Person-Level Intent7 min read

Privacy and GDPR for person-level intent

Key Takeaways

  • Person-level intent data about an identifiable individual is personal data under the GDPR, even in a B2B context.
  • Legitimate interest is the legal basis most B2B teams rely on for this kind of processing, but it requires a genuine balancing test.
  • Data minimization and purpose limitation matter: collect and retain what you actually need, for as long as you need it.
  • People have rights - access, objection, erasure - that your process needs to be able to honor.
  • This article is general information, not legal advice; consult a qualified privacy professional for your specific situation.

Person-level intent data is more powerful than account-level data precisely because it is tied to an identifiable individual - which also means it carries more privacy responsibility.

For B2B teams operating in Europe, that responsibility is shaped by the GDPR. This article explains the general principles at play. It is educational content, not legal advice - always involve your own legal or privacy counsel before making compliance decisions.

B2B intent data is still personal data

A common misconception is that "B2B data" is somehow outside the scope of the GDPR. It is not. If a piece of data can identify a specific individual - a name, an email address, a LinkedIn profile, a device or browser identifier tied to a person - it is personal data, whether that person is a private consumer or a Head of Marketing at a software company.

Person-level intent data, by definition, is built to identify individuals. That makes GDPR compliance a design requirement, not an afterthought.

Data minimization and purpose limitation

Two core GDPR principles apply directly to person-level intent: collect only the data you need for a clearly defined purpose, and do not keep it longer than that purpose requires.

In practice, this means being deliberate about which signals you capture, how long engagement history is retained, and making sure the stated purpose (e.g. "identifying relevant sales opportunities") genuinely matches how the data is used.

Respecting individual rights

The GDPR gives individuals rights over their personal data, including the right to know what is held about them, the right to object to processing, and the right to have data corrected or erased.

A responsible person-level intent process needs a practical way to honor these rights when someone exercises them - not just a policy stating that they exist.

  • A clear, accessible privacy notice explaining what is collected and why
  • A straightforward way for someone to object to being tracked or contacted
  • A process for erasing or correcting data on request

What to check when working with a GTM intelligence vendor

If you use a platform like Stairoids to collect person-level signals, compliance is a shared responsibility between you and the vendor. It is reasonable to ask any vendor how signals are sourced, what legal basis they rely on, how long data is retained, and how they support your obligations to honor individual rights.

None of this replaces your own legal advice - every organization's data flows and risk profile are different, so this should always be reviewed with qualified counsel.

Ask us how Stairoids approaches this

Talk to our team about how person-level signals are sourced and handled.

Table of Contents