2026-09-24 · 6 min read
B2B data provenance means that every fact in a company record carries two extra pieces of information: where it came from and when it was last checked. A registered address should point to the company register it was read from. A general inbox should point to the page of the company's website that published it. Without that, you cannot tell a current fact from a stale guess, and you cannot defend how you got the data if anyone asks.
This post explains why provenance matters, what good provenance looks like in practice, and the questions to ask any data provider before you rely on their records.
What is data provenance in B2B data?
Provenance is the history of a piece of data: its origin and every step it went through before it reached you. For company data the useful version is simple. Each field should answer three questions:
- What is the value? For example, a company's legal name, status, website or main phone number.
- Where did it come from? A named company register, a global identifier such as an LEI, a licensed dataset, or a specific public page on the company's own website.
- When was it seen? The date the value was last read from that source.
A record that stores these per field is traceable. A record that stores only the value is a claim you have to take on trust.
Why should every company record show its source?
Data goes stale faster than people expect
Companies move offices, change domains, get dissolved, merge and rebrand. A field that was correct two years ago may now be wrong, and without a check date there is no way to know. A check date lets you set your own rules, such as only using phone numbers seen in the last 90 days, and lets you spot the parts of your database that need refreshing.
Different sources deserve different levels of trust
A company's legal status read directly from an official register is strong evidence. The same field inferred by a model from a news article is much weaker. When a record mixes both without labels, you have to treat everything at the level of the weakest source. When each field is labelled, you can trust the strong ones fully and treat the weak ones with care.
Conflicts become visible and solvable
Two sources often disagree. The register says one address; the website footer shows another. With provenance you can see both, see which is newer, and decide. Without it you see one value and never learn there was a conflict at all.
You can answer questions about how you got the data
If you contact businesses in the EU or UK, someone may ask where you got their details. Regulators expect you to be able to say. "From the company's own contact page, read on this date" is a clear answer. "From a list we bought" is not. Our GDPR-aware prospecting checklist covers this in more detail.
Corrections are possible
When a company tells you a detail is wrong, provenance shows you where the wrong value came from. You can fix it at the source, or stop trusting that source, instead of correcting one row and having the bad value come back with the next import.
What does good provenance look like?
A practical standard for a company record:
- Every field has its own source and date, not one date for the whole record. A record refreshed last week may still contain a phone number nobody has seen for a year.
- Sources are specific. "Company register" is not enough; it should name which register. "Website" is not enough; it should give the page URL.
- Official identifiers are kept. Register numbers and LEIs let you match a company across systems without guessing from the name.
- Inferred values are marked as inferred. If something was derived rather than read, such as an industry classification, the record should say so.
- History is kept. When a value changes, the old value and its dates should still be available.
This is how we built SyntoraData. Records start from official company registers, global identifiers such as LEI and Wikidata, and licensed company datasets. They are then enriched from each company's own public website by our crawler, SyntoraDataBot, which honours robots.txt, waits between requests and reads only a small number of public pages per site. Every fact keeps its source page or register and the date it was seen.
How do you judge a B2B data provider?
Whichever supplier you use, these questions separate traceable data from opaque data. Start with the licence and the sourcing, then look at price.
Where does each field come from?
Ask for a sample record with sources shown per field. A provider that cannot show you this for a single record will not be able to show it for a million.
When was each field last checked?
Ask whether the date shown is when the record was created, when it was last touched, or when each individual value was last confirmed. Only the last one is useful.
How is website data collected?
Ask whether their crawler identifies itself, honours robots.txt and limits its request rate, or whether it relies on proxies and logins to get past restrictions. How data is collected affects whether you can comfortably use it.
What are you allowed to do with the data?
Read the licence. Some data can be used internally but not resold. Some can be shown in a dashboard but not exported in bulk. Some sources carry their own attribution or reuse terms. Knowing this before you build on it saves a painful rebuild later.
How are corrections and removals handled?
Ask how a company or a person can ask for their details to be corrected or removed, and how quickly that change reaches your copy. A provider with no answer here is a risk to you.
Is personal data separated from company data?
Company facts such as a registered address are a different category from information about named individuals. A good provider keeps them separate, applies different retention rules, and can tell you which is which.
What should you do with data that has no provenance?
You do not have to throw it away. Mark it as unsourced, give it the lowest trust level, and replace it gradually as you confirm values from a known source. Prioritise the fields you actually use for decisions or contact. A clean record for 1,000 companies you will really approach is worth more than an unsourced list many times that size.
If email addresses are part of the record, verify them before use and store the check date alongside the result. Our guide on how to verify an email address without sending an email explains how.
Working with Syntora Ai
Syntora Ai builds and runs SyntoraData, company data where every fact shows its source and when it was checked. Access is by request at syntoradata.com. If you need provenance built into your own data pipeline or CRM instead, our growth and data practice does that work. Write to hello@syntorahq.ai or use the contact page.