The European Commission's Q4 2025 Digital Package proposes expanding the Records of Processing Activities exemption from under 250 to under 750 employees. It also mandates one-click reject mechanisms for cookies. Neither change is law yet. The legislative timeline runs to 2031 or later. Enforcement, meanwhile, is not waiting: €1.2 billion in GDPR fines landed during 2024 alone.
So the practical answer for anyone running outbound right now is: nothing changes today, but the direction of travel matters for how you build your list hygiene and consent flows over the next 18 months.
The SME exemption expansion is real, but it's not a free pass
Here's what the proposal actually says. Companies with fewer than 750 employees would no longer need to maintain the full Article 30 Records of Processing Activities register. That's the internal document where you're supposed to log every category of personal data you process, why, where it came from, and who you share it with.
If you're a five-person SaaS company running outbound to EU prospects, you are almost certainly already exempt under the current 250-employee threshold. The expansion matters for the 250–750 band: agencies, mid-market services firms, and scale-ups that crossed the line and suddenly had to hire a DPO or bolt on a compliance tool.
What it does not do:
- Remove your obligation to have a lawful basis for processing (legitimate interest still needs a documented balancing test)
- Exempt you from subject access requests, deletion requests, or breach notification
- Change anything about ePrivacy rules on cold email, which sit separately from GDPR
- Apply retroactively to enforcement actions already in flight
We've watched founders read "SME exemption" and hear "we can stop worrying about compliance." That's the wrong read. The exemption is about paperwork, not about the underlying principles. You still need to know where your prospect data came from and be able to justify why you're emailing them.
One-click cookie rejection will change your website, not your outbound
The mandatory one-click reject requirement is the more interesting piece for anyone running a website with analytics or retargeting pixels. Right now, most consent management platforms offer a "reject all" button that's technically one click but often buried behind a "manage preferences" flow. The proposal would force the reject option to be as prominent and as easy as the accept option.
For outbound specifically, this matters in one indirect way: if you're using website visitor identification tools (the ones that deanonymise traffic and feed it into your CRM), your pool of identifiable visitors shrinks when rejection becomes frictionless. Expect a 15–30% drop in matched visitors for EU traffic once this lands. We've seen similar drops in the UK post-PECR enforcement.
If your outbound pipeline depends on website visitor data as a top-of-funnel source, start building a second channel now. Conference lists, LinkedIn engagement, and inbound content all survive cookie rejection. Retargeting-based intent data does not.
Enforcement is the part that actually costs you money
The €1.2 billion in 2024 fines is not a rounding error. And the pattern we've seen across the last three years is that regulators target the easy cases first: companies with obvious consent violations, pre-checked boxes, and enrichment workflows that scrape personal data without a documented lawful basis.
We wrote about this in our breakdown of how GDPR fines are now targeting AI enrichment and pre-checked boxes. The short version: if your outbound stack includes an enrichment tool that pulls personal emails from LinkedIn or scrapes contact data without consent, you are the low-hanging fruit.
The reform timeline doesn't protect you from this. Fines issued under the current regime stand. And national regulators have shown no appetite for pausing enforcement while Brussels debates.
What to actually do before 2031
Three things, in order of urgency.
First, document your lawful basis for outbound. Legitimate interest is the usual answer for B2B cold email, but it requires a Legitimate Interest Assessment. If you don't have one written down, you don't have one. This is a two-page document, not a legal project. Templates exist.
Second, audit your enrichment sources. Every tool in your stack that adds email addresses, phone numbers, or firmographic data to your CRM should have a documented source. If you can't answer "where did this email come from" for a given record, that record is a liability. We covered the practical version of this in our post on why your prospect list became a liability in July 2026.
Third, fix your cookie banner now, not in 2031. One-click reject is coming. The CMPs that support it today are the ones you want to be on. If your current setup requires a user to click through three screens to reject, you're accumulating risk for no benefit.
What we would not do: hire a compliance consultant to prepare for a reform that may not pass in its current form. The proposal has to go through trilogue, and the timeline extends past 2031. Spend the money on list hygiene instead.
The honest trade-off
Stricter consent rules make outbound harder. That's the point. The founders who win over the next five years will be the ones who built clean lists, documented their processes, and didn't rely on scraped data as a shortcut. The ones who treated compliance as a checkbox will keep paying fines.
We built MiraReach on the assumption that human review beats automation for anything that touches a prospect's inbox. Every message waits for a human to press send. That's not a compliance feature, but it happens to make compliance easier: you know exactly what went out, to whom, and why.
If you want to see how MiraReach handles prospect sourcing and email drafting without the scraped-data problem, give MiraReach a try.
— Mira