Definition
B2B data is information about businesses and the people who work in them, collected and organized so sales, marketing and revenue operations teams can find, qualify and contact the right accounts.
It covers who a company is, what it uses, what it is doing now, and who inside it makes or influences a buying decision. A row of B2B data might hold a company name, industry, headcount, the CRM it runs, a recent hiring signal, and the name, role and work email of one contact.
B2B data is not one product. It is a set of data types that come from different sources, age at different speeds and fall under different rules. In this page's view, treating it as one list causes a large share of bad targeting and of avoidable compliance problems.
Why B2B data matters to sales and marketing
Targeting decisions in B2B selling rest on data. The ideal customer profile is written in firmographic and technographic terms, territories are split by region and size, and lead routing reads fields such as industry and role before a person ever sees the lead.
When the data is right, reps spend their day on accounts that fit and on people who own the problem. When it is wrong, the same reps email people who left, call switchboards, and pitch companies that were never a fit, while reports built on the CRM tell leadership the wrong story.
- Sales teams: building account lists, finding the buying group, and reaching contacts by email and phone.
- Marketing teams: segmenting campaigns, scoring leads, and matching ad audiences to target accounts.
- Revenue operations: routing, territory design, deduplication, and reporting that everyone trusts.
- Leadership: sizing the market and deciding which segments to enter next.
B2B data vs B2C data
Consumer data describes a person or a household as a buyer. B2B data describes an organization as a buyer, plus the people who act for it at work. That one difference changes what a record contains, how it ages and which rules apply.
| Question | B2B data | B2C data |
|---|---|---|
| Who is the buyer? | A company, usually through several people with different roles | One person or one household |
| Core record | Account plus contacts linked to it | Individual customer profile |
| Typical fields | Industry, headcount, tech stack, job title, seniority, work email | Age band, location, interests, purchase history, personal email |
| What makes it stale | Job changes, promotions, mergers, new domains, replaced software | Moves, life events, changed preferences |
| Privacy law | Contact details about a named person are still personal data | Personal data throughout |
The last row is the one teams get wrong. The ICO's business-to-business guidance says that processing personal data for direct marketing, even in a business context, falls under the UK GDPR. A work address does not turn a person into a company.
What teams actually do with B2B data
The same database serves several jobs, and each one leans on a different set of fields. Naming the job first keeps you from buying information nobody will use.
| Use case | Fields it leans on | What good data changes |
|---|---|---|
| Market sizing | Industry, headcount, revenue band, region | A total addressable market you can defend, not a guess |
| Ideal customer profile | Firmographic and technographic fields on the deals you won | Targeting built on customers, not on opinion |
| List building and prospecting | Contact data, titles, seniority, signals | Reps work accounts that fit and people who own the problem |
| Campaign segmentation | Industry, size, technology, intent topics | Messages written for one situation instead of for everyone |
| Lead scoring and routing | Standardized industry, size, role and region fields | Leads reach the right owner without manual triage |
| Territory and quota planning | Location, size, account counts | Territories with comparable potential |
| Reporting and analytics | Consistent account and contact records | Pipeline reports that leadership trusts |
Sales teams, marketing teams and revenue operations read the same records for different reasons. That is why field standards matter more than volume: one title field nobody standardized breaks routing, scoring and reporting at the same time.
The main types of B2B data
The guides that rank for this term split B2B data into anything from four to ten types. This page uses five core types, because each one answers a different question about an account or a person, and then names the extra types some teams track.
| Type | Question it answers | Examples of fields |
|---|---|---|
| Firmographic data | Who is the company? | Industry, headcount, revenue band, location, ownership, legal entity |
| Technographic data | What does it run? | CRM, marketing automation, cloud host, ecommerce platform, competing tools |
| Contact data | Who works there, and how do I reach them? | Name, job title, department, seniority, work email, direct dial, profile URL |
| Intent data | What is it researching now? | Topics researched, pages visited, content downloaded, review site activity |
| Chronographic data | What changed, and when? | Funding round, new executive, hiring spree, office move, merger, product launch |
A simple way to remember the split: firmographic and technographic data describe fit, intent and chronographic data describe timing, and contact data tells you who to talk to. Good targeting needs at least one field from each group.
Firmographic data
Firmographic data is the B2B version of demographics: the attributes of a company. Industry, employee count, revenue range, headquarters, number of locations, ownership and growth stage are the usual fields. Each field has its own origin, which is covered field by field in where firmographic data comes from.
Firmographics tend to change slowly, because a company rarely changes industry or headquarters. They are also a weak signal of need. Two companies with identical firmographics can have completely different problems, so firmographics define the pool, not the priority.
B2B technographic data
B2B technographic data lists the software, platforms and infrastructure a company uses: its CRM, marketing automation, cloud host, analytics, security and ecommerce tools. Together these fields describe its tech stack, and changes to the stack can be a buying signal in their own right.
Technographic data is collected in several ways: scanning public website code, reading job postings that name tools, checking public integrations and partner listings, and running surveys. Detection from website code can only see tools that leave a trace on public pages, so back-office systems may be missing. The full picture is in technographics.
It matters most when your product replaces, integrates with or depends on another tool. A company running a competing platform is a displacement target. A company running a technology you integrate with is a better fit. Treat each detected technology as inferred, not declared, until a conversation confirms it.
Contact data
Contact data describes people: name, job title, department, seniority, work email, direct phone and mobile, and a professional profile URL. It is what turns an account list into outreach. Phone fields have their own rules, covered in direct dial phone numbers.
Contact data is the type that most clearly counts as personal data, because it identifies a person. It is also the type that goes stale first when people change jobs. That makes it the part of any B2B database that needs the most verification and the most care.
B2B intent data
B2B intent data records research behavior that suggests a company may be in the market. First-party intent comes from your own website, content, emails and product. Third-party intent is collected by providers across publisher networks, review sites and other sources, then matched to companies. Sources and scoring are covered in B2B intent data.
Intent is a probability, not a fact. A spike in research on a topic can mean a buying project, a student, a competitor or one curious employee. Use buyer intent signals to decide which accounts to look at this week, then confirm the need in a conversation.
Sales and marketing teams use intent data in different ways. Marketing teams use account-level intent to choose which accounts see ads and content. Sales teams use it to order their prospects, open with a relevant topic, and reach the buying group while the research is still recent.
Intent data can also be personal data. The GDPR's definition in Article 4(1) names online identifiers among the ways a person can be identified, so engagement tied to a person or a device is not anonymous company data.
Chronographic data and signals
Chronographic data, often called signals or trigger events, tracks changes over time: new funding, leadership hires, layoffs, acquisitions, new offices, job postings and product launches.
Events like these can change priorities and budgets. A new leader may review the tools they inherited, and a funding round may come with hiring plans. Treat a signal as a reason to look closer and to give outreach a reason about the prospect, not as proof of need.
Other types some teams track
- Engagement data: how an account interacts with your emails, ads, events and website. It is first-party and can be the freshest data you have.
- Hierarchy data: parent companies, subsidiaries and locations, so ten offices of one group are not worked as ten separate accounts.
- Relationship data: existing customers, open opportunities, partners and past conversations held in your own CRM.
- Professional data: role history, skills and tenure, used to judge whether a contact is likely to own the problem.
B2B data sources: first, second and third party
Every B2B database is assembled from a mix of sources. Knowing the source of a field tells you how fresh it is likely to be, how much to trust it, and what you are allowed to do with it.
| Source | What it provides | Watch for |
|---|---|---|
| First-party data | Your CRM, form fills, product usage, website visits, support tickets, billing | Fields go stale after the deal closes; duplicates across systems |
| Second-party data | Another organization's first-party data shared with you, such as a partner or event co-host | What the people were told about sharing |
| Third-party data | Compiled company and contact databases, enrichment, intent feeds from data providers | Coverage varies by region and segment; ask how each field is sourced |
| Public records | Regulatory filings, business registries, industry classifications | Accurate for legal entities, thin on people |
| Public web sources | Company websites, press releases, job postings, news | Personal data stays personal data even when public |
| Professional networks | Titles, roles, employment history, company pages | Platform terms on automated collection |
First-party data
First-party data is what you collect yourself: CRM records, form fills, product sign-ups, website visits, email engagement and support history. It covers people who already know you, so it tends to be the most relevant and the smallest. The wider view of what your own records hold is in customer data.
Second-party data
Second-party data is first-party data that another organization shares with you directly, such as attendee lists from a co-hosted event or leads from a co-marketing program. The European Commission's guidance on acquired lists says the sharing organization must be able to show the data was obtained lawfully and may be used for advertising.
Third-party data
Third-party data comes from providers whose business is collecting and compiling data about companies and people they have no direct relationship with. It widens the pool to accounts that have never heard of you, at the cost of more checking and more legal homework, because the people in it never dealt with you.
Professional networks sit in a special place. LinkedIn's User Agreement prohibits using software, scripts, crawlers or browser plugins to scrape or copy the service, including profiles. A provider that cannot explain how it collects profile fields is a provider to question.
Public records: free B2B data sources
Government sources are where you confirm that a company exists, what it is legally called, and what it reports. They are thin on people and say nothing about buying intent, but they are free to read and anyone can check them.
SEC EDGAR filings
The SEC describes EDGAR as free public access to millions of documents filed by publicly traded companies and others. You can search by company name or ticker, run full text searches across more than 20 years of filings, and use EDGAR's RESTful APIs for filing history and financial statement data.
EDGAR also publishes the SIC codes used to indicate a company's type of business. Its limit is coverage: a private company that does not file with the SEC will not appear, so EDGAR confirms public companies, their reports and their filers, not your whole market.
State business registries
The SBA's guide to registering a business says most states require registration with the Secretary of State's office, a business bureau or a business agency. Those registries are where a legal entity's name, formation date and registered agent are recorded.
Delaware's Division of Corporations is a useful example of what a registry gives you. Its free search returns the entity name, file number, formation date, registered agent details and residency. Results include inactive entities and do not show status, which is available for a fee.
Delaware also states that it strictly prohibits mining data from the search and that automated tools may get access suspended. Registries are for confirming an entity, not for bulk list building, and a registered agent's address may not be where the company works.
Outside the US, registries play the same role. The ICO names Companies House among the places publicly available data can come from, and adds that personal data found in such sources is still covered by the UK GDPR.
Census NAICS industry codes
The U.S. Census Bureau describes NAICS as the standard federal statistical agencies use to classify business establishments. Codes run from a two-digit sector to a six-digit national industry, and each extra digit is a narrower category.
The Census NAICS FAQs add a point every data buyer should know: no central agency assigns, monitors or approves NAICS codes for businesses, and there is no official register of them. An industry code in a B2B file is somebody's classification, so ask who assigned it and how.
Census County Business Patterns
County Business Patterns is an annual Census series with the number of establishments, employment and payroll by industry and employment size, down to county and ZIP code level. The Census Bureau says private businesses use it to analyze market potential, measure sales and advertising programs, set sales quotas and develop budgets.
It counts establishments; it does not name them. Its disclosure methods are changing: the Census Bureau says it is evaluating new approaches after a Commerce Department order prohibiting noise infusion. Use it to size a segment and check whether a vendor's account count for that segment is plausible, not to build a list.
B2B data validation: how records are checked
B2B data validation is checking that a record is correctly formed, still true and safe to use before it drives an email, a call or a routing rule. Different checks catch different errors, so ask any source which checks it runs on which fields, and when it ran them.
| Check | What it catches | What it cannot prove |
|---|---|---|
| Syntax and format | Typos, missing fields, invalid phone formats | That the address or number belongs to the person |
| Domain and mail server | Dead domains, domains that cannot receive mail | That a given mailbox exists |
| Mailbox check | Mailboxes the server rejects outright | Existence, when the server accepts everything or will not say |
| Catch-all detection | Domains that accept every address | Whether the person still works there |
| Phone line check | Disconnected or invalid numbers | That the right person answers |
| Cross-source match | Fields that disagree between sources | Truth, when all sources copied the same error |
| Human research | Wrong titles, departed contacts | Anything after the date it was done |
Email checks have a hard limit set by the protocol itself. RFC 5321, the SMTP standard, lets sites disable the VRFY command for security reasons, and says a server that cannot verify an address in real time should answer with code 252 rather than a yes or a no.
The same RFC describes mail that is accepted during the session and bounced later. So a mailbox check can return accepted for an address that will still bounce, and domains that accept every address make the result meaningless. That is the problem described in catch-all email.
A verified flag is only as good as its date. Ask when each record was last verified, not just whether it was, and store that date on the record.
B2B data decay: why every database ages
Data decay is the gradual loss of accuracy in a database as the real world changes and the records do not. B2B data describes jobs and companies, and both change, so a B2B database starts aging the day it is built. The causes and how to measure them are in data decay.
The common causes are people changing jobs or getting promoted, companies merging, closing, rebranding or moving to a new email domain, phone systems changing, and tools being replaced. Each event breaks one or more fields while the rest of the record still looks fine.
Decay is uneven. Industry and location change slowly. Titles, emails and phone numbers change faster. Intent and signal data are only useful while recent, so an intent spike from last quarter is closer to history than to a signal.
Decay is also a legal issue. Article 5(1)(d) of the GDPR requires personal data to be accurate and, where necessary, kept up to date, with every reasonable step taken to erase or correct inaccurate data. The ICO adds that the source and status of personal data should be clear.
Vendors and blogs publish yearly decay, accuracy and coverage rates for B2B data, usually measured on their own databases or without a stated method. None are quoted on this page. Measure your own: track hard bounces, wrong-person replies and changed titles on a sample of your CRM every quarter.
How to judge B2B data quality
Quality is not one number. A source can be accurate but thin, or broad but stale. Judge it on the dimensions that matter for your use.
The only reliable test is your own. Take a sample of accounts you know well, including recent wins and lost deals, request the source's records for them, and check fields against what you know. Then send a small batch and measure bounces and wrong-person replies.
Score coverage and accuracy separately. A file can hold a record for every account on your list and still have the wrong person in half of them, and a file that is right about everyone it holds can miss your best segment entirely.
B2B data hygiene: keeping the database clean
Data hygiene is the routine work that keeps a database usable: removing duplicates, fixing formats, updating stale records and suppressing people who objected. It is maintenance, not a project, because decay never stops.
- Deduplicate: merge duplicate accounts and contacts, using the company domain as the main key for accounts.
- Standardize: one picklist for industry, country and seniority, and job titles mapped to departments and levels.
- Validate on entry: check emails and required fields when records are created, not months later.
- Refresh on a schedule: re-verify active accounts and contacts before each campaign and on a fixed cycle.
- Act on bounces: a hard bounce means the record is wrong; update it or retire it.
- Keep a suppression list: objections, unsubscribes and do not contact requests, applied to every import.
- Assign an owner: someone in revenue operations is accountable for each object and field.
B2B data enrichment
Data enrichment adds missing or updated fields to records you already have. A form fill with only a name and a work email becomes a record with company, industry, headcount, title and seniority, so it can be routed and scored straight away.
Enrichment runs in three ways: in bulk on an existing database, in real time when a form is submitted, or on a schedule that refreshes records before they decay. The full process, including waterfall enrichment across several sources, is covered in lead enrichment.
Enrichment is only as good as the match. A shared inbox or a personal email address can match to the wrong company or to nothing, so check the match key before you trust the fields that came back.
B2B data integration: getting data into your stack
B2B data integration is connecting outside data to the systems people work in. In many teams the CRM is the system of record, and other tools should write to it through one agreed path rather than through several separate imports.
- Pick the key: match accounts on the company domain and contacts on the work email, so the same company does not enter twice under two names.
- Enrich at creation: fill firmographic and role fields in real time when a lead is created, so scoring and routing run on a complete record.
- Refresh in batches: run bulk updates on a schedule for the accounts that matter, instead of re-enriching the whole database every month.
- Store provenance: keep the source, the collection date and the last verification date on each record as ordinary fields.
- Map fields once: agree how a provider's industry and seniority values map to your picklists before the first import, not after it.
- Limit write access: decide which tool may overwrite which field, and let the rest suggest changes rather than silently replace values.
B2B data API
A B2B data API is a programmatic interface to a provider's company and contact data. Your system sends a request, such as a domain, an email or a set of filters, and gets structured records back. It suits enrichment that has to happen the moment a form is submitted or a record is created.
| Operation | What you send | What comes back |
|---|---|---|
| Search | Filters: industry, headcount, region, technology, title, seniority | Matching companies or people, often as IDs to fetch next |
| Match or enrich | A domain, email, name and company, or profile URL | One record with the provider's fields, or no match |
| Bulk | A file or batch of records | Enriched records, usually by callback or download |
| Change feed | A list of accounts or contacts to watch | Updates such as job changes or new signals |
Before you build on any provider's API, read its documentation. The developer side, including waterfall calls across several providers, is covered in data enrichment API. These are the points worth checking first.
- Authentication: how API keys are issued, scoped and rotated, and whether each user or system gets its own key.
- Rate limits: requests per second and per day, and what happens to a real-time form enrichment when you hit the limit.
- Pricing model: whether the API is metered per record, per credit or by subscription tier, and whether a no-match or a repeated lookup costs anything.
- Field definitions: what each returned field means, which values are inferred, and the date each field was last verified.
- Free tiers and trials: what a free or trial key returns, so a test is run on the same data you would pay for.
- Licensing: whether you may store API results in your CRM, and what must be deleted when the contract ends.
Real-time and batch APIs serve different jobs. A real-time enrichment API answers in the moment, so routing and lead scoring run on a complete record. A batch API refreshes thousands of records overnight. Some teams need both, so check whether a provider returns the same fields through its real-time and batch APIs.
AI agents can consume B2B data APIs too. The Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external systems such as data sources and tools. If a provider offers data through MCP, ask the same provenance, licensing and suppression questions as for any other API.
Agents also raise a write question. Decide which agent may update CRM fields on its own and which may only suggest changes, so an agent's guess does not overwrite a verified value.
Free public data APIs
Public data has APIs as well. The SEC lists EDGAR APIs for filing history and financial statement data, which can confirm details about public companies without going through a data provider.
The Census Bureau offers a free Data API that developers can call from their own applications, with an API key on request. It serves aggregate statistics such as County Business Patterns, not named companies or contacts, so it supports market sizing rather than list building.
Is B2B data legal? GDPR, CCPA and email rules
Under the GDPR, personal data is any information relating to an identified or identifiable natural person. Company-level facts such as industry and headcount are generally not personal data. A named contact's work email, direct dial and title are, because they identify a person. This section summarizes the official sources and is not legal advice.
GDPR and legitimate interest for B2B data
Processing personal data needs a legal basis. For B2B prospecting, many teams rely on legitimate interests in Article 6(1)(f), which applies unless the person's interests or fundamental rights override yours. Recital 47 says processing for direct marketing may be regarded as carried out for a legitimate interest.
"May" is not "always". You still have to show the interest is real, the processing is necessary for it, and it does not override the person's rights, and you should document that assessment. Contacting a relevant role about a relevant offer is easier to defend than emailing everyone at a company.
Article 14 covers data you did not collect from the person. You must tell them, among other things, what categories of data you hold and the source it came from.
Article 14(3) sets the timing: within a reasonable period and at the latest within one month, and if you use the data to contact them, at the latest at the first communication.
Article 21 gives people the right to object to direct marketing at any time. Once they object, the data can no longer be processed for that purpose, and the right must be brought to their attention clearly and separately at the first communication at the latest.
The European Commission adds points for bought lists: the seller must be able to show the data was obtained lawfully and may be used for advertising, you must keep the list up to date and exclude people who objected, and email marketing must also follow the ePrivacy Directive.
Check the national email marketing rules in each EU market you send to; this page does not summarize them.
UK rules for business contacts
The ICO's business-to-business guidance says the UK GDPR applies when you process personal data for direct marketing, even in a business context.
The PECR rule on marketing by electronic mail does not apply to corporate subscribers, so companies can be emailed without consent if you do not hide your identity and give a valid opt-out address.
Sole traders and some partnerships count as individual subscribers, so they can only be emailed with consent or under the soft opt-in. Live calls must be screened against both the TPS and CTPS registers. The ICO notes this guidance is under review after the Data (Use and Access) Act.
CCPA and business contact data
The California Privacy Protection Agency states that the CCPA exemptions for personal information reflecting business-to-business transactions, and for employment data, expired on December 31, 2022. Its FAQ adds that California residents include contacts for business customers, vendors and independent contractors.
That gives California business contacts the CCPA rights the agency lists: to know, delete and correct personal information, to opt out of its sale or sharing, to limit the use of sensitive information, and to equal treatment when they use those rights.
Data brokers and the California Delete Act
Under the Delete Act, a business that knowingly collects and sells personal information about consumers it has no direct relationship with is a data broker. The CPPA says brokers must register every year, with a January 31 deadline, or risk fines.
The CPPA also runs the Delete Request and Opt-out Platform (DROP). Beginning August 1, 2026, registered brokers must access it at least once every 45 days and process the deletion requests it holds. When you evaluate a provider, ask whether it is registered and how DROP deletions reach your copy of the data.
CAN-SPAM applies to B2B email
The FTC's compliance guide states that CAN-SPAM makes no exception for business-to-business email. Commercial emails need accurate headers and subject lines, a valid physical postal address and a clear way to opt out, and opt-outs must be honored within 10 business days, including when another company sends for you.
The same guide says that once people opt out, you cannot sell or transfer their email addresses, even as part of a mailing list. That rule matters when you share or resell lists, not just when you send.
Security for B2B contact data
A contact database holds personal information, so it needs protecting. The FTC's guide for businesses builds a data security plan on five principles: take stock, scale down, lock it, pitch it and plan ahead.
For a B2B team, that means knowing which exports exist, limiting who can download lists, and deleting what you no longer need.
| Rule | What it means for B2B data | Official source |
|---|---|---|
| GDPR Art. 4(1) | Named business contacts are personal data | GDPR text |
| GDPR Art. 5(1)(d) | Keep personal data accurate and, where necessary, up to date | GDPR text |
| GDPR Art. 6(1)(f), Recital 47 | Legitimate interest can support direct marketing, after a balancing test | GDPR text |
| GDPR Art. 14 | Tell contacts the source and categories of data, at first contact at the latest | GDPR text |
| GDPR Art. 21 | Honor objections to direct marketing and keep a suppression list | GDPR text |
| UK PECR | Corporate subscribers can be emailed with identification and opt-out; sole traders need consent or soft opt-in | ICO |
| CCPA | B2B exemption expired; California business contacts have privacy rights | CPPA |
| California Delete Act | Data brokers register yearly and process deletion requests through DROP | CPPA |
| CAN-SPAM | No B2B exception; opt-outs honored within 10 business days | FTC |
Buying vs building a B2B database
There are several ways to get B2B data, and many teams combine them. The right mix depends on how narrow your market is, how many records you need, and who has time to maintain them.
| Approach | Works best when | Trade-off |
|---|---|---|
| Subscribe to a B2B database | A broad market, many roles, fast list building | Shared with competitors, coverage gaps in some niches and regions, ongoing cost |
| Build your own list | A narrow market of a few hundred accounts you can research by hand | Slow, needs research time, still needs validation and hygiene |
| Buy a one-time list | Rarely, in this page's view, for outreach | Starts decaying the day it arrives, and provenance can be unclear |
| License a raw dataset | You have data engineers and want to build your own models | You own matching, cleaning, storage and compliance |
| Enrich first-party data | You already have traffic, sign-ups or customers | Only covers people who already found you |
Building by hand fits a short account list in an ABM strategy, where each account deserves research anyway. A database subscription makes more sense when volume is high and the market is broad, across many segments and regions.
How to evaluate B2B data providers
This page does not rank vendors or quote prices. Providers fall into categories, and the right category depends on the job you named at the start.
Search, filters and export of contacts and accounts for prospecting, sometimes with email and phone.
Add firmographic and contact fields to records you already have, in bulk or through an API.
Research activity and company events matched to accounts, used to prioritize outreach.
Large company or people datasets delivered as files or APIs, for teams that build their own models and tools.
Whatever the category, test coverage on your own accounts, ask for the source and last verification date of each field, read how opt-outs and deletions are handled, and check whether the provider is registered where registration is required.
Evaluating B2B intent data providers
Intent feeds need extra questions, because the signal is inferred and the method is not always disclosed. Ask where the activity comes from: your own site, a data co-op, publisher sites, review sites or ad exchanges. Then ask how activity is matched to a company, which topics exist, and how long a spike stays active.
Ask for a test on accounts you already know: recent wins, open deals and accounts you know are not buying. If the feed cannot tell those groups apart better than your own engagement data, it adds noise, not timing.
We are evaluating B2B data for {{segment}} in {{regions}}. 1. How is each field collected: contact email, direct dial, title, industry, technology? 2. When was each record last verified, and is that date visible per record? 3. Can you run a match on these {{sampleSize}} accounts we know well, so we can check accuracy? 4. How do you give notice to the people in your database, and how do objections and deletions reach us? 5. What is your legal basis for EU and UK contacts, and are you registered as a data broker where required? 6. Through which channels can we access the data: interface, export, API, files? 7. What happens to exported records when our contract ends? {{senderName}}
You send it before defining your segment and sample, or you accept a demo on accounts the provider picked. Every source looks good on its own examples. Insist on your list, and compare the answers in writing across providers.
This question list was written for this page. Adapt it to your segment and region.
A practical B2B data checklist
Write the profile first
Define the accounts and roles you sell to in data terms: industry, size, region, technology, and the titles in the buying group. The profile decides which fields matter.
Map fields to uses
List which fields drive routing, scoring, segmentation and outreach. Anything that drives nothing is not worth buying or maintaining.
Start from first-party data
Clean and enrich what you already have before adding outside sources. Customers and past deals are your best model of fit.
Confirm entities in public records
Check legal names, parents and industry codes against filings and registries for the accounts that matter most.
Test sources on known accounts
Compare each candidate source on the same sample. Measure accuracy, coverage and bounces yourself.
Record provenance and legal basis
Store the source and collection date on each record, document your legitimate interest assessment, and prepare the notice for first contact.
Validate before every send
Validate emails and check suppression lists before a campaign or sequence, not after the bounces arrive.
Refresh and retire
Re-verify active records on a schedule and retire contacts that have left or stopped responding for a long time.
Using B2B data in outreach
Data finds the person; the message still has to earn the reply. Use firmographic and technographic data to choose the account, signals to choose the moment, and contact data to reach the right role, then write about the prospect's situation, not the fields you hold.
Put accounts with a fresh signal first in your sequences across email, phone and LinkedIn. Bounces, wrong-person replies and job changes that come back from outreach are data too, so route them back to whoever owns hygiene.
Common mistakes with B2B data
- Buying a list before writing the ideal customer profile, so the list decides the market.
- Treating verified as permanent, and sending to records last checked long ago.
- Reading an accepted mailbox check as proof that a person exists.
- Assuming B2B contact data is outside privacy law because the email is a work address.
- Skipping the first-contact notice and opt-out for contacts you did not collect yourself.
- Trusting an industry code without asking who assigned it.
- Letting every tool write to the CRM with no owner, so duplicates multiply.
- Reading an intent spike as a buying decision instead of a reason to look closer.
- Judging a provider on a demo of accounts it chose.
B2B data in a first email
When the contact came from a third-party source, the first email is also the moment the GDPR asks you to say where the data came from and how to object. The template below was written for this page and does both in two plain lines.
Subject: {{signal}} at {{companyName}} Hi {{firstName}}, I saw that {{companyName}} {{signal}}. For {{roleArea}} teams, that can put {{problem}} on the list. We help companies like {{similarCustomer}} with {{outcome}}. Is that yours to solve, or should I be asking someone else? {{senderName}} {{senderCompany}}, {{postalAddress}} Where your details came from: {{sourceName}}, a business contact database that lists people by role. I hold your name, role and work email. You can object at any time: reply with the word remove and I will delete your record and stop writing.
You paste a source line but name a vague source, or the remove promise is not wired to a suppression list.
A notice nobody can check, and an objection nobody actions, are worse than no line at all. Name the real source, and make the suppression automatic before the first send.
Frequently asked questions
What is B2B data?
B2B data is information about businesses and the people who work in them, organized so sales and marketing teams can find, qualify and contact the right accounts. It covers company attributes, technology, contacts, research behavior and recent changes such as funding or new executives.
What are the main types of B2B data?
This page uses five core types. Firmographic data describes the company, technographic data lists the software it runs, contact data identifies people and how to reach them, intent data shows what it is researching, and chronographic data records changes such as funding or a new executive.
What is B2B technographic data?
B2B technographic data lists the software, platforms and infrastructure a company uses, such as its CRM, cloud host and marketing tools. It is inferred from website code, job postings, integrations and surveys, so treat each detected tool as likely rather than confirmed until a conversation proves it.
What is B2B intent data?
B2B intent data records research activity suggesting a company may be in the market. First-party intent comes from your own site, emails and product. Third-party intent is collected across publisher and review networks, then matched to a company. It is a probability, not a fact.
Where does B2B data come from?
From four places: first-party data you collect yourself, second-party data a partner shares with you, third-party data compiled by data providers, and public records such as regulatory filings and business registries. Each source ages differently and carries different legal duties.
Is there a free B2B data API?
For company facts, yes. The SEC's EDGAR APIs return filing history and financial statement data for companies that file with it, and the free Census Data API serves aggregate statistics such as County Business Patterns. Neither returns named contacts, and some state registries prohibit data mining.
What is a B2B data API?
A B2B data API is a programmatic interface to a provider's company and contact data. Your system sends a domain, an email or a set of filters and gets structured records back, which suits real-time enrichment when a form is submitted or a CRM record is created.
What is B2B data validation?
B2B data validation checks that a record is correctly formed, still true and safe to use. It covers syntax, domain and mailbox checks, catch-all detection, phone line checks, cross-source matching and human research. Each check proves something different, so ask which ones were run and when.
How fast does B2B data decay?
This page quotes no decay rate, because a rate measured on someone else's database does not describe yours. Measure your own instead: sample your CRM each quarter and track hard bounces, wrong-person replies and titles that no longer match.
Is B2B contact data personal data under GDPR?
Yes, when it identifies a person. The GDPR defines personal data as any information relating to an identified or identifiable natural person, so a named contact's work email, direct dial and title count. Company facts such as industry and headcount generally do not.
Do I have to tell people where I got their data?
Under the GDPR, yes. Article 14 requires telling people whose data you did not collect from them which categories you hold and where it came from, within one month at the latest, and at the first communication at the latest if you use it to contact them.
Does the CCPA cover B2B contact data?
Yes. The California Privacy Protection Agency states that the exemption for personal information reflecting business-to-business transactions expired on December 31, 2022, and that California residents include contacts for business customers. They have rights to know, delete, correct and opt out of sale or sharing.
Does CAN-SPAM apply to B2B emails?
Yes. The FTC's compliance guide states the law makes no exception for business-to-business email. Commercial emails need accurate headers, a valid physical postal address and a working opt-out, and opt-out requests must be honored within 10 business days.
How do I choose a B2B data provider?
Start from your segment, then test each provider on accounts you already know well. Ask how each field is collected, when it was last verified, how objections and deletions are handled, and whether the provider is registered as a data broker where required.
- EUR-Lex, Regulation (EU) 2016/679 (GDPR), Articles 4(1), 5(1)(d), 6(1)(f), 14 and 21 and Recital 47, for the definition of personal data, the accuracy principle, legitimate interests, the notice owed when data was not collected from the person with its timing, and the right to object to direct marketing, checked Oct 1, 2026.
- EUR-Lex answers scripted requests with a bot check, so the GDPR wording above was read in the official English text of the regulation served by the EU Publications Office.
- European Commission, Can data received from a third party be used for marketing?, for the conditions on acquired contact lists, keeping lists up to date, excluding objectors and the ePrivacy Directive, checked Oct 1, 2026.
- ICO, Business-to-business marketing, for UK GDPR applying to business contacts, corporate and individual subscribers under PECR, the soft opt-in, TPS and CTPS screening, publicly available data including Companies House, and the review after the Data (Use and Access) Act, checked Oct 1, 2026.
- ICO, Principle (d): Accuracy, for reasonable steps and keeping the source and status of personal data clear, checked Oct 1, 2026.
- California Privacy Protection Agency, Frequently Asked Questions, for the expiry of the business-to-business exemption on December 31, 2022, business contacts as California residents, and the list of CCPA rights, checked Oct 1, 2026.
- California Privacy Protection Agency, Data Brokers, for the data broker definition, annual registration by January 31, and DROP access every 45 days from August 1, 2026, checked Oct 1, 2026.
- Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business, for no business-to-business exception, the postal address, the 10 business day opt-out, shared responsibility when another company sends, and the ban on transferring opted-out addresses, checked Oct 1, 2026.
- Federal Trade Commission, Protecting Personal Information: A Guide for Business, for the five principles of a data security plan, checked Oct 1, 2026.
- U.S. Securities and Exchange Commission, Search Filings (sec.gov/search-filings), for free public access to EDGAR filings, search by name or ticker, full text search across more than 20 years, EDGAR APIs and the SIC code list, checked Oct 1, 2026. The SEC blocks scripted requests, so the page was read in a browser and is named here without a link.
- U.S. Small Business Administration, Register your business, for most states requiring registration with the Secretary of State's office, a business bureau or a business agency, checked Oct 1, 2026.
- Delaware Division of Corporations, General Information Name Search, for the free entity fields (name, file number, formation date, registered agent details, residency), inactive entities without status, the fee for status, and the prohibition on data mining and automated tools, checked Oct 1, 2026.
- U.S. Census Bureau, North American Industry Classification System, and its FAQs tab, for NAICS as the federal standard for classifying business establishments, the two to six digit structure, and the absence of a central agency or official register for NAICS codes, checked Oct 1, 2026.
- U.S. Census Bureau, County Business Patterns: About this program, for the annual establishment, employment and payroll series by industry, employment size and geography, its use by private businesses for market potential and sales quotas, and its notice that disclosure methods are under review after an order prohibiting noise infusion, checked Oct 1, 2026.
- U.S. Census Bureau, Developers, for the free Census Data API and API keys, checked Oct 1, 2026.
- IETF, RFC 5321 Simple Mail Transfer Protocol, sections 3.5.3 and 7.3 and the discussion of bounces, for disabled VRFY, the 252 reply when an address cannot be verified, and mail bounced after acceptance, checked Oct 1, 2026.
- LinkedIn, User Agreement (effective November 3, 2025), for the prohibition on scraping or copying the services, including profiles, checked Oct 1, 2026.
- Model Context Protocol, What is the Model Context Protocol (MCP)?, for MCP as an open-source standard for connecting AI applications to external systems, checked Oct 1, 2026.
- Jeluvi entries this term builds on: B2B intent data, technographics, firmographics source, data decay, catch-all email, customer data, lead enrichment, data enrichment API.
- This page does not rank or recommend data providers, quotes no prices, and quotes no vendor accuracy, coverage or decay figures. Nothing here is legal advice.