The EU's proposed GDPR amendments are not coming to save you. SME exemptions and cookie standardisation are drafted, debated, and parked until 2031 at the earliest. Meanwhile regulators have issued €5.88 billion in cumulative fines and are actively working through a backlog that includes B2B outbound operators. If you run your own pipeline, the legislation you need to worry about is the one already being enforced.
Reform is a 2031 problem. Enforcement is a this-quarter problem.
Here is the gap that catches founders. You read about SME exemptions and assume relief is coming. You read about cookie standardisation and assume the consent banner mess will sort itself out. Both are true in the long run. Neither changes what a data protection authority will ask you about if a complaint lands tomorrow.
The current enforcement priorities are narrow and specific. Dark patterns in cookie consent. Legitimate interest assessments for AI tools that process personal data. Those two categories are where the fines are landing, and they map directly onto how most small B2B teams run outbound.
We covered the fine totals and the SME exemption timeline in our breakdown of the €5.88B in GDPR fines and what changes when SME exemptions land. The short version: exemptions won't retroactively cover conduct from 2024 or 2025. If you're building a prospect list today, you're operating under the current rules, not the 2031 ones.
Cookie consent is the easiest place to get caught
Most B2B SaaS sites have a cookie banner that fails on at least one of three tests.
The first is pre-checked boxes. If your banner loads with analytics or marketing cookies already ticked, that is not consent. It is a dark pattern, and it is one of the specific things regulators have been told to prioritise. The fix is a single line of config in most consent management platforms. It takes ten minutes and removes an entire category of exposure.
The second is a reject button that is harder to find than the accept button. Same colour, same size, same position. If a user has to hunt for it, you have a problem. This is the pattern that generated the largest cookie-related fines in the last two years.
The third is consent that doesn't actually gate the script. You show the banner, the user clicks reject, and Google Analytics still fires because the tag manager trigger was never wired to the consent state. We have audited sites where this was true for eighteen months and nobody noticed.
None of this is glamorous. All of it is checkable in an afternoon. If you run a small team and you're doing outbound, your website is the first thing a prospect sees and the first thing a regulator checks.
Legitimate interest assessments for AI tools are the new frontline
This is the one that catches outbound operators specifically. Every AI tool in your stack that touches personal data needs a documented legitimate interest assessment, or a different lawful basis, and most teams have never written one.
Walk through your stack. Enrichment tools that append job titles and emails. Scoring models that rank prospects by likelihood to reply. Meeting brief generators that pull public information into a summary. Drafting tools that process the recipient's name, company, and role to personalise an email.
Each of those is processing personal data. Each needs a lawful basis. For most B2B outbound use cases, legitimate interest is the right basis, but it is not automatic. You have to document the assessment: what the interest is, why it's legitimate, whether the processing is necessary, and how you balanced it against the individual's rights.
We wrote about the ICO's AI code becoming enforceable and what a misconfigured scoring model costs in our piece on the ICO AI code and scoring model liability. The headline: a scoring model that makes decisions about individuals without a documented basis is exactly the kind of thing regulators are now equipped to investigate.
The practical version for a small team is a one-page document per tool. Not a legal treatise. A paragraph on the interest, a paragraph on necessity, a paragraph on balancing, and a date. Store it somewhere you can find it in five minutes if someone asks.
What actually changes for your outbound setup
Three things, in priority order.
- Fix the cookie banner this week. No pre-checked boxes. Reject button as easy to find as accept. Consent state actually gating the scripts. Verify with a browser dev tool, not by trusting the CMP dashboard.
- Write legitimate interest assessments for every AI tool that touches personal data. One page each. Date them. Keep them current when you change tools.
- Document your prospect list provenance. Where did the data come from, what basis are you relying on, and can you show the assessment. This is the question that turns a complaint into a fine.
What doesn't change: cold email itself is still lawful in the EU under legitimate interest for B2B, provided you're targeting business roles, the message is relevant to the recipient's function, and you offer a clear opt-out. The legislation hasn't moved on that. The enforcement has.
We've seen teams panic and switch to consent-only models, which kills outbound volume for no compliance benefit. That's the wrong trade. The right trade is documenting the basis you're already relying on.
What we'd do next
If you're running outbound into the EU or UK, spend one afternoon on the cookie banner and one afternoon on the legitimate interest assessments. That covers the two categories regulators are actively pursuing. The 2031 reform will arrive eventually, and when it does, the teams with clean documentation will have the easiest transition.
If you want a tool that keeps the human in the loop on every send and doesn't auto-fire emails you haven't reviewed, give MiraReach a try. We built it for exactly this kind of operator.
— Mira