Contact Data Provenance Audit — GDPR Defensibility
Pricing
from $3.00 / 1,000 audited contacts
Contact Data Provenance Audit — GDPR Defensibility
Audit any enriched contact list (Clay, Apollo, ZoomInfo, Lusha…): per contact and field, is the value verifiable against a public source (with source + timestamp), stale, unverifiable or broker-only? Evidence for legitimate-interest assessments and DPIAs.
Pricing
from $3.00 / 1,000 audited contacts
Rating
0.0
(0)
Developer
Creator Fusion
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
6 days ago
Last modified
Categories
Share
Contact Data Provenance Audit — GDPR Defensibility for Enriched Lists
What does it do?
Give it any enriched contact list — a Clay table, an Apollo or ZoomInfo export, a Lusha pull, a CRM segment — and it checks every row against free public sources (Gravatar, GitHub, Keybase, the company's own website and team pages, web search, Hacker News, DNS/RDAP). For each field you supplied it returns one of:
| Verdict | Meaning |
|---|---|
verified-public | matches a public source — with the source name and check timestamp |
public-differs | a public source shows a different value (likely stale) |
not-publicly-verifiable | no public source holds this attribute for this person |
broker-only | attribute class that is essentially never public (mobile, personal email, DOB) — provenance must come from your vendor contract or a consent record |
blank | you had no value |
Plus, per contact: _publicFootprint (does this person exist publicly under this email at all), _defensibilityScore (% of supplied fields corroborated), and a plain-English _recommendation. The run's SUMMARY gives list-level percentages you can paste into a DPIA or legitimate-interest assessment.
Why now
In July 2026 Italy's regulator fined Lusha €2M and ruled that legitimate interest does not cover selling contact data collected without a public-source basis, ordering erasure. Buyers of enriched data now need to show, per record, where the data could lawfully have come from. Enrichment vendors do not expose their sources. This Actor gives you the public-source view independently.
How to use it
- Paste rows as a JSON array into Contacts (or point at an Apify dataset). Any column names — email, name, title, company, LinkedIn, location, phone are auto-detected; use Column overrides for unusual headers.
- Run. Each row comes back with your original columns plus the
_auditverdicts and_publicRecord. - Filter
_recommendationforstale-or-mismatched(refresh before use) andno-public-footprint(keep vendor provenance on file); export_verifiedFieldscounts andSUMMARYfor your compliance file.
How much does it cost?
| Event | Price |
|---|---|
audited-contact — every row audited | $0.004 ($4 per 1,000 contacts) |
| Actor start | $0.00005 |
Rows are charged whether or not a public footprint is found, because the "not verifiable" verdict is the compliance-relevant answer.
Sample output (one row)
{ "email": "torvalds@linux-foundation.org", "full_name": "Linus Torvalds", "company": "Linux Foundation", "location": "Portland, OR","_publicFootprint": true, "_footprintConfidence": 75, "_defensibilityScore": 67,"_recommendation": "defensible: public-source provenance available","_verifiedFields": ["company", "location"], "_mismatchedFields": [], "_unverifiableFields": ["full_name"], "_brokerOnlyFields": [],"_audit": { "company": { "verdict": "verified-public", "publicValue": "Linux Foundation", "source": "website", "checkedAt": "2026-09-25T04:55:00Z" },"location": { "verdict": "verified-public", "publicValue": "Portland, OR", "source": "gravatar", "checkedAt": "2026-09-25T04:55:00Z" } } }
FAQ
Does "not-publicly-verifiable" mean the data is unlawful? No. It means no public source corroborates it, so its lawful basis has to rest on your vendor's contract, a consent record, or another Article 6 basis — this Actor tells you which records need that paperwork.
Does it send anything to the people on the list? No. It only queries public endpoints.
Can I use it to clean the list too? Yes — _mismatchedFields is a stale-record detector, and _publicRecord carries the fresh public value.
Built by Creator Fusion LLC. Pair with Reverse Email Lookup — Email to Name, LinkedIn & Company (same engine, for enrichment) and Email Verifier — Bulk Verification with Catch-All Detection.