A surprising amount of diligence risk lives not in the collection step but in what happens after: how long is the founder's data kept, who can see it, and is there any actual process for deleting it once a decision has been made?
GDPR's storage limitation principle says personal data shouldn't be kept longer than necessary for the purpose it was collected for. "We might need it again someday" is not, on its own, a retention policy — it's the absence of one.
This is where informal diligence tends to quietly accumulate risk over time: old spreadsheets, old screenshots, old notes on founders from deals that closed or fell through years ago, sitting in someone's drive with no owner and no deletion date. Every one of those records is still personal data, still subject to the same rules it was the day it was collected.
A structured process needs an equally structured answer to "and then what happens to it," not just a good answer to "how did we get it."
See how a consent-based check actually works.