# 152-FZ and Personal Data in B2B Outreach

Russia’s Federal Law No. 152-FZ sets rules for collecting, storing and using personal data. In B2B outreach, a work email can be personal data when it identifies a specific person, so you need to know where the contact came from, why you use it, who can access it and how requests to stop communication are handled.

## Which B2B list data needs its own process?

A company name and a shared address such as info@company.ru do not, by themselves, identify a person. But a record such as “Irina Petrova, Commercial Director, irina@company.ru” does. Access to such records should be controlled, especially when an agency delivers [white-label outreach](/en/services/white-label-outreach/) for another business.

| List record | Check before sending | Record internally |
|---|---|---|
| Decision-maker’s work email | Where it came from and whether it is current | Source and validation date |
| Name and job title | Whether they are necessary for the message | Purpose of use |
| Request not to be contacted | Who receives and acts on the request | Suppression status |

A short operating procedure is more useful than a folder of declarations: document the contact source, appoint an owner for the list, limit access and maintain a separate suppression list.

## Why does contact handling affect replies, not just risk?

Recipients judge a cold email in seconds. Using someone’s name without a clear connection to their role or company can feel like surveillance rather than a business approach, and trust is lost before they consider the offer. Preparing contact records is part of [B2B lead list building](/en/services/lead-list-building/), not a task to leave until after launch.

A weak opening is: “Alexey, we found your phone number and email and would like to offer our services.” It tells the reader that data was collected but gives no reason for a conversation. A better approach is: “Alexey, we saw that your company supplies packaging to food manufacturers. Is expanding your regional dealer network currently on the agenda?” The name does not replace relevance; the question gives the recipient an easy way to reply.

- Define which roles and fields are genuinely needed for the outreach hypothesis.
- Keep the source and validation date for every record; do not merge exports with unknown provenance.
- Send only the fields needed to personalise the message and route a reply.
- When someone asks not to be contacted, stop all future touches immediately and record the reason.

List hygiene solves a different problem: invalid addresses and duplicates should be removed before launch through [email list verification](/en/services/list-verification/). It does not replace a personal-data process, but it helps prevent the same person receiving a message twice from duplicate records.

## When is this approach not enough?

A sound data process does not make a cold email welcome. If the offer is irrelevant to the recipient’s role, the company does not serve that market, or the record is outdated, careful storage will not create interest. Do not launch from a purchased list with no clear provenance: you cannot reliably check either the currency of the records or the basis for using them.

The “collect everything and sort it out later” approach is not suitable either. Personal phone numbers, dates of birth and sales notes add risk without being needed for a first B2B email. When returning to existing customers, separate CRM relationship history from a cold list first; see [CRM reactivation for former B2B customers](/en/cases/crm-reactivation/).

- Every record has a clear source.
- No unnecessary fields are passed into outreach.
- Only campaign participants can access the list.
- A request not to be contacted stops every future touch.

Personal data handling sits alongside [cold email](/en/glossary/cold-email/), [B2B outreach](/en/glossary/outreach/) and email suppression practices. Treat them together: one concerns the message, another the end of communication, and the third the wider process for launching a campaign.

## Frequently asked questions

**Is an employee’s work email personal data?**

If the address is linked to an identifiable person, treat it as personal data for campaign planning. Record the source, intended use and the people who can access that contact record.

**Can you email a company’s shared inbox?**

A shared inbox does not usually identify a specific person, but the message still needs to be relevant to the company. Do not automatically add the employee who replies to a new sequence without a separate reason to do so.

**What should happen when a recipient asks for their data to be deleted?**

First, stop every active sequence for that contact so no further messages are sent. Then route the request to the person responsible for the list and preserve a suppression record so the address is not reintroduced in a later export.

**Is a link to a privacy policy enough?**

A privacy-policy link can explain your approach, but it does not replace the process itself. You still need a clear data source, restricted access and a working way to act on recipient requests.

---
Source: https://ot9.ru/en/glossary/152-fz/ · OT9 (KAP Group) · updated 2026-08-10