Every US team expanding healthcare outreach into the EU eventually produces a slide that says "GDPR compliant" with a checkmark next to it, as if that resolves the question. It doesn't. GDPR isn't a single rule you satisfy once — it's a framework that interacts differently with email law, member-state practice, and the specific sensitivity of health-adjacent data, and most of the friction shows up in places US teams never thought to look.
- "Legitimate interest" is not a synonym for "we didn't ask permission." US teams often treat legitimate interest as the loophole that lets B2B outreach continue without consent, and functionally it can — but only if you've actually done the balancing test and can produce it on request. That means documenting why the outreach is proportionate, why a less intrusive method wasn't viable, and why the HCP's reasonable expectations weren't violated. Most teams have never written this document; they've just decided legitimate interest applies and moved on.
- GDPR and the ePrivacy Directive are not the same law, and cold email lives under the second one. GDPR governs how you process personal data; ePrivacy (and its national implementations) governs whether you're allowed to email someone in the first place. This distinction matters because a lawful basis under GDPR does not automatically make an unsolicited email legal — Germany's implementation, for instance, is considerably stricter on B2B cold email than what most US teams assume "GDPR-compliant" means.
- The EU is not one jurisdiction with 27 flags. Germany's data protection authorities interpret legitimate interest more conservatively than France's CNIL, and Nordic countries often sit somewhere in between. A messaging cadence that clears review in the Netherlands can generate a formal complaint in Germany, and campaign plans built around "the EU" as a single ruleset consistently underestimate this variance until a complaint actually lands.
- HCP data can drift into special category territory faster than people expect. Article 9 protections apply to health data, and while a name-title-email record isn't inherently health data, appending clinical specialty, prescribing indicators, or affiliation with specific patient populations can start to imply health-related information about the individual, not just their job function. Teams doing enrichment on HCP records rarely stop to ask whether the enriched fields have quietly changed the data's legal classification.
- Where the data came from matters more than what you plan to do with it. A lawful basis has to trace back through the entire chain — original collection, any resale or licensing, and your own processing — and you can't retroactively legitimize a list by writing a good privacy policy on your end. If a vendor's original collection method wouldn't hold up to scrutiny, no amount of downstream compliance language fixes that; this is one area where provenance questions that sound like procurement due diligence are actually legal due diligence.
- Access and erasure requests are operational, not theoretical. US teams frequently have no defined workflow for a "please delete my data" email from an EU contact — it gets treated as a nuisance or forwarded to whoever's free, with no SLA and no designated owner. Under GDPR this has a response clock attached, and the absence of a process is itself a compliance gap regulators specifically look for during any inquiry.
- A privacy policy is not a Record of Processing Activities. Article 30 documentation — what data you hold, why, for how long, and who touches it — is a distinct artifact from the public-facing privacy notice most companies already have. Teams under time pressure often assume the public policy covers this obligation; it doesn't, and it's usually the first thing requested if a data protection authority ever opens a file.
- Post-Schrems II, "our CRM is in the US" is a real question, not a footnote. If EU contact data flows into US-hosted systems, you need a valid transfer mechanism — Standard Contractual Clauses plus a genuine assessment of US government access risk, not just a checkbox in a vendor contract. Teams building outreach infrastructure around US-based CRMs and enrichment tools often haven't confirmed this is actually documented anywhere, which becomes a problem the moment a partner or prospect asks.
- "Consent" collected for one purpose doesn't travel to another. A specialty conference sign-up, a webinar registration, or a content download often comes with a narrowly scoped consent statement, and US teams routinely treat that as a green light for ongoing sales outreach months later. If the original consent language didn't cover commercial follow-up from a third party, reusing that contact for a different campaign — even with good intentions — reopens the same lawful-basis question from scratch, and this is one of the more common gaps we see when reviewing how outreach lists were actually assembled, including in our own client audits at NPLUS Global.
None of this makes EU healthcare outreach impossible — plenty of US teams run it well, but the ones who do usually stopped treating GDPR as a legal sign-off and started treating it as an operational discipline: documented reasoning, traceable data lineage, and a real process for the messy parts like deletion requests. The teams that get burned aren't the ones who misunderstood the law; they're the ones who assumed understanding it once was the same as maintaining it.
Ready to see what we can build for your ICP?
Send us your ICP — sample in 2–3 hours, full delivery in 48–72 hours.
Request a free sample →