How to Vet a B2B Data Provider GDPR and Do-Not-Call Compliance Before You Sign
Four pre-contract checks to verify a data provider compliance posture: DNC screening, legitimate interest, CCPA registration, and security certifications.
If you buy B2B contact data, you have signed a data processing agreement, which means you have already accepted - mostly on the vendor's word - that the phone numbers and email addresses about to flow into your outbound stack were collected and screened lawfully. I have sat on both sides of that negotiation, first as the RevOps buyer who needed 5,000 records before the quarter ended, later as the person who had to explain to leadership why a campaign I approved was suddenly a regulatory conversation. Most teams never pressure-test a provider's GDPR and Do-Not-Call posture before signing. They compare price, match rate, and record count, then route the CSV straight into the sequencer. The liability does not stay with the vendor when a recipient complains; it lands on whoever contacted them.
The good news is that compliance posture is now auditable before you commit, because the vendors who take it seriously publish enough detail to check. The bad news is that almost nobody asks for it. Here is the pre-contract checklist I wish I had used.
Ask where the records actually come from
GDPR compliance starts upstream of the database. A provider that scrapes, buys, or otherwise assembles contact records has to be able to tell you, concretely, what its sourcing actually is, because that determines whether the data can be lawfully processed by anyone downstream. The cleanest public statement of what that answer should look like comes from Cognism's compliance explainer, which is unusually specific:
Cognism only obtains business contact data from publicly available sources. We validate our dataset on an ongoing basis. [...] Cognism has conducted a legitimate interest assessment, balancing tests, a transfer impact assessment and a data protection impact assessment with external legal counsel.
- Cognism Help Centre, How Does Cognism Comply with the Requirements of the GDPR?
Read that carefully and notice what a vendor with nothing to hide says out loud. It names a sourcing category (publicly available sources), commits to ongoing validation, and discloses that external counsel ran a legitimate interest assessment, a balancing test, a transfer impact assessment, and a DPIA. Now ask your shortlist the same questions and time how long it takes them to answer in writing. A vendor that can point you at a published compliance page is different from one that says "our legal team handles that" and goes quiet.
The follow-up question matters more: what does "publicly available" mean in practice, and who validates the records and how often? If a provider's records mostly trace back to scraped CRM exports and rep-uploaded lists, then "we comply with GDPR" is a slogan, not a process, and the accuracy problem will surface later as hard bounces and undeliverable calls regardless of what the contract says.
Match the Do-Not-Call screening to the numbers you will actually dial
Do Not Call registries are national, and so is the screening obligation. A Do-Not-Call registry, as the same documentation puts it, is a list that lets individuals register their phone numbers to indicate they do not wish to receive sales or marketing calls, and every country runs its own version, which means a provider's screening is only as good as the registry coverage it actually maintains. Cognism states it matches its database against Do Not Call lists covering Australia, Belgium, Croatia, Finland, France, Germany, Ireland, Italy, New Zealand, Norway, Portugal, Spain, Sweden, the United Kingdom's TPS and CTPS, and the United States, and that numbers appearing on a registry get flagged and masked in the platform rather than sold on.
The buyer's move here is to compare that list against the countries your SDRs will actually dial. If your team calls into Germany and France, you need the provider's screening to cover the German and French registries, not just the US one. Ask for the registry list in writing, then spot-check it, and request the masking behaviour in the contract rather than as a courtesy. The practical test I trust most is a small trial: take 50 numbers from a market you target, run them against the public registry where one exists, and see whether the vendor's flags match reality before you pay for the full file.
Ask for the Article 14 notice and a legitimate interest assessment you can actually read
When a provider sells you a contact record, it is transferring personal data it did not collect from the data subject, and under the GDPR that triggers the transparency obligation in Article 14: the data subject has to be notified that the organisation holds their data, how it will be processed, and how they can object. The vendor's job is to run that notice; your job is to verify it happens and to inherit the resulting opt-out data, because those preferences follow the record. I wrote about the mechanics of this from the outbound side in my post on GDPR Article 14 notices and legitimate interest for EMEA outbound, and the same logic applies in reverse when you are the buyer holding the vendor's feet to the fire.
The strongest single document you can request during procurement is the legitimate interest assessment itself. A real LIA is not a one-page "we have legitimate interest" sign-off; it is a documented balancing test that weighs the vendor's processing purpose against the data subject's rights and shows its working. Ask for it, expect a redacted version, and treat a flat refusal as a finding. If a vendor will not show you the balancing test that justifies selling business contact data, you are being asked to underwrite that legal position with your own campaigns.
This is exactly the seam where I have watched buyers get the division of responsibility wrong. When you licence data and run it through your own dialler and sequencer, you are making your own decision about legitimate interest for the outreach itself, which is separate from the vendor's basis for selling the record. The California side of the same question has its own machinery, and the buyer-side duties of honouring suppression and deletion requests are covered in my piece on CCPA opt-out suppression and DSAR duties for data buyers. Together they form the compliance surface you are signing up to: the vendor's upstream basis, your downstream handling, and the suppression data that has to travel with the records.
Confirm data broker registration and certifications against the public registers
Registration is the easiest thing to fake-claim and the easiest thing to verify, so verify it before you negotiate price. Under the California Consumer Privacy Act, a data broker is a business that knowingly collects and sells to third parties the personal information of a consumer with whom it has no direct relationship, and covered businesses have to register with the state. The CCPA applies to for-profit businesses that do business in California and either have gross annual revenue over $25 million, buy, sell, or share the personal information of 100,000 or more California residents or households, or derive 50% or more of their revenue from selling California residents' personal information, per the California Attorney General's CCPA explainer. The registry lives with the California Privacy Protection Agency, and it is public, so you can look a vendor up before the first sales call ends.
Do the same against the UK register at the Information Commissioner's Office if you buy for EMEA outreach, and treat the pair as a minimum. A vendor that sells contact data into California while claiming it is not a data broker, or that cannot point to its ICO registration, is describing its own compliance posture inaccurately. Layer the security certifications on top: ISO 27001 and SOC 2 Type II are the two that recur in this category, and both are attestable by a named certification body rather than by the vendor's marketing team. These certificates do not make the data lawful to use, but their absence signals that the compliance story is probably being improvised.

The email half of the stack has its own regime. If your outbound runs on email, the messages fall under the FTC's CAN-SPAM rule, and the obligations there - truthful headers, a working opt-out mechanism, prompt honouring of opt-outs - sit on you as the sender, not on your data provider, as the FTC's CAN-SPAM rule makes clear. The Gmail and Yahoo sender requirements that now gate bulk mail make that overlap harder to hand-wave, and I covered the practical fallout in my post on Gmail and Yahoo permanently rejecting mail from senders without DMARC.
We built Leadex with a deliberately different shape than the proprietary database vendors, because the compliance question changes when the data is not the product. Leadex does not sell contact records; it runs research against the open web with your own enrichment keys on top, so instead of vetting one vendor's database you are connecting your own providers. Every row carries its source URL and timestamp, which is the provenance trail the rest of this post is about asking other vendors to produce. You can read more about how that works on the Leadex site.
One more habit worth stealing from procurement teams that buy data well: put the audit in the renewal. Lock in the right to re-request the LIA, the registry coverage list, and the certifications annually, because providers get acquired, swap data sources, and quietly change their screening coverage between your signing and your renewal. The vendor that hands over the documents happily on day one is the vendor you can afford to re-audit on day 365.
FAQ
Does buying from a GDPR-compliant provider make my own campaigns compliant?
No. The provider's compliance covers its collection and sale of the data. Your outreach is your own processing, which means your own legitimate interest decision and your own obligation to honour the opt-outs and suppressions that come attached to the records.
Which Do-Not-Call registries should I care about as a US-based buyer?
The ones for the countries you actually dial. The US registry matters if you call US numbers, the UK's TPS and CTPS if you call the UK, and so on. Get the provider's covered-registry list in writing and compare it against your calling footprint before you sign.
Can I really ask a vendor to show me its legitimate interest assessment?
Yes. It is a normal part of procurement due diligence for data. Expect a redacted version, and treat a flat refusal as a signal that the vendor cannot defend its legal basis.
How do I check whether a data provider is a registered data broker?
Search the California Privacy Protection Agency's public data broker registry for CCPA-covered businesses, and check the UK Information Commissioner's Office register if you buy for EMEA outreach. Both are public and free to search.
Does ISO 27001 certification prove GDPR compliance?
No. ISO 27001 certifies an information security management system, not a lawful basis for processing. It is a useful control signal, but it does not tell you anything about sourcing, DNC screening, or the legitimate interest assessment.