Back to all lessons
Awareness Lessons
4 months ago

CNPD Refuses to Investigate Rocketreach Over GDPR Data Sales

Rocketreach, a foreign company selling personal data of EU residents without a legal basis, escaped regulatory scrutiny because it lacked an EU establishment and a designated EU representative — both requirements under GDPR Articles 3 and 27. The Luxembourg CNPD acknowledged potential GDPR violations but declined to investigate due to these jurisdictional gaps. This case highlights a critical enforcement loophole: non-EU companies can process and monetize EU personal data while remaining practically unaccountable if they ignore GDPR establishment requirements. The decision undermines data subject rights and erodes trust in GDPR as a globally enforceable framework.

Tactical Insight

Immediate actions

  • Verify that any third-party data broker or vendor processing EU personal data has a designated EU representative as required by GDPR Article 27.
  • Conduct a data flow audit to identify personal data being shared with or sourced from foreign entities lacking GDPR compliance documentation.

Regulatory & contractual controls

  • Include mandatory GDPR compliance clauses (legal basis, DPA agreements) in all contracts with external data processors or brokers.
  • Report non-compliant foreign data brokers to both the relevant lead supervisory authority and the EDPB to trigger coordinated enforcement action.
  • Avoid purchasing or using data from brokers who cannot demonstrate a lawful basis for processing EU personal data.

Long-term improvements

  • Advocate internally and externally for EDPB guidance that closes the enforcement gap for non-EU-established entities processing EU data.
  • Maintain an up-to-date Records of Processing Activities (RoPA) log identifying all external data sources and their legal bases.
  • Implement periodic third-party risk assessments specifically evaluating GDPR jurisdictional compliance of data suppliers.