July 2026 was the month the EU stopped writing rules and started collecting. A €550 million fine against AliExpress, the Digital Omnibus on AI entering into force, and the UK upholding a £12.7 million penalty against TikTok. Three separate enforcement actions, one message: the legislation governing how you collect, store, and act on personal data is now being enforced at a scale that changes the maths on your prospect list.
If you run outbound, this is not abstract. Your CRM is a database of personal data. Your enrichment tool is a processor. Your cold email is a communication under GDPR. The question is whether your setup survives contact with a regulator who just demonstrated they will fine nine figures for getting it wrong.
The €550M AliExpress fine is about data governance, not e-commerce
Strip away the headline number and the AliExpress case is a data governance failure. The fine centred on how the platform handled user data across borders, what it disclosed to users, and whether its consent mechanisms held up. The specifics matter less than the pattern: regulators are now auditing the plumbing, not just the policy documents.
For a founder running outbound, the equivalent plumbing is your enrichment stack. Where does the data come from? Who processed it? What's your lawful basis for holding it? If you can't answer those three questions in under a minute, you have the same exposure AliExpress had, just at a smaller scale.
We've written before about how GDPR fines are now targeting AI enrichment and pre-checked boxes. July's enforcement confirms that trajectory. The €5.88 billion in cumulative GDPR fines since 2018 isn't a historical footnote. It's a running total that just got bigger.
The Digital Omnibus on AI is now law, and it touches your scoring model
The EU's Digital Omnibus on AI Regulation entered into force in July. The practical effect for outbound teams is that any AI system used to evaluate, score, or rank individuals now sits inside a regulatory framework with real teeth.
Your lead scoring model qualifies. So does your inbox scoring tool. So does any enrichment workflow that uses AI to infer something about a prospect, whether that's their likely budget, their seniority, or their intent.
We covered the UK's equivalent earlier this year: the ICO's AI Code is now law, and one misconfigured scoring model could cost you £20k. The EU Omnibus extends that logic across the bloc. If you're selling into Europe, you now have two regulatory regimes to satisfy, and they don't always align.
What this means in practice:
- Document what your scoring model does and why. "It ranks leads" is not documentation.
- Know your lawful basis for processing. Legitimate interest works, but you have to be able to articulate it.
- Keep a record of what data went in and what came out. If a regulator asks, "we don't log that" is not an answer.
- Check your vendors. If your enrichment provider can't tell you where their data comes from, you've inherited their problem.
The UK upheld a £12.7M TikTok fine, which tells you enforcement is not slowing down
The UK's decision to uphold the TikTok penalty matters because it signals that post-Brexit, the ICO is not softening its stance to attract business. If anything, the opposite. The UK is building its own enforcement track record, and it's running parallel to the EU's.
For outbound teams, the practical implication is that you can't assume one jurisdiction's compliance covers you in another. A prospect list that's clean under UK rules might not be clean under EU rules, and vice versa. We wrote about this dynamic in the context of 20 U.S. states with no federal floor, and the same fragmentation logic applies across the Atlantic.
The founders we see doing this well have stopped treating compliance as a one-time setup. They treat it as a recurring audit. Every quarter, they check: where did this data come from, who touched it, and does our lawful basis still hold? It takes an afternoon. It's cheaper than a fine.
What this actually changes for your outbound workflow
Most of the outbound advice you'll read this month will tell you to "be more careful." That's not useful. Here's what we'd actually change.
Audit your enrichment sources. If you're using a tool that scrapes data without a clear provenance trail, you're carrying risk you didn't price in. Switch to providers who can document their sources. It costs more. It's worth it.
Log your scoring decisions. If your AI ranks a prospect as high-intent, you should be able to explain why. Not for every lead, but for any lead a regulator might ask about. A simple log file is enough.
Separate your lists by jurisdiction. If you're selling into the EU, the UK, and the US, you have three different compliance regimes. Don't run one list through all three and hope. Tag your prospects by region and apply the right rules to each.
Stop pre-checking consent boxes. This one keeps showing up in enforcement actions. If you're collecting any data through a form, the box starts unchecked. No exceptions.
None of this is glamorous. It's the unglamorous work that keeps you out of the enforcement headlines.
What we'd do next
If you're running outbound into Europe or the UK, spend an hour this week auditing your data sources and your scoring model. Document what you find. If you can't document it, you have a problem worth fixing before a regulator finds it for you.
MiraReach was built with this in mind. We don't auto-send, we log what our scoring does, and we keep a human in the loop on every message. If you want to see how that works in practice, give MiraReach a try.
— Mira