell into, record the calling and emailing position for each, and screen every list against that country's registry before the first dial. Our country pages note the calling rules and registries market by market.
Habits that keep a programme clean in every market
Screen before dialling, identify yourself on every call, honour opt-outs instantly and forever, and keep records of all three. These four habits satisfy the core of every regime.
Every regime above reduces to the same operational discipline. Screening removes people who have asked not to be called. Identification removes the deception complaint that starts most investigations. Instant suppression turns an objection into proof of good practice rather than a second complaint. Records turn your word into evidence.
This is also how we run the data side. Suppression requests flow into a single list applied to every future batch, wrong or stale records are replaced rather than argued about, and the opt-out page is linked from every list email we send.
- Screen new lists against the relevant do not call registries before the first dial.
- State your name, company and reason for calling in the first sentence.
- Log every opt-out with a date and apply it across all campaigns permanently.
- Keep a short written note of your lawful basis and targeting logic for each market.
Key takeaways
- The TCPA targets autodialers and prerecorded voice to US mobiles, not ordinary B2B calling.
- GDPR allows B2B outreach on legitimate interest, provided you can show the balancing test and act on objections.
- European ePrivacy rules differ by country, so record the position for each market you call.
- Screening, identification, instant suppression and records are the universal defence.
See the data behind the advice
Five ICP matched prospects with mobile numbers, direct dials and work emails, free. Same pipeline that fills a paid account, no credit card.
Frequently asked questions
Is cold calling mobile numbers legal under the TCPA?
Yes, when a person dials. The TCPA's strict consent rules target automatic dialing systems and prerecorded or artificial voice to mobile numbers. Manual or click to dial B2B calls to business contacts are generally permitted, subject to state rules and do not call requests.
Does GDPR ban B2B cold calling?
No. GDPR requires a lawful basis for processing personal data, and legitimate interest covers carefully targeted B2B outreach in most cases. You must also meet the ePrivacy calling rules of the specific country, tell people where their data came from, and honour objections immediately.
Do I need consent to email a business contact in Europe?
It depends on the country. Germany effectively requires prior consent even for B2B email. France permits B2B email on an opt-out basis when the message matches the recipient's professional role. Record the position for each country before you send.
What records should a calling team keep?
Keep the source and date of every record, your legitimate interest or consent basis per market, the registry screening you ran, and a timestamped log of every opt-out. Those four items answer almost every regulator or complaint question.
Is this legal advice?
No. This is general information for operators. The details depend on your markets, technology and contracts, so take advice from a qualified lawyer on your own programme.
Keep reading
Compliance
B2B cold calling compliance basics for the US, Canada and the UK
A practical overview of do not call rules, consent, suppression and record keeping for B2B outbound calling and email in the United States, Canada and the United Kingdom.
Data
Direct dials versus mobile numbers, and when each one wins
What separates a direct dial from a mobile number, how each is sourced and verified, which roles answer which, and how to spot a switchboard number sold as a direct dial.
Benchmarks
Is cold calling still effective for B2B in 2026?
Cold calling still books meetings in B2B, but only on mobile numbers and direct dials. Here are the current connect, conversation and meeting rates.