← Back to Blog GDPR Reform Is Stalled Until 2031. Enforcement Just Cost €5.88B—and Your Cold Email Setup Is Next.

GDPR Reform Is Stalled Until 2031. Enforcement Just Cost €5.88B—and Your Cold Email Setup Is Next.

EU GDPR reform is stalled until 2031, but enforcement is aggressive now. Fix cookie consent dark patterns and AI legitimate interest assessments before fines hit.

The EU's GDPR reform package is dead on arrival until 2031. But the regulator isn't waiting. Cumulative fines hit €5.88 billion, and enforcement is targeting two things that directly affect your outbound: cookie consent dark patterns and legitimate interest assessments for AI tools. Fix both now, or your pipeline becomes a liability.

The reform you're waiting for isn't coming

The proposed GDPR amendments promise SME exemptions and cookie standardisation. Sounds great. It's also years away. The legislative process in Brussels moves slower than a cold email reply from a C-suite exec. Even if the text passes tomorrow, the transition period runs to 2031.

Meanwhile, the European Data Protection Board and national authorities are not slowing down. They're hiring. They're building case law. And they're looking at the same tools you use every day.

We track this because it changes who we can prospect and how. The last time we wrote about the EU AI Act, the enforcement gap was obvious. Unit A3 has 40 staff to enforce the entire AI Act. The DSA team has 160. That gap means enforcement lands where it's easiest to prove harm, not where the law is most complex.

GDPR enforcement is the same. Regulators go after clear, visible violations. Dark patterns in cookie banners are visible. AI tools processing personal data without a documented legitimate interest assessment are visible. Both are easy to prove. Both carry fines up to 4% of global turnover.

Dark patterns in cookie consent are the easiest fine you'll ever avoid

We audited our own cookie banner last month. It was bad. Pre-ticked boxes, a green "Accept" button and a grey "Manage preferences" link buried in the footer. That's a dark pattern. The European Data Protection Board has been explicit about this since 2022. The Irish DPC fined Meta €390 million for exactly this. The French CNIL has issued dozens of fines for the same issue.

Here's what compliance looks like in practice:

That last point matters for B2B. Most analytics cookies can run on legitimate interest. But you have to offer a clear opt-out. If your banner only offers consent or reject, you're forcing a choice that the law doesn't require. That's a dark pattern.

We rebuilt ours in a day. It took longer to argue about the button colours than to implement the logic. If you're using a cookie consent tool, check the settings. Most default configurations are non-compliant. Turn off pre-ticking, make reject equal weight, and test it on mobile.

Legitimate interest assessments for AI tools are the new frontline

Here's where it gets personal. Every AI tool you use for outbound is processing personal data. That includes the enrichment tools, the email drafting assistants, and the scoring models. If you're relying on legitimate interest as your legal basis, you need a documented assessment. Not a paragraph in your privacy policy. A real assessment.

The assessment has three parts. First, the purpose test. What are you actually doing with the data? Second, the necessity test. Is there a less intrusive way to achieve the same result? Third, the balancing test. Does your interest outweigh the data subject's rights?

For B2B outbound, the balancing test is where most assessments fail. You're processing data about individuals at companies. Their professional email addresses are personal data. Their job titles are personal data. Their LinkedIn activity is personal data. The fact that they work at a company that matches your ICP is personal data.

We wrote our assessment in an afternoon. It's not legal advice, but it's a working document. We documented what data we process, why, and how we minimise it. We noted that we only contact business email addresses, that we include a clear opt-out in every message, and that we delete data on request within 72 hours. That's the minimum bar.

If you're using AI to draft emails, the assessment gets more complex. The AI model is processing the prospect's data to generate a personalised message. That's a separate processing activity. You need to document it. The EU AI Act adds another layer, and the August 2026 deadline for high-risk systems is closer than you think.

What this means for your prospect list

This isn't just a compliance exercise. It changes who you can target and how. Companies that have already fixed their cookie consent and documented their legitimate interest assessments are safer prospects. They understand the regulatory environment. They're less likely to ghost you because their legal team flagged your outreach as a risk.

We've seen this pattern before. When the EU AI Act enforcement timeline shifted, the companies that were prepared became better buyers. They had budget set aside for compliance tools. They had processes in place. They were easier to sell to because they understood the problem.

The same logic applies here. A company that has a compliant cookie banner and a documented legitimate interest assessment is a company that takes data protection seriously. They're more likely to respond to a GDPR-compliant cold email. They're more likely to appreciate a clear opt-out link. They're more likely to buy from someone who speaks their language.

Build a segment in your CRM for "GDPR-compliant" and prioritise it. Check their cookie banners. Look for the equal-weight reject button. If they have it, they're ahead of the curve. If they don't, they're a compliance risk waiting to happen, and they're probably not buying anything that isn't a legal retainer.

What we'd do next

Fix your cookie banner this week. It's a day of work and it removes the most visible risk. Then write your legitimate interest assessment for your AI tools. It doesn't need to be perfect. It needs to exist and be honest.

If you want to see how we handle this in our own outbound, give MiraReach a try. We built it for founders who need to move fast without becoming a compliance headline.

— Mira

Share on X Share on LinkedIn
Until next time — keep sending emails that are worth reading.
M
Mira
Head of Content at MiraReach
★ The Solopreneur Playbook · Free

Find 50 customers in 12 minutes.

Five customer-discovery prompts. Eight cold-email templates that hit 8% reply rate. The honest math: manual = 4 hours, MiraReach = 12 minutes.

Read the playbook →