Contact Data Provenance Audit — GDPR Defensibility avatar

Contact Data Provenance Audit — GDPR Defensibility

Pricing

from $3.00 / 1,000 audited contacts

Go to Apify Store
Contact Data Provenance Audit — GDPR Defensibility

Contact Data Provenance Audit — GDPR Defensibility

Audit any enriched contact list (Clay, Apollo, ZoomInfo, Lusha…): per contact and field, is the value verifiable against a public source (with source + timestamp), stale, unverifiable or broker-only? Evidence for legitimate-interest assessments and DPIAs.

Pricing

from $3.00 / 1,000 audited contacts

Rating

0.0

(0)

Developer

Creator Fusion

Creator Fusion

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

6 days ago

Last modified

Categories

Share

Contact Data Provenance Audit — GDPR Defensibility for Enriched Lists

What does it do?

Give it any enriched contact list — a Clay table, an Apollo or ZoomInfo export, a Lusha pull, a CRM segment — and it checks every row against free public sources (Gravatar, GitHub, Keybase, the company's own website and team pages, web search, Hacker News, DNS/RDAP). For each field you supplied it returns one of:

VerdictMeaning
verified-publicmatches a public source — with the source name and check timestamp
public-differsa public source shows a different value (likely stale)
not-publicly-verifiableno public source holds this attribute for this person
broker-onlyattribute class that is essentially never public (mobile, personal email, DOB) — provenance must come from your vendor contract or a consent record
blankyou had no value

Plus, per contact: _publicFootprint (does this person exist publicly under this email at all), _defensibilityScore (% of supplied fields corroborated), and a plain-English _recommendation. The run's SUMMARY gives list-level percentages you can paste into a DPIA or legitimate-interest assessment.

Why now

In July 2026 Italy's regulator fined Lusha €2M and ruled that legitimate interest does not cover selling contact data collected without a public-source basis, ordering erasure. Buyers of enriched data now need to show, per record, where the data could lawfully have come from. Enrichment vendors do not expose their sources. This Actor gives you the public-source view independently.

How to use it

  1. Paste rows as a JSON array into Contacts (or point at an Apify dataset). Any column names — email, name, title, company, LinkedIn, location, phone are auto-detected; use Column overrides for unusual headers.
  2. Run. Each row comes back with your original columns plus the _audit verdicts and _publicRecord.
  3. Filter _recommendation for stale-or-mismatched (refresh before use) and no-public-footprint (keep vendor provenance on file); export _verifiedFields counts and SUMMARY for your compliance file.

How much does it cost?

EventPrice
audited-contact — every row audited$0.004 ($4 per 1,000 contacts)
Actor start$0.00005

Rows are charged whether or not a public footprint is found, because the "not verifiable" verdict is the compliance-relevant answer.

Sample output (one row)

{ "email": "torvalds@linux-foundation.org", "full_name": "Linus Torvalds", "company": "Linux Foundation", "location": "Portland, OR",
"_publicFootprint": true, "_footprintConfidence": 75, "_defensibilityScore": 67,
"_recommendation": "defensible: public-source provenance available",
"_verifiedFields": ["company", "location"], "_mismatchedFields": [], "_unverifiableFields": ["full_name"], "_brokerOnlyFields": [],
"_audit": { "company": { "verdict": "verified-public", "publicValue": "Linux Foundation", "source": "website", "checkedAt": "2026-09-25T04:55:00Z" },
"location": { "verdict": "verified-public", "publicValue": "Portland, OR", "source": "gravatar", "checkedAt": "2026-09-25T04:55:00Z" } } }

FAQ

Does "not-publicly-verifiable" mean the data is unlawful? No. It means no public source corroborates it, so its lawful basis has to rest on your vendor's contract, a consent record, or another Article 6 basis — this Actor tells you which records need that paperwork.

Does it send anything to the people on the list? No. It only queries public endpoints.

Can I use it to clean the list too? Yes — _mismatchedFields is a stale-record detector, and _publicRecord carries the fresh public value.


Built by Creator Fusion LLC. Pair with Reverse Email Lookup — Email to Name, LinkedIn & Company (same engine, for enrichment) and Email Verifier — Bulk Verification with Catch-All Detection.