It is going to happen. You send a cold email to an enriched contact, and they reply with: How did you get my email address? Or the slightly more aggressive version: I never gave you permission to contact me. Where did you get my information?
This moment is not a crisis. It is an opportunity. How you respond determines whether this person becomes a future customer, a neutral contact, or someone who files a complaint with a regulator.
Most sales teams handle this badly. They panic, get defensive, ignore the question, or worse, lie. None of those approaches work. Here is what actually works.
Why People Ask This Question
Before we get to response templates, it helps to understand the motivation behind the question. People ask where you got their information for several reasons:
Genuine curiosity. They are not angry. They just want to know how you found them. This is actually a positive signal because it means they read your email closely enough to wonder about the source.
Privacy concern. They are aware of data privacy regulations and want to ensure their rights are being respected. This is increasingly common since GDPR became mainstream knowledge.
Testing your legitimacy. Sophisticated buyers use this question to evaluate whether you are a legitimate business or a spammer. Your answer tells them a lot about your organization.
Annoyance. They did not want to be contacted and they are expressing frustration. This is the most delicate scenario and requires the most empathy.
Regulatory probe. Rarely, but occasionally, someone is documenting a potential complaint. Your response could be used in a regulatory filing.
The good news: a professional, transparent response works well for all five motivations.
The Core Response Framework
Every good response includes four elements:
- Acknowledge the question directly. Do not dodge it or change the subject.
- Explain your data source honestly. Be specific enough to satisfy the question without over-sharing technical details.
- Offer immediate control. Give them the power to opt out, request deletion, or modify preferences.
- Keep the door open. Do not be so apologetic that you close off future business potential.
Response Templates by Scenario
Scenario 1: Neutral Inquiry
They asked casually, no apparent anger or frustration.
Response:
Good question. We use a professional business contact database to identify people in [their role] at companies like [their company] that match the profile of businesses we work with. We focus on reaching people where our [product/service] tends to be relevant. If you would rather not receive messages from us, I can remove you from our contact list immediately. Just say the word. And if the timing is wrong but you are open to connecting later, happy to follow up at a better time.
Scenario 2: Privacy-Concerned
They specifically mention privacy, GDPR, or data protection.
Response:
Completely understand your concern. We take data privacy seriously. Your business email was identified through a professional data enrichment service that aggregates publicly available business information. We process this data under legitimate interest for B2B outreach, and we maintain full compliance with applicable data protection regulations. You have several options: I can remove your email from our contact database entirely, I can provide details on what information we hold about you, or I can ensure you are not contacted again while keeping your data on our suppression list. Which would you prefer? I can process any of these immediately.
Scenario 3: Annoyed or Hostile
They are clearly frustrated about being contacted.
Response:
I apologize for the unwanted email. I am removing you from our contact list right now. You will not receive any further outreach from our team. For context, we identified your contact information through a professional business database, not through any personal data. But I completely respect your preference not to be contacted. The removal is effective immediately. If you need any additional information about the data we held or want to confirm deletion, I am happy to provide that.
Scenario 4: Formal or Regulatory Tone
The message reads like a formal request or potential regulatory inquiry.
Response:
Thank you for your inquiry regarding your personal data. We obtained your business email address through [enrichment vendor name], a professional data enrichment service that aggregates business contact information from publicly available sources. We process this information under the lawful basis of legitimate interest for B2B business development purposes. Under [GDPR/CCPA/applicable regulation], you have the right to: access the personal data we hold about you, request erasure of your personal data, object to processing of your personal data, and request restriction of processing. Please let me know which of these rights you would like to exercise, and I will ensure your request is processed within the required timeframe. Our Data Protection contact can be reached at [email] for any further questions.
The Do Not List
Equally important as what to say is what not to say:
Do not lie about your source. Saying a mutual connection referred me or I saw your LinkedIn post when that is not true destroys credibility and can constitute deceptive practices under some regulations.
Do not get defensive. Your cold email is your responsibility, not theirs. Responding with something like this is standard business practice comes across as dismissive.
Do not ignore the question. Replying with a follow-up sales pitch while ignoring their data question is the fastest way to generate a complaint.
Do not over-explain the technical process. They do not need to know about waterfall cascading across 17 data providers. Keep it simple: professional business database or business contact service.
Do not delay. If someone asks about their data, respond quickly. Under GDPR, you have 30 days for a formal DSAR, but best practice is responding within 24-48 hours for informal inquiries.
Turning Data Questions into Positive Outcomes
Here is something most teams miss: a data source question is actually an engagement signal. The person read your email carefully enough to have a question. That is more engagement than 90% of cold email recipients provide.
After addressing their question, some of these conversations do turn into business discussions. Not because you pushed. But because your professional, transparent response built trust. People respect honesty, especially in an era where they are bombarded with sketchy outreach.
Some practical approaches:
- After confirming their data preferences, ask if the topic you raised in your original email is relevant to their current priorities. Keep it low-pressure.
- If they express any interest in data privacy (many decision-makers are dealing with compliance themselves), you might find common ground.
- If they simply want removal, execute it gracefully and quickly. They might think of you positively later if a need arises.
Building a Systematic Response Process
Do not leave data inquiries to individual reps to handle on their own. Build a process:
Step 1: Create Response Templates
Provide your team with pre-approved response templates for each scenario above. These should be reviewed by your legal or compliance team to ensure they are accurate and appropriate.
Step 2: Define Escalation Criteria
Most data inquiries can be handled by the sales rep who sent the original outreach. But some require escalation:
- Formal data subject access requests (DSARs) should go to your compliance or legal team
- Threats of regulatory complaints should be escalated to management and legal
- Questions about specific data sources that the rep cannot answer should go to your data operations team
Step 3: Process Removal Requests Immediately
When someone requests removal, it should happen in real time. Not at the end of the week. Not during the next suppression list update. Now. Set up your systems so that reps can add contacts to the suppression list directly from their inbox.
Step 4: Log Every Interaction
Keep a record of every data inquiry, your response, and the action taken. This log serves two purposes: it demonstrates compliance process to regulators, and it helps you identify patterns (if you are getting lots of data inquiries, something about your outreach targeting might need adjustment).
Step 5: Review and Improve
Monthly, review data inquiry logs for patterns:
- Are inquiries increasing? You might be targeting too broadly.
- Are they concentrated in certain regions? Your jurisdiction handling might need work.
- Are they coming from specific campaigns? The messaging might be triggering suspicion.
- Are they overwhelmingly negative? Your outreach relevance might need improvement.
Prevention: Reducing Data Inquiries in the First Place
The best way to handle data source questions is to get fewer of them. Not by hiding your outreach. But by making it so relevant and professional that recipients focus on the value proposition instead of questioning the source.
High-quality enrichment data plays a role here. When you reach the right person with the right title at the right company with a relevant message, they are far less likely to question how you found them. When you reach the wrong person with an irrelevant pitch, the data source question is often a proxy for who are you and why are you wasting my time?
Using a pay-per-valid enrichment model like BetterEnrich reduces the chance of reaching wrong contacts because you are only paying for verified, accurate data. That accuracy translates directly into fewer data inquiries and more productive conversations.
The prospect who asks where you got their information is not your enemy. They are a person exercising legitimate curiosity or rights. Treat them with respect, give them control, and move forward. That is really all there is to it.




