Privacy and GDPR for person-level intent
Key Takeaways
- •Person-level intent data about an identifiable individual is personal data under the GDPR, even in a B2B context.
- •Legitimate interest is the legal basis most B2B teams rely on for this kind of processing, but it requires a genuine balancing test.
- •Data minimization and purpose limitation matter: collect and retain what you actually need, for as long as you need it.
- •People have rights - access, objection, erasure - that your process needs to be able to honor.
- •This article is general information, not legal advice; consult a qualified privacy professional for your specific situation.
Person-level intent data is more powerful than account-level data precisely because it is tied to an identifiable individual - which also means it carries more privacy responsibility.
For B2B teams operating in Europe, that responsibility is shaped by the GDPR. This article explains the general principles at play. It is educational content, not legal advice - always involve your own legal or privacy counsel before making compliance decisions.
B2B intent data is still personal data
A common misconception is that "B2B data" is somehow outside the scope of the GDPR. It is not. If a piece of data can identify a specific individual - a name, an email address, a LinkedIn profile, a device or browser identifier tied to a person - it is personal data, whether that person is a private consumer or a Head of Marketing at a software company.
Person-level intent data, by definition, is built to identify individuals. That makes GDPR compliance a design requirement, not an afterthought.
Legal basis: legitimate interest, in general
Many B2B vendors rely on "legitimate interest" as the legal basis for processing professional contact and engagement data, on the reasoning that reaching out to a business contact about a relevant product, in a professional capacity, is a reasonable and expected form of processing.
Legitimate interest is not an automatic pass - it requires a genuine balancing test between your business interest and the individual's rights and expectations, and it needs to be documented. Depending on the specific processing activity, other legal bases (such as consent, for certain tracking technologies) may also apply.
This is general information about how the concept is commonly applied - not a legal assessment of your specific processing activities.
Data minimization and purpose limitation
Two core GDPR principles apply directly to person-level intent: collect only the data you need for a clearly defined purpose, and do not keep it longer than that purpose requires.
In practice, this means being deliberate about which signals you capture, how long engagement history is retained, and making sure the stated purpose (e.g. "identifying relevant sales opportunities") genuinely matches how the data is used.
Respecting individual rights
The GDPR gives individuals rights over their personal data, including the right to know what is held about them, the right to object to processing, and the right to have data corrected or erased.
A responsible person-level intent process needs a practical way to honor these rights when someone exercises them - not just a policy stating that they exist.
- •A clear, accessible privacy notice explaining what is collected and why
- •A straightforward way for someone to object to being tracked or contacted
- •A process for erasing or correcting data on request
What to check when working with a GTM intelligence vendor
If you use a platform like Stairoids to collect person-level signals, compliance is a shared responsibility between you and the vendor. It is reasonable to ask any vendor how signals are sourced, what legal basis they rely on, how long data is retained, and how they support your obligations to honor individual rights.
None of this replaces your own legal advice - every organization's data flows and risk profile are different, so this should always be reviewed with qualified counsel.
Ask us how Stairoids approaches this
Talk to our team about how person-level signals are sourced and handled.
