The European Commission's Q4 2025 Digital Package proposes expanding the Records of Processing Activities exemption from under 250 to under 750 employees. It also mandates one-click reject mechanisms for cookies. But the legislative timeline runs to 2031 or later, and enforcement hasn't slowed. €1.2 billion in GDPR fines landed in 2024 alone.
So the reform is real. The relief is not here yet. If you're running outbound into the EU, nothing about your current setup changes this quarter.
What the SME exemption actually covers
Article 30 of GDPR currently exempts organisations with fewer than 250 employees from maintaining Records of Processing Activities (RoPA), with carve-outs for regular processing or sensitive data. The proposed expansion pushes that threshold to 750.
For a 400-person SaaS company running outbound, this matters. Today, you likely need a RoPA documenting every processing activity: prospect lists, enrichment sources, email sequencing tools, CRM records, meeting notes. Under the reform, you'd fall under the exemption.
But here's the catch. The exemption only covers Article 30. It doesn't touch lawful basis, consent, or subject access requests. You still need a legitimate interest assessment for cold email. You still need to honour deletion requests within 30 days. You still can't scrape LinkedIn and pretend it's consent.
We've seen founders read "SME exemption" and assume it means "no compliance work." That's not what this is. It's one less document to maintain, not a free pass.
The one-click cookie rejection mandate is the bigger operational shift
Cookie consent has been a mess since 2018. Most sites still use dark patterns: pre-checked boxes, hidden reject buttons, "manage preferences" mazes that take six clicks to opt out.
The Digital Package proposes mandatory one-click rejection. Same prominence as accept. No pre-checked boxes. No greyed-out reject text.
If you run a website with analytics, retargeting pixels, or chat widgets, this affects you. And it affects your outbound indirectly. When prospects land on your site from a cold email, their cookie choices determine what data you can collect. If they reject everything, your retargeting audience shrinks. Your intent data gets thinner.
We're not there yet. But the direction is clear. Build for a world where prospects can opt out of tracking in one click, and your outbound has to stand on the email itself, not on a retargeting sequence that follows them around the internet.
Enforcement is not waiting for the reform
€1.2 billion in fines during 2024. That's not a rounding error. And the targets are getting more specific.
Spain's AEPD has accelerated enforcement against AI enrichment tools and pre-checked consent boxes. The ICO's AI Code is now law in the UK, with fines up to £20k for misconfigured scoring models. The pattern is clear: regulators are looking at how you source data, how you score it, and whether you have a lawful basis.
For cold email specifically, the risk areas are:
- Enrichment sources. If you're buying lists from a vendor who scraped them, you inherit that liability. Legitimate interest doesn't cover data obtained unlawfully.
- Scoring models. If your AI tool scores prospects and that scoring affects what they see or don't see, you may need to explain the logic. The ICO's code applies here.
- Consent boxes. Pre-checked boxes are already non-compliant. The reform just makes it explicit.
- Subject access requests. If a prospect asks what data you hold, you have 30 days. Most outbound stacks can't answer that question cleanly.
We wrote about the AI enrichment and consent box enforcement trend earlier this year. The reform doesn't change that trajectory. It just adds a longer runway for companies that want to get compliant before the rules shift.
What this means for your outbound setup right now
Nothing changes today. The reform is a proposal. The timeline runs to 2031 or later. But the enforcement environment is already aggressive, and the direction of travel is toward stricter consent and clearer data provenance.
Here's what we'd do if we were running outbound into the EU this quarter:
Document your lawful basis. Legitimate interest is the usual answer for B2B cold email. But you need a Legitimate Interest Assessment (LIA) that explains why your outreach is proportionate and why the prospect would expect it. If you can't write that down, you have a problem.
Audit your enrichment sources. Where did the data come from? If the answer is "a vendor sent us a CSV," dig deeper. You need to know the provenance. If the vendor can't tell you, find another vendor.
Check your cookie setup. If you have pre-checked boxes or a reject button that's harder to find than accept, fix it now. The reform will mandate one-click rejection. You might as well get ahead of it.
Build for deletion. If a prospect asks you to delete their data, can you do it across every tool in your stack? CRM, sequencing tool, enrichment platform, analytics? Most stacks can't. That's a gap.
We covered the broader GDPR enforcement picture in a previous post. The reform doesn't change the fundamentals. It just gives you more time to get them right.
What we'd do next
The reform is a signal, not a reprieve. Enforcement is happening now. The exemption expansion and one-click cookie mandate are coming, but they won't save you from a fine if your current setup is sloppy.
If you want to see how MiraReach handles compliance in the outbound workflow, give MiraReach a try. We don't auto-send. We don't scrape. And we keep a clean audit trail of where every prospect came from.
— Mira