It's an easy line to blur: if a founder's GitHub, X account, and LinkedIn are all public, surely reading them and drawing conclusions is fine. Legally, "public" and "consented" are two different questions, and due diligence usually only asks the first one.
Under GDPR, processing someone's personal data — and a diligence write-up built from their public footprint is exactly that — needs a lawful basis. Visibility isn't one of the six bases in Article 6. Consent is. So is, in narrower cases, legitimate interest, but that one comes with its own balancing test, not a blanket pass.
None of this makes reading a public profile illegal. It makes systematically compiling one into a formal assessment, without the subject's knowledge, a different kind of activity than a person casually clicking through someone's tweets. The scale and the paper trail are what change the analysis.
This is the gap consent-based diligence closes: the founder is told exactly what's being checked, agrees to it, connects the accounts themselves, and can revoke that access afterward. The information available is often similar. The legal footing underneath it is not.
This is general information about how GDPR's consent framework works, not legal advice for your specific process — if diligence at your fund touches EU data subjects at any volume, it's worth a real conversation with counsel.
See how a consent-based check actually works.