← All posts
GDPRcompliance

What a "legitimate interest" argument really covers — and where it stops

26 January 2026

"We have a legitimate interest in knowing who we're funding" is the sentence that ends most internal debates about whether diligence needs consent. It's not wrong that funds have a legitimate interest — it's that legitimate interest as a GDPR basis requires passing a specific three-part test, not just having a good reason.

The test asks: is there a genuine, specific interest (not just "due diligence in general")? Is the processing actually necessary to achieve it? And does that interest outweigh the individual's own rights and reasonable expectations, given the context?

That third part is where informal diligence usually loses. A founder pitching a fund reasonably expects some scrutiny of their pitch, their traction, their references. They don't necessarily expect a scored dossier assembled from their entire public digital footprint, compiled without their knowledge, kept indefinitely in someone's private notes.

Consent removes the ambiguity. Instead of arguing after the fact that a check was proportionate and expected, the founder confirms upfront that it is. It's a lower-risk foundation for the exact same diligence work.

General information, not a legal opinion on any specific fund's practices.

See how a consent-based check actually works.

See pricingTry the free badge

More from the blog

Due diligence for recruiters: same problem, different subjectHow to read a Growth Readiness Score without over-indexing on one numberThe real cost of skipping diligence on a co-founder