Article 6 of the GDPR lists exactly six lawful bases for processing someone's personal data: consent, contract necessity, legal obligation, vital interests, public task, and legitimate interest. Founder due diligence — compiling and scoring a person's professional footprint — has to fit under one of these to be lawful when it touches an EU data subject.
Contract necessity, legal obligation, vital interests, and public task rarely apply to a fund or recruiter checking a founder before a decision. That leaves two realistic options in practice: legitimate interest, or consent.
Legitimate interest sounds like the convenient default, but it comes with a mandatory balancing test — your interest in checking the founder has to be weighed against their rights and reasonable expectations. A founder who never agreed to be profiled, and never expected a stranger to build a scored dossier on them, has a real argument that the balance doesn't favor you.
Consent sidesteps that argument entirely. If the subject explicitly agrees to what's being checked, the lawful basis is settled and documented before anything is gathered. That's the entire premise behind how Potentia's consent flow works: the founder sees exactly what's being requested, agrees, and connects the data themselves.
This explains the general framework, not a specific legal opinion — every fund's actual exposure depends on facts a lawyer, not a blog post, should weigh in on.
See how a consent-based check actually works.