Lead Generation
ZoomInfo
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by ZoomInfo Technologies Inc. · www.zoominfo.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
ZoomInfo's public help documentation describes a lead-generation product whose visible strength is plumbing rather than data. CRM sync and export leads, with scores of 4-5: out-of-the-box writeback to Salesforce, HubSpot and Microsoft Dynamics, Salesforce deduplication tasks, and an HTTP Enterprise API that creates, updates and enriches records. Visitor identification scores run 3-5: WebSights Buyer ID surfaces a visitor's name, title and visited pages, but only when the page visit occurs on a device in the United States. The rest is thin. Data coverage scores sit at 0, and we found no public information on record counts, verification, refresh cadence or DACH coverage. Data provenance scores run 0-1; we found no public information on sourcing, lawful basis, or a removal route for people in the database. Sovereignty scores sit at 0, with legal entity jurisdiction, ownership, data residency and subprocessor exposure all unknown. No prices appear on the pages; features gate to Copilot Advanced and Copilot Enterprise.
Speaks for it
- CRM Writeback integrates out of the box with Salesforce, HubSpot and Microsoft Dynamics, with selectable activity sync and settings editable at any time.
- A documented HTTP Enterprise API supports create, update and enrich operations against CRM, marketing automation and internal systems, with a getting-started guide.
- Salesforce deduplication tasks ship with run history, side-by-side comparison, and a report card covering duplicate records and unused fields.
- WebSights Buyer ID surfaces named visitors from Target Accounts — name, title and visited pages — with third-party cookies off by default and admins told to obtain legally required consent before enhanced identification.
Held against it
- We found no public information on database coverage — no record counts, verification method, refresh cadence, or coverage of Germany, Austria or Switzerland.
- We found no public information on where contact data is sourced, the lawful basis claimed for it, or a removal route for the people in the database.
- The sovereignty attributes — legal entity jurisdiction, ownership, data residency and subprocessor exposure — all read unknown.
- Person-level visitor identification requires the page visit to occur on a device in the United States.
Best for
- You run Salesforce, HubSpot or Microsoft Dynamics and want outreach activity logged back into your CRM automatically, with deduplication and empty-field analysis on Salesforce objects.
- You need a documented HTTP API to create, update and enrich records inside your CRM, marketing automation platform or internal systems.
- Your target accounts' web traffic comes largely from devices in the United States and named-visitor signals would feed your reps.
Avoid if
- Your buyers visit your site from devices outside the United States — the person-level identification criterion will not match them.
- You want visitor identification off until consent is settled — WebSights Buyer ID is enabled by default once the ZI Script is added.
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
None of the captured pages gives coverage figures, a verification method, or a refresh cadence for the database — we found no public information on DACH or EU record counts at all. The only data-quality material is a report card scoring the buyer's own Salesforce duplicates and empty fields, which says nothing about the vendor's own records. 1
The RevOps Manager
Every captured page is product help documentation, and we found no public information on record counts, coverage by country or region, verification method or refresh cadence for the contact database. The nearest thing to a data-quality claim is a report card about the customer's own Salesforce duplicates and unused fields, not about the vendor's data. 1
The Data Protection Officer
The captured pages deal with the buyer's own Salesforce hygiene, meeting recordings and API plumbing, not the contact database itself; I found no public information on record counts, coverage by country — let alone DACH — a verification method, a refresh cadence, or any bounce guarantee. 1 5
The ABM Marketer
I found no public information on record counts, verification methods, refresh cadence, or coverage of Germany, Austria or any European market — nothing my account list can be sized against. The only data-quality page captured concerns duplicates and empty fields in the customer's own Salesforce, not the vendor's database. 1
The DACH Sales Director
The captured pages state no database size, no coverage for Germany, Austria or Switzerland, and no verification or refresh method — we found no public information on any of it. The only coverage-relevant fact is that visitor identification requires a visit from a device in the United States, which tells a DACH buyer nothing about how many Mittelstand firms sit in the records. 2
The Skeptic
The captured help pages cover meeting-recording consent, CRM mechanics and an API, and none of them states coverage by country or region, a verification method, or a refresh cadence — we found no public information on database size, on DACH or EU coverage, or even a headline accuracy figure with anything behind it. Judged on what the vendor publishes about its database, this is the bottom. 2 5
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
We found no public information on where the contact records come from or on what legal basis they are processed — no source categories, no legitimate-interest statement, and no notice, objection or removal route for the people in the database. The GDPR content that does exist covers meeting-recording consent and website-visitor notices, which concerns the buyer's own meetings and traffic. 2 3
The RevOps Manager
We found no public information on where contact data comes from, on what legal basis it is processed, or how a listed person could find and remove their record. The only consent machinery captured concerns meeting-recording attendees and website visitors, not the people in the database, and the sole legal statement is a disclaimer to consult your own advisors. 2 3
The Data Protection Officer
The consent machinery on display — join-with-recording choices for GDPR-region attendees and a warning that website consent must be obtained — concerns meetings and website visitors, not the people in the database; I found no public information on where contact records are sourced, the lawful basis claimed for them, an Art. 14 notice, or any route for a listed person to object or be removed. 2 3
The ABM Marketer
Nothing captured says where the contact records come from or on what legal basis they are processed, and I found no public information on a privacy notice or removal route for the people in the database. The only lawful-basis content is meeting-recording consent in the Chorus compliance center, a different dataset entirely. 3
The DACH Sales Director
We found no public information on where the contact data is sourced or on what legal basis it is processed — no Art. 14 notice, no legitimate-interest statement, no removal route for the people held in the database. The consent machinery that is documented serves meeting recording and website visitors, which are different data subjects entirely. 2 3
The Skeptic
We found no public information on where the contact data comes from, on what lawful basis EU records are processed, or on any route for a person in the database to object and be removed. The one consent pipeline documented — GDPR-region attendees choosing Join with Recording or Join without Recording via Go-Links — protects the buyer's meeting participants, a different population from the people whose records are being sold. 3
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
Real capability here: specific visitors from target accounts are surfaced with name, title and pages visited, with target-account and buying-group filters, an explicit requirement that admins obtain any legally required consent before enabling it, and third-party cookies off by default. But identification of named people is restricted to devices in the United States with no published position for EU visitors or the German tracking law, and we found no public information on a cookieless mode, consent-platform integration, or where the Signals and intent data come from. 2
The RevOps Manager
Buyer ID surfaces the visitor's name, title and pages visited, restricted to visits from a device in the United States, and admins are told to disclose the collection and obtain any legally required consent before enabling it — a stated consent position, with third-party cookies an opt-in. We found no public information on a cookieless or consent-mode option, the source of any third-party intent data, or alert routing to account owners. 2
The Data Protection Officer
Identification runs at person level — surfacing name, title and visited pages — with a stated requirement to obtain legally required consent before Enhanced Visitor Identification, and matching is restricted to devices in the United States, which keeps EU visitors out of this feature as captured. But the feature is enabled by default once the script is added, third-party cookies are offered for cross-domain accuracy, and I found no public information on cookieless operation, consent-platform integration, or the vendor's position on the German rule requiring consent before a script reads a device. 2
The ABM Marketer
WebSights surfaces visitors from configured target accounts with name, title and visited pages, but only when the visit occurs on a device in the United States — so none of my DACH accounts' traffic gets identified. The documentation does tell admins to obtain legally required consent before enabling Enhanced Visitor Identification and third-party cookies are optional, but I found no public information on a cookieless or consent-mode option, a named third-party intent source, or alerts routed to account owners. 2
The DACH Sales Director
Buyer ID surfaces the individual visitor's name, title and visited pages — person-level, not company-level — though only when the visit comes from a device in the United States, which at least keeps EU visitors out of the person-level net. Admins are told to obtain legally required consent before Enhanced Visitor Identification, yet an optional third-party-cookie mode is offered, and we found no public information on cookieless operation, consent-platform integration, or the position under German tracking law. 2
The Skeptic
WebSights Buyer ID surfaces name, title and visited pages for specific visitors from target accounts — person-level identification, though the stated criteria require the visit to come from a device in the United States. The pages do tell admins to obtain "legally required consent" before enabling enhanced identification and keep third-party cookies off by default, but identification switches on by default once the tracking script is added, and we found no public information on cookieless operation, consent-platform integration, or the vendor's position on German tracking law. 2
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
The compliance machinery on these pages is about recording consent for the buyer's own meetings — Go-Links, join-with-recording choices, opt-out notifications — and the vendor states that this provides no legal guidance, directing buyers to their own advisors. We found no public information on search filters, saved lists, suppression, or any help with cold-outreach rules in EU markets, so the legal risk on a prospect list sits entirely with my reps. 3
The RevOps Manager
The compliance tooling captured governs meeting recording — Go-Links, join-without-recording, a purge policy for recordings — rather than prospecting or outreach. 3
The Data Protection Officer
Nothing captured shows the search and list-building side of prospecting, and the only compliance statement is a disclaimer that the product provides no legal guidance and buyers should consult their own advisors — the legal risk of outreach sits entirely with the customer. I found no public information on do-not-contact suppression, outreach opt-outs syncing back, or country-aware handling of German contacts. 3
The ABM Marketer
I found no public information on search filters, saved lists, do-not-contact suppression, or outreach rules in any market for contact data. 3 2
The DACH Sales Director
The single compliance statement is a disclaimer that the product provides no legal guidance and the customer must consult their own advisors — under UWG §7 that leaves the entire cold-outreach risk on the buyer. We found no public information on suppression lists, do-not-call register checks, or consent guidance for German contacts; the documented Compliance Center governs meeting recording, not prospecting. 3
The Skeptic
To ensure your compliance processes are appropriate for your organization, consult with your appropriate internal teams or legal advisors." The compliance tooling that is documented — recording consent collected per meeting, compliance mode enforced by role — governs the buyer's own calls rather than outreach to purchased contacts. 3
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
There is genuine plumbing: outreach activity writes back to Salesforce, HubSpot and Dynamics, Salesforce deduplication tasks and empty-field analysis run with CSV export of the results, and a documented Enterprise API supports create, update and enrich against CRM and marketing systems. We found no public information on API limits or per-call costs, bidirectional record sync that propagates objections and deletions, or what happens to exported and synced data after cancellation. 1 4 5
The RevOps Manager
CRM Writeback pushes outreach activity into Salesforce, HubSpot and Dynamics with mapping to CRM activity types, the Enterprise API can create, update and enrich CRM records, and Salesforce deduplication tasks exist with run history and side-by-side comparison — genuinely more than a one-way push to one CRM. But we found no public information on bidirectional record sync, scheduled re-enrichment, propagation of objections into synced records, or which exported data the customer may keep after cancellation. 1 4 5
The Data Protection Officer
Out-of-the-box integrations with leading CRMs, activity writeback to Salesforce, HubSpot and Dynamics, create/update/enrich operations through a documented Enterprise API, and Salesforce deduplication tasks are all evidenced. But the writeback is activity logging rather than record-level sync, and I found no public information on API limits, per-call credit costs, or — the question that matters most to me — which exported data the buyer may keep, and for how long, after cancelling. 1 4 5
The ABM Marketer
CRM Writeback logs activity into Salesforce, HubSpot and Microsoft Dynamics with selective activity mapping, Salesforce deduplication tasks come with health checks and run history, and the Enterprise API can create, update and enrich records with public documentation. I found no public information on API rate limits, webhooks, or what happens to exported data and access after cancellation. 4 5 1
The DACH Sales Director
The strongest area: native writeback to Salesforce, HubSpot and Dynamics, deduplication tasks on Salesforce objects, enrichment of empty fields through the data-quality tooling, and an HTTP Enterprise API that creates, updates and enriches records with a getting-started guide. The harder promises go unrecorded — we found no public information on propagating deletions or objections, per-call costs, or what the customer may keep after cancelling. 1 4 5
The Skeptic
Out-of-the-box integrations with the major CRMs, writeback to Salesforce, HubSpot and Dynamics, Salesforce deduplication tasks with run history and field-fill analysis, and an HTTP Enterprise API with a getting-started guide that can create, update and enrich records. What holds it mid-table: we found no public information on API rate limits or per-call costs, on propagation of objections or deletions into synced records, or on what happens to exported data after cancellation. 1 4 5
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
Every attribute here is unrecorded: we found no public information on hosting location, contracting entity, data residency, or a single subprocessor, and the vendor is a US-incorporated company. The only geography statement in the captures is that visitor identification requires a device in the United States, with no transfer basis stated for EU residents' contact data. 2
The RevOps Manager
The contracting entity is ZoomInfo Technologies Inc., and we found no public information on hosting, data residency, ownership or subprocessors. The captured visitor-identification flow even requires a device in the United States and has ZoomInfo placing its own cookies on visitors' devices, so an EU-resident data footing is not evidenced anywhere on these pages. 2
The Data Protection Officer
I found no public information on the contracting entity's jurisdiction, where EU residents' data is hosted, or which subprocessors see it; nothing captured names an EU representative, EU infrastructure, or a transfer basis. The only territorial facts are localized consent pages for meeting attendees and a United States device restriction in the visitor product, which is not a hosting arrangement. 2 3
The ABM Marketer
The vendor is named as ZoomInfo Technologies Inc., and I found no public information on the contracting entity, hosting location, subprocessors, or any transfer basis for EU residents' data — every sovereignty attribute comes back unknown. Visitor identification is built around devices in the United States, and nothing captured shows a European-hosted or European-controlled alternative. 2 5
The DACH Sales Director
The contracting entity is ZoomInfo Technologies Inc. and we found no public information on hosting location, an EU representative, or the subprocessors and data partners that would see European records. The captured pages are themselves US-facing, with visitor identification firing only for devices in the United States, and no transfer basis for EU personal data is stated on these pages. 2 3
The Skeptic
Contracting entity jurisdiction, ownership, hosting location and subprocessor exposure are all unaddressed — we found no public information on any of them, nor on a transfer mechanism for EU personal data. For a product that is personal data about people who never chose the vendor, we found nothing a DACH buyer could put in front of a data-protection officer. 2 3 5
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
We found no public prices on the captured pages — no tier prices, credit allowances, per-seat costs, or expiry terms, so an annual invoice is not computable from what is public. Capabilities are gated behind named plans like Copilot Advanced and Copilot Enterprise, and we found no public information on what those plans cost. 2 4
The RevOps Manager
No price appears anywhere on the captured pages; the only pricing-adjacent facts are that Advanced Activity Sync requires Copilot Advanced or Enterprise and that website-visitor Signals require Copilot Enterprise. Credits per data type, credit expiry, seat costs, API costs and the annual invoice are all things we found no public information on. 2 4
The Data Protection Officer
No price figures appear anywhere in the captured pages — only plan names, with features gated to Copilot Advanced and Copilot Enterprise. I found no public information on tier prices, what a credit buys, credit expiry, seat costs or API charges, so no annual cost can be derived from what was captured. 2 4
The ABM Marketer
No price figures appear on any captured page — no tier prices, credit costs per data type, seat costs or credit expiry terms. The only commercial facts published are which features require which plans, so an annual invoice cannot be computed from public pages. 4 2
The DACH Sales Director
The only pricing-adjacent facts are tier gates — Advanced Activity Sync requires Copilot Advanced or Enterprise, and website-visitor Signals require Copilot Enterprise — with no price, credit allowance, seat cost, expiry or VAT treatment published. A Mittelstand buyer cannot estimate even a rough annual invoice from this. 2 4
The Skeptic
We found no public information on prices at all — no tier pricing, no credit costs, no seat pricing, no expiry or overage terms; the only cost-adjacent facts are plan gates such as advanced activity sync requiring Copilot Advanced or Enterprise and website visitor signals requiring Copilot Enterprise. The annual invoice is not derivable from the captured pages. 2 4
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 1 Oct 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 4 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
Sources (5)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Data sources & lawful basis — found from sitemap help.zoominfo.com Checked 1 Oct 2026 Details →
- 2 Visitor identification & intent signals — found from sitemap help.zoominfo.com Checked 1 Oct 2026 Details →
- 3 Prospecting workflow & outreach rules — found from sitemap help.zoominfo.com Checked 1 Oct 2026 Details →
- 4 CRM sync, enrichment & export — found from sitemap help.zoominfo.com Checked 1 Oct 2026 Details →
- 5 CRM sync, enrichment & export — found from sitemap help.zoominfo.com Checked 1 Oct 2026 Details →