
Buying email lists is one of those areas where many businesses assume that because something is commercially available, it must be legal to use. That assumption can be costly. The reality is that the legality of purchasing email lists in the UK is not a simple yes or no question. It depends entirely on how the data was collected, what individuals consented to, and whether the list you are buying meets the standards set by UK data protection law.
This guide cuts through the complexity, examining what UK law actually requires, what the financial consequences of non-compliance look like, and why building your own list remains the safest strategy for any business serious about email marketing.
Can I Purchase an Email List?
The short answer is that purchasing an email list is not automatically illegal, but using it almost always is. Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, any organisation that processes personal data must have a lawful basis for doing so. When you buy an email list, you are taking on responsibility for data that was collected by someone else, and that transfers the compliance burden directly to you.
The critical question is not whether money changed hands for the list, but whether every individual on it provided valid consent to receive marketing communications from third parties, specifically your business. For consent to be valid under UK GDPR, it must have been freely given, specific, informed, and unambiguous. It must also have been obtained through a clear, affirmative action, such as ticking an unticked opt-in box. Pre-ticked boxes, implied consent, or bundled consent buried in terms and conditions do not qualify.
In practice, the vast majority of commercially sold email lists cannot demonstrate this standard of consent. When vendors supply these lists, they rarely provide the audit trail necessary to prove that each contact knowingly agreed to receive communications from your specific organisation. Without that evidence, you are exposed.
The Privacy and Electronic Communications Regulations (PECR) add a further layer of restriction. PECR governs the sending of electronic marketing messages in the UK and applies independently of UK GDPR. Under PECR, sending unsolicited marketing emails to individuals without prior consent is a breach, regardless of how the data was acquired.
Need Help? Speak with our Consumer Data Team

How Much is a 1000 Email List Worth?
Email list pricing varies considerably depending on the quality of the data, the level of targeting, and what compliance claims the vendor makes. Generic consumer lists tend to sit at the lower end of the price range, whilst tightly segmented business-to-business lists command a significant premium.
What the purchase price does not reflect, however, is the true financial exposure that comes with using non-compliant data. The Information Commissioner’s Office (ICO) is the UK’s data protection regulator, and it holds significant enforcement powers. Under UK GDPR, the ICO can issue fines of up to £17.5 million or 4% of annual global turnover, whichever is higher. Under PECR, fines can reach £500,000. When set against those numbers, even a premium email list represents a poor return on investment if the data does not meet legal standards.
| List Type | Typical Price (per 1,000 contacts) | Compliance Risk |
|---|---|---|
| Generic consumer | £50 to £150 | Very high |
| Targeted consumer | £150 to £300 | High |
| B2B general | £200 to £500 | High |
| Specialist B2B | £500 to £1,000 | Medium to high |
The pricing table above reflects current market rates, but it is worth noting that even lists at the higher end of the price range are not necessarily more compliant. Specialist lists may carry a premium because of their targeting precision, not because of stronger consent practices. Any vendor claiming full GDPR compliance should be asked to supply documented consent records, opt-in dates, and the specific wording individuals agreed to at the point of collection. If that documentation is not readily available, that should be treated as a significant warning sign.
Is it Illegal to Subscribe Someone to an Email List?
Subscribing individuals to email lists without their explicit consent constitutes a clear violation of UK electronic marketing regulations under the Privacy and Electronic Communications Regulations (PECR). This practice, commonly known as “list stuffing” or unauthorised subscription, can result in substantial penalties from the Information Commissioner’s Office.
The legal requirement mandates that individuals must actively opt-in to receive marketing communications, with clear information provided about how their data will be used. Simply adding someone to an email list because you have their contact details from another source violates both GDPR consent principles and PECR marketing regulations, potentially exposing businesses to fines up to £500,000 under PECR provisions.
Is it Legal to Sell Contact Lists?
The legality of selling contact lists hinges entirely on the lawful basis under which the personal data was originally collected and whether appropriate consent exists for onward sharing. Under GDPR Article 6, organisations must demonstrate a legitimate legal basis for processing personal data, and this basis must extend to any subsequent sale or transfer of that information.
Most legitimate email list sales occur in business-to-business contexts where professional contact information is considered publicly available or where specific consent for data sharing was obtained during initial collection. However, the Data Protection Act 2018 requires data controllers to ensure that any purchasers of personal data maintain the same level of protection and use the data only for compatible purposes with the original collection intent.
The sale of consumer email lists presents significantly higher legal risks, particularly when individuals have not explicitly consented to their data being shared with third parties for marketing purposes. The ICO has consistently taken enforcement action against organisations that trade in non-compliant personal data, emphasising that both sellers and purchasers bear responsibility for ensuring lawful processing.
| Legal Basis | Consumer Lists | B2B Lists | Risk Level |
|---|---|---|---|
| Explicit Consent | Potentially Legal | Potentially Legal | Low |
| Legitimate Interest | Generally Illegal | Sometimes Legal | High |
| No Legal Basis | Always Illegal | Always Illegal | Very High |
Need Help with Public Sector Database? Speak with our Professional Public Sector Team
Understanding Email List Purchase Legality in the UK
The fundamental challenge with purchasing email lists lies in verifying the legitimate collection and consent status of the contained personal data. Even when vendors claim compliance with data protection regulations, purchasers remain legally responsible for ensuring any marketing activities meet GDPR and PECR requirements.
Building organic email lists through proper consent mechanisms represents the most legally secure approach to email marketing. This method ensures clear audit trails, explicit consent records, and full compliance with UK data protection standards whilst protecting businesses from regulatory scrutiny.
The Information Commissioner’s Office guidance emphasises that consent must be freely given, specific, informed, and unambiguous. These criteria are rarely met by commercial email lists, making organic list building the preferred strategy for compliance-conscious businesses.
Key considerations for email marketing compliance include:
What Information is Classed as a Data Breach: Frequently Asked Questions
The ICO can impose fines up to £17.5 million or 4% of annual global turnover under GDPR for serious data protection breaches. Additional penalties under PECR can reach £500,000 for unauthorised marketing communications.
Request detailed documentation showing how consent was obtained, including opt-in dates, methods, and clear records of what individuals consented to receive. Legitimate vendors should provide comprehensive audit trails and consent verification processes.
B2B email marketing has slightly more flexibility under the “soft opt-in” provisions, but only for existing customers and similar products/services. Cold B2B marketing still requires explicit consent or legitimate interest justification under GDPR.
Valid consent must be freely given, specific, informed, and unambiguous, typically through positive action like ticking a box. For more detailed information about consent requirements, visit the GDPR consent guidelines on Wikipedia.
Simply collecting business cards doesn’t constitute consent for email marketing; you must obtain explicit permission to send marketing communications. Professional contact sharing differs from marketing consent under data protection law.
Data retention must be proportionate and limited to what’s necessary for your stated purposes. Without ongoing consent refresh and engagement, retention periods should typically not exceed 24 months for marketing purposes.
Stop using the lists immediately, document your compliance review process, and consider seeking legal advice. Proactive compliance measures may help mitigate potential penalties if regulatory issues arise.
Very few commercial email list providers can demonstrate full GDPR compliance. Industry association membership lists or conference attendee lists with proper consent may offer more legitimate options than general commercial databases.
The UK retained GDPR principles through the Data Protection Act 2018, so compliance requirements remain largely unchanged. Cross-border data transfers may require additional safeguards depending on recipient countries.
Maintain detailed consent records including dates, methods of collection, specific permissions granted, and any changes to consent status. The UK government’s data protection guidance provides comprehensive record-keeping requirements.
Existing customers may receive marketing for similar products/services under soft opt-in provisions, but you must provide clear opt-out options and respect any previous unsubscribe requests.
Unsubscribe requests must be processed within one month, ideally immediately, and should be simple one-click processes. You cannot charge fees or require additional information beyond email confirmation for unsubscribe requests.
Implement clear opt-in processes on your website, use lead magnets with explicit consent checkboxes, and ensure all marketing materials clearly explain what communications subscribers will receive and how often.
Privacy notices should explain data collection purposes, retention periods, sharing practices, individual rights, and contact information for data protection queries. Include links to full privacy policies and ICO complaint procedures.
