A browser extension. You visit a LinkedIn profile, you click, and the personal phone number appears, along with the work address.
One hundred and sixty million records built that way. Two hundred and forty thousand euros in fines, and an injunction.
The French data protection authority’s decision of 5 December 2024 against KASPR is the most instructive document in existence on what a scraped business contact database is worth legally.
The mechanism, as described by the authority
The description is neutral, which makes it more effective than an indictment:
“La société KASPR commercialise une extension payante pour le navigateur Chrome qui permet à ses clients d’obtenir les coordonnées professionnelles de personnes dont ils visitent le profil sur le réseau social LinkedIn. Pour ce faire, la société se constitue une base de coordonnées à partir de Linkedin et d’autres sites web, tels que des annuaires de noms de domaines.”
And the order of magnitude: “Environ 160 millions de contacts figurent dans la base de données constituée par la société KASPR.”
The intended use is explicit: “Les coordonnées ainsi collectées sont susceptibles de permettre aux clients de la société de contacter les personnes cibles, par exemple pour de la prospection commerciale ou de la vérification d’identité.”
This is exactly the use case half the B2B data enrichment market sells today.
The first finding: reasonable expectations
The Article 6 breach does not concern the principle of public collection. It concerns what the individual could reasonably foresee.
“La CNIL a considéré que la collecte par KASPR de coordonnées pour lesquelles les utilisateurs de Linkedin avaient expressément limité la visibilité excédait ce à quoi pouvaient raisonnablement s’attendre les personnes qui s’inscrivent sur un réseau social professionnel.”
The test is therefore not “was the data accessible”, but “could the person have expected this use”. A visible professional profile is not authorisation to build a commercial file from restricted contact details.
It is the same reasoning that governs legitimate interest in B2B prospecting: the balancing test looks at the person’s expectations, not the technical availability of the data.
The second finding: notice, four years late and in English
This is the most transferable breach, because it concerns everyone exploiting data not collected from the individuals themselves.
“La société n’a commencé à informer les personnes concernées que leurs données personnelles avaient été collectées qu’en 2022, soit quatre ans après la mise en œuvre de l’extension KASPR. L’information se fait par un courriel en anglais, renvoyant vers un lien permettant de s’opposer au traitement.”
Then the clarification that will shape practice:
“Outre l’absence d’information des personnes sur la collecte de leurs données jusqu’en 2022, la CNIL a considéré que le fait d’adresser un courriel rédigé en anglais ne permettait pas une information transparente et compréhensible.”
A notice email written in English, sent to people in France, does not count as notice. Language is part of transparency.
Recall that this notice obligation is not optional and has a deadline: Article 14 requires writing within a month, or at the latest with the first message.
The third finding: where did this address come from?
The Article 15 breach is the most fearsome for anyone exploiting an aggregated database.
“Lorsque des personnes ayant fait l’objet de démarchage interrogeaient la société KASPR sur la manière dont leurs coordonnées avaient été obtenues, celle-ci se contentait de leur indiquer que leurs coordonnées avaient été collectées à partir de sources publiquement accessibles.”
That answer was found insufficient:
“Après avoir rappelé que la société devait pouvoir indiquer ‘toute information disponible quant à la source’ des données, la CNIL a estimé que même si la société était dans l’incapacité technique de préciser la source des données collectées pour chaque personne concernée, elle avait cependant connaissance d’une partie des sources qui alimentent sa base.”
Read the construction: technical inability does not excuse. If you know some of your sources, you must disclose that part.
“Publicly accessible sources” is not an answer. It is a category.
What this decision requires of a contact database
Put together, the three requirements sketch the specification of a B2B database that would survive an inspection.
Provenance retained per record, or at minimum a documented and disclosable set of sources.
Notice sent to individuals within the deadline, in their language, and not four years later.
An objection right that works first time, and that covers the whole database.
None of those three requirements is technical. All three are nonetheless absent from nearly every enrichment offer sold today, and the buyer remains the controller.
M3AAWG, on the operator side, condemns the practice in terms that leave no ambiguity: “Email appending is a direct violation of core M3AAWG values”. Law and operators, for once, are saying the same thing.
What to do tomorrow morning
If you use an enrichment extension, open its privacy policy and look for the answer to one question: what does the vendor tell someone who asks where their number came from?
If you exploit a purchased database, test your own answer to that question. A prospect writes to you asking for the source. You have one month to answer, and “publicly accessible sources” will not do.
Then check the language of your notice emails. A template in English sent to French recipients has already been found non-compliant.
And if you build a database, build it on criteria you can explain to the person concerned. Sestaro’s contact search rests on explicit professional criteria, role, company, sector, territory, and lets you search for free before revealing anything: you qualify the target before paying, which is also the best way to know why you are writing to someone.
Sources
- CNIL (19 December 2024). Aspiration de données : sanction de 240 000 euros à l’encontre de la société KASPR, decision SAN-2024-020
- European Union (27 April 2016). Regulation (EU) 2016/679 (GDPR), Articles 6, 12, 14 and 15
- CNIL. Sanctions et mesures correctrices : bilan 2024 de l’action de la CNIL
- M3AAWG. M3AAWG Position on Email Appending
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
