Skip to content
New: connect Linkly to your favourite AI and ask about your tradeshow results and leads
Blog · compliance

Is enriching trade-fair leads from public sources legal? What the EU AI Act changes from August 2026

Public-source lead enrichment and the law: what the EU AI Act changes from August 2026 and what stays governed by GDPR for B2B exhibitors and their sales teams.

by Veronica Pisana · August 3, 2026 · 8 min read

The AI Act has entered every procurement committee’s vocabulary. And the question we hear most from Heads of Sales after a fair is blunt: is enriching a contact — finding an email, phone, LinkedIn from public sources — still legal in 2026?

Short answer: yes, if you do it right. But “right” has a precise meaning, and it shifts slightly with the AI Act milestones maturing from August 2026. Let’s separate fact from noise.

In short:

  • GDPR does not ban enriching leads from public sources. It requires a legal basis (usually legitimate interest) and a notice within a month (Art. 14).
  • The AI Act does not replace GDPR: it adds obligations on AI systems. For lead enrichment the impact is mostly documentary, not a ban.
  • “Public on LinkedIn” ≠ “usable without limits.” Publicity of the data does not cancel the individual’s rights.
  • The exhibitor is the data controller; the enrichment vendor is the processor. Without a signed DPA, the risk is yours.
  • The real compliance lever is traceability: sources, legal basis, notice, retention, data in the EU. Automation is not the problem; undocumented automation is.

What GDPR actually says about public-source enrichment

When you capture a badge at the stand and the system then recovers a business email, direct line and LinkedIn profile from public sources, you are processing personal data. GDPR allows it under three practical conditions:

  1. Legal basis. For B2B it is almost always legitimate interest (Art. 6.1.f), not consent. But it must be documented with a balancing test (LIA): your commercial interest vs the contact’s rights.
  2. Notice. When you don’t get the data directly from the person but “enrich” it, Art. 14 applies: you must inform them — usually within a month, or at the first useful contact. In practice, your first follow-up is also the notice moment.
  3. Minimisation and retention. Enrich only what the commercial follow-up needs. A LinkedIn profile and a direct email are relevant; mass scraping of irrelevant data is not.

This frame is the “downstream” part of capture. The “upstream” part — consent at the moment of badge capture — is in our dedicated piece: GDPR and trade-fair leads.

What the AI Act adds from August 2026 (and what it doesn’t)

Let’s clear a common misunderstanding. The AI Act is not a new privacy law. It is a risk-based regulation of AI systems. It does not rewrite the rules on who can process which data — those stay in GDPR.

What changes concretely for an exhibitor using an AI enrichment tool:

  • System transparency. The application milestones through 2026 (including those on general-purpose models under Chapter V and the enforcement framework) push toward documentation: which AI runs behind your tool, on what data it was trained, what guarantees it offers.
  • Vendor governance. Your DPO’s question is no longer just “where is the data,” but also “which AI system processes it, and with what logic.” You need to be able to explain it.
  • No ban on enrichment. There is no AI Act rule saying “you cannot find a lead’s email from public sources.” The limits on personal data stay a GDPR matter.

In short: the AI Act raises the bar on demonstrability. It does not switch off enrichment. Those working with serious vendors barely notice, because the documentation already existed.

When you should NOT enrich

Let’s be honest, because compliance is also knowing when to stop:

  • B2C contacts disguised as B2B. A private gmail is not a business lead. Legitimate interest holds up far less.
  • No real stand interaction. Enriching a bought list or randomly scanned badges is not follow-up: it is cold marketing, and the balancing test gets harder.
  • Vendor with no DPA and no EU data location. If you can’t say where the data is and who processes it, upload nothing. As controller, the risk is all yours.

The operational checklist before the next fair

  1. Written legal basis. A one-page LIA for B2B follow-up. That’s plenty, but it must exist.
  2. Notice ready. An Art. 14 paragraph in the first follow-up, with a link to the privacy policy.
  3. Signed DPA with the vendor. Declared sources, purposes, retention, sub-processors, data location. Our template is here: Linkly DPA.
  4. Data in the EU. Check the infrastructure. A GDPR-compliant vendor on EU cloud removes half the DPO’s questions.
  5. Source traceability. If you don’t know where a data point comes from, you can’t defend it.

How Linkly handles it

Linkly’s Enrichment Agent works across 30+ data sources to recover email, phone, LinkedIn and company info, on EU GDPR-compliant infrastructure with a DPA included in onboarding. It’s not a legal shortcut: it’s governed enrichment, with tracked sources and data in Europe. Your controller responsibility stays yours — what changes is that you have the documentation to defend it. To see the full scope of the six agents, start with what is Linkly.

The AI Act does not close the door on enrichment. It only asks you to show how you do it. If you already work with serious vendors, August 2026 is a documentary chore, not a commercial brake.

Next step: want to check whether your current enrichment process survives the balancing test and Art. 14? Book a demo and we’ll bring your real case, not a slide deck.

FAQ

Is enriching a fair contact with email and LinkedIn from public sources legal? +

Yes, with conditions. GDPR does not ban processing personal data from public sources, but it requires a legal basis (usually legitimate interest) and a privacy notice within a month (Art. 14). 'Public on LinkedIn' does not mean 'freely usable for marketing with no limits.'

What actually changes with the AI Act from August 2026? +

The AI Act does not rewrite GDPR: it adds obligations on AI systems. The Chapter V application milestones (GPAI models) and the enforcement framework extend through 2026. For lead enrichment the practical impact is documentary: knowing which AI your vendor uses, on what data, and being able to prove it. Liability over personal data stays with GDPR.

Who is liable if the enrichment vendor gets it wrong? +

Typically the exhibitor is the data controller and the vendor is the processor. You need a signed DPA defining sources, purposes and retention. Without a DPA, the risk lands on you. Check it before you upload the first badge.

Is legitimate interest enough for B2B follow-up? +

Often yes for a relevant first B2B commercial contact, but it must be documented with a balancing test (LIA), and the right to object remains. For repeated email marketing, ePrivacy rules are stricter. From our experience, a targeted first follow-up after a stand meeting is defensible; an endless automated sequence is not.

Should I stop automated enrichment to be safe? +

No, that is not necessary. Well-governed enrichment — tracked sources, clear legal basis, notice sent, DPA signed, data in the EU — is compliant. The problem is not automation: it is automation without documentation.

Ready to turn your next trade fair's contacts into pipeline?

Linkly captures, enriches, qualifies and follows up every lead, from badge to CRM to follow-up.

Go deeper with AI

Linkly pages are optimised to be read correctly by AI assistants. Open the conversation in your preferred one with the context already in place, or copy the prompt to use it anywhere.