Notes on GDPR-compliant founder diligence, the Growth Readiness Score methodology, and practical guidance for investors, accelerators, and recruiters who'd rather ask than scrape.
Checking a senior hire before an offer shares almost everything with checking a founder before a check — including the consent question.
A 41 and a 74 both come with ten sub-scores behind them. The single number is a starting point, not the whole answer.
The bring-on-a-co-founder decision gets less scrutiny than the fundraise it's meant to support — and it shouldn't.
Every extra step in a process is usually framed as friction. Consent is one of the rare steps that builds trust instead of costing it.
Both are real, consent-based data. The difference is who they're built for and how much detail comes back.
A free, no-consent-required search-based check has real limits — and being upfront about them is part of using it well.
Twenty founders admitted in one batch is twenty separate diligence problems, usually handled with far less rigor than one.
The math of angel investing rarely allows deep diligence on every founder in the pipeline — until the check itself gets faster.
The same slide can be read for its story, or read for what it quietly reveals about the team behind it.
Is the current pitch tightly focused, or scattered across unrelated themes stitched together after the fact?
A team's mix of backgrounds either matches the range of problems the business will face, or it doesn't.
Does the founder's demonstrated technical work actually match the business described in their pitch?
Irreplaceable people, growth without margin, and CEO bottlenecks — three specific patterns that predict strain before it shows up in the numbers.
A story that quietly changes every few months is a specific, checkable pattern — not just a feeling.
A single score is only useful if you know exactly what's underneath it. Here's what goes into a GRS.
Not every scoring system is built the same way underneath. A few direct questions surface the difference fast.
Collecting the data with a lawful basis is only step one. What happens to it afterward is its own separate obligation.
A slightly unusual test for whether a diligence process is well-designed: would the subject approve of how it was run?
A US fund checking a founder based in Berlin is still subject to GDPR for that specific processing.
GDPR gives data subjects the right to ask what's been collected about them, and get a copy of it.
Common practice and lawful practice aren't the same thing, and regulators have made that distinction before.
GDPR's minimization principle isn't just a compliance checkbox — it's often a better diligence process too.
Framing matters. Sent well, a consent request reads as respect. Sent badly, it reads as an accusation.
The regulatory penalty is the headline. The founder-relationship damage is the part that actually shows up first.
Checking a founder often means touching data about people who never applied to your fund at all.
It's the most commonly cited GDPR basis for informal diligence, and the most commonly misapplied.
The subject agrees to the check, connects their own accounts, and can see and revoke what was shared. That's the entire model.
None of these look like a compliance problem in the moment. Stacked together across a portfolio, they usually are one.
Six lawful bases exist for processing personal data. Most informal due-diligence workflows don't clearly rely on any of them.
A LinkedIn profile being visible to anyone doesn't mean its owner agreed to be profiled, scored, and filed away by a stranger doing diligence.