Swap "founder" for "senior candidate" and most of the diligence problem stays identical: a public footprint that's easy to skim but hard to properly assess, real pressure to move fast, and a genuine, unresolved question about whether informal background checking respects the candidate's rights.
The GDPR analysis doesn't change either. A recruiter compiling a dossier on a candidate from public sources, without the candidate's knowledge, is processing personal data under the same rules a fund would be processing a founder's data under. The candidate relationship — someone a company hopes will trust it enough to join — arguably makes getting this wrong even more costly.
A consent-based check works the same way here as it does for founder diligence: the candidate is told what's being checked, agrees, and connects it themselves. It's a different subject, but not, underneath it, a different problem.
See how a consent-based check actually works.