GDPR overview

A practical playbook for marketing, sales, and RevOps teams who source, store, and act on personal data across borders — without setting off the next fine.

July 6, 2026
Operating GTM Systems in a GDPR World
ARTICLE 01

Your GTM stack is a data controller, whether you planned that or not

The moment a CRM, enrichment tool, or ad platform touches a name, email, or IP address tied to a real person, your go-to-market stack is processing personal data — and GDPR's six processing principles now apply to it.

Every enrichment record, every intent signal, every list pulled into an outbound sequence has to be processed lawfully and transparently, collected for a stated purpose, limited to what's actually needed, kept accurate, retained only as long as necessary, and secured against loss or misuse. None of this is optional because the data came from a vendor rather than a form fill — the obligation follows the data, not the source.

Why this matters for GTM: a purchased contact list doesn't inherit a clean bill of health. If your team is the one calling, emailing, or retargeting the person, your organization typically carries controller obligations for that outreach — regardless of who originally sourced the record.
ARTICLE 02

Pick a lawful basis before the first send, not after a complaint

Every contact in your GTM system needs a defensible reason for being there. In practice, revenue teams lean on three of the six lawful bases:

  • Consent — the person actively opted in to be contacted for this purpose. Bundled, pre-checked, or vague consent doesn't count.
  • Legitimate interest — a documented, balanced judgment that outreach serves a reasonable business purpose without overriding the person's rights. This needs a paper trail, not a shrug.
  • Contract — the data is needed to deliver something the person already asked for, like a demo they requested.

The failure mode isn't picking the wrong basis — it's not picking one at all, then trying to reconstruct a justification after a data protection authority asks.

ARTICLE 03

Consent and opt-out rules don't travel the same way across borders

One of the more expensive assumptions in global GTM is treating "compliant" as a single setting. In reality, the acceptable pattern for contacting a purchased or sourced record shifts meaningfully by market — some jurisdictions expect opt-in before first contact, others allow opt-out after notice, and a few require dual, documented consent before any commercial use.

Illustrative regional pattern — always confirm current local requirements
Region Typical pattern Operational note
European Union Explicit opt-in Consent must be specific per purpose — no bundled checkboxes.
Brazil Dual opt-in Vendors should be able to produce proof of consent on request.
Argentina / Peru / Chile Notice + opt-out Check numbers against national do-not-call registries before dialing.
Singapore Notice + opt-out Public business data can be used, but do-not-call screening still applies.
South Korea Dual opt-in Purchased data is high-risk; many teams avoid third-party sourcing entirely.
Malaysia / Thailand Dual opt-in Written notice may need to be provided in the local language as well as English.

The practical upshot: your data vendor contracts and your CRM's suppression logic both need a country field that actually changes behavior, not just a label.

ARTICLE 04

Vendor due diligence is where most GTM risk actually lives

Marketing and sales rarely collect raw data themselves anymore — enrichment providers, intent data platforms, and list vendors do. That makes vendor contracts the real control point.

Ask every data vendor for:

  • Written confirmation of the lawful basis they used to collect each record.
  • The ability to produce proof of consent or notice on request, not just an assurance that it exists.
  • A contractual obligation to flag and exclude numbers or addresses on relevant do-not-contact registries.
  • Clear terms on how long they'll retain source records for audit purposes.
Red flag: a vendor that can't explain, market by market, how consent or notice was obtained for a given record. "Trust us, it's clean" is not a lawful basis.
ARTICLE 05

Design consent capture and CRM hygiene as one system

Consent that lives in a form tool but never reaches the CRM is functionally invisible — and unenforceable suppression is the fastest way to end up emailing someone who withdrew consent six months ago.

  • Sync consent status and its source (form, vendor, event, call) into the record itself, not a side spreadsheet.
  • Make opt-out at least as easy as opt-in — a two-click unsubscribe honored instantly across every connected tool.
  • Re-verify consent state at the point of send, not just at the point of import, since preferences change.
  • Log automated decisions (lead scoring, routing) that meaningfully affect a person, since GDPR gives individuals a right to contest purely automated decisions with legal or similarly significant effects.
ARTICLE 06

Cross-border transfers need a named legal mechanism

If personal data collected in the EEA flows into a GTM stack hosted or operated outside it, that transfer needs a recognized safeguard — an adequacy decision covering the destination country, standard contractual clauses, or binding corporate rules. "The tool is based in the US" is a fact, not a safeguard.

This is worth checking now, quietly, rather than during due diligence for a partnership or acquisition: which of your GTM tools store or process EEA contact data outside the EEA, and what mechanism covers that transfer today?

ARTICLE 07

When something goes wrong, the clock starts immediately

A data controller generally has 72 hours from becoming aware of a breach to notify the relevant supervisory authority, unless the breach is unlikely to pose a risk to individuals. For GTM teams, that means knowing in advance who gets pulled into the room the moment a CRM export leaks or a vendor reports an incident — legal, security, and whoever owns the affected campaign.

Before you need it: a one-page breach playbook naming who's notified, in what order, within the first hour — not something written for the first time during the incident.
FINAL
REVIEW

The pre-flight checklist

Before your next campaign, list pull, or vendor contract renewal, run it against these seven questions.

  • Does every contact have a documented lawful basis for this specific outreach?
  • Does the destination country's opt-in or opt-out pattern match how this record was sourced?
  • Can the data vendor produce proof of consent or notice on request?
  • Does an opt-out anywhere suppress the contact everywhere, within minutes?
  • Is there a named legal mechanism covering any cross-border transfer involved?
  • Does someone own the 72-hour breach notification clock if this data is ever exposed?
  • Could you answer a data subject's access or erasure request using this system today?
FIELD GUIDE — REVENUE OPERATIONS & DATA PRIVACY · GENERAL INFORMATION, NOT LEGAL ADVICE
Our Resources

Learn From Our Resources

Discover expert insights, practical guides, and proven strategies to power your go-to-market success.

The Audience Layer Is Eating Ad Tech

Publicis just paid $2.2 billion for LiveRamp. The platforms are quietly losing the most important real estate in advertising, and most B2B marketers have not noticed yet.

read more

The Quiet Failure of B2B Paid Media

Why more budget isn't fixing your pipeline, and why the system can be working perfectly while your business gets less efficient by the quarter.

read more

What Does an AdGenius Performance Blueprint Consist Of?

An AdGenius Performance Blueprint is a custom, data-driven paid media diagnosis that combines funnel analysis, channel strategy, audience targeting, a 90-day flight plan, and KPI targets to show digital marketing leaders exactly where demand is leaking and what to do next.

read more

Ready to Find the
Contacts That Matter?

Get precise, compliant, and on-demand contact data—tailored to your business needs.