Treat a purchased lead list as a chain of custody. Before anyone uses a record, you should be able to say who collected it, where the contact saw the request, which organisation was named, what later enrichment changed, and what the lawful basis permits. Provenance can split within a record: a lead may enter through a direct interaction and pick up third-party data later.1 A vendor label for the whole row can hide different origins for individual fields. Base the approval decision on the field trail, consent recipient, and stated use.
Map the scope
Start with the records you plan to use and the people they describe. Set the scope before discussing outreach, since the classification determines which checks belong in the file.
Personal data is information that relates to an identified or identifiable natural person.2 The GDPR provides the legal framework for collecting, processing, and storing personal data of individuals in the EU, while UK GDPR applies to individuals in the UK.3 Lawful processing requires an appropriate lawful basis and compliance with other statutory or common-law obligations.4
Create a record for each source or batch you may use. Include the data fields, intended purpose, population, source, collection method, and proposed lawful basis. Before collecting personal data, identify and document that lawful basis.5
Trace collection
Ask the provider to show the route from the person to your file. Check the collection method, original source, and every third party that handled the record.
Ask the provider to explain "How personal data will be collected".6 Data brokers often collect personal information indirectly through third-party sources rather than directly from consumers.7 Begin by identifying all third-party sources that use external lead forms.8
Record the source of every address so you can evaluate the provider and answer provenance questions later.9 Ask for the source at record level where possible. Continue only when the provider can explain the collection path for the records you plan to use.
Keep provenance at field level
A source label for a whole record is too broad when fields arrived through different routes. Keep the original collection source visible after enrichment and attach later additions to their own source.
Each field should carry provenance metadata so the teams handling the records know where it came from.10 A SourceName property is the name of the source where records originated.11 Use that pattern for the fields you plan to activate, and preserve the original source when another provider adds or changes a value.
The review file should let someone inspect an email address, phone number, or other personal data field and see its origin without rebuilding the history from memory. If the provider can explain only the list's general origin, pause the record until field level provenance is available.
Verify permission
Treat permission as a record with a recipient and a purpose. A vendor's statement that people agreed to marketing is only a starting point. Establish what each person agreed to and who that agreement covered.
Consent is an unambiguous, informed, and freely given indication that an individual agrees to personal data being processed.12 Businesses using lead generators to source consent should verify that the lead generators obtain individual, one-to-one consent.13
Ask to see the wording shown to the person, the organisation or organisations named, the collection context, and the record connecting that wording to the contact. Check whether the permission covers the channel and purpose you plan to use. Continue only when the permission record matches your intended use and identifies the relevant recipient.
Set the lawful basis and notice
Choose the permitted use before the list enters your workflow. Keep the basis attached to its purpose, since a basis selected for one activity may not support another.
Consent and legitimate interests are the lawful bases commonly used for marketing and lead generation processing.14 Legitimate interests applies when processing is necessary for a business or organisation's legitimate interests unless the individual's interests require protection and override those interests.15
Document the basis and state it clearly in your privacy policy and privacy notice.16 Record the purpose in the same review file as the source and consent details. Some marketing activities require consent as the only appropriate lawful basis.17 That decision determines whether the list can proceed to the channel you have chosen.
Decide whether the list can be used
Make the approval decision explicit. A list passes when its source trail, field provenance, permission record, lawful basis, and notice position are clear enough for someone else to check.
Public professional sources and vendor databases with disclosed provenance are described as defensible data sources.18 Use that as a source quality test, then check the provider's collection and documentation before accepting its list.
Keep the approval record with the list. It should show the provider reviewed, the sources identified, the collection method, the permission record, the intended purpose, and why the lawful basis covers that purpose. If any item is missing, hold the records out of outreach until the gap is resolved.
What not to do
These mistakes turn a provenance check into a vendor trust exercise. Tie the decision to records you can inspect.
- Do not accept a list from a provider without investigating the provider and requiring support for the information in the list.19
- Do not assume a lead generator's consent covers your outreach. Verify consent specific to the lead buyer or caller.20
- Do not change the lawful basis later without a good reason.21
- Do not use legitimate interests for an activity where consent is the only appropriate lawful basis.17