Many lookup solutions quietly run on static or leaked databases. For the buyer, the risk is invisible — until it becomes a problem.
What leaked databases are
They are personal-data packages copied in the past and traded irregularly — often originating from security incidents. They circulate with no guarantee of origin, integrity or currency.
Why they are dangerous
- Outdated: they reflect an old snapshot.
- Incomplete and inconsistent: they accumulate gaps and errors.
- Illicit origin: the provenance cannot be proven.
The compliance risk under the LGPD
The most sensitive point is not only poor quality — it is legal exposure. Processing personal information of illicit origin, without a legal basis and without ensuring the source, contradicts LGPD principles and may constitute a violation, with risk of sanctions and reputational damage. In a vendor review, being unable to prove data origin is a red flag.
How to spot and avoid it
- Demand proof of origin.
- Check currency: see the guide on real-time data (D+0).
- Assess governance: certifications (ISO/IEC 27001 and 27701) and LGPD adherence.
The alternative: official sources, in real time
The opposite of a leaked base is official-source lookups in real time (D+0): today’s data, with provable origin and compliant processing. See the guide Registration data and the LGPD. CPF.CNPJ never uses leaked databases. See the packages.

