Compliance

A GDPR vendor checklist for hiring a B2B outbound agency in Germany

Done-for-you B2B outbound · Original data

In short

An outbound agency stating that it is GDPR compliant is a marketing sentence, not evidence. This checklist sets out what to actually request before signing: the legal basis used for cold B2B outreach, a real data processing agreement with named clauses, disclosure of where data is stored and who the sub-processors are, and a stated opt-out handling commitment. This page covers the process to request, not a specific vendor's compliance status, and no vendor, Ripe Leads included, should be taken at its word on this without the documentation to back it up.

On this page
  1. A GDPR claim is not a GDPR process
  2. Legal basis: what to ask for in writing
  3. The data processing agreement: clauses worth requesting
  4. Where the data actually lives
  5. Opt-out handling and its service commitment
  6. Copy quality as a compliance signal, not just a language signal
  7. Putting the checklist to use on a vendor call

A GDPR claim is not a GDPR process

Nearly every outbound agency selling into Germany states somewhere on its site that it is GDPR compliant. That sentence costs nothing to write and proves nothing on its own. GDPR compliance is a set of documented decisions, a legal basis, a processing agreement, a data residency answer, not a single fact a vendor can assert and move on from.

This page is a procurement checklist rather than legal advice: a set of specific things to request from any outbound vendor before signing, so the buyer can judge whether a real process sits behind the compliance sentence on the homepage. It applies to any outbound agency selling into the German market, whichever country the agency itself is based in.

No agency should be exempted from this checklist on the basis of reputation or size, Ripe Leads included. A vendor that resists a straightforward request for its DPA or its legal-basis documentation has already answered the question the checklist is trying to ask.

The checklist below is organised around five specific requests, legal basis, the data processing agreement, data residency, opt-out handling, and copy quality as an indirect signal. Each one is something a buyer can ask for directly and receive a concrete answer to, rather than a general assurance that has to be taken on trust.

Cold B2B outreach under GDPR generally relies on one of two legal bases: consent, obtained before the first message, or legitimate interest, a narrower basis that requires the sender to have weighed its own interest against the recipient's rights and to be able to show that weighing was actually done, not just asserted after the fact.

The specific request to make is for the vendor's written legitimate-interest assessment, or its consent-capture method if it relies on consent instead, not a verbal assurance that "we have a legal basis." A vendor with a real process will have this documented already, because it needed to write it down for its own compliance purposes regardless of whether a prospective client ever asked to see it.

A vendor relying on legitimate interest should also be able to explain, specifically, why cold B2B outreach to the recipient's business role falls within that basis, rather than repeating the phrase "legitimate interest" as though naming it were the same as justifying it. The assessment itself is meant to weigh the sender's interest against the recipient's rights in writing, and a vendor unable to produce that reasoning has not actually done the assessment it is claiming.

The data processing agreement: clauses worth requesting

Any agency processing contact data on a client's behalf should be able to produce a data processing agreement, a DPA, without hesitation. The document itself is standard enough that its absence, or a vendor's reluctance to produce one quickly, is itself informative.

A vendor able to produce a document covering all five points quickly is showing a real, existing process. A vendor that needs to draft one from scratch once asked is, at best, treating GDPR as a checkbox to complete only when a client requests it.

It is worth reading the DPA itself rather than accepting a vendor's summary of it. A document that is long on general reassurance and short on the five specific points above is not meaningfully different from having no DPA at all, since the whole purpose of the document is to make each of those five points checkable rather than asserted.

Where the data actually lives

Data residency and sub-processor location matter specifically for German buyers, who tend to scrutinise this more closely than buyers in some other European markets. The question worth asking directly is where contact data is stored, which country's data protection regime governs that storage, and whether any part of the processing chain sits outside the European Economic Area without an appropriate safeguard in place.

A vendor should be able to answer this in one or two sentences, naming the actual storage location and any relevant safeguard, rather than a general statement that "we take data security seriously." The specificity of the answer is itself part of the signal.

This question also surfaces how many hands the data actually passes through. An agency that builds and hosts its own contact database has a shorter, easier-to-audit chain than one that resells data sourced from a separate third-party provider, and asking who that provider is, and where it is based, is a reasonable follow-up rather than an intrusive one.

Opt-out handling and its service commitment

An opt-out or unsubscribe request needs to be honoured promptly, and a vendor should be able to state, specifically, how quickly a recipient's opt-out is processed and confirmed across every list and campaign that contact might otherwise appear on. A vague answer, "we handle opt-outs," without a stated timeframe or a description of how the suppression is enforced across future sends, is not a real service-level commitment.

This is worth confirming in writing before a campaign starts, not discovering after a first complaint arrives from a recipient who unsubscribed and was contacted again regardless.

A related question worth asking directly is whether an opt-out on one campaign or one product line carries across every future campaign the vendor runs on the client's behalf, or only the specific send it was recorded against. A suppression list that resets between campaigns is a compliance gap dressed up as a technical limitation, and a vendor should be able to describe how it prevents exactly that.

Copy quality as a compliance signal, not just a language signal

German outbound copy that is clearly translated from an English template, rather than written for a German business audience in the formal Sie register, is a signal worth reading alongside the compliance checklist above, not instead of it. An agency that has not invested in genuinely localised messaging has often not invested in a genuinely localised compliance process either; the two tend to travel together in practice.

Requesting a real, recent, unedited outbound sample sent to a German company, and having someone fluent read it before signing, is a low-cost check that surfaces more than it might first appear to.

The correlation is not a legal rule, and a well-localised vendor can still have a weak compliance process, or the reverse. It is offered here as a practical heuristic rather than a substitute for the checklist itself: a signal worth noting alongside the direct questions, not instead of asking them.

Putting the checklist to use on a vendor call

Bring five specific requests into the vendor conversation rather than a general question about GDPR compliance: the legal-basis documentation, the DPA itself, the data storage and sub-processor answer, the opt-out handling commitment in writing, and a real German-language copy sample.

A vendor able to produce all five without delay has shown a real process. A vendor that answers with reassurance rather than documentation has not, regardless of how confidently the reassurance is delivered, and that gap is worth treating as decisive rather than as a minor procedural detail to sort out later.

None of this checklist requires legal training to use. It requires asking for documents instead of accepting sentences, and treating a vendor's hesitation to produce one as an answer in itself, which is often the single most useful piece of information the whole vetting process turns up.

Keep a written record of what each vendor actually sent, not just what was said out loud on the call. A DPA received by email is easy to compare against another vendor's DPA later on; a verbal assurance that everything is fully compliant is not, and that difference matters most if a real question ever comes up after the contract has already been signed.

Frequently asked

What is a data processing agreement and why does it matter?
A DPA is the contract governing how a vendor processes personal data on a client's behalf. It should name the scope of processing, any sub-processors, how data subject rights requests are handled, breach notification terms, and what happens to the data at contract end. A vendor unable to produce one is not showing a real GDPR process.
What is the difference between legitimate interest and consent for cold outreach in Germany?
Consent means the recipient agreed to be contacted before the first message. Legitimate interest is a narrower basis requiring the sender to document that it weighed its own interest against the recipient's rights before relying on it. A vendor relying on legitimate interest should have that documented assessment in writing, not just an assertion that it applies.
What should data residency documentation actually show?
The specific country or region where contact data is stored, which data protection regime governs it, and whether any part of the processing chain sits outside the European Economic Area, along with what safeguard applies if it does. A vague reassurance without a named location is not sufficient.
What counts as a real opt-out handling commitment?
A stated timeframe for processing an opt-out request and a description of how that suppression is enforced across every future campaign and list, not just a general statement that opt-outs are handled.
Does any outbound agency guarantee full GDPR compliance?
No vendor can honestly guarantee compliance outright, since compliance depends on how a documented process is actually applied to a specific campaign, not on a single claim. What a buyer can check is whether a real, checkable process, legal basis, DPA, data residency answer, opt-out handling, exists behind the claim.

Want the accounts behind these numbers?

Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.

Book a strategy call