Are B2B Data Providers GDPR Compliant? What Each One Says

Short answer

Apollo, ZoomInfo, Cognism and Lusha all say yes, but their own documents show four very different amounts of proof, and part of the job stays with you.

Artem Smirnov
Artem Smirnov

Last updated · 10 min read

Artem Smirnov in a dark suit against a charcoal studio backdrop, next to the line 'GDPR compliant, says who? Usually the vendor, about itself.'

GDPR has no list of approved data vendors, so "GDPR compliant" on a B2B data provider's website is not an official stamp. Certification under the regulation is voluntary, and Article 42(4) says a certificate "does not reduce the responsibility of the controller or the processor." When Apollo, ZoomInfo, Cognism or Lusha say they comply, that is a claim each company makes about its own processes.

I read each vendor's own privacy, trust and help pages in September 2026. All four state that they comply. The real differences sit in the paperwork: where the data comes from, whether the people in the database are told, which outside firm reviewed what, and what happens to a contact you already exported once that person opts out.

One more thing before the tables. The moment you export a contact and email them, you have your own GDPR duties, whatever the vendor promises, and the email rules differ from one European country to the next. This is not legal advice, just a buyer's reading of public documents.

What does "GDPR compliant" mean when a data vendor says it?

It means the vendor believes its own processing meets the regulation. Nobody outside has to agree before the vendor prints it on a page. Three pieces of the law decide what the claim is worth to you.

Telling people their data is held. When a company collects personal data without getting it from the person, Article 14 requires it to tell that person within one month at the latest, or at the first communication if the data is used to contact them.

That notice has to name the source of the data and whether it came from publicly accessible sources. Data providers mostly collect this way, so the duty lands on them for their own database.

The legal basis. Most B2B providers rely on legitimate interest. The GDPR's own Recital 47 treats marketing to people directly as something that "may be regarded as" a legitimate interest, then adds that it needs "careful assessment," including whether the person could reasonably expect it. The word is "may." Here is a completed example of that assessment, test by test.

The contract. A Data Processing Agreement (DPA) is the contract Article 28(3) requires whenever a company processes personal data on your behalf. It covers the data you put into their platform, such as your CRM sync or your uploads. It does not hand you the vendor's legal basis for its database.

Apollo's own help center says as much: it "can't advise whether GDPR applies to your business," and it talks about customers needing "an independent legal basis" to keep or contact people (Apollo GDPR settings article).

Where do Apollo, ZoomInfo, Cognism and Lusha get their data?

This table covers sourcing, the stated legal basis and notice to the people in the database. Everything comes from each vendor's own pages, checked on 2026-09-28.

ProviderData sources they nameLegal basis they stateDo they say they notify people?
ApolloPublic websites and directories, plus regulator and government records; data submitted by customers; "vetted third-party data providers"Legitimate interestsThe privacy policy points to a separate "Article 14 Processing Notice"; it does not say individuals are contacted one by one
ZoomInfoMachine reading of 28M+ public websites a day; data partners; a contributory community of 200,000+ professionals who share contacts for free access; an in-house research teamNot named on its trust center privacy pageDescribes a "notice and choice program" and links a December 2022 audit of its email privacy notice program
CognismPublicly available sources only, validated on an ongoing basisLegitimate interest; says outside lawyers helped with its legitimate interest assessment, a DPIA, a transfer impact assessment and balancing testsYes, "where required under Article 14," with an opt-out in the notice
LushaA Community Program where members share their business network; data brokers and public APIs; LinkedIn profile data read through its browser extension; affiliates and partnersLegitimate interestThe privacy policy does not say it notifies people when they enter the database

Sources: Apollo privacy policy (last updated August 10, 2026), ZoomInfo data sources and ZoomInfo trust center privacy page, Cognism GDPR help article, Lusha privacy policy (updated September 2026).

Two rows deserve a second look. ZoomInfo's contributory community and Lusha's Community Program both mean some contact data arrives because someone else shared their address book. Ask how those people were told. And "where required" in Cognism's line is Cognism's own reading of when Article 14 applies.

Which certifications and audits does each one claim?

This one covers the proof: certificates, named outside reviews and what happens after an opt-out.

ProviderCertifications claimedOutside review they nameAfter an opt-outPhone Do Not Call screening
ApolloNone listed on the two pages I checked; the DPA sits in its Trust CenterNone named; uses Standard Contractual Clauses and the EU-U.S., UK and Swiss-U.S. Data Privacy Frameworks for transfersRemoved from Apollo's database, but contacts you already saved stay in your workspace until you delete themSupported registries "including the UK, France, and Germany"
ZoomInfoSOC 2, ISO 27001, ISO 27701A TRUSTe GDPR privacy practices validation findings letter (via its trust center resources page); a 2023 privacy program review by Lucid Privacy Group (linked PDF); a December 2022 deliverability audit by Email IndustriesSelf-service privacy center; says it extends data subject rights "to our entire database""any supported Do Not Call lists," with no countries named on the page
CognismISO 27001, SOC 2 Type IIExternal legal counsel for its assessments (firm not named); registered with the UK ICO and as a CCPA data brokerA dedicated team handles access requests "within the required timeframes"Registries in 11 countries listed: Belgium, Canada, Croatia, France, Germany, Ireland, Portugal, Spain, Sweden, the UK (TPS and CTPS) and the US
LushaSOC 2 Type 2, ISO 27001, ISO 27018, ISO 27701"Trust and ePrivacy," named as two independent auditorsAdded to a suppression list; Lusha says it will "inform the customers that purchased your data""Do-not-call lists" named as a privacy tool

Sources: Apollo GDPR settings article, Apollo privacy policy, ZoomInfo trust center privacy page, Cognism GDPR help article, Lusha data privacy page (last modified November 20, 2024, almost 2 years before this comparison), Lusha privacy policy for the opt-out column.

The opt-out column is the one I would read twice. Apollo is open about it: when a person asks to be removed, Apollo removes them from its own database, but a copy you saved before that stays in your account. Lusha says it tells buyers. Either way, your own suppression list is what protects you.

Which of these claims has anyone outside actually checked?

Put every claim in the tables into one of three buckets.

Named outside review. ZoomInfo names three outside firms and Lusha names two. That is more than a bare statement. But the two dated reviews are from 2022 and 2023, and neither page describes any of these reviews as a GDPR certification approved under Article 42.

Security certificates. SOC 2 and ISO 27001 are security audits. They tell you how carefully data is stored and accessed. They say nothing on whether it was lawful to collect a given person's data in the first place. ISO 27701 goes further into privacy management, but it certifies a management system. It does not rule on how a vendor's database was built.

Self-description. Cognism's help article sets out a nine-step compliance process, the most detailed of the four, and it names the actual legal work behind it. It is still Cognism describing Cognism. Apollo's pages describe tools and settings more than their own assessment.

None of the four pages points to a regulator's finding in its favor. What regulators do publish are decisions against companies that emailed people, and in several of the fines behind real cold outreach cases the list came from somebody else.

Why can't a vendor's comparison page settle the question?

Because the vendor has a side. Two examples that show up when you search this question.

Cognism's own "Cognism vs Apollo.io" page says Apollo's Do Not Call checking "is in beta for new direct dial requests" and that Apollo "may deduct credits" when a revealed number turns out to be on a DNC list. Nothing in the two Apollo pages I read uses the word beta. Treat it as one vendor describing a rival, nothing more.

The same comparison page says Cognism screens against DNC lists in 15 countries. Cognism's own help article, checked the same day, lists 11 countries. Maybe the help article is behind, maybe the sales page counts differently. Either way, the help article is the document I would rely on.

The second example is a comparison of six vendors published in May 2026 by the cofounder of a LinkedIn export tool. It rates its own tool as having the "cleanest compliance posture," because it pulls data live from LinkedIn profiles at export time instead of storing a database. It links to no GDPR text and no vendor document.

The live-pull argument deserves a straight answer. A tool that stores nothing has less to explain about its own database. But once you export the rows, you hold the data, you collected it without asking the person, and the Article 14 notice, the legal basis and the opt-outs are all yours. Pulling live moves the question onto you; it does not remove it.

What should you ask a data provider before emailing anyone in the EU?

Seven questions, starting with the paperwork.

  1. Send me your DPA. Check that it exists, who signs it, and what data it covers. Apollo points customers to its Trust Center for it.
  2. What legal basis do you rely on, and have you done a written assessment? Then write your own for your campaign. The vendor's basis covers the vendor.
  3. Where exactly does a given record come from? Article 14 expects you to tell people the source. "Public sources" is thin; "company website" or "shared by a community member" is something you can write in a first email.
  4. Do you notify the people in your database, and can I see the notice? Cognism says yes where required. ZoomInfo describes a notice program. Apollo's privacy policy refers to a separate Article 14 notice. Lusha's policy is silent.
  5. What happens to contacts I exported when someone opts out with you? Get the answer in writing. Under Article 21(3), once a person objects to direct marketing, you must stop using their data for it, and the same article requires the right to object to be shown clearly at the first communication at the latest.
  6. Can I read the actual audit letter? Some findings letters sit behind a request form on a trust center. Ask for them.
  7. When was this page last updated? A privacy page from 2024 describing a product that changed in 2026 is worth a follow-up question.

My rule on lists fits in one line: "A list built with Sales Navigator, Apollo, UpLead, ZoomInfo and RocketReach beats a scraped list." Running outbound from Prague for clients in Germany, the UK and Switzerland, I have come to value a second reason for that rule.

A provider-sourced list comes with a paper trail (a source, a DPA, an opt-out process) that you can put in writing when someone asks how you got their email. A scraped list comes with nothing. The same logic runs through my piece on lists versus copy.

None of this replaces verification. Compliance and deliverability are separate problems, and a record with perfect paperwork can still be an address that has gone stale. Run every address through NeverBounce or DeBounce before a sequence touches it, and keep bounces under 0.5%.

Questions founders ask about data providers and GDPR

Is Apollo GDPR compliant?

Apollo says it is. Its privacy policy (updated August 10, 2026) names legitimate interests as its basis, lists Standard Contractual Clauses and the Data Privacy Frameworks for transfers, and offers a DPA through its Trust Center. Its help center also says it cannot advise whether you comply. That part stays with you.

Is ZoomInfo GDPR compliant?

ZoomInfo says so and backs it with more named outside review than the other three: a TRUSTe validation letter, a 2023 Lucid Privacy Group review and SOC 2 and ISO certificates. Those are reviews and security audits. No regulator approved anything, so ask to read the letters themselves.

Cognism or Apollo, which is safer for GDPR?

On their own documents, Cognism describes more of its legal process: legitimate interest assessment, DPIA, Article 14 notices, ICO registration. Apollo's documentation focuses on controls you run yourself, such as settings that block prospecting and emailing of people it locates in the EU. Neither page is a verdict, and a vendor's own comparison page is never neutral.

Can I use Apollo data for cold email in Europe?

People do, but the legal basis, the notice in your first email and your suppression list all sit with you as the sender. Apollo's GDPR settings only work where it can determine a prospect's location, so check location yourself. This is not legal advice; for a specific campaign, ask a lawyer in the country you are emailing.

Want to get more B2B clients for your business?

I help B2B companies book 10 to 100+ qualified sales calls per month with outbound. Let's see if it fits yours.

Artem Smirnov
Artem Smirnov

I help B2B companies book qualified sales calls with cold email and LinkedIn outbound.