Most conversations about GDPR risk jump straight to fine amounts. In practice, for a fund or accelerator, the more immediate cost of unconsented profiling is rarely a regulator — it's the founder finding out.
Founder communities talk. A fund known for quietly compiling dossiers on people who pitch them, without ever asking, is a fund whose deal flow gets a specific reputation among exactly the people it needs to keep pitching it. That's a slower, quieter cost than a fine, and much harder to reverse.
Consent-based diligence flips that dynamic. A founder who's asked, told exactly what's being checked, and given control over what they connect walks away from the process — even a rejection — with a very different story to tell than one who later learns they were scored without ever knowing it happened.
The compliance argument and the relationship argument point in the same direction here, which is unusual enough to be worth noticing.
See how a consent-based check actually works.