Outbound Wiki

Lead source provenance

How to verify and document the origin, collection method and permitted use of contact data from public sources, vendors and enrichment tools.

Treat a purchased lead list as a chain of custody. Before anyone uses a record, you should be able to say who collected it, where the contact saw the request, which organisation was named, what later enrichment changed, and what the lawful basis permits. Provenance can split within a record: a lead may enter through a direct interaction and pick up third-party data later.1 A vendor label for the whole row can hide different origins for individual fields. Base the approval decision on the field trail, consent recipient, and stated use.

Map the scope

Start with the records you plan to use and the people they describe. Set the scope before discussing outreach, since the classification determines which checks belong in the file.

Personal data is information that relates to an identified or identifiable natural person.2 The GDPR provides the legal framework for collecting, processing, and storing personal data of individuals in the EU, while UK GDPR applies to individuals in the UK.3 Lawful processing requires an appropriate lawful basis and compliance with other statutory or common-law obligations.4

Create a record for each source or batch you may use. Include the data fields, intended purpose, population, source, collection method, and proposed lawful basis. Before collecting personal data, identify and document that lawful basis.5

Trace collection

Ask the provider to show the route from the person to your file. Check the collection method, original source, and every third party that handled the record.

Ask the provider to explain "How personal data will be collected".6 Data brokers often collect personal information indirectly through third-party sources rather than directly from consumers.7 Begin by identifying all third-party sources that use external lead forms.8

Record the source of every address so you can evaluate the provider and answer provenance questions later.9 Ask for the source at record level where possible. Continue only when the provider can explain the collection path for the records you plan to use.

Keep provenance at field level

A source label for a whole record is too broad when fields arrived through different routes. Keep the original collection source visible after enrichment and attach later additions to their own source.

Each field should carry provenance metadata so the teams handling the records know where it came from.10 A SourceName property is the name of the source where records originated.11 Use that pattern for the fields you plan to activate, and preserve the original source when another provider adds or changes a value.

The review file should let someone inspect an email address, phone number, or other personal data field and see its origin without rebuilding the history from memory. If the provider can explain only the list's general origin, pause the record until field level provenance is available.

Verify permission

Treat permission as a record with a recipient and a purpose. A vendor's statement that people agreed to marketing is only a starting point. Establish what each person agreed to and who that agreement covered.

Consent is an unambiguous, informed, and freely given indication that an individual agrees to personal data being processed.12 Businesses using lead generators to source consent should verify that the lead generators obtain individual, one-to-one consent.13

Ask to see the wording shown to the person, the organisation or organisations named, the collection context, and the record connecting that wording to the contact. Check whether the permission covers the channel and purpose you plan to use. Continue only when the permission record matches your intended use and identifies the relevant recipient.

Set the lawful basis and notice

Choose the permitted use before the list enters your workflow. Keep the basis attached to its purpose, since a basis selected for one activity may not support another.

Consent and legitimate interests are the lawful bases commonly used for marketing and lead generation processing.14 Legitimate interests applies when processing is necessary for a business or organisation's legitimate interests unless the individual's interests require protection and override those interests.15

Document the basis and state it clearly in your privacy policy and privacy notice.16 Record the purpose in the same review file as the source and consent details. Some marketing activities require consent as the only appropriate lawful basis.17 That decision determines whether the list can proceed to the channel you have chosen.

Decide whether the list can be used

Make the approval decision explicit. A list passes when its source trail, field provenance, permission record, lawful basis, and notice position are clear enough for someone else to check.

Public professional sources and vendor databases with disclosed provenance are described as defensible data sources.18 Use that as a source quality test, then check the provider's collection and documentation before accepting its list.

Keep the approval record with the list. It should show the provider reviewed, the sources identified, the collection method, the permission record, the intended purpose, and why the lawful basis covers that purpose. If any item is missing, hold the records out of outreach until the gap is resolved.

What not to do

These mistakes turn a provenance check into a vendor trust exercise. Tie the decision to records you can inspect.

  • Do not accept a list from a provider without investigating the provider and requiring support for the information in the list.19
  • Do not assume a lead generator's consent covers your outreach. Verify consent specific to the lead buyer or caller.20
  • Do not change the lawful basis later without a good reason.21
  • Do not use legitimate interests for an activity where consent is the only appropriate lawful basis.17

Tool for this

Reaching the people who decide

For the contact side I would point to Intedat. It lists the people at each company it selects with position, department and level, purchasing, directors, statutory bodies and the C-level included, and a workflow can name the department it wants reached first. You still pick the person yourself, and an address it guessed from the company's email pattern carries a badge saying so, which is how I want to be told.

Open Intedat

Sources

  1. 1
    “A lead may be collected directly, then enriched or supplemented with third-party data later.”
  2. 2
    “personal dataInformation which relates to an identified or identifiable natural person.”
  3. 3
    “The General Data Protection Regulation (GDPR) provides the legal framework for the collection, processing, and storage of personal data of individuals in the EU (with the UK GDPR applying to individuals in the UK).”
  4. 4
    “lawfullyIn data protection terms, 'lawfully' must satisfy one of the appropriate lawful basis for processing and must not contravene any other statutory or common law obligations.”
  5. 5
    “before collecting any personal data, you must first identify and document the lawful basis for doing so.”
  6. 6
    “How personal data will be collected”
  7. 7
    “Data brokers often collect personal information indirectly, through third-party sources rather than from consumers.”
  8. 8
    “Start by identifying all third-party sources using external lead forms.”
  9. 9
    “Record the source of every address if possible. It's how you evaluate providers, and it's your answer when someone asks where their data came from.”
  10. 10
    “Tag each field with provenance metadata so GTM, ops, and compliance teams know where it came from”
  11. 11
    “The name of the source where the records originated.”
  12. 12
    “ConsentAn unambiguous, informed and freely given indication by an individual agreeing to their personal data being processed. – where an individual has given consent for their personal data to be processed”
  13. 13
    “In order to be prepared for this rule to come into effect, and in an abundance of caution, businesses who use lead generators to source potential consumers’ consent should ascertain that the lead generators are obtaining individual, one-to-one consent.”
  14. 14
    “The lawful bases commonly used for processing personal data for marketing and lead generation purposes are consent and legitimate interests.”
  15. 15
    “Legitimate InterestsLegitimate interests is one of the six lawful bases for processing personal data. You must have a lawful basis in order to process personal data in line with the ‘lawfulness, fairness and transparency’ principle. – where the processing of an individual’s personal data is necessary for the legitimate interests of a business or organisation, unless there is a good reason to protect the individual’s personal data, which then overrides those legitimate interests”
  16. 16
    “After determining a lawful basis, you must document it and ensure the information is clearly stated in your privacy policy and privacy noticeA clear, open and honest explanation of how an organisation processes personal data..”
  17. 17
    “For certain types of marketing activities, consent is the only appropriate lawful basis to use.”
  18. 18
    “Public professional sources and vendor databases with disclosed provenance are defensible.”
  19. 19
    “You’ve really got to do your due diligence on anybody that's providing you with those types of [lead] lists because you live or die…on whether you can support and substantiate what's been provided to you in those lists. It’s really important that you make sure that you work with quality lead generators and that you do your due diligence.”
  20. 20
    “Lead buyers will need to increase their vigilance to make sure that any lead sold to them provides specific consent to the lead buyer/caller.”
  21. 21
    “It is important to choose the most appropriate lawful basis, as it is difficult to change later without good reason.”