Browse templates

B2B data: what it is, the five types, where it comes from, why it decays, and the rules that apply before you press send.

Last checked Oct 1, 202626 min readNo vendor rankings

Definition

B2B data is information about businesses and the people who work in them, collected and organized so sales, marketing and revenue operations teams can find, qualify and contact the right accounts.

It covers who a company is, what it uses, what it is doing now, and who inside it makes or influences a buying decision. A row of B2B data might hold a company name, industry, headcount, the CRM it runs, a recent hiring signal, and the name, role and work email of one contact.

B2B data is not one product. It is a set of data types that come from different sources, age at different speeds and fall under different rules. In this page's view, treating it as one list causes a large share of bad targeting and of avoidable compliance problems.

Why B2B data matters to sales and marketing

Targeting decisions in B2B selling rest on data. The ideal customer profile is written in firmographic and technographic terms, territories are split by region and size, and lead routing reads fields such as industry and role before a person ever sees the lead.

When the data is right, reps spend their day on accounts that fit and on people who own the problem. When it is wrong, the same reps email people who left, call switchboards, and pitch companies that were never a fit, while reports built on the CRM tell leadership the wrong story.

  • Sales teams: building account lists, finding the buying group, and reaching contacts by email and phone.
  • Marketing teams: segmenting campaigns, scoring leads, and matching ad audiences to target accounts.
  • Revenue operations: routing, territory design, deduplication, and reporting that everyone trusts.
  • Leadership: sizing the market and deciding which segments to enter next.

B2B data vs B2C data

Consumer data describes a person or a household as a buyer. B2B data describes an organization as a buyer, plus the people who act for it at work. That one difference changes what a record contains, how it ages and which rules apply.

QuestionB2B dataB2C data
Who is the buyer?A company, usually through several people with different rolesOne person or one household
Core recordAccount plus contacts linked to itIndividual customer profile
Typical fieldsIndustry, headcount, tech stack, job title, seniority, work emailAge band, location, interests, purchase history, personal email
What makes it staleJob changes, promotions, mergers, new domains, replaced softwareMoves, life events, changed preferences
Privacy lawContact details about a named person are still personal dataPersonal data throughout

The last row is the one teams get wrong. The ICO's business-to-business guidance says that processing personal data for direct marketing, even in a business context, falls under the UK GDPR. A work address does not turn a person into a company.

What teams actually do with B2B data

The same database serves several jobs, and each one leans on a different set of fields. Naming the job first keeps you from buying information nobody will use.

Use caseFields it leans onWhat good data changes
Market sizingIndustry, headcount, revenue band, regionA total addressable market you can defend, not a guess
Ideal customer profileFirmographic and technographic fields on the deals you wonTargeting built on customers, not on opinion
List building and prospectingContact data, titles, seniority, signalsReps work accounts that fit and people who own the problem
Campaign segmentationIndustry, size, technology, intent topicsMessages written for one situation instead of for everyone
Lead scoring and routingStandardized industry, size, role and region fieldsLeads reach the right owner without manual triage
Territory and quota planningLocation, size, account countsTerritories with comparable potential
Reporting and analyticsConsistent account and contact recordsPipeline reports that leadership trusts

Sales teams, marketing teams and revenue operations read the same records for different reasons. That is why field standards matter more than volume: one title field nobody standardized breaks routing, scoring and reporting at the same time.

The main types of B2B data

The guides that rank for this term split B2B data into anything from four to ten types. This page uses five core types, because each one answers a different question about an account or a person, and then names the extra types some teams track.

TypeQuestion it answersExamples of fields
Firmographic dataWho is the company?Industry, headcount, revenue band, location, ownership, legal entity
Technographic dataWhat does it run?CRM, marketing automation, cloud host, ecommerce platform, competing tools
Contact dataWho works there, and how do I reach them?Name, job title, department, seniority, work email, direct dial, profile URL
Intent dataWhat is it researching now?Topics researched, pages visited, content downloaded, review site activity
Chronographic dataWhat changed, and when?Funding round, new executive, hiring spree, office move, merger, product launch

A simple way to remember the split: firmographic and technographic data describe fit, intent and chronographic data describe timing, and contact data tells you who to talk to. Good targeting needs at least one field from each group.

Firmographic data

Firmographic data is the B2B version of demographics: the attributes of a company. Industry, employee count, revenue range, headquarters, number of locations, ownership and growth stage are the usual fields. Each field has its own origin, which is covered field by field in where firmographic data comes from.

Firmographics tend to change slowly, because a company rarely changes industry or headquarters. They are also a weak signal of need. Two companies with identical firmographics can have completely different problems, so firmographics define the pool, not the priority.

B2B technographic data

B2B technographic data lists the software, platforms and infrastructure a company uses: its CRM, marketing automation, cloud host, analytics, security and ecommerce tools. Together these fields describe its tech stack, and changes to the stack can be a buying signal in their own right.

Technographic data is collected in several ways: scanning public website code, reading job postings that name tools, checking public integrations and partner listings, and running surveys. Detection from website code can only see tools that leave a trace on public pages, so back-office systems may be missing. The full picture is in technographics.

It matters most when your product replaces, integrates with or depends on another tool. A company running a competing platform is a displacement target. A company running a technology you integrate with is a better fit. Treat each detected technology as inferred, not declared, until a conversation confirms it.

Contact data

Contact data describes people: name, job title, department, seniority, work email, direct phone and mobile, and a professional profile URL. It is what turns an account list into outreach. Phone fields have their own rules, covered in direct dial phone numbers.

Contact data is the type that most clearly counts as personal data, because it identifies a person. It is also the type that goes stale first when people change jobs. That makes it the part of any B2B database that needs the most verification and the most care.

B2B intent data

B2B intent data records research behavior that suggests a company may be in the market. First-party intent comes from your own website, content, emails and product. Third-party intent is collected by providers across publisher networks, review sites and other sources, then matched to companies. Sources and scoring are covered in B2B intent data.

Intent is a probability, not a fact. A spike in research on a topic can mean a buying project, a student, a competitor or one curious employee. Use buyer intent signals to decide which accounts to look at this week, then confirm the need in a conversation.

Sales and marketing teams use intent data in different ways. Marketing teams use account-level intent to choose which accounts see ads and content. Sales teams use it to order their prospects, open with a relevant topic, and reach the buying group while the research is still recent.

Intent data can also be personal data. The GDPR's definition in Article 4(1) names online identifiers among the ways a person can be identified, so engagement tied to a person or a device is not anonymous company data.

Chronographic data and signals

Chronographic data, often called signals or trigger events, tracks changes over time: new funding, leadership hires, layoffs, acquisitions, new offices, job postings and product launches.

Events like these can change priorities and budgets. A new leader may review the tools they inherited, and a funding round may come with hiring plans. Treat a signal as a reason to look closer and to give outreach a reason about the prospect, not as proof of need.

Other types some teams track

  • Engagement data: how an account interacts with your emails, ads, events and website. It is first-party and can be the freshest data you have.
  • Hierarchy data: parent companies, subsidiaries and locations, so ten offices of one group are not worked as ten separate accounts.
  • Relationship data: existing customers, open opportunities, partners and past conversations held in your own CRM.
  • Professional data: role history, skills and tenure, used to judge whether a contact is likely to own the problem.

B2B data sources: first, second and third party

Every B2B database is assembled from a mix of sources. Knowing the source of a field tells you how fresh it is likely to be, how much to trust it, and what you are allowed to do with it.

SourceWhat it providesWatch for
First-party dataYour CRM, form fills, product usage, website visits, support tickets, billingFields go stale after the deal closes; duplicates across systems
Second-party dataAnother organization's first-party data shared with you, such as a partner or event co-hostWhat the people were told about sharing
Third-party dataCompiled company and contact databases, enrichment, intent feeds from data providersCoverage varies by region and segment; ask how each field is sourced
Public recordsRegulatory filings, business registries, industry classificationsAccurate for legal entities, thin on people
Public web sourcesCompany websites, press releases, job postings, newsPersonal data stays personal data even when public
Professional networksTitles, roles, employment history, company pagesPlatform terms on automated collection

First-party data

First-party data is what you collect yourself: CRM records, form fills, product sign-ups, website visits, email engagement and support history. It covers people who already know you, so it tends to be the most relevant and the smallest. The wider view of what your own records hold is in customer data.

Second-party data

Second-party data is first-party data that another organization shares with you directly, such as attendee lists from a co-hosted event or leads from a co-marketing program. The European Commission's guidance on acquired lists says the sharing organization must be able to show the data was obtained lawfully and may be used for advertising.

Third-party data

Third-party data comes from providers whose business is collecting and compiling data about companies and people they have no direct relationship with. It widens the pool to accounts that have never heard of you, at the cost of more checking and more legal homework, because the people in it never dealt with you.

Professional networks sit in a special place. LinkedIn's User Agreement prohibits using software, scripts, crawlers or browser plugins to scrape or copy the service, including profiles. A provider that cannot explain how it collects profile fields is a provider to question.

Public records: free B2B data sources

Government sources are where you confirm that a company exists, what it is legally called, and what it reports. They are thin on people and say nothing about buying intent, but they are free to read and anyone can check them.

SEC EDGAR filings

The SEC describes EDGAR as free public access to millions of documents filed by publicly traded companies and others. You can search by company name or ticker, run full text searches across more than 20 years of filings, and use EDGAR's RESTful APIs for filing history and financial statement data.

EDGAR also publishes the SIC codes used to indicate a company's type of business. Its limit is coverage: a private company that does not file with the SEC will not appear, so EDGAR confirms public companies, their reports and their filers, not your whole market.

State business registries

The SBA's guide to registering a business says most states require registration with the Secretary of State's office, a business bureau or a business agency. Those registries are where a legal entity's name, formation date and registered agent are recorded.

Delaware's Division of Corporations is a useful example of what a registry gives you. Its free search returns the entity name, file number, formation date, registered agent details and residency. Results include inactive entities and do not show status, which is available for a fee.

Delaware also states that it strictly prohibits mining data from the search and that automated tools may get access suspended. Registries are for confirming an entity, not for bulk list building, and a registered agent's address may not be where the company works.

Outside the US, registries play the same role. The ICO names Companies House among the places publicly available data can come from, and adds that personal data found in such sources is still covered by the UK GDPR.

Census NAICS industry codes

The U.S. Census Bureau describes NAICS as the standard federal statistical agencies use to classify business establishments. Codes run from a two-digit sector to a six-digit national industry, and each extra digit is a narrower category.

The Census NAICS FAQs add a point every data buyer should know: no central agency assigns, monitors or approves NAICS codes for businesses, and there is no official register of them. An industry code in a B2B file is somebody's classification, so ask who assigned it and how.

Census County Business Patterns

County Business Patterns is an annual Census series with the number of establishments, employment and payroll by industry and employment size, down to county and ZIP code level. The Census Bureau says private businesses use it to analyze market potential, measure sales and advertising programs, set sales quotas and develop budgets.

It counts establishments; it does not name them. Its disclosure methods are changing: the Census Bureau says it is evaluating new approaches after a Commerce Department order prohibiting noise infusion. Use it to size a segment and check whether a vendor's account count for that segment is plausible, not to build a list.

B2B data validation: how records are checked

B2B data validation is checking that a record is correctly formed, still true and safe to use before it drives an email, a call or a routing rule. Different checks catch different errors, so ask any source which checks it runs on which fields, and when it ran them.

CheckWhat it catchesWhat it cannot prove
Syntax and formatTypos, missing fields, invalid phone formatsThat the address or number belongs to the person
Domain and mail serverDead domains, domains that cannot receive mailThat a given mailbox exists
Mailbox checkMailboxes the server rejects outrightExistence, when the server accepts everything or will not say
Catch-all detectionDomains that accept every addressWhether the person still works there
Phone line checkDisconnected or invalid numbersThat the right person answers
Cross-source matchFields that disagree between sourcesTruth, when all sources copied the same error
Human researchWrong titles, departed contactsAnything after the date it was done

Email checks have a hard limit set by the protocol itself. RFC 5321, the SMTP standard, lets sites disable the VRFY command for security reasons, and says a server that cannot verify an address in real time should answer with code 252 rather than a yes or a no.

The same RFC describes mail that is accepted during the session and bounced later. So a mailbox check can return accepted for an address that will still bounce, and domains that accept every address make the result meaningless. That is the problem described in catch-all email.

A verified flag is only as good as its date. Ask when each record was last verified, not just whether it was, and store that date on the record.

B2B data decay: why every database ages

Data decay is the gradual loss of accuracy in a database as the real world changes and the records do not. B2B data describes jobs and companies, and both change, so a B2B database starts aging the day it is built. The causes and how to measure them are in data decay.

Person changes jobemail bounces, title is wrong
Role changessame company, new responsibility
Company changesmerger, rebrand, new domain
Stack changestool replaced, contract ends
Contact dataContact and role dataFirmographic dataTechnographic data

The common causes are people changing jobs or getting promoted, companies merging, closing, rebranding or moving to a new email domain, phone systems changing, and tools being replaced. Each event breaks one or more fields while the rest of the record still looks fine.

Decay is uneven. Industry and location change slowly. Titles, emails and phone numbers change faster. Intent and signal data are only useful while recent, so an intent spike from last quarter is closer to history than to a signal.

Decay is also a legal issue. Article 5(1)(d) of the GDPR requires personal data to be accurate and, where necessary, kept up to date, with every reasonable step taken to erase or correct inaccurate data. The ICO adds that the source and status of personal data should be clear.

No benchmarks here

Vendors and blogs publish yearly decay, accuracy and coverage rates for B2B data, usually measured on their own databases or without a stated method. None are quoted on this page. Measure your own: track hard bounces, wrong-person replies and changed titles on a sample of your CRM every quarter.

How to judge B2B data quality

Quality is not one number. A source can be accurate but thin, or broad but stale. Judge it on the dimensions that matter for your use.

DimensionThe question to ask
AccuracyIs the field right for the records you test?
CoverageDoes it include your segments, regions and roles?
FreshnessWhen was each record last verified?
CompletenessAre the fields you route and score on filled?
ConsistencyAre industries, titles and countries standardized?
UniquenessIs each company and person in the file once?
ProvenanceCan the source show how each record was collected?

The only reliable test is your own. Take a sample of accounts you know well, including recent wins and lost deals, request the source's records for them, and check fields against what you know. Then send a small batch and measure bounces and wrong-person replies.

Score coverage and accuracy separately. A file can hold a record for every account on your list and still have the wrong person in half of them, and a file that is right about everyone it holds can miss your best segment entirely.

B2B data hygiene: keeping the database clean

Data hygiene is the routine work that keeps a database usable: removing duplicates, fixing formats, updating stale records and suppressing people who objected. It is maintenance, not a project, because decay never stops.

  • Deduplicate: merge duplicate accounts and contacts, using the company domain as the main key for accounts.
  • Standardize: one picklist for industry, country and seniority, and job titles mapped to departments and levels.
  • Validate on entry: check emails and required fields when records are created, not months later.
  • Refresh on a schedule: re-verify active accounts and contacts before each campaign and on a fixed cycle.
  • Act on bounces: a hard bounce means the record is wrong; update it or retire it.
  • Keep a suppression list: objections, unsubscribes and do not contact requests, applied to every import.
  • Assign an owner: someone in revenue operations is accountable for each object and field.

B2B data enrichment

Data enrichment adds missing or updated fields to records you already have. A form fill with only a name and a work email becomes a record with company, industry, headcount, title and seniority, so it can be routed and scored straight away.

Enrichment runs in three ways: in bulk on an existing database, in real time when a form is submitted, or on a schedule that refreshes records before they decay. The full process, including waterfall enrichment across several sources, is covered in lead enrichment.

Enrichment is only as good as the match. A shared inbox or a personal email address can match to the wrong company or to nothing, so check the match key before you trust the fields that came back.

B2B data integration: getting data into your stack

B2B data integration is connecting outside data to the systems people work in. In many teams the CRM is the system of record, and other tools should write to it through one agreed path rather than through several separate imports.

  • Pick the key: match accounts on the company domain and contacts on the work email, so the same company does not enter twice under two names.
  • Enrich at creation: fill firmographic and role fields in real time when a lead is created, so scoring and routing run on a complete record.
  • Refresh in batches: run bulk updates on a schedule for the accounts that matter, instead of re-enriching the whole database every month.
  • Store provenance: keep the source, the collection date and the last verification date on each record as ordinary fields.
  • Map fields once: agree how a provider's industry and seniority values map to your picklists before the first import, not after it.
  • Limit write access: decide which tool may overwrite which field, and let the rest suggest changes rather than silently replace values.

B2B data API

A B2B data API is a programmatic interface to a provider's company and contact data. Your system sends a request, such as a domain, an email or a set of filters, and gets structured records back. It suits enrichment that has to happen the moment a form is submitted or a record is created.

OperationWhat you sendWhat comes back
SearchFilters: industry, headcount, region, technology, title, seniorityMatching companies or people, often as IDs to fetch next
Match or enrichA domain, email, name and company, or profile URLOne record with the provider's fields, or no match
BulkA file or batch of recordsEnriched records, usually by callback or download
Change feedA list of accounts or contacts to watchUpdates such as job changes or new signals

Before you build on any provider's API, read its documentation. The developer side, including waterfall calls across several providers, is covered in data enrichment API. These are the points worth checking first.

  • Authentication: how API keys are issued, scoped and rotated, and whether each user or system gets its own key.
  • Rate limits: requests per second and per day, and what happens to a real-time form enrichment when you hit the limit.
  • Pricing model: whether the API is metered per record, per credit or by subscription tier, and whether a no-match or a repeated lookup costs anything.
  • Field definitions: what each returned field means, which values are inferred, and the date each field was last verified.
  • Free tiers and trials: what a free or trial key returns, so a test is run on the same data you would pay for.
  • Licensing: whether you may store API results in your CRM, and what must be deleted when the contract ends.

Real-time and batch APIs serve different jobs. A real-time enrichment API answers in the moment, so routing and lead scoring run on a complete record. A batch API refreshes thousands of records overnight. Some teams need both, so check whether a provider returns the same fields through its real-time and batch APIs.

AI agents can consume B2B data APIs too. The Model Context Protocol (MCP) is an open-source standard for connecting AI applications to external systems such as data sources and tools. If a provider offers data through MCP, ask the same provenance, licensing and suppression questions as for any other API.

Agents also raise a write question. Decide which agent may update CRM fields on its own and which may only suggest changes, so an agent's guess does not overwrite a verified value.

Free public data APIs

Public data has APIs as well. The SEC lists EDGAR APIs for filing history and financial statement data, which can confirm details about public companies without going through a data provider.

The Census Bureau offers a free Data API that developers can call from their own applications, with an API key on request. It serves aggregate statistics such as County Business Patterns, not named companies or contacts, so it supports market sizing rather than list building.

Is B2B data legal? GDPR, CCPA and email rules

Under the GDPR, personal data is any information relating to an identified or identifiable natural person. Company-level facts such as industry and headcount are generally not personal data. A named contact's work email, direct dial and title are, because they identify a person. This section summarizes the official sources and is not legal advice.

GDPR and legitimate interest for B2B data

Processing personal data needs a legal basis. For B2B prospecting, many teams rely on legitimate interests in Article 6(1)(f), which applies unless the person's interests or fundamental rights override yours. Recital 47 says processing for direct marketing may be regarded as carried out for a legitimate interest.

"May" is not "always". You still have to show the interest is real, the processing is necessary for it, and it does not override the person's rights, and you should document that assessment. Contacting a relevant role about a relevant offer is easier to defend than emailing everyone at a company.

Article 14 covers data you did not collect from the person. You must tell them, among other things, what categories of data you hold and the source it came from.

Article 14(3) sets the timing: within a reasonable period and at the latest within one month, and if you use the data to contact them, at the latest at the first communication.

Article 21 gives people the right to object to direct marketing at any time. Once they object, the data can no longer be processed for that purpose, and the right must be brought to their attention clearly and separately at the first communication at the latest.

The European Commission adds points for bought lists: the seller must be able to show the data was obtained lawfully and may be used for advertising, you must keep the list up to date and exclude people who objected, and email marketing must also follow the ePrivacy Directive.

Check the national email marketing rules in each EU market you send to; this page does not summarize them.

UK rules for business contacts

The ICO's business-to-business guidance says the UK GDPR applies when you process personal data for direct marketing, even in a business context.

The PECR rule on marketing by electronic mail does not apply to corporate subscribers, so companies can be emailed without consent if you do not hide your identity and give a valid opt-out address.

Sole traders and some partnerships count as individual subscribers, so they can only be emailed with consent or under the soft opt-in. Live calls must be screened against both the TPS and CTPS registers. The ICO notes this guidance is under review after the Data (Use and Access) Act.

CCPA and business contact data

The California Privacy Protection Agency states that the CCPA exemptions for personal information reflecting business-to-business transactions, and for employment data, expired on December 31, 2022. Its FAQ adds that California residents include contacts for business customers, vendors and independent contractors.

That gives California business contacts the CCPA rights the agency lists: to know, delete and correct personal information, to opt out of its sale or sharing, to limit the use of sensitive information, and to equal treatment when they use those rights.

Data brokers and the California Delete Act

Under the Delete Act, a business that knowingly collects and sells personal information about consumers it has no direct relationship with is a data broker. The CPPA says brokers must register every year, with a January 31 deadline, or risk fines.

The CPPA also runs the Delete Request and Opt-out Platform (DROP). Beginning August 1, 2026, registered brokers must access it at least once every 45 days and process the deletion requests it holds. When you evaluate a provider, ask whether it is registered and how DROP deletions reach your copy of the data.

CAN-SPAM applies to B2B email

The FTC's compliance guide states that CAN-SPAM makes no exception for business-to-business email. Commercial emails need accurate headers and subject lines, a valid physical postal address and a clear way to opt out, and opt-outs must be honored within 10 business days, including when another company sends for you.

The same guide says that once people opt out, you cannot sell or transfer their email addresses, even as part of a mailing list. That rule matters when you share or resell lists, not just when you send.

Security for B2B contact data

A contact database holds personal information, so it needs protecting. The FTC's guide for businesses builds a data security plan on five principles: take stock, scale down, lock it, pitch it and plan ahead.

For a B2B team, that means knowing which exports exist, limiting who can download lists, and deleting what you no longer need.

RuleWhat it means for B2B dataOfficial source
GDPR Art. 4(1)Named business contacts are personal dataGDPR text
GDPR Art. 5(1)(d)Keep personal data accurate and, where necessary, up to dateGDPR text
GDPR Art. 6(1)(f), Recital 47Legitimate interest can support direct marketing, after a balancing testGDPR text
GDPR Art. 14Tell contacts the source and categories of data, at first contact at the latestGDPR text
GDPR Art. 21Honor objections to direct marketing and keep a suppression listGDPR text
UK PECRCorporate subscribers can be emailed with identification and opt-out; sole traders need consent or soft opt-inICO
CCPAB2B exemption expired; California business contacts have privacy rightsCPPA
California Delete ActData brokers register yearly and process deletion requests through DROPCPPA
CAN-SPAMNo B2B exception; opt-outs honored within 10 business daysFTC

Buying vs building a B2B database

There are several ways to get B2B data, and many teams combine them. The right mix depends on how narrow your market is, how many records you need, and who has time to maintain them.

ApproachWorks best whenTrade-off
Subscribe to a B2B databaseA broad market, many roles, fast list buildingShared with competitors, coverage gaps in some niches and regions, ongoing cost
Build your own listA narrow market of a few hundred accounts you can research by handSlow, needs research time, still needs validation and hygiene
Buy a one-time listRarely, in this page's view, for outreachStarts decaying the day it arrives, and provenance can be unclear
License a raw datasetYou have data engineers and want to build your own modelsYou own matching, cleaning, storage and compliance
Enrich first-party dataYou already have traffic, sign-ups or customersOnly covers people who already found you

Building by hand fits a short account list in an ABM strategy, where each account deserves research anyway. A database subscription makes more sense when volume is high and the market is broad, across many segments and regions.

How to evaluate B2B data providers

This page does not rank vendors or quote prices. Providers fall into categories, and the right category depends on the job you named at the start.

Contact databasesPeople and company records

Search, filters and export of contacts and accounts for prospecting, sometimes with email and phone.

Enrichment servicesFill and refresh fields

Add firmographic and contact fields to records you already have, in bulk or through an API.

Intent and signal providersTiming

Research activity and company events matched to accounts, used to prioritize outreach.

Raw datasetsData to build on

Large company or people datasets delivered as files or APIs, for teams that build their own models and tools.

Whatever the category, test coverage on your own accounts, ask for the source and last verification date of each field, read how opt-outs and deletions are handled, and check whether the provider is registered where registration is required.

Evaluating B2B intent data providers

Intent feeds need extra questions, because the signal is inferred and the method is not always disclosed. Ask where the activity comes from: your own site, a data co-op, publisher sites, review sites or ad exchanges. Then ask how activity is matched to a company, which topics exist, and how long a spike stays active.

Ask for a test on accounts you already know: recent wins, open deals and accounts you know are not buying. If the feed cannot tell those groups apart better than your own engagement data, it adds noise, not timing.

Questions for a data provider
We are evaluating B2B data for {{segment}} in {{regions}}.

1. How is each field collected: contact email, direct dial, title, industry, technology?
2. When was each record last verified, and is that date visible per record?
3. Can you run a match on these {{sampleSize}} accounts we know well, so we can check accuracy?
4. How do you give notice to the people in your database, and how do objections and deletions reach us?
5. What is your legal basis for EU and UK contacts, and are you registered as a data broker where required?
6. Through which channels can we access the data: interface, export, API, files?
7. What happens to exported records when our contract ends?

{{senderName}}
Backfires when

You send it before defining your segment and sample, or you accept a demo on accounts the provider picked. Every source looks good on its own examples. Insist on your list, and compare the answers in writing across providers.

This question list was written for this page. Adapt it to your segment and region.

A practical B2B data checklist

  1. Write the profile first

    Define the accounts and roles you sell to in data terms: industry, size, region, technology, and the titles in the buying group. The profile decides which fields matter.

  2. Map fields to uses

    List which fields drive routing, scoring, segmentation and outreach. Anything that drives nothing is not worth buying or maintaining.

  3. Start from first-party data

    Clean and enrich what you already have before adding outside sources. Customers and past deals are your best model of fit.

  4. Confirm entities in public records

    Check legal names, parents and industry codes against filings and registries for the accounts that matter most.

  5. Test sources on known accounts

    Compare each candidate source on the same sample. Measure accuracy, coverage and bounces yourself.

  6. Record provenance and legal basis

    Store the source and collection date on each record, document your legitimate interest assessment, and prepare the notice for first contact.

  7. Validate before every send

    Validate emails and check suppression lists before a campaign or sequence, not after the bounces arrive.

  8. Refresh and retire

    Re-verify active records on a schedule and retire contacts that have left or stopped responding for a long time.

Using B2B data in outreach

Data finds the person; the message still has to earn the reply. Use firmographic and technographic data to choose the account, signals to choose the moment, and contact data to reach the right role, then write about the prospect's situation, not the fields you hold.

Put accounts with a fresh signal first in your sequences across email, phone and LinkedIn. Bounces, wrong-person replies and job changes that come back from outreach are data too, so route them back to whoever owns hygiene.

Common mistakes with B2B data

  • Buying a list before writing the ideal customer profile, so the list decides the market.
  • Treating verified as permanent, and sending to records last checked long ago.
  • Reading an accepted mailbox check as proof that a person exists.
  • Assuming B2B contact data is outside privacy law because the email is a work address.
  • Skipping the first-contact notice and opt-out for contacts you did not collect yourself.
  • Trusting an industry code without asking who assigned it.
  • Letting every tool write to the CRM with no owner, so duplicates multiply.
  • Reading an intent spike as a buying decision instead of a reason to look closer.
  • Judging a provider on a demo of accounts it chose.

B2B data in a first email

When the contact came from a third-party source, the first email is also the moment the GDPR asks you to say where the data came from and how to object. The template below was written for this page and does both in two plain lines.

First email to a contact whose details came from a third-party source
Subject: {{signal}} at {{companyName}}

Hi {{firstName}},

I saw that {{companyName}} {{signal}}. For {{roleArea}} teams, that can put {{problem}} on the list.

We help companies like {{similarCustomer}} with {{outcome}}. Is that yours to solve, or should I be asking someone else?

{{senderName}}
{{senderCompany}}, {{postalAddress}}

Where your details came from: {{sourceName}}, a business contact database that lists people by role. I hold your name, role and work email. You can object at any time: reply with the word remove and I will delete your record and stop writing.
Backfires when

You paste a source line but name a vague source, or the remove promise is not wired to a suppression list.

A notice nobody can check, and an objection nobody actions, are worse than no line at all. Name the real source, and make the suppression automatic before the first send.

Frequently asked questions

What is B2B data?

B2B data is information about businesses and the people who work in them, organized so sales and marketing teams can find, qualify and contact the right accounts. It covers company attributes, technology, contacts, research behavior and recent changes such as funding or new executives.

What are the main types of B2B data?

This page uses five core types. Firmographic data describes the company, technographic data lists the software it runs, contact data identifies people and how to reach them, intent data shows what it is researching, and chronographic data records changes such as funding or a new executive.

What is B2B technographic data?

B2B technographic data lists the software, platforms and infrastructure a company uses, such as its CRM, cloud host and marketing tools. It is inferred from website code, job postings, integrations and surveys, so treat each detected tool as likely rather than confirmed until a conversation proves it.

What is B2B intent data?

B2B intent data records research activity suggesting a company may be in the market. First-party intent comes from your own site, emails and product. Third-party intent is collected across publisher and review networks, then matched to a company. It is a probability, not a fact.

Where does B2B data come from?

From four places: first-party data you collect yourself, second-party data a partner shares with you, third-party data compiled by data providers, and public records such as regulatory filings and business registries. Each source ages differently and carries different legal duties.

Is there a free B2B data API?

For company facts, yes. The SEC's EDGAR APIs return filing history and financial statement data for companies that file with it, and the free Census Data API serves aggregate statistics such as County Business Patterns. Neither returns named contacts, and some state registries prohibit data mining.

What is a B2B data API?

A B2B data API is a programmatic interface to a provider's company and contact data. Your system sends a domain, an email or a set of filters and gets structured records back, which suits real-time enrichment when a form is submitted or a CRM record is created.

What is B2B data validation?

B2B data validation checks that a record is correctly formed, still true and safe to use. It covers syntax, domain and mailbox checks, catch-all detection, phone line checks, cross-source matching and human research. Each check proves something different, so ask which ones were run and when.

How fast does B2B data decay?

This page quotes no decay rate, because a rate measured on someone else's database does not describe yours. Measure your own instead: sample your CRM each quarter and track hard bounces, wrong-person replies and titles that no longer match.

Is B2B contact data personal data under GDPR?

Yes, when it identifies a person. The GDPR defines personal data as any information relating to an identified or identifiable natural person, so a named contact's work email, direct dial and title count. Company facts such as industry and headcount generally do not.

Do I have to tell people where I got their data?

Under the GDPR, yes. Article 14 requires telling people whose data you did not collect from them which categories you hold and where it came from, within one month at the latest, and at the first communication at the latest if you use it to contact them.

Does the CCPA cover B2B contact data?

Yes. The California Privacy Protection Agency states that the exemption for personal information reflecting business-to-business transactions expired on December 31, 2022, and that California residents include contacts for business customers. They have rights to know, delete, correct and opt out of sale or sharing.

Does CAN-SPAM apply to B2B emails?

Yes. The FTC's compliance guide states the law makes no exception for business-to-business email. Commercial emails need accurate headers, a valid physical postal address and a working opt-out, and opt-out requests must be honored within 10 business days.

How do I choose a B2B data provider?

Start from your segment, then test each provider on accounts you already know well. Ask how each field is collected, when it was last verified, how objections and deletions are handled, and whether the provider is registered as a data broker where required.

Sources and reading
  1. EUR-Lex, Regulation (EU) 2016/679 (GDPR), Articles 4(1), 5(1)(d), 6(1)(f), 14 and 21 and Recital 47, for the definition of personal data, the accuracy principle, legitimate interests, the notice owed when data was not collected from the person with its timing, and the right to object to direct marketing, checked Oct 1, 2026.
  2. EUR-Lex answers scripted requests with a bot check, so the GDPR wording above was read in the official English text of the regulation served by the EU Publications Office.
  3. European Commission, Can data received from a third party be used for marketing?, for the conditions on acquired contact lists, keeping lists up to date, excluding objectors and the ePrivacy Directive, checked Oct 1, 2026.
  4. ICO, Business-to-business marketing, for UK GDPR applying to business contacts, corporate and individual subscribers under PECR, the soft opt-in, TPS and CTPS screening, publicly available data including Companies House, and the review after the Data (Use and Access) Act, checked Oct 1, 2026.
  5. ICO, Principle (d): Accuracy, for reasonable steps and keeping the source and status of personal data clear, checked Oct 1, 2026.
  6. California Privacy Protection Agency, Frequently Asked Questions, for the expiry of the business-to-business exemption on December 31, 2022, business contacts as California residents, and the list of CCPA rights, checked Oct 1, 2026.
  7. California Privacy Protection Agency, Data Brokers, for the data broker definition, annual registration by January 31, and DROP access every 45 days from August 1, 2026, checked Oct 1, 2026.
  8. Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business, for no business-to-business exception, the postal address, the 10 business day opt-out, shared responsibility when another company sends, and the ban on transferring opted-out addresses, checked Oct 1, 2026.
  9. Federal Trade Commission, Protecting Personal Information: A Guide for Business, for the five principles of a data security plan, checked Oct 1, 2026.
  10. U.S. Securities and Exchange Commission, Search Filings (sec.gov/search-filings), for free public access to EDGAR filings, search by name or ticker, full text search across more than 20 years, EDGAR APIs and the SIC code list, checked Oct 1, 2026. The SEC blocks scripted requests, so the page was read in a browser and is named here without a link.
  11. U.S. Small Business Administration, Register your business, for most states requiring registration with the Secretary of State's office, a business bureau or a business agency, checked Oct 1, 2026.
  12. Delaware Division of Corporations, General Information Name Search, for the free entity fields (name, file number, formation date, registered agent details, residency), inactive entities without status, the fee for status, and the prohibition on data mining and automated tools, checked Oct 1, 2026.
  13. U.S. Census Bureau, North American Industry Classification System, and its FAQs tab, for NAICS as the federal standard for classifying business establishments, the two to six digit structure, and the absence of a central agency or official register for NAICS codes, checked Oct 1, 2026.
  14. U.S. Census Bureau, County Business Patterns: About this program, for the annual establishment, employment and payroll series by industry, employment size and geography, its use by private businesses for market potential and sales quotas, and its notice that disclosure methods are under review after an order prohibiting noise infusion, checked Oct 1, 2026.
  15. U.S. Census Bureau, Developers, for the free Census Data API and API keys, checked Oct 1, 2026.
  16. IETF, RFC 5321 Simple Mail Transfer Protocol, sections 3.5.3 and 7.3 and the discussion of bounces, for disabled VRFY, the 252 reply when an address cannot be verified, and mail bounced after acceptance, checked Oct 1, 2026.
  17. LinkedIn, User Agreement (effective November 3, 2025), for the prohibition on scraping or copying the services, including profiles, checked Oct 1, 2026.
  18. Model Context Protocol, What is the Model Context Protocol (MCP)?, for MCP as an open-source standard for connecting AI applications to external systems, checked Oct 1, 2026.
  19. Jeluvi entries this term builds on: B2B intent data, technographics, firmographics source, data decay, catch-all email, customer data, lead enrichment, data enrichment API.
  20. This page does not rank or recommend data providers, quotes no prices, and quotes no vendor accuracy, coverage or decay figures. Nothing here is legal advice.
Take the sequence with you

The 10-day cadence, five templates, one email.

Five touches across email, LinkedIn and phone, five templates with placeholders marked, and the first-30-days checklist. One email.

Build a LinkedIn or outreach tool? Jeluvi is read by the people who use them. See how partners appear on Jeluvi.