DPDP for Sales Teams: CRM Data, Lead Lists and Cold Outreach
Purchased lead lists, scraped contacts and CRM enrichment all carry personal data risk. What sales teams need to check before hitting send.
Where a lead list actually came from matters
A phone number or email address in your CRM is personal data regardless of whether the person is a 'lead' or a 'customer,' and the lawful basis question doesn't disappear just because outreach is business-to-business. If a list was purchased from a data broker, scraped from public directories, or passed along by an event organiser, ask what that source actually told the individual and whether it covers your outreach.
Self-published, publicly available personal data has a narrow exemption under Section 3 for data an individual has voluntarily made public — but this is easy to over-read. A person's name on a company website does not automatically mean unlimited cold outreach to their personal contact details was contemplated, especially where the data was aggregated from multiple sources into a purchased list.
Enrichment tools and third-party data
CRM enrichment tools that append phone numbers, social profiles or firmographic data to a contact record are themselves handling personal data on your behalf, and function as Data Processors — Section 8(2) contract expectations apply. Confirm what source data these tools draw from and whether their own collection practices would hold up if a contact asked where you got their number.
Treat 'the vendor said their data is compliant' as a starting point for diligence, not the end of it — you remain responsible for the lawfulness of processing once the enriched data sits in your CRM.
Cold outreach, opt-outs and suppression
Build a real suppression list mechanism — when a contact replies 'remove me' or 'unsubscribe,' that should propagate across every sequence and campaign touching that contact, not just the one tool that received the reply. A prospect who opts out of email but keeps getting called by a different rep is a compliance gap as much as a bad customer experience.
Where outreach relies on consent rather than a business-contact carve-out, make withdrawal genuinely simple, consistent with Section 6 — a one-line reply should be enough; don't require a form, a login, or a phone call to opt out.
Handoff to customer data
Once a lead converts, the personal data collected during the sales process (call notes, personal preferences mentioned in conversation, personal email used pre-signup) becomes part of the customer record and inherits the same access, correction and erasure rights as any other customer data — don't treat pre-sale CRM notes as somehow exempt because they were 'sales data.'
Where to go next
Run lead-list and enrichment vendors through the Vendor Assessment before adopting them, and use the Consent Notice Builder for any outreach channel where you're relying on consent rather than a legitimate-use argument.