Method

GDPR-compliant B2B prospecting: where our data comes from and how we contact it

Updated September 19, 2026 · Ripe Leads

Done-for-you B2B outbound · Original data

In short

Every list Ripe Leads runs is built from public business data: national company registers, company websites, public job adverts and public professional profiles. Nothing is purchased from a data broker. We hold and use a business contact's data under GDPR Article 6(1)(f), legitimate interest, backed by a documented balancing assessment, and we only work with corporate or role-based addresses. Because the data was not collected from the person directly, Article 14 requires every first message to name the sender, state where the data came from and explain how to object, so that is what our first message does. Opt-outs are honoured immediately and permanently, across every campaign and every client. A separate, per-country send rule sits on top of this lawful basis: see our pharma send-rule matrix for how that plays out by country. For a campaign, the client is the controller and Ripe Leads is the processor, under a signed data processing agreement.

On this page
  1. Why a purchased list fails, legally and commercially
  2. The sources, in order
  3. From a company record to a contactable person
  4. The legitimate interest test, in plain words
  5. Article 14: what the first message has to say
  6. Retention and opt-outs
  7. The country layer sits on top, and it is a separate question
  8. Controller and processor: who holds which responsibility
  9. What to ask any agency to prove

Why a purchased list fails, legally and commercially

A purchased list is a shortcut with two separate failure points. Legally, a data broker's list arrives with no record of where each address came from, no balancing assessment behind it and usually no way to prove a lawful basis if a recipient ever asks. Commercially, a bought list is stale the moment it changes hands, resold to whoever else bought it, and full of addresses that were never checked against a real company or a real role.

Ripe Leads does not buy lists. Every contact we work with is built from public business data, sourced and verified by us, not licensed from a third party. That is a slower way to build a list than buying one, and it is the reason the list holds up when a recipient asks where their details came from.

The commercial cost of a bought list shows up downstream, in the reply rate and in the sender's own reputation. An address nobody verified bounces, and a bounce rate that climbs high enough gets a sending domain flagged by mailbox providers, which then hurts every other message that domain sends, not just the ones aimed at the stale address. Building the list ourselves is the only way to keep that risk inside our own control rather than inheriting it from whoever sold the list last.

The sources, in order

Four sources feed every list, checked in this order. National company registers come first: in Lithuania that means Registrų centras, the state register, cross-checked against the public business directory rekvizitai.vz.lt for current trading status. A company website comes next, for the structure, the roles and the corporate email format a company actually uses. Public job adverts follow, for hiring signal and for confirming a department or a seniority level is current. Public professional profiles close the loop, for a named person's current title and employer.

Each source answers a different question. The register confirms the company exists and is active. The website confirms how that company is structured and how it writes its own email addresses. The job advert and the professional profile confirm a specific person holds a specific role right now, not eighteen months ago.

SourceWhat it gives usWhat we verify before use
National company register (Registrų centras, rekvizitai.vz.lt)Legal name, registration status, registered addressThe company is currently active and the legal name matches
Company websiteOrganisational structure, named roles, corporate email formatThe role and the site itself look current, not abandoned
Public job advertsHiring signal, department, seniority levelThe advert is recent and the role is genuinely relevant
Public professional profilesA named person's current title and employerThe title matches the company website and the advert, not an old employer

From a company record to a contactable person

A register entry is a company, not a contact. Turning one into the other means matching a role, not a random name, to the outreach: a website's structure page or leadership list names the function we need, a job advert confirms the same function is active and hiring, and a professional profile confirms the person named against that function still holds it. The address we use follows the company's own published format, a corporate or role-based address, never a personal account scraped from somewhere the company itself did not publish.

That is a deliberate narrowing. We are not building the largest possible list from a register of 224,096 Lithuanian companies; we are building the list of people whose role makes the message relevant to them. Method behind that Lithuanian index is published separately, at Lithuanian Company Database Methodology.

A record that fails any one of those checks is dropped rather than used anyway. A role that a job advert names but a professional profile does not confirm, or a company website structure that has clearly not been updated in years, is a reason to leave that contact off the list rather than to guess.

The legitimate interest test, in plain words

GDPR gives a data holder several lawful bases for processing personal data. For a business contact's corporate or role-based details, the basis we rely on is legitimate interest, Article 6(1)(f). In plain words, that basis asks three questions: is there a real, specific interest behind the processing, is processing this data actually necessary to serve that interest, and does that interest outweigh the individual's own rights and expectations once the two are weighed against each other. We document that balancing assessment rather than asserting the basis without it.

Two limits keep that basis defensible. We work only with corporate and role-based addresses, the kind a company itself publishes for business contact, not a personal account. And we do not process any special category of data, sensitive personal information, to build or run a list.

The balancing assessment is not a one-line note. It records the specific interest behind a given campaign, why the sourcing method used was necessary to serve it rather than some broader or more intrusive alternative, and what safeguards, the sourcing limits, the Article 14 wording, the immediate opt-out, offset the impact on the person being contacted. That written record is what lets us answer a recipient's question about the basis with a specific document rather than a general reassurance.

Article 14: what the first message has to say

GDPR Article 14 applies whenever personal data was not collected from the person it describes, which is the case for every contact on a list we build from a register, a website, a job advert or a profile rather than from the person directly. Article 14 requires that the person be told, in reasonable time and in practice at first contact, who is processing their data, where it came from and how to object.

That requirement shapes the first message itself. Every first email identifies the sender by name and company, states in plain terms where the recipient's details came from, and explains how to object or opt out. None of that sits in a footnote or a linked policy the recipient has to go looking for; it sits in the message they actually read.

Retention and opt-outs

An opt-out is honoured immediately and permanently. That applies across every campaign and every client we run, not only the campaign the request arrived on, so a person who objects once does not have to object again the next time a different client's campaign happens to reach the same company. Data that is no longer needed for an active or planned campaign is not kept on the chance it might be useful later.

Permanent means what it says: an opt-out is not a flag that lapses after a campaign ends or a client relationship changes. The point of holding it that way is straightforward. A recipient who has already said no should never have to say it twice, and a list that keeps growing while never actually shrinking is a sign the opt-out process is not working, whatever it claims to do on paper.

The country layer sits on top, and it is a separate question

Everything above is the GDPR layer: the lawful basis for holding and using a business contact's data, which does not change by the recipient's country. A second, separate layer decides whether that specific country requires prior consent before the send itself, and it varies sharply. Germany requires prior consent for advertising email under UWG Section 7. Switzerland requires opt-in under UWG Article 3(1)(o), with no business-to-business exception, which is why we use phone and LinkedIn there instead of email. Ireland runs a genuine corporate opt-out lane under Regulation 13 of S.I. 336/2011. The UK's PECR treats limited companies and LLPs as opt-out but sole traders as opt-in. Poland's UŚUDE is unsettled for business-to-business email. Lithuania sits on the EU ePrivacy baseline, with no stricter national overlay on top.

That country-by-country detail is covered in full, channel by channel, in our cold email rules matrix for Europe. This page is about the data underneath every one of those rows: where it came from and on what basis we hold it, before the country-specific send rule is even applied.

Controller and processor: who holds which responsibility

For a client campaign, the client is the data controller: they decide the purpose of the campaign and, ultimately, whose data is contacted on their behalf. Ripe Leads acts as the data processor, running the sourcing, the sending and the day-to-day technical execution under the client's instructions. That split is formalised in a signed data processing agreement before a campaign starts, setting out what we process, on whose instruction, and what happens to the data once the engagement ends.

The distinction is not a formality. It decides who answers which question if a recipient or a regulator ever asks one: the controller answers for the purpose of the campaign, the processor answers for how the data was handled while carrying that purpose out. Having both roles named and agreed before the first message goes out is what lets either side actually answer, rather than pointing at the other.

What to ask any agency to prove

An agency that cannot answer these plainly is worth a harder look before you sign. Ask where the list came from, by name, not "our proprietary database." Ask to see the legitimate interest balancing assessment behind the lawful basis, not just a claim that one exists. Ask for a sample of the first message and check it actually names the sender and the data source, the way Article 14 requires. Ask how an opt-out is recorded and whether it carries across other campaigns and other clients. And ask for the data processing agreement itself, not a verbal assurance that one is available on request.

Ripe Leads is the trading name of UAB Kofi tech, registered in Vilnius, Lithuania, company code 305994397, founded by Dovydas Liaudanskas. A first month runs EUR 3,750 including setup, then EUR 2,850 a month, cancel anytime.

Frequently asked

Is cold email legal in the EU?
It can be, under a documented lawful basis and, depending on the recipient's country, a per-country send rule layered on top. We hold and use business contact data under GDPR Article 6(1)(f), legitimate interest, with a documented balancing assessment, and we apply the recipient country's own rule, from Germany's prior-consent requirement to Ireland's corporate opt-out lane, on top of that basis.
Where do you get your lead lists?
From public business data only: national company registers, in Lithuania Registrų centras and rekvizitai.vz.lt, company websites, public job adverts and public professional profiles. We source and verify every contact ourselves rather than licensing a list from a third party.
Do you buy data from a data broker?
No. Nothing in a Ripe Leads list is purchased from a data broker. Every contact is built from the public sources listed above and matched to a current role before it goes on a list.
What happens when someone asks to be removed?
The opt-out is honoured immediately and permanently, across every campaign and every client we run, so the same person is not recontacted later by a different campaign.
Who is the data controller for my campaign, you or us?
You are the controller: you decide the purpose of the campaign. Ripe Leads acts as the processor, running the sourcing and the send under your instructions, formalised in a signed data processing agreement before the campaign starts.

Want the accounts behind these numbers?

Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.

Book a strategy call