1. Identify the recipient and rules that may apply
“B2B email” is not one universal legal category. Rules can differ for corporate addresses, sole traders, partnerships and named employees. They can also depend on where the sender and recipient are located and how the contact data was obtained.
This checklist is operational guidance, not legal advice. Before launching a campaign, identify the jurisdictions and recipient types in scope. The UK Information Commissioner’s Office explains that consent and legitimate interests are especially relevant lawful bases in B2B marketing, while electronic-marketing rules can treat individual subscribers differently from corporate bodies.
2. Record the source and provide appropriate transparency
Keep a record of where the contact information came from and why it was selected. If personal data came from a public or third-party source, check the applicable transparency obligations and timing rather than assuming that public visibility removes them.
The ICO states that people must be told about collection and use of their personal data for direct marketing, including when data comes from sources other than the individual. Your privacy notice and outreach process should match the actual data flow.
3. Check identity, role and contact suitability
Confirm that the domain belongs to the intended organisation, that a named person still works there, and that the available address is appropriate for the purpose. A contact field in a database is not proof of current employment, deliverability or permission.
Avoid presenting a general inbox as a named decision-maker. If the only route is support, decide whether the message genuinely belongs there. Verify important addresses, and remove records that cannot be connected to a clear business purpose.
4. Keep the message accurate and the sender identifiable
Describe public observations accurately and avoid invented intent. A technology signal does not prove a company is dissatisfied or ready to buy. Make the sender and commercial purpose understandable, and do not use deceptive routing information or subject lines.
For US commercial email, the Federal Trade Commission’s CAN-SPAM guidance covers accurate headers and subjects, identifying commercial messages, including a valid postal address and providing a working opt-out method. Check the complete official requirements for your campaign.
5. Apply suppression and honor objections
Check every export against customers, competitors, previous objections, unsubscribes and internal do-not-contact records. Suppression is not a one-time cleanup: it must continue when data is moved between prospecting, CRM and sending tools.
Make stopping future messages straightforward and process requests within the applicable deadline. Do not re-import an opted-out address from a new data source. Keep enough suppression information to prevent accidental contact without using it for another purpose.