B2B is not exempt. The obligations are more workable than most teams assume, and the record-keeping is where programmes fail.
There is a persistent belief in B2B marketing that consent rules are a consumer concern. It is wrong, and it is expensive to hold. Business contact details identify individuals, and the major privacy frameworks apply to personal data about individuals regardless of whether the context is commercial.
This is a working explanation for marketers, not legal advice. Obligations differ by jurisdiction and change, and specific decisions warrant qualified counsel.
What the main frameworks actually require
Under the GDPR, processing personal data requires a lawful basis. Consent is one, and for marketing purposes legitimate interests can be another, subject to a balancing assessment and an unconditional right to object. Electronic direct marketing carries additional rules that vary by member state, which is why practice differs across Europe more than people expect. Whatever basis is used, it has to be identified before processing and be capable of being evidenced afterwards.
Under the CCPA as amended by the CPRA, the model is different. It is built on disclosure and opt-out rather than prior consent: individuals must be told what is collected and why, and given a route to opt out of sale or sharing of their personal information, including for cross-context behavioural advertising. Recognised opt-out preference signals, such as Global Privacy Control, must be honoured where the law requires it.
Under India's Digital Personal Data Protection Act, the model is consent-forward, with requirements around clear notice, purpose limitation, and mechanisms for individuals to withdraw consent and raise grievances.
The practical consequence of three different models is that a single global consent posture is usually built to the strictest applicable standard, because maintaining separate regimes by geography is harder to operate than it looks on a slide.
Where B2B programmes actually fail
Rarely at the moment of collection. Most teams put a checkbox on a form. The failures come afterwards, in three places.
The record. Consent is only useful if it can be evidenced. That means storing what the person was shown, in the words they saw it, along with when, on which property, and for which purpose. Storing a boolean flag against a record proves nothing, because the wording that flag refers to has probably changed since.
The scope. Consent given for one purpose does not extend to another. Someone who subscribed to a newsletter has not agreed to receive product promotions from a partner company, and someone who downloaded a report has not agreed to an ongoing relationship unless that was stated at the time.
The transfer. This is the one most relevant to demand generation. When a lead is passed to a sponsor or a partner, the person must have been told at the point of collection that this would happen, and ideally who would receive it. Naming the recipient in the consent text at the point of submission is materially stronger than a general statement that data may be shared with partners.
What good practice looks like operationally
Name the recipient in the consent text itself, not in a linked policy. If a form generates a lead for a specific sponsor, that sponsor's name belongs in the sentence the person reads before submitting.
Never pre-tick a consent box. In several jurisdictions this invalidates the consent, and in all of them it undermines the evidence.
Store the consent string verbatim with a timestamp and the source property, and keep it for as long as you rely on it.
Make withdrawal genuinely easy and act on it quickly across every system, not only the one that sent the email.
Treat freshness as meaningful. A consent given years ago and never reconfirmed is a weaker basis than a recent one, whatever the technical position.
Why this is a commercial issue
Beyond the compliance argument, consent records have become a diligence asset. Data partners, marketplaces and enterprise buyers increasingly ask how a contact was obtained and expect a specific answer. Teams that can produce the consent text, the timestamp and the source property answer that question in minutes. Teams that cannot spend weeks reconstructing provenance, and frequently discover they cannot.
The record-keeping is dull. It is also the difference between an audience you can sell against and a database you have to apologise for.
This is reporting, not legal advice. Requirements differ by jurisdiction and change. Take qualified advice on your specific circumstances.
How we work. This article was researched and written by the Marketing Hub Media editorial team. We do not republish press releases. Where we cite data we name the source and the method. Corrections are made openly on the article - if you believe something here is wrong, write to info@marketinghubmedia.com.
Filed under Data, Privacy & Consent · Get the weekly brief

