Outbound Wiki

Outbound data vendors

How to assess enrichment providers, lead databases, email platforms and other vendors that process prospect data for an outreach program.

Buying a lead database, enrichment service, or email platform changes who handles prospect data. Use the review as a gate: map the data, test how the vendor got and uses it, inspect the people and systems in the chain, then settle the controls and contract terms. Outside data and profiling can improve targeting.1 That use must be fair, and people must be told about it.2 If the vendor cannot show how those conditions are met, stop before comparing coverage or price.

Stage What you are trying to learn Example question
Scope Which people, data and markets enter the review Which records and markets will this vendor touch?
Source and purpose Where the data came from and why you need it For each field, what is its source and intended use?
Notice and lawful basis What people are told and what permits the processing What notice and lawful basis cover this use?
Data chain Who handles the data and where it moves Who are the processors and sub-processors?
Controls and rights How security, transfers, objections and deletion work Show the process when someone objects or asks for removal.
Agreement and review Which risks remain and when the vendor is reviewed again What needs to be recorded in the DPA?

Scope the review

Decide first what data and markets the vendor will touch. This keeps a vendor questionnaire from replacing a decision about your outreach program.

Personal data is information that relates to an identified or identifiable natural person.3 If the program handles EU or UK personal data, it must be collected, processed, and stored lawfully, transparently, and securely.4 Record the lawful basis for the processing and check the other statutory or common-law duties that apply.5

If your company is based outside the EU, audit the data before assuming the program sits outside the review.6 Record the markets, data categories, intended uses, and teams that will receive the vendor's output. Proceed once you can describe the program without relying on the vendor's product labels.

Check source and purpose

Ask the vendor to explain each field when it enters your workflow. You need a usable record of the source, purpose, and notice that supports the use.

Organizations may obtain contact details and additional information from several source types.7 Ask whether each record came from someone with a direct relationship, a third party that sells or rents lists, or a publicly available source. Your organization must tell people that it wants to collect and use their information for direct marketing.8 The privacy information must clearly explain what you want to do and be easy for people to understand.9

Ask for the purpose attached to each field, when people receive the relevant information, and how the vendor corrects a bad record. Continue only when the vendor can answer those questions without sending you to a general privacy page.

Map the data chain

Connect each data field to a system, location, and party before you assess assurances or negotiate terms.

Ask for the vendor's data inventory and flow map. Providers with strong privacy programs will have much of the relevant data-location information in those records.10 Record the country where data is stored and whether it sits on a legacy machine, an on-premises server, or in the cloud.11

Keep identity information for every processor, sub-processor, and other relevant party readily available.12 That information should include the processor's name, position, contact details, and task, including how its task is separated from other sub-processors where needed.13 Processors should proactively provide current identity information for relevant sub-processors.14 The DPA can specify how that information reaches you.15

Name each party in the chain, explain its task, and locate the systems involved. If the vendor cannot provide that view, leave the purchase paused.

Classify the vendor model

A service may be more than a software utility if it supplies personal data about people with whom it has no direct relationship. Classify the model before deciding which checks and registrations belong in the review.

A data broker generally collects personal information about people with whom it has no direct relationship and sells or licenses that information to third parties.16 Most businesses offering lead generation services will qualify as data brokers when they sell personal data about people who are not direct customers.17 That classification creates standalone compliance obligations regardless of where the data originated.18

Ask whether the vendor sells, licenses, enriches, or only processes the records for your program. Ask who owns the source relationship and who answers a person's request. Use the answer to set the diligence path, contract review, and market checks.

Test controls and rights

Use the vendor's operating details to test what happens when something goes wrong. Ask for documents or demonstrations that let you judge the control itself.

Run these checks:

  • Review the vendor's data handling practices.19
  • Assess its policies and procedures.20
  • Evaluate its technical security measures.21
  • Review its international data transfer controls and processes.22
  • Mitigate the remaining risks and finalise the DPA.23

Test the objection, opt-out, and deletion path separately. Ask what happens in the vendor's system, what reaches downstream parties, and how your outreach records are updated. Require notification systems and monitoring protocols that support compliance.24 Proceed only when the path has an owner, a response process, and a way to confirm that the action reached the relevant systems.

Check local requirements

A vendor can pass your internal review and still leave a market-specific question unanswered. Run this check alongside the data-chain review because the vendor's operating model can trigger duties outside the contract.

Lead generation activities are regulated by privacy laws and typically trigger state data broker law obligations when they involve selling data about people with whom the company has no direct relationship.25 An increasing number of states have enacted data broker laws.26 Many states require annual registration with a designated regulator.27

Ask whether the vendor's model triggers registration or other local requirements in each market where you trade. Record who owns that check and what the vendor must provide to support it.

Close the review and set the cadence

Approval should leave a record of the decision, the open risks, and when you will look again. A signed document without that record leaves the operational questions unresolved.

For the initial processor, run a case-by-case analysis at appropriate review intervals and count only safeguards that the processor has demonstrated to your satisfaction.28 When a vendor handles personal data, document the data-protection responsibilities of both parties.29 Work with IT, compliance, and legal teams on the review.30

Set a trigger for changes to the source, sub-processors, storage locations, transfer route, or rights process. Approve the vendor when the remaining risk has an owner, the agreement records the required terms, and the next review has a clear reason to happen.

What not to do

Watch for these failure modes:

  • Do not treat the vendor's source label as proof that the data is safe to use. Data brokers may ignore opt-out requests and may offer no opt-out option.31
  • Do not assume a GDPR review covers every market. GDPR compliance does not establish compliance everywhere.32 Local rules such as the CCPA can apply where you trade.33

Tool for this

Reaching the people who decide

For the contact side I would point to Intedat. It lists the people at each company it selects with position, department and level, purchasing, directors, statutory bodies and the C-level included, and a workflow can name the department it wants reached first. You still pick the person yourself, and an address it guessed from the company's email pattern carries a badge saying so, which is how I want to be told.

Open Intedat

Sources

  1. 1
    “Getting new information about people from other sources or by profiling their interests and habits can help target your direct marketing more effectively.”
  2. 2
    “But you must ensure that doing this is fair and tell people about it.”
  3. 3
    “personal dataInformation which relates to an identified or identifiable natural person.”
  4. 4
    “it is crucial to understand your responsibilities under data protection laws to ensure that all EU and UK personal dataInformation which relates to an identified or identifiable natural person. is collected, processed, and stored lawfullyIn data protection terms, 'lawfully' must satisfy one of the appropriate lawful basis for processing and must not contravene any other statutory or common law obligations., transparently, and securely.”
  5. 5
    “lawfullyIn data protection terms, 'lawfully' must satisfy one of the appropriate lawful basis for processing and must not contravene any other statutory or common law obligations.”
  6. 6
    “Many companies based outside of the EU may also inadvertently process data relating to EU citizens, so the first step for those companies is to audit their data and discover whether any of it relates to EU citizens.”
  7. 7
    “There are a number of ways that you may decide to seek contact details and additional information to use for your direct marketing, including from:”
  8. 8
    “You must tell people that you want to collect and use their information for direct marketing purposes.”
  9. 9
    “You must be clear about what you want to do and your privacy information must be easy for people to understand.”
  10. 10
    “Providers with robust privacy programs will have much of this information in data inventories and flow maps.”
  11. 11
    “Knowing where data is stored (In what country is it stored? Is it on a legacy machine or a server on premises? Is it in the cloud?)”
  12. 12
    “Yes, the EDPB considers that controllers should have identity information for all processors, sub-processors "etc." readily available at all times.”
  13. 13
    “Identity information should include the name, position and contact details of the (sub-) processor and a description of its task (if applicable, including the delimitation of the task compared to other sub-processors).”
  14. 14
    “To enable the controller to comply, processors should proactively provide the required and up-to-date identity information of all relevant sub-processors to the controller.”
  15. 15
    “How this information is communicated can be specified in the data processing agreement.”
  16. 16
    “While definitions vary, a “data broker” is generally a business that collects personal information about individuals with whom it has no direct relationship and sells or licenses that information to third parties.”
  17. 17
    “Because lead generation services involve selling personal data about individuals who are not direct customers, most Companies offering these services will qualify as data brokers.”
  18. 18
    “This classification creates standalone compliance obligations, regardless of where the data originates, and often increases visibility with regulators and plaintiffs’ lawyers.”
  19. 19
    “Review the vendor’s data handling practices”
  20. 20
    “Assess policies and procedures”
  21. 21
    “Evaluate technical security measures”
  22. 22
    “Review international data transfer controls and processes”
  23. 23
    “Mitigate risks & finalise the Data Processor Agreement (DPA)”
  24. 24
    “With stricter enforcement and penalties, data brokers must implement notification systems and monitoring protocols to ensure compliance.”
  25. 25
    “These activities are regulated not only by comprehensive privacy laws (“Privacy Laws”) but also, because these services involve selling data about individuals with no direct relationship with the Company, they also typically trigger obligations under state data broker laws (“Data Broker Laws”).”
  26. 26
    “An increasing number of states – including California, Vermont, Texas, and Oregon – have enacted Data Broker Laws, with more states expected to follow.”
  27. 27
    “1. Registration – Many states require annual registration with a designated regulator. Registration fees can be significant – for example, California charges $6,600 annually – and failure to register may result in penalties (e.g., $200 per day and expenses incurred by the CPPA in administration of registration in California).”
  28. 28
    “For the initial processor, controllers must conduct a case-by-case analysis (to be reviewed at appropriate intervals), taking into account only the safeguards effectively demonstrated by the processor "to the satisfaction of the controller."”
  29. 29
    “However, when you have vendors handling personal data, it’s critical to understand the associated data protection responsibilities of both parties.”
  30. 30
    “In this guide, we’ll discuss the items that fall under marketing, but you will need to work closely with your IT department, compliance and legal teams.”
  31. 31
    “However, in practice, many data brokers simply ignore opt-out requests and do not offer an opt-out option.”
  32. 32
    “Don’t make the mistake of assuming that if you’re GDPR-compliant, you’re probably compliant in all markets.”
  33. 33
    “Although GDPR is arguably the most robust data regulation in the world, you must also be aware of the nuances of local regulations in any markets that you trade in, such as the California Consumer Privacy Act (CCPA).”