Buying a lead database, enrichment service, or email platform changes who handles prospect data. Use the review as a gate: map the data, test how the vendor got and uses it, inspect the people and systems in the chain, then settle the controls and contract terms. Outside data and profiling can improve targeting.1 That use must be fair, and people must be told about it.2 If the vendor cannot show how those conditions are met, stop before comparing coverage or price.
| Stage | What you are trying to learn | Example question |
|---|---|---|
| Scope | Which people, data and markets enter the review | Which records and markets will this vendor touch? |
| Source and purpose | Where the data came from and why you need it | For each field, what is its source and intended use? |
| Notice and lawful basis | What people are told and what permits the processing | What notice and lawful basis cover this use? |
| Data chain | Who handles the data and where it moves | Who are the processors and sub-processors? |
| Controls and rights | How security, transfers, objections and deletion work | Show the process when someone objects or asks for removal. |
| Agreement and review | Which risks remain and when the vendor is reviewed again | What needs to be recorded in the DPA? |
Scope the review
Decide first what data and markets the vendor will touch. This keeps a vendor questionnaire from replacing a decision about your outreach program.
Personal data is information that relates to an identified or identifiable natural person.3 If the program handles EU or UK personal data, it must be collected, processed, and stored lawfully, transparently, and securely.4 Record the lawful basis for the processing and check the other statutory or common-law duties that apply.5
If your company is based outside the EU, audit the data before assuming the program sits outside the review.6 Record the markets, data categories, intended uses, and teams that will receive the vendor's output. Proceed once you can describe the program without relying on the vendor's product labels.
Check source and purpose
Ask the vendor to explain each field when it enters your workflow. You need a usable record of the source, purpose, and notice that supports the use.
Organizations may obtain contact details and additional information from several source types.7 Ask whether each record came from someone with a direct relationship, a third party that sells or rents lists, or a publicly available source. Your organization must tell people that it wants to collect and use their information for direct marketing.8 The privacy information must clearly explain what you want to do and be easy for people to understand.9
Ask for the purpose attached to each field, when people receive the relevant information, and how the vendor corrects a bad record. Continue only when the vendor can answer those questions without sending you to a general privacy page.
Map the data chain
Connect each data field to a system, location, and party before you assess assurances or negotiate terms.
Ask for the vendor's data inventory and flow map. Providers with strong privacy programs will have much of the relevant data-location information in those records.10 Record the country where data is stored and whether it sits on a legacy machine, an on-premises server, or in the cloud.11
Keep identity information for every processor, sub-processor, and other relevant party readily available.12 That information should include the processor's name, position, contact details, and task, including how its task is separated from other sub-processors where needed.13 Processors should proactively provide current identity information for relevant sub-processors.14 The DPA can specify how that information reaches you.15
Name each party in the chain, explain its task, and locate the systems involved. If the vendor cannot provide that view, leave the purchase paused.
Classify the vendor model
A service may be more than a software utility if it supplies personal data about people with whom it has no direct relationship. Classify the model before deciding which checks and registrations belong in the review.
A data broker generally collects personal information about people with whom it has no direct relationship and sells or licenses that information to third parties.16 Most businesses offering lead generation services will qualify as data brokers when they sell personal data about people who are not direct customers.17 That classification creates standalone compliance obligations regardless of where the data originated.18
Ask whether the vendor sells, licenses, enriches, or only processes the records for your program. Ask who owns the source relationship and who answers a person's request. Use the answer to set the diligence path, contract review, and market checks.
Test controls and rights
Use the vendor's operating details to test what happens when something goes wrong. Ask for documents or demonstrations that let you judge the control itself.
Run these checks:
- Review the vendor's data handling practices.19
- Assess its policies and procedures.20
- Evaluate its technical security measures.21
- Review its international data transfer controls and processes.22
- Mitigate the remaining risks and finalise the DPA.23
Test the objection, opt-out, and deletion path separately. Ask what happens in the vendor's system, what reaches downstream parties, and how your outreach records are updated. Require notification systems and monitoring protocols that support compliance.24 Proceed only when the path has an owner, a response process, and a way to confirm that the action reached the relevant systems.
Check local requirements
A vendor can pass your internal review and still leave a market-specific question unanswered. Run this check alongside the data-chain review because the vendor's operating model can trigger duties outside the contract.
Lead generation activities are regulated by privacy laws and typically trigger state data broker law obligations when they involve selling data about people with whom the company has no direct relationship.25 An increasing number of states have enacted data broker laws.26 Many states require annual registration with a designated regulator.27
Ask whether the vendor's model triggers registration or other local requirements in each market where you trade. Record who owns that check and what the vendor must provide to support it.
Close the review and set the cadence
Approval should leave a record of the decision, the open risks, and when you will look again. A signed document without that record leaves the operational questions unresolved.
For the initial processor, run a case-by-case analysis at appropriate review intervals and count only safeguards that the processor has demonstrated to your satisfaction.28 When a vendor handles personal data, document the data-protection responsibilities of both parties.29 Work with IT, compliance, and legal teams on the review.30
Set a trigger for changes to the source, sub-processors, storage locations, transfer route, or rights process. Approve the vendor when the remaining risk has an owner, the agreement records the required terms, and the next review has a clear reason to happen.
What not to do
Watch for these failure modes:
- Do not treat the vendor's source label as proof that the data is safe to use. Data brokers may ignore opt-out requests and may offer no opt-out option.31
- Do not assume a GDPR review covers every market. GDPR compliance does not establish compliance everywhere.32 Local rules such as the CCPA can apply where you trade.33