Sharing a business contact's details across borders: GDPR basics
A work email naming a person is personal data under the GDPR, so sharing it with a third party needs a lawful basis and minimal data. For introductions, the simplest route is to ask the person first, share only what they agreed to, keep a record and step back.
Can you share a business contact's details with a third party under GDPR?
Often yes, if you have a lawful basis, share only what is needed and are open about it. A business email address that names a person is personal data under the GDPR, even when it is a work address, so "it is only a business contact" is not a safe assumption.
The safest route for an introduction is the simplest: ask the person first, share only the details they agreed to, and let them take it from there. This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
What the GDPR says, in outline
The official text is Regulation (EU) 2016/679. It applies from 25 May 2018 and can apply to organizations outside the EU in some situations. The UK has its own version, the UK GDPR, with the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). Those are separate texts you should read on the UK government's legislation site, and your ICO guidance applies if you are in the UK.
The ideas that matter for an introduction are these.
| Idea | What it means | How it applies to an introduction |
|---|---|---|
| Personal data | Information about an identifiable person, including a work email | A name plus company email is personal data |
| Lawful basis | You need a reason in Article 6, such as consent or legitimate interests | Consent from the person is the clearest basis |
| Legitimate interests | A balancing test: your interest, necessity, and the person's rights | Possible, but you must be able to show the balance |
| Data minimisation | Share only what is needed | Name, role, company and email, not more |
| Transparency | Tell people what you do with their data | Tell the contact that you are passing on their details |
| Transfers | Special rules apply to moving data outside the EU or UK | An introduction to a US recipient is a cross-border transfer |
Is a business introduction email "marketing"?
It depends on its purpose. If the message is primarily to promote a product or service, electronic marketing rules, such as PECR in the UK and national rules implementing the EU ePrivacy Directive, may apply as well as the GDPR. Rules for emailing businesses differ between corporate and individual subscribers and by country, so check the position in each country involved. A permissioned introduction the contact asked for is a very different case from an unsolicited promotion, and the US side has its own rules, covered in whether CAN-SPAM applies to a one-to-one B2B email and not repeated here.
How does permission-first minimize the data you share?
The program is designed so that partners handle very little personal data. A partner makes an introduction and gives basic fit information only. A partner never exports, uploads or describes confidential records. The owner decides whether to be introduced, and the company, not the partner, takes any later steps.
For an introduction, that points to a short routine.
- Ask first. Tell the person who you want to introduce them to, why, and what you will share.
- Share the minimum. A name, role, company and work email are normally enough.
- Say it in writing. Keep the person's yes, with the date.
- Introduce, then step back. Let them continue the conversation directly.
- Do not keep extra. Delete working notes you no longer need.
- Honor objections. If they ask you to stop, stop and note it.
Situations and what to check
| Situation | What to check | Typical approach to confirm |
|---|---|---|
| A UK or EU adviser introduces a US owner | The adviser's own data-protection duties and the lawful basis | Consent from the owner before sharing |
| You paste a client list into an email | Whether each person agreed to be shared | Do not; share one person at a time |
| You share a contact's mobile number | Whether it is needed | Usually not needed; use email |
| You forward a contact's reply to SourceX | Whether the person knows you will forward | Tell them first |
| You store contact details in a CRM | Retention and access | Keep a purpose and a deletion date |
| You are an authorized professional | Your professional rules on client confidentiality | Check them before any introduction |
Who is the controller, and does the program change that?
Whoever decides why and how personal data is used is a controller in the GDPR's terms. When you pass on a contact's details, you may well be using personal data for your own purpose, which is the introduction, so you may carry responsibility for that step. This is one reason to keep what you share small. How SourceX processes data after the introduction is described in its own privacy information, which you should read on the site, and the program terms cover what partners agree to.
Scenarios worth working through
Illustrative and fictional. A UK fractional finance director wants to introduce the US owner of a 90-person staffing firm. She messages the owner privately, explains that she would pass on his name, job title, company and work email, and says why. He replies yes. She then writes one short introduction email, which includes a sentence disclosing a possible referral reward, and steps back. She keeps his yes and deletes her working notes. The routine takes ten minutes and leaves her with a record.
Contrast an adviser who sends a whole client list to a third party without asking. That second pattern is the one data-protection regulators worry about, and it is not how this program works.
Questions for your counsel or data-protection adviser
- Which lawful basis should I rely on for an introduction: consent or legitimate interests?
- What do I need to tell the contact, and when?
- Do the rules differ because the recipient is in the US?
- What should I keep as a record, and for how long?
- Do my professional rules add to the legal requirements?
Next step
Ask first, share the minimum, keep a record, and then register as a partner. The introduction email builder drafts the owner-approved message, the LinkedIn introduction guide covers the permission step, and the employee count guide helps you check the 50+ full-time employees at peak baseline (contractors excluded). Credit rules are explained in what an attribution window is, and partners outside the US may also read introducer agreements and referral fee clawbacks. Rewards are 25% of the eligible platform fees SourceX actually collects, capped at $100,000 cumulative per referred company, and they become payable only after the buyer pays and SourceX receives its fee. No reward is guaranteed.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is a work email address personal data under GDPR?
Yes, if it relates to an identifiable person, such as a name at a company domain. The fact that it is a business address does not remove it from the GDPR. Treat contact details as personal data and share them only with a lawful basis, in the smallest amount needed.
Do I need consent to introduce a contact to a third party?
Consent is the clearest basis and the simplest practice: ask the person, get a yes, and keep a record. Legitimate interests can sometimes apply, but they require a balancing test that you must be able to explain. Confirm with your own adviser which basis fits your situation.
What is the difference between UK GDPR and EU GDPR for this?
The UK has retained its own version, the UK GDPR, alongside the Data Protection Act 2018 and PECR, and the ICO is its regulator. The EU text is Regulation 2016/679. The core ideas are similar, but read the UK texts if you are in the UK, and confirm details with a local adviser.
Can I send a business introduction email without consent?
It depends on whether the message is primarily marketing and on the rules of each country involved, including how corporate and individual subscribers are treated. A permissioned introduction the contact asked for is safest. If you are unsure, ask the person first or seek advice before sending.
Does sending a UK contact's details to the US need special steps?
Moving personal data outside the UK or EU triggers transfer rules in the GDPR framework. The simplest route is to let the person introduce themselves or to share only what they agreed to, in writing. Confirm with a data-protection adviser which mechanism, if any, applies to your case.
Related pages
- How to find a private company's employee count and its peak headcount
- How to introduce two people on LinkedIn (with permission first)
- Introducer agreements: what UK and international partners should know
- Referral fee clawbacks: when a paid reward can be reversed
- Does CAN-SPAM apply to a one-to-one B2B introduction email?
- What is an attribution window in a referral program?
Free resources
- Cash conversion cycle calculator — DIO, DSO, DPO and the cash conversion cycle.
- Operational data inventory builder — List systems, record types, years held and owners.
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment