Lead Forensics
Last Reviewed: 17 Jun 2026
At a Glance
Lead Forensics' DPA addresses EU and UK GDPR requirements, with SCCs, processor-only restrictions and strong sub-processor flowdown in place. A notable positive is the 48-hour data breach notification commitment — stricter than the standard 72-hour GDPR requirement.
Company & Product Details
HQ
United Kingdom
Products
Website Visitor Identification
Product description
Identifies the businesses visiting a customer's website and provides actionable B2B lead and contact data.
What data is being processed?
IP addresses (website visitors), B2B contact data (first name, surname, job title, LinkedIn URL) from matched companies, customer-uploaded contact data, employee login credentials (first name, surname, email)
Document Details
Date of DPA
01 Oct 2024
Additional date information
DPA states "V5.1, Last modified October 2024" in the footer. No specific day given; recorded as 1 October 2024 as a conservative approximation.
What jurisdictions are covered?
EU GDPR (Regulation 2016/679), UK GDPR, and the Data Protection Act 2018. EEA is defined to include Switzerland (clause 2.1d). The DPA is governed by the laws of England and Wales, with courts of the relevant EU Member State having jurisdiction for Data Subject claims (clauses 8.3–8.5).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not Explicitly Stated The DPA does not explicitly name specific countries where data is stored. The Lead Forensics data-compliance page (same official website) states that data is sent to "UK/EU servers for processing and analysis." The DPA acknowledges that sub-processors may process Personal Data outside the UK and EEA in countries without adequacy decisions, with appropriate transfer mechanisms required (clause 6.2).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Detailed technical and organisational measures set out in Appendix B of the DPA: (1) ISO 27001-certified ISMS with risk-based approach (Appendix B clause 3.2); (2) Physical security — locked/access-controlled entrances, 24/7 security, CCTV, secure disposal (Appendix B clause 5); (3) Access controls — MFA for all remote access, role-based least-privilege access, unique user logins, complex passwords (Appendix B clauses 5.10–5.15); (4) Encryption — data encrypted in transit over public networks; at rest for cloud-hosted data (on-premise databases not encrypted at rest but with other physical controls) (Appendix B clauses 5.13–5.14, 12); (5) Cyber-attack protections — firewalls, anti-virus/anti-malware, regular security updates, MFA on cloud management platforms (Appendix B clause 6); (6) Penetration testing — annual 3rd-party and monthly internal pen testing (Appendix B clauses 6.11–6.12); (7) Incident management — pre-approved response plans for ransomware, personal data breaches, and denial of service; BCP reviewed annually (Appendix B clause 13); (8) Supplier due diligence — annual supply chain audit, DPAs required with processors (Appendix B clause 7.1); (9) PCI DSS certified (Appendix B clause 18.2).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Lead Forensics will notify the Customer without undue delay and, in any event, within 48 hours of becoming aware of a Personal Data Breach impacting the Customer's Personal Data. Lead Forensics will also assist the Customer in notifying the breach to competent supervisory authorities unless DP Laws do not require such notification (clauses 5.3.1–5.3.2). Note: the 48-hour obligation is stricter than the standard 72-hour GDPR requirement.
What happens to the data on termination?
Live Personal Data deleted from the Services within 30 days of confirmed contract termination; Customer must retrieve required data via self-serve options within the same 30-day window (clauses 9.2, 9.4). Backup data retained by sub-processors for 2 years from termination, unless the Customer submits a written request for earlier deletion or DP Laws require retention. DPA considered terminated when Personal Data has been deleted per Lead Forensics' retention policy or on Customer's written request, whichever is first (clauses 9.3–9.5).