Lead Forensics

Last Reviewed: 17 Jun 2026

GDPR Addressed

At a Glance

Lead Forensics' DPA addresses EU and UK GDPR requirements, with SCCs, processor-only restrictions and strong sub-processor flowdown in place. A notable positive is the 48-hour data breach notification commitment — stricter than the standard 72-hour GDPR requirement.

Company & Product Details

HQ

United Kingdom

Products

Website Visitor Identification

Product description

Identifies the businesses visiting a customer's website and provides actionable B2B lead and contact data.

What data is being processed?

IP addresses (website visitors), B2B contact data (first name, surname, job title, LinkedIn URL) from matched companies, customer-uploaded contact data, employee login credentials (first name, surname, email)

Document Details

Date of DPA

01 Oct 2024

Additional date information

DPA states "V5.1, Last modified October 2024" in the footer. No specific day given; recorded as 1 October 2024 as a conservative approximation.

What jurisdictions are covered?

EU GDPR (Regulation 2016/679), UK GDPR, and the Data Protection Act 2018. EEA is defined to include Switzerland (clause 2.1d). The DPA is governed by the laws of England and Wales, with courts of the relevant EU Member State having jurisdiction for Data Subject claims (clauses 8.3–8.5).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA forms part of the agreement between Lead Forensics and Customer for the purchase of services. In the event of contradiction between the DPA and related agreements, the DPA prevails. By signing the Agreement, the Customer enters the terms of the DPA on behalf of itself and its affiliates (preamble, clause 1.1).

Location & Transfers

Where is data held or processed?

Not Explicitly Stated The DPA does not explicitly name specific countries where data is stored. The Lead Forensics data-compliance page (same official website) states that data is sent to "UK/EU servers for processing and analysis." The DPA acknowledges that sub-processors may process Personal Data outside the UK and EEA in countries without adequacy decisions, with appropriate transfer mechanisms required (clause 6.2).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
SCCs (Commission Implementing Decision 2021/914), the IDTA (ICO Section 119A), and the UK Addendum are referenced as applicable transfer mechanisms for sub-processor transfers outside the UK/EEA to countries without adequacy decisions. No specific SCC modules are identified; the DPA refers to these mechanisms generically. Implementation is required of Lead Forensics where sub-processors are engaged outside the UK/EEA (clause 6.2).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Detailed technical and organisational measures set out in Appendix B of the DPA: (1) ISO 27001-certified ISMS with risk-based approach (Appendix B clause 3.2); (2) Physical security — locked/access-controlled entrances, 24/7 security, CCTV, secure disposal (Appendix B clause 5); (3) Access controls — MFA for all remote access, role-based least-privilege access, unique user logins, complex passwords (Appendix B clauses 5.10–5.15); (4) Encryption — data encrypted in transit over public networks; at rest for cloud-hosted data (on-premise databases not encrypted at rest but with other physical controls) (Appendix B clauses 5.13–5.14, 12); (5) Cyber-attack protections — firewalls, anti-virus/anti-malware, regular security updates, MFA on cloud management platforms (Appendix B clause 6); (6) Penetration testing — annual 3rd-party and monthly internal pen testing (Appendix B clauses 6.11–6.12); (7) Incident management — pre-approved response plans for ransomware, personal data breaches, and denial of service; BCP reviewed annually (Appendix B clause 13); (8) Supplier due diligence — annual supply chain audit, DPAs required with processors (Appendix B clause 7.1); (9) PCI DSS certified (Appendix B clause 18.2).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Clause 1.1 explicitly states: "Lead Forensics shall always be a Data Processor, and the Customer shall be a Data Controller." No independent controller rights are claimed. Clause 3.2 permits processing of Customer Personal Data to produce aggregated, anonymised statistics for customer reporting purposes as part of the Service, but this does not enable identification of individuals and does not constitute independent use of the data for Lead Forensics' own purposes (clause 3.2).

Subprocessing

General authorization

General
General authorisation to use sub-processors already engaged prior to the DPA effective date (deemed approved via published list). New or changed sub-processors published on the Lead Forensics website, which constitutes notice to the Customer. Customer has 30 working days to raise written objections; Lead Forensics will work in good faith to address concerns, which may include not using the sub-processor or restricting its use. Absence of objection within that period is deemed approval (clauses 6.1–6.5).

Do all the DPA terms flow down to sub-processors?

Yes
Lead Forensics requires sub-processors to have a contract offering "substantially the same level of protection for Personal Data as those set out in this DPA." Lead Forensics remains liable to the Customer for the performance of each sub-processor in accordance with the DPA (clauses 6.7–6.8).

Is data only processed on the instruction of the controller?

Yes
Lead Forensics will only use Personal Data in accordance with the Customer's instructions (specific or general) to perform the Services, except where required by DP Laws. If required by law to process or share data contrary to instructions, Lead Forensics will inform the Customer unless prohibited from doing so (clause 3.1).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Lead Forensics will promptly notify the Customer of any Data Subject request received and will not respond to it without Customer authorisation. Lead Forensics will assist the Customer in fulfilling its obligations to respond to Data Subject requests, taking into account the nature of processing (clauses 7.3–7.4). Lead Forensics will also make reasonable effort to support the Customer in the event of supervisory authority inspections or third-party claims (clause 7.2).

Does the contract include staff confidentiality clauses?

Yes
Personnel with access to Customer data are limited and are subject to contractual terms of confidentiality (clause 5.2.1).

Are there audit rights for the data?

Structured
Audit rights exist but are subject to limitations. The Customer may audit Lead Forensics' compliance on giving reasonable written notice, with audit costs borne by the Customer. Third-party auditors appointed by the Customer must agree to a Non-Disclosure Agreement issued by Lead Forensics. The scope of any audit is limited to the Customer's Personal Data processed by Lead Forensics as defined in Appendix A and as relevant to the Customer's processing activities (clauses 7.6.1–7.6.2).

Is there assistance with DPIA requests?

Yes
Lead Forensics will provide reasonable assistance to the Customer with any data protection impact assessments required under Articles 35 or 36 of EU/UK GDPR or equivalent DP Laws, taking into account the nature of data processing (clause 7.5.1).

How much notice is provided for data breaches?

Lead Forensics will notify the Customer without undue delay and, in any event, within 48 hours of becoming aware of a Personal Data Breach impacting the Customer's Personal Data. Lead Forensics will also assist the Customer in notifying the breach to competent supervisory authorities unless DP Laws do not require such notification (clauses 5.3.1–5.3.2). Note: the 48-hour obligation is stricter than the standard 72-hour GDPR requirement.

What happens to the data on termination?

Live Personal Data deleted from the Services within 30 days of confirmed contract termination; Customer must retrieve required data via self-serve options within the same 30-day window (clauses 9.2, 9.4). Backup data retained by sub-processors for 2 years from termination, unless the Customer submits a written request for earlier deletion or DP Laws require retention. DPA considered terminated when Personal Data has been deleted per Lead Forensics' retention policy or on Customer's written request, whichever is first (clauses 9.3–9.5).