European regulators have issued €5.88 billion in GDPR fines across 2,245 penalties since May 2018. Spain leads on enforcement frequency. And the European Commission's Q4 2025 Digital Package proposes expanding SME exemptions, mandating one-click cookie reject, and clarifying legitimate interests for AI processing. Implementation lands in 2031 at the earliest.
If you run outbound, here's the practical read: nothing changes this quarter, but the direction of travel matters for how you build your list hygiene and consent trail now.
Spain is the enforcement lab. Watch what they do.
Spain's AEPD has issued more GDPR penalties than any other EU regulator. Not the biggest fines, but the most frequent. That frequency matters because it tells you what enforcement looks like when it becomes routine rather than theatrical.
Most Spanish penalties target small and mid-sized businesses. Marketing lists without documented consent. Cookie banners that pre-tick boxes. Data processing agreements that don't exist. The fines are often €5,000 to €50,000. Small enough to be survivable, large enough to hurt.
The procedural mechanics are what outbound teams should study. AEPD complaints typically begin with a single individual exercising rights — an access request, an erasure demand, an objection to processing. The regulator then examines the controller's records: consent capture, lawful basis, retention schedule, processor contracts. Where documentation is absent, the burden shifts to the business to reconstruct its legal basis after the fact. That reconstruction is rarely persuasive. Most Spanish decisions turn on the same failure: the controller cannot demonstrate how a given address entered its database, so the processing is deemed unlawful by default rather than by proven harm.
This is why the AEPD model tends to spread. It requires no novel legal theory, only routine case handling, and it scales across a market dominated by small firms. Other supervisory authorities watching Spain see a template they can adopt without new legislation. For outbound teams, the pattern is clear: regulators aren't hunting whales. They're processing complaints from individuals who felt their data was mishandled. One angry prospect who files a complaint can trigger a review of your entire list-building process.
We've written before about what Spain's enforcement acceleration means for outbound. The short version: document where every email address came from, and be ready to show it.
The Digital Package proposes three changes. None arrive before 2031.
The European Commission published its Digital Package in Q4 2025. It contains three proposals relevant to outbound teams.
- SME exemption expansion. Smaller businesses would face lighter documentation requirements for legitimate interest processing. The current threshold is fuzzy. The proposal would clarify it.
- Mandatory one-click cookie reject. No more burying the reject button behind three screens. One click, same prominence as accept.
- AI legitimate interests clarification. Explicit guidance on whether AI-driven lead scoring and enrichment can rely on legitimate interests as a legal basis.
All three proposals require trilogue negotiation between the Commission, Parliament, and Council. Then member states get years to transpose. The Commission's own timeline puts implementation at 2031 or later.
The delay is structural, not incidental. Trilogue negotiations on data protection files routinely run eighteen to twenty-four months, because Parliament and Council rarely share the Commission's starting position on scope. The cookie provision is the clearest example: Parliament has historically pushed for stricter consent defaults, while Council tends to defend publisher flexibility. Each iteration pulls the text in a different direction, and nothing binds until a final compromise is published in the Official Journal.
Transposition adds a second lag. Member states have historically used the full window granted under a directive, and several have missed it outright. Even after national laws pass, supervisory authorities need time to issue guidance before enforcement becomes predictable. The practical effect is that a proposal published in 2025 shapes behaviour somewhere around 2032.
So why care now? Because the proposals signal what regulators will expect. If you build your compliance posture around the direction of travel, you won't scramble when the rules land. The SME exemption is the one to watch most closely. If the threshold is clarified in your favour, your documentation burden drops. If it is not, you have years to build the records that a stricter reading would demand. Either way, the cost of preparing early is far lower than the cost of retrofitting consent flows, suppression logic, and audit trails after the deadline passes.
What actually changes for your outbound setup today
Nothing in your inbox changes this week. But three things are worth doing now, because they're cheap and they compound.
First, audit your legitimate interest assessments. If you're relying on legitimate interests to email prospects, you need a documented balancing test. Why does your interest outweigh theirs? What's the minimal data you need? How do you honour objections? Most teams have nothing written down. Write it down. The reason this matters more than it used to: the proposed amendments don't create a new legal basis for outbound — they clarify how existing bases apply to automated processing. That means the assessment you write today is the one a supervisory authority will read later. Treat it as a living document, not a one-time artefact. Revisit it when your data sources change, when you add a new enrichment vendor, or when your targeting logic shifts. A stale assessment is worse than none, because it implies you knew the risk and stopped paying attention.
Second, check your cookie setup. If you're running any tracking on your site, the one-click reject proposal tells you where the bar is heading. Fix it now. It's a two-hour job with most consent management platforms. The deeper issue is consent symmetry: if accepting is one click, rejecting must be one click too, and neither option can be visually privileged. Audit your banner for dark patterns — pre-ticked boxes, buried reject links, colour contrast that nudges toward acceptance. These are the exact things regulators cite when they issue fines, and they're trivial to fix before anyone complains.
Third, document your AI enrichment sources. If you're using tools that scrape LinkedIn, infer email addresses, or score leads with AI, know where the data comes from. The AI legitimate interests clarification will likely require you to show that your processing is proportionate and transparent. In practice, that means a data map: which vendor, which source, which legal basis, which retention period. If a vendor can't tell you where their data originates, that's a signal to reconsider the vendor, not just the contract.
We covered the AI enrichment and consent box angle in more detail. The core point: regulators are starting to ask questions about automated decision-making in sales workflows.
The SME exemption won't save you if your list is dirty
There's a tempting read of the SME exemption expansion: smaller businesses get a pass. That's not what the proposal says.
The exemption would reduce documentation burden. It wouldn't eliminate the requirement to have a lawful basis for processing. If your list is scraped, unverified, or built without any consent trail, an expanded exemption doesn't help you.
What it does help with is proportionality. A five-person sales team shouldn't need the same compliance infrastructure as a 500-person enterprise. The proposal acknowledges that. But it still expects you to know where your data came from.
The distinction matters because documentation and lawfulness are separate obligations that get conflated. Article 5(2) accountability requires you to demonstrate compliance; Article 6 requires a lawful basis to process in the first place. An exemption that trims record-keeping under Article 30 does nothing to cure a list with no valid basis under Article 6. The supervisory authority can still act on a complaint, and the burden shifts to you to show the basis existed at the point of collection — not reconstructed after the fact.
For outbound teams, the practical exposure sits in three places:
- Provenance. Can you trace each record to a source, a date, and the basis relied on? If not, the exemption is irrelevant.
- Suppression integrity. Opt-outs and objections must persist across tools. A clean CRM with a dirty enrichment layer is still a dirty list.
- Retention. Indefinite storage of unengaged contacts is hard to justify regardless of company size.
We've seen teams interpret SME exemptions as permission to skip the basics. That's the wrong read. The basics are what protect you when a complaint lands.
What we'd do next
If you're running outbound into the EU or UK, spend an hour this week documenting your legitimate interest basis and your data sources. It's boring. It's also the difference between a €5,000 fine and a €50,000 one. The distinction rarely comes down to whether you had a lawful basis at all — it comes down to whether you can evidence the balancing test you supposedly performed before the first email went out. Regulators have been consistent on this point: a legitimate interest assessment written after a complaint arrives reads as a retrofit, not a process.
Concretely, that means three things worth doing now rather than in Q1:
- Write the balancing test down. For each outbound motion, record the interest you're pursuing, the necessity of the processing, and the reasonable expectations of the person on the other end. A one-page memo per motion beats a generic policy nobody has read.
- Map your data sources. If enrichment or scraping tools feed your sequences, you need to know what they collected, under what basis, and whether that basis survives transfer to you. "The vendor said it was compliant" is not a defensible answer.
- Build the suppression path before you need it. Objections and erasure requests should route somewhere a human actually checks, with a timestamp. The speed of your response is often the whole case.
None of this is glamorous, and none of it requires new tooling. It requires that the reasoning behind your outreach exists somewhere other than your head. If you want a tool that keeps the human in the loop on every send, give MiraReach a try. We built it so you can see exactly what's going out, to whom, and why.
— Mira