- 83.4% of new EU businesses in 2023 were sole proprietorships.
- Claiming a legitimate interest isn't enough to process personal data.
- Choosing a compliant data processor reduces legal exposure.
Buying company data feels like one of the safer purchases a data team can make, since revenue bands and industry codes describe organizations rather than people.
In practice, plenty of firmographic fields point back to an identifiable person, and the buyer carries responsibility for that once the data lands in their systems.
This checklist covers how to spot those fields, and what to require from the provider selling them to you.
1. Distinguish Company Data From Personal Data
Under the General Data Protection Regulation (GDPR), protections apply strictly to identifiable individuals, leaving corporate attributes outside its scope.
However, B2B datasets can frequently mix organizational details with individual contact info.
Distinguishing between the two types of data requires some checks, which we’ll outline next.
1a. Confirm the Attribute Is Truly Company Level
Deciding whether an attribute is company level looks obvious until you work through an actual field list.
Data like turnover figures and industry classification codes describe an organization rather than anyone working inside it, so they raise no questions.
The picture changes as soon as a field points back to a specific individual, and the definition governing that is broader than most teams expect.
To see why, it helps to start with how the European Commission explains the term “personal data” in its own guidance.

Source: European Commission
What stands out is that the definition reaches well beyond names and direct contact details.
In fact, pseudonymised or encrypted records still count whenever they can lead back to a particular person.
With that scope established, the split between the two categories becomes easier to apply, as the comparison below shows.

Source: Veridion
As an example, take the email addresses.
A generic company address like “info@company.com” will identify only the business, while a work address such as “john.d@company.com” names a specific individual and is protected.
For that reason, any field that can somehow be tied to a named person deserves a second look before it enters your pipeline.
Public availability changes nothing here either, as Poland's data protection authority made clear after a company built commercial profiles from national business registers.

In other words, the Polish regulator held that open access to a source does not remove the duty to tell people their data is being processed.
As a rule of thumb, ask whether an attribute is completely decoupled from an individual.
If it isn't, the safe bet is to classify that attribute as personal data.
1b. Watch for Data That Blurs the Line
The boundary between corporate and personal data collapses when a business entity and an individual share the exact same legal identity.
Sole proprietors and freelancers are the clearest case, since the business has no separate staff or address of its own.
That situation is far more common, as Eurostat's figures on new business creation show.

Only a minority of businesses launched in 2023 had any employees, which puts this data distinction problem at the centre of the European market.
When a company and an individual are functionally identical, a registered business address is frequently a private home, and a main office number is a personal mobile phone.
The graphic below shows some other scenarios to keep in mind.

Source: Veridion
Because this overlap occurs across multiple attributes, records like these should go through a manual review before they reach a contact list or an outbound campaign.
That way, you avoid treating personal data with the same lighter handling as ordinary company data.
Having said that, protecting personal data in some cases is nuanced.
As shown in a Court of Justice case summarized below, there are instances where public interest or legal transparency outweighs an individual’s privacy rights.

Yet the fact that these disputes reach the EU's highest court shows just how heavily regulators scrutinize the line between business and personal identity.
Whether you’re looking at sole proprietors or corporate directors, any field connected to a real person demands deliberate and precise handling.
2. Establish a Legal Basis for Firmographic Enrichment
Knowing which attributes count as personal data only settles half the question.
The other half is whether you're allowed to process them in the first place.
Even when firmographic enrichment targets purely corporate profiles, personal data often enters the pipeline along the way.
So, before processing begins, organizations must establish and document a solid legal basis under GDPR.
2a. Identify When Legitimate Interest Applies
While teams frequently cite "legitimate interest" to justify data processing, claiming an interest is vastly different from legally defending it.
Article 6(1)(f) of the GDPR requires a Legitimate Interest Assessment (LIA), an internal document recording why the processing is justified and what it costs the people whose data is involved.
The assessment works through three tests in sequence, shown below.

Source: Veridion
Naming a specific commercial purpose often satisfies the first test on its own.
However, necessity forces you to show the same purpose cannot be reached with fewer data points or a less intrusive method.
And even if you prove that, the final test weighs your commercial interests against the individual's fundamental privacy rights, factoring in the safeguards implemented to protect their data.
The European Data Protection Board is direct about this in its guidelines on legitimate interest:
“[The] existence and identification of a legitimate interest pursued by the controller or a third party is not in itself sufficient to rely on Article 6(1)(f) GDPR as a legal basis.”
Even so, regulators encounter the gap between the claim and the evidence constantly, and the GDPR Enforcement Tracker's breakdown of violation types shows that is the case.

Illustration: Veridion / Data: Enforcement Tracker
Insufficient legal basis leads every other category with 973 fines issued across 32 countries.
In these cases, documentation is the sole buffer separating a defensible compliance posture from an enforcement action.
In practice, working with the least personal data for your purposes and recording the safeguards you implement to protect it is what keeps you on the compliant side.
2b. Know When Contact-Level Data Needs More
Some use cases cannot be served by company attributes alone.
Qualifying a new vendor or launching a targeted outreach campaign eventually requires a named decision-maker, which means the record stops describing an organisation and starts describing a person.
That step is often necessary, so it is worth handling deliberately rather than as a side effect of contact-level data enrichment.
Once it happens, a different set of obligations switches on, and the comparison below shows how far apart the two sides sit.

Source: Veridion
We’ve already covered some aspects of Article 6, which requires a lawful basis to be named and documented before the data is used.
Article 14 follows this thread. Because you acquired the personal data indirectly, you must inform the individual where their information originated.
In practice, that notice should be done within a month, or at first contact if you reach out sooner.
Most importantly, individuals have a right to opt out of direct marketing or their data being processed.
Crucially, these legal duties reach backwards into how the data was collected in the first place, which makes your provider's methods part of your own exposure.
A French enforcement decision from 2024 illustrates the point well.
Regulators penalized KASPR, a web extension used to scrape LinkedIn data, noting that the tool collected information even from users who had explicitly set their profiles to private.

Source: CNIL
Beyond the financial penalty, the company had to contact the people concerned individually, which is a costly process that damages a brand’s reputation.
For that reason, before purchasing or enriching contact-level fields, audit your provider's sourcing methods.
Ask specifically how each personal attribute was collected and whether affected individuals received Article 14 notices at the point of collection.
3. Vet Your Data Provider's Compliance Posture
Outsourcing data collection does not outsource compliance responsibility.
Purchasing a firmographic dataset transfers the data but not the legal liability associated with how it was sourced or managed.
So, conducting thorough due diligence on your data provider is an essential prerequisite to entering any agreement.
3a. Confirm EU Hosting and Transparent Sourcing
Sourcing transparency is the foundation of vendor due diligence because it determines whether you can answer basic questions about your own dataset.
A data provider that cannot say where a record came from leaves a buyer unable to satisfy Article 14 or answer an access request.
The privacy group Noyb ran into exactly that problem while investigating the Austrian credit reporting market, and Max Schrems described what they found.

As the quote makes clear, the supplier in question had sold millions of records without being able to identify their origin, and buyers sit further down that chain.
An undocumented source like this one inevitably becomes a compliance risk inside your own database.
This data transparency extends to where the data is hosted.
As an example at Veridion, we host data in the EU on an in-house infrastructure.
Hosting data in this manner keeps the chain of custody short and eliminates the need for GDPR Chapter V transfer mechanisms, such as Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs).
These mechanisms are legal safeguards strictly required when personal data leaves the EEA to ensure foreign countries protect it, making them unnecessary when data is stored and processed locally.
Plus, Veridion’s data collection methodology is transparent about the scope of what gets sourced.

Source: Veridion
Still, none of these safeguards limit the data depth and accuracy.
As the attribute categories below show, Veridion collects extensive company data including over 120 firmographic attributes.

Source: Veridion
These firmographics are part of a total of 461 company attributes divided among 24 dimensions like technographics, product-level data, and ownership status.
Overall, by prioritizing transparent sourcing and local infrastructure, you can build a legally sound database while still leveraging rich, multidimensional insights.
3b. Require a Signed Data Processing Agreement
A Data Processing Agreement (DPA) is the contract that governs what a processor may do with personal data on your behalf.
Under Article 28 of the GDPR, processing personal data without one is a violation in its own right, regardless of how carefully everything else is handled.
In other words, the agreement is part of being compliant, and the regulation is specific about what it has to contain.
The list below covers the main points that need to be specified in a DPA.

Source: Veridion
Of those, sub-processor rules deserve particular attention, since data providers routinely rely on external infrastructure that never comes up in a sales conversation.
A compliant DPA mandates advance notice and approval before any sub-processor handles your data.
Importantly, a compliant provider should offer this DPA document as standard rather than on request.
As French data protection lawyer Thiébaut Devergranne emphasizes, a vendor that hesitates in this regard leaves no room for compromise.

Furthermore, signing the initial DPA is not a one-time process.
Ongoing data vendor management requires periodic reviews and routine audits to ensure sub-processor lists, technical safeguards, and data retention schedules remain fully aligned with evolving regulations.
To see the cost of a deficient agreement, a French enforcement decision shows what it looks like when a provider's standard paperwork falls short.

What matters in our case is that the contractual failure was treated separately from the breach itself.
Dedalus Biologie’s terms of sale simply did not contain key Article 28(3) terms, and the regulator placed that responsibility on the processor alone.
For that reason, ask to see the DPA before any data purchasing conversation gets serious.
Conclusion
That brings the checklist to a close.
The theme running through each step is that accountability follows the data that you purchase.
The good news is that GDPR compliance relies far more on proper documentation than on blanket restrictions, making a defensible pipeline well within reach.
Start by auditing the data you already manage, and ensure you meet the GDPR compliance standards.
Articles
Discuss how these trends affect your organization.
Our analysts are available for a short call. Bring a specific question and we will ground it in the data.
Insights
Keep reading
More analysis, research, and outcomes grounded in live company intelligence.
Best Practices for Data Enrichment
Learn how data enrichment best practices help businesses turn raw data into accurate and actionable insights.
Looking for a Global Data Collection Partner? These Companies are Worth Considering
Looking for a global data collection partner? This guide will introduce companies worth considering and explain what sets them apart.
Which Online Business Data Providers Stand Out in Today's Market?
This article will highlight online business data providers that businesses trust for accurate company information and actionable insights.
