Under the GDPR, a database of B2B contacts is lawful only if each record can pass four tests: a legal basis (in practice legitimate interest), a notice to the person (Art. 14), proportionate retention, and an honest answer to "where did you get my data?". The US data-vendor model of crawling LinkedIn and the web, never telling the people concerned, and keeping records forever fails at least three of them. The CNIL fined KASPR €240,000 in December 2024 on exactly those points. In March 2026 KASPR chose to erase its database and stop all collection on LinkedIn rather than sort out which records were lawful (CNIL).
The second enforcer is LinkedIn itself, using contract and computer-misuse claims rather than privacy law. Proxycurl, an API reselling LinkedIn profile data, shut down on 4 July 2025, six months after LinkedIn sued. Its founder said "there is no winning in fighting this" (Nubela blog).
The four tests, record by record
| Test | GDPR article | What fails it | Precedent |
|---|---|---|---|
| Legal basis | Art. 6(1)(f) | Collecting what the person restricted (e.g. LinkedIn contact info visible to 1st/2nd-degree connections only); processing beyond reasonable expectations | KASPR (CNIL); KNLTB C-621/22 on reasonable expectations (A&O Shearman) |
| Notice | Art. 14 | No notice; late notice; notice in a language the person does not read | KASPR: none until 2022, then English only |
| Retention | Art. 5(1)(e) | Retention clock that resets on every profile update | KASPR: 5 years renewed on each job change |
| Access / source | Art. 15(1)(g) | Answering "publicly available sources" instead of naming the source | KASPR |
KASPR's legal basis failed only for the contacts whose visibility the person had restricted. For contacts left public, the CNIL accepted legitimate interest but attacked retention, notice and access. The lesson: B2B contact data can be lawful, but only if every record carries metadata on where it came from, when, under what visibility, and when it expires.
Art. 14 in practice
The notice is due within one month of obtaining the data, or at the latest at the first communication if the data is used to contact the person (Art. 14(3)). It must name the source. The "disproportionate effort" exemption (Art. 14(5)(b)) is narrow. The Polish DPA rejected it in its first GDPR fine: Bisnode, a data broker, had argued that posting letters to millions of people listed in public business registers was too expensive.
The Bisnode details (UODO, March 2019, about PLN 943,000 / €220,000, roughly 6 million people, notices by post deemed required) are from prior knowledge. We could not fetch the UODO or EDPB pages in this pass.
Buyers inherit sellers' problems
The CNIL fined Solocal Marketing Services €900,000 in May 2025 for prospecting with data it had bought from brokers whose collection forms did not produce valid consent (CNIL). The remedy it accepted in September 2026 was automated analysis of every supplier's collection forms plus human review. The CNIL still reminded Solocal that it "remains responsible" (CNIL). That case involved B2C consent, but the principle carries over to B2B: the party using a list must be able to show it was lawfully built. DLA Piper's Czech chapter puts it the same way: the sender must ensure the data "were lawfully obtained and can be lawfully disposed of by the database owner" (DLA CZ).
Scraping: what regulators and courts have said
| Actor | Date | What | Outcome | Source |
|---|---|---|---|---|
| CNIL v KASPR (FR) | 5 Dec 2024 | Chrome extension + LinkedIn and web scraping, ~160M contacts | €240k; injunction; DB erased (closure 4 Mar 2026) | CNIL |
| CNIL guidance (FR) | 19 Jun 2025 | Legitimate interest for web scraping (AI context) | Respect robots.txt and CAPTCHAs, minimise, exclusion lists, inform before collection | CNIL |
| Dutch AP v Clearview AI (NL) | 3 Sep 2024 | Scraped facial-image database | €30.5m fine | Dutch AP |
| LinkedIn v Proxycurl (US) | Jan–Jul 2025 | LinkedIn profile-data API | Shut down 4 Jul 2025; ~$10M revenue (founder's claim) | Nubela |
| hiQ v LinkedIn (US) | 2019–2022 | Scraping public profiles | 9th Cir.: public scraping not "without authorization" under the CFAA; hiQ later found in breach of LinkedIn's User Agreement and settled | Wikipedia summary |
Three items in this area could not be verified in this pass. First, the hiQ settlement terms (reported as a December 2022 consent judgment with a payment and data deletion). Second, a 2024 Dutch AP guidance note saying scraping by private parties is "almost always" unlawful. Third, LinkedIn's early-2025 removal of Apollo's and Seamless.ai's company pages. The AP site blocked our fetch, and the other two are from prior knowledge.
hiQ is often cited as "scraping LinkedIn is legal". That reading is wrong on two counts. In the US, hiQ won on the computer-misuse question and lost on contract. In the EU, hiQ is irrelevant: the question is GDPR compliance per record, and KASPR answers it.
Where the big vendors stand
Apollo.io, ZoomInfo, Lusha and Cognism all sell EU contact data to EU buyers. We did not verify how each one handles Art. 14 notices, retention or source disclosure in October 2026.
We found no published EU DPA decision against Apollo, ZoomInfo or Lusha by October 2026. That is not evidence of compliance. KASPR was decided on complaints from people who had been contacted, and any large vendor is exposed to the same trigger. The vendor-by-vendor review belongs on Contact data and enrichment and Built-in lead database.
Checklist: a platform with a built-in EU lead database
| Obligation | Concrete implementation |
|---|---|
| Be honest about your role | You are the controller of the database. Customers who export and email are separate controllers. You are a processor only for their campaign data |
| Legitimate interest assessment per source | Written LIA per source type (company sites, registers, social profiles); exclude sources where people restricted visibility or where robots.txt or terms prohibit collection |
| Minimise | Business identity, role, business contact, company. No private emails, no personal phone numbers, no special-category inferences |
| Art. 14 notice | Send within one month, in the person's language. Name the source. Include an objection link. Log delivery |
| Retention | Fixed horizon with no auto-renewal on updates (the KASPR failure). Purge stale records |
| Access requests | Answer with the actual source per record, the recipients (which customers received the record) and the dates |
| Objection (Art. 21) | Global suppression that survives re-crawls and blocks future exports to all customers |
| DPIA + Art. 30 record | Large-scale profiling of millions of people almost certainly triggers a DPIA |
| Customer terms | Customers must give their own Art. 14 notice at first contact and comply with national email rules. Lawful data does not make a lawful send in Germany. See EU/EEA country matrix |
| Transfers | If hosted or enriched in the US, use the EU-US Data Privacy Framework or standard contractual clauses |
What this means for an entrant
- A "LinkedIn-sourced" EU contact database is a liability, not a moat. KASPR deleted about 160M records and Proxycurl shut down. Build on sources you can document per record, or integrate third-party data and push the controller risk onto the vendor contractually. See Contact data and enrichment and Clay.
- Provenance metadata is the product. Source, collection date, visibility at collection, notice sent, expiry date, objection status. A sequencer that stores these per contact can answer access requests, defend a legitimate-interest assessment and pass a buyer's DPO review. Incumbents built for the US market do not expose them.
- Automate Art. 14 notices at first contact. Inserting a localised, source-naming notice into step one of a sequence costs almost nothing to build and removes a whole category of breach. It is the cheapest EU differentiator available. See GDPR and ePrivacy.
- List-provenance scoring for imports. The CNIL accepted automated supplier-form analysis as a remedy. A "provenance check" that scores a CSV by source, age, generic versus personal addresses and recipient countries is a sellable feature for agencies importing client lists. See Lead-gen agencies and the openings.
- The supply gap is real. With KASPR and Proxycurl out and LinkedIn litigating, EU-lawful B2B contact data is scarcer than US data. An entrant with clean, notified, EU-sourced data has a defensible position, though it is slow and expensive to build. See Kill criteria.