The Practice |
The sales team uses third-party tools to scrape or extract publicly visible LinkedIn profile data — names, designations, company, and in some cases inferred email addresses — to build cold outreach lists for lead generation campaigns run through email sequencing tools.
Questions Raised for Compliance Review |
- Does using scraped professional contact data for cold outreach constitute lawful processing under DPDP, given the data was publicly visible?
- What risks arise from using third-party scraping tools and email-inference services in this workflow?
- What is the compliant approach to building outreach lists for lead generation?
Is This Permitted Under DPDP? |
Not permissible as commonly practised.
Public visibility of a LinkedIn profile does not equate to consent for that data to be scraped, aggregated, and used for unsolicited commercial outreach. The individual made their designation and company visible for professional networking purposes on that platform — not for third parties to build a marketing contact list. DPDP's consent and purpose limitation requirements apply regardless of whether the source data happened to be publicly accessible.
Where the Breach Risks Sit |
- No consent for the specific purpose of outreach — A LinkedIn profile being visible to the public or to a platform's user base is not equivalent to the individual agreeing to receive commercial email or calls generated from that visibility — the purpose the data is now being used for is entirely different from the purpose it was shared for.
- Scraping tools breach platform terms and may be unlawful independent of DPDP — Most professional networking platforms explicitly prohibit automated scraping in their terms of service; using such tools creates a parallel contractual and potentially legal exposure alongside the DPDP risk.
- Inferred or guessed email addresses compound the risk — Email-finder tools that guess or infer a person's email address from name-and-company patterns introduce a data point the individual never made available at all, extending the processing activity beyond even what was publicly visible.
- No mechanism for opt-out or correction — Individuals contacted through scraped lists typically have no visibility into how the organisation obtained their details, and no straightforward way to have their information removed from that specific list or any downstream CRM record.
The Ideal Compliant Approach |
- Shift to consent-based or legitimate-interest-documented channels. Prioritise inbound leads, referral-based introductions, and outreach to individuals who have engaged with the organisation's content or attended an event — where a reasonable basis for contact exists — over cold scraping.
- Discontinue use of scraping and email-inference tools for list-building. Replace scraping tools with data providers that can demonstrate a lawful basis for their own data collection and provide contractual assurances of compliant sourcing.
- Provide a clear, immediate opt-out on every outreach communication. Every cold outreach email must include a simple mechanism to opt out of further contact, and that request must be honoured across all sales tools and CRM records, not just the sending platform.
- Maintain a suppression list. Individuals who opt out or request removal should be added to an organisation-wide suppression list checked before any future campaign, preventing repeat unwanted contact through a different tool or team.
DPDP Risk Summary
| Element | Status | Recommended Action |
|---|---|---|
| Scraped LinkedIn data used for cold outreach | No lawful basis | Shift to inbound/referral-based outreach channels |
| Third-party scraping tools in use | Platform terms + DPDP risk | Discontinue scraping tools; use lawfully-sourced providers |
| Inferred/guessed email addresses contacted | Beyond publicly available data | Cease use of email-inference tools |
| No opt-out on cold outreach emails | Mandatory requirement | Add opt-out mechanism to every outreach communication |
| No cross-tool suppression list | Repeat contact risk | Maintain and check a central suppression list before campaigns |