Cross-referencing a founder's GitHub against their LinkedIn to check for inflated titles. Screenshotting old tweets before they get deleted. Pulling a Crunchbase snapshot into a shared doc. Asking a portfolio company's other founders what they've heard. Keeping an informal spreadsheet of "flags" on people you've met at demo days.
Individually, each of these feels like ordinary diligence hygiene. Together, they're a pattern GDPR has a name for: systematic profiling without a documented lawful basis, without the subject's knowledge, and usually without a retention policy for how long that spreadsheet sticks around.
The fix isn't to stop doing diligence — it's to make the process the founder is a participant in rather than a subject of. Tell them what's being checked. Let them decide whether to connect an account or not. Keep a real record of when they agreed, not a spreadsheet nobody remembers starting.
That's the difference between due diligence and a shadow file: whether the person it's about ever got asked.
See how a consent-based check actually works.