Is It Legal to Buy an Email List?

Buying data and sending to it are two different legal questions, and only the second one has consequences. What US, EU, UK, and Canadian rules actually require.

10 min read
August 31, 2026
Compliance
Short Answer

In the United States, buying an email list is legal, and sending B2B cold email to it is legal under CAN-SPAM provided you meet the statute's requirements. In the EU and UK, GDPR requires a lawful basis before you send, and legitimate interest can sometimes cover B2B outreach, but the rules vary by member state. In Canada, CASL requires consent before sending, and purchased lists almost never supply it. Jurisdiction is determined by where the recipient is, not where you are.

This page is general information, not legal advice. Get advice from a qualified lawyer for your specific situation.

Buying is not the regulated act. Sending is.

No major jurisdiction prohibits the purchase or possession of business contact data as such. Every regime described below regulates what you do next: whether you may send a commercial message to that address, and what the message must contain. Answering "is it legal to buy an email list" therefore always resolves into two separate questions, and only the second one has teeth:

  1. Was the data lawfully collected and lawfully transferred to you? (Data protection law, primarily in the EU, UK, and increasingly US states.)
  2. May you send commercial email to these people, and what must the email contain? (CAN-SPAM, CASL, GDPR plus ePrivacy.)

United States: CAN-SPAM

CAN-SPAM is an opt-out regime, not an opt-in one. It does not require prior consent, it does not distinguish B2B from B2C, and it does not prohibit purchased lists. It sets requirements for the message itself. Each separate violating email can carry a civil penalty of up to $53,088 under the 2025 statutory maximum, which is a ceiling rather than a typical fine, but it is enough that the requirements are not optional detail.

RequirementWhat it means in practice
Accurate header information"From", "Reply-To", and routing data must identify the actual sender. No spoofed domains or fake sender names.
Non-deceptive subject lineThe subject must reflect the content of the message.
Identify the message as an adRequired, though the disclosure can be brief and does not need a specific form of words.
Valid physical postal addressA real street address or registered PO box for your business, in every message.
Clear opt-out mechanismA visible, working way to unsubscribe that stays live for at least 30 days after sending.
Honour opt-outs within 10 business daysAnd you may not charge a fee, require any information beyond an email address, or make the recipient log in.
You stay liable for vendorsHiring an agency to send does not transfer legal responsibility away from the company being promoted.

Note what is absent: no consent requirement, no ban on purchased data, no B2B carve-out needed because none is necessary. This is why US B2B cold email is a functioning industry and EU cold email is a much narrower one.

State law adds a thin layer on top. Several states have anti-spam statutes, but CAN-SPAM preempts most of them except for provisions addressing falsity and deception. Separately, state privacy laws such as the CCPA/CPRA in California give residents rights over their personal data, including business contact data, which can mean disclosure and deletion obligations for the data you hold rather than a restriction on sending.

European Union: GDPR and ePrivacy

Two instruments apply together, and people frequently cite only the first.

GDPR governs whether you may process the personal data at all. A work email address in the form firstname.lastname@company.com is personal data. You need a lawful basis, and for cold B2B outreach the realistic candidate is legitimate interest under Article 6(1)(f), which requires a documented balancing test weighing your interest against the recipient's rights. GDPR also requires that you tell the person you hold their data, under the Article 14 notice obligation for data not collected from the data subject. For cold outreach the timing is not "within a month": Article 14(3)(b) requires the information at the latest at the time of the first communication with the data subject, and a cold email is that first communication. In practice the notice has to travel in or with the first email itself. Buying a list does not remove that obligation, it creates it.

ePrivacy (implemented separately in each member state) governs the sending itself, and this is where the variation lives. The directive's consent requirement is directed at natural persons; member states chose different treatments for corporate subscribers. Some permit unsolicited B2B email on a legitimate-interest basis with an opt-out, others require opt-in for all recipients. Germany is generally treated as strict, and several other member states apply the consent rule to business addresses too. There is no single EU answer, which is the practical point: an EU-wide cold campaign is governed by roughly 27 different local rules.

Whichever basis you rely on, GDPR obligations follow the data: an opt-out must be honoured, subject access and erasure requests must be answered, and you must be able to show where the data came from. Vendors who cannot document provenance are the real exposure.

United Kingdom: UK GDPR and PECR

The UK operates the same two-layer structure: UK GDPR for the lawful basis, PECR for the sending. PECR's marketing consent rule applies to "individual subscribers", a category that covers consumers, sole traders, and most partnerships. Corporate bodies (limited companies, LLPs, public bodies) fall outside it, which means B2B email to a named person at a limited company can rely on legitimate interest with an opt-out rather than prior consent. The ICO publishes direct marketing guidance covering this distinction, and it is the reason UK B2B cold email remains more workable than in much of the EU.

Canada: CASL

CASL is the strictest of the three regimes and is the one most often overlooked by US senders. It requires express or implied consent before sending a commercial electronic message, so the burden runs the opposite way to CAN-SPAM. Implied consent has narrow defined routes, including an existing business relationship within the last two years, and the conspicuous-publication route where a business address is published publicly without a statement refusing unsolicited messages and your message is relevant to that person's role.

That last route is how legitimate B2B outreach to Canada is usually justified, and it is genuinely narrow: publication, no stated refusal, and relevance all have to hold. Every message must also identify the sender, give contact information valid for 60 days, and include a working unsubscribe honoured within 10 business days. Penalties reach up to CAD $1 million per violation for individuals and CAD $10 million for organisations. A generic purchased list, sent to indiscriminately, does not satisfy CASL.

The three regimes side by side

US (CAN-SPAM)EU (GDPR + ePrivacy)Canada (CASL)
Consent needed before sending?NoDepends on member state; legitimate interest possible in someYes, express or implied
Purchased lists permitted?YesOnly with a documented lawful basis and provenanceEffectively no
Unsubscribe required?Yes, honoured within 10 business daysYesYes, honoured within 10 business days
Physical address required?YesSender identity requiredYes, contact details valid 60 days
Notify people you hold their data?NoYes, Article 14, in or with the first emailNo
B2B treated differently?No, same rules as B2CVaries by member state; UK exempts corporate subscribersNo general B2B exemption
Practical stance for cold outreachWorkableNarrow and country-specificVery narrow

Compliance checklist for a purchased-list campaign

What actually causes problems

For US B2B senders, enforcement is not the common failure mode. Deliverability is. Google and Yahoo require bulk senders to keep spam complaints under 0.3 percent, and mailbox providers block on bounce and complaint signals long before any regulator takes an interest. A campaign can be fully CAN-SPAM compliant and still be entirely undeliverable. The compliance rules and the deliverability rules point the same direction anyway: accurate identity, easy opt-out, relevant targeting, verified data. Both are covered in bulk email sender requirements.

If the list itself is the question rather than the law, see whether buying a list is worth it. Sales.co's US profession lists are US-only business contact data, which keeps the analysis inside the CAN-SPAM regime described above.

Frequently asked questions

Is it legal to buy an email list in the United States?

Yes. No US law prohibits buying or possessing business contact data, and CAN-SPAM does not require prior consent before sending commercial email. CAN-SPAM instead sets requirements for the message: accurate header information, a non-deceptive subject line, identification as an advertisement, a valid physical postal address, and a working opt-out honoured within 10 business days.

Does CAN-SPAM require opt-in consent?

No. CAN-SPAM is an opt-out regime. You may send commercial email without prior consent as long as the message meets the statutory requirements and you stop sending to anyone who opts out, within 10 business days. This is the main structural difference from Canada's CASL, which requires consent before the first message.

Can I cold email people in the EU using a purchased list?

It is far more restricted. GDPR requires a lawful basis for processing the data, usually legitimate interest, backed by a documented balancing test, plus an Article 14 notice telling the person you hold their data. Separately, ePrivacy rules on sending are implemented individually by each member state, and some require opt-in even for business addresses. There is no single EU-wide answer, so a pan-EU campaign faces roughly 27 different local rules.

Is cold email to Canada legal with a purchased list?

Rarely. CASL requires express or implied consent before sending. Implied consent has narrow routes, the most relevant being conspicuous publication: the business address was published publicly, without a statement refusing unsolicited messages, and your message is relevant to that person's role. Sending indiscriminately to a generic purchased list does not meet that test. Penalties reach up to CAD $10 million per violation for organisations.

What must a compliant cold email contain?

For US B2B outreach: truthful sender identity and headers, a subject line that reflects the content, identification of the message as an advertisement, your real physical postal address, and a clear opt-out that requires no login or extra information and is honoured within 10 business days. Suppress opt-outs permanently across every domain and inbox you send from.

Does hiring an agency shift legal responsibility for cold email?

No. Under CAN-SPAM the company whose product is being promoted remains liable alongside the party that sends the message. Outsourcing sending changes who operates the campaign, not who is accountable for its compliance.

Compliant outbound, run for you

Sales.co runs US B2B cold email end to end: verified lists, dedicated domains, copy, deliverability, and positive replies answered in under 10 minutes. From $1,000/month, no setup fees.

Book an Intro Call

Related Articles

Is Buying an Email List Worth It?

When a purchased list is cheap pipeline and when it burns your domain

Read More →

Bulk Email Sender Requirements

Google and Yahoo sender rules, SPF, DKIM, DMARC, and complaint thresholds

Read More →

Cold Email Deliverability Guide

Keeping cold outreach out of the spam folder at volume

Read More →