← All posts
GDPROSINT

The hidden liability of scraping a founder's social graph

29 January 2026

Founder diligence rarely stops at the founder. Pulling their network — co-founders, early collaborators, follower lists, mentioned colleagues — means processing personal data belonging to people who never applied for anything, never pitched anyone, and have no idea they're now part of someone's diligence file.

This is where a lot of informal OSINT work quietly expands its own legal exposure. A tool that maps "who does this founder collaborate with" by name is processing multiple people's personal data at once, each of whom would need their own lawful basis under a strict reading of GDPR.

This is one reason Potentia's Network Environment sub-score is computed only from aggregate counts — org memberships, collaborator counts, follow counts — never by fetching, identifying, or scoring another named person. The signal (how connected is this founder's environment) survives; the exposure of scoring uninvolved third parties doesn't.

It's a narrower feature than a full social-graph map would be. It's also one that doesn't quietly turn a founder check into a check on a dozen people who never agreed to anything.

See how a consent-based check actually works.

See pricingTry the free badge

More from the blog

Due diligence for recruiters: same problem, different subjectHow to read a Growth Readiness Score without over-indexing on one numberThe real cost of skipping diligence on a co-founder