Your GTM stack is a data controller, whether you planned that or not
The moment a CRM, enrichment tool, or ad platform touches a name, email, or IP address tied to a real person, your go-to-market stack is processing personal data — and GDPR's six processing principles now apply to it.
Every enrichment record, every intent signal, every list pulled into an outbound sequence has to be processed lawfully and transparently, collected for a stated purpose, limited to what's actually needed, kept accurate, retained only as long as necessary, and secured against loss or misuse. None of this is optional because the data came from a vendor rather than a form fill — the obligation follows the data, not the source.
Pick a lawful basis before the first send, not after a complaint
Every contact in your GTM system needs a defensible reason for being there. In practice, revenue teams lean on three of the six lawful bases:
- Consent — the person actively opted in to be contacted for this purpose. Bundled, pre-checked, or vague consent doesn't count.
- Legitimate interest — a documented, balanced judgment that outreach serves a reasonable business purpose without overriding the person's rights. This needs a paper trail, not a shrug.
- Contract — the data is needed to deliver something the person already asked for, like a demo they requested.
The failure mode isn't picking the wrong basis — it's not picking one at all, then trying to reconstruct a justification after a data protection authority asks.
Consent and opt-out rules don't travel the same way across borders
One of the more expensive assumptions in global GTM is treating "compliant" as a single setting. In reality, the acceptable pattern for contacting a purchased or sourced record shifts meaningfully by market — some jurisdictions expect opt-in before first contact, others allow opt-out after notice, and a few require dual, documented consent before any commercial use.
| Region | Typical pattern | Operational note |
|---|---|---|
| European Union | Explicit opt-in | Consent must be specific per purpose — no bundled checkboxes. |
| Brazil | Dual opt-in | Vendors should be able to produce proof of consent on request. |
| Argentina / Peru / Chile | Notice + opt-out | Check numbers against national do-not-call registries before dialing. |
| Singapore | Notice + opt-out | Public business data can be used, but do-not-call screening still applies. |
| South Korea | Dual opt-in | Purchased data is high-risk; many teams avoid third-party sourcing entirely. |
| Malaysia / Thailand | Dual opt-in | Written notice may need to be provided in the local language as well as English. |
The practical upshot: your data vendor contracts and your CRM's suppression logic both need a country field that actually changes behavior, not just a label.
Vendor due diligence is where most GTM risk actually lives
Marketing and sales rarely collect raw data themselves anymore — enrichment providers, intent data platforms, and list vendors do. That makes vendor contracts the real control point.
Ask every data vendor for:
- Written confirmation of the lawful basis they used to collect each record.
- The ability to produce proof of consent or notice on request, not just an assurance that it exists.
- A contractual obligation to flag and exclude numbers or addresses on relevant do-not-contact registries.
- Clear terms on how long they'll retain source records for audit purposes.
Design consent capture and CRM hygiene as one system
Consent that lives in a form tool but never reaches the CRM is functionally invisible — and unenforceable suppression is the fastest way to end up emailing someone who withdrew consent six months ago.
- Sync consent status and its source (form, vendor, event, call) into the record itself, not a side spreadsheet.
- Make opt-out at least as easy as opt-in — a two-click unsubscribe honored instantly across every connected tool.
- Re-verify consent state at the point of send, not just at the point of import, since preferences change.
- Log automated decisions (lead scoring, routing) that meaningfully affect a person, since GDPR gives individuals a right to contest purely automated decisions with legal or similarly significant effects.
Cross-border transfers need a named legal mechanism
If personal data collected in the EEA flows into a GTM stack hosted or operated outside it, that transfer needs a recognized safeguard — an adequacy decision covering the destination country, standard contractual clauses, or binding corporate rules. "The tool is based in the US" is a fact, not a safeguard.
This is worth checking now, quietly, rather than during due diligence for a partnership or acquisition: which of your GTM tools store or process EEA contact data outside the EEA, and what mechanism covers that transfer today?
When something goes wrong, the clock starts immediately
A data controller generally has 72 hours from becoming aware of a breach to notify the relevant supervisory authority, unless the breach is unlikely to pose a risk to individuals. For GTM teams, that means knowing in advance who gets pulled into the room the moment a CRM export leaks or a vendor reports an incident — legal, security, and whoever owns the affected campaign.
REVIEW
The pre-flight checklist
Before your next campaign, list pull, or vendor contract renewal, run it against these seven questions.
- Does every contact have a documented lawful basis for this specific outreach?
- Does the destination country's opt-in or opt-out pattern match how this record was sourced?
- Can the data vendor produce proof of consent or notice on request?
- Does an opt-out anywhere suppress the contact everywhere, within minutes?
- Is there a named legal mechanism covering any cross-border transfer involved?
- Does someone own the 72-hour breach notification clock if this data is ever exposed?
- Could you answer a data subject's access or erasure request using this system today?



