Skip to content

Is Buying B2B Email Lists Legal? Only One Country Bans the Purchase

September 5, 2026. Of the five jurisdictions most outbound teams sell into, exactly one makes buying an email list an offence in itself. In Australia, Section 21 of the Spam Act makes it a civil penalty contravention merely to acquire a harvested-address list or the right to use one, before a single message is sent, and Section 20 catches the vendor who supplies it. Everywhere else, liability attaches at sending: the United States asks whether the message itself broke the rules, the United Kingdom and Canada ask whether the recipient consented to hear from you specifically, and the European Union asks whether you told the person, within a month, where you got their data. The practical answer to "is buying B2B email lists legal" is therefore not yes or no. It is a set of conditions that most list vendors cannot meet on your behalf, and in two countries the law puts the burden of proving consent on you by statute. Here is each regime from its own text.

Nothing in CAN-SPAM, 15 U.S.C. 7704, or the FTC's compliance guide prohibits buying a list, and the guide never mentions list purchase at all. It does say the law makes no exception for business-to-business email. Every message needs accurate headers, an honest subject line, ad identification, a postal address and an opt-out honoured within 10 business days. Two list-specific rules sit inside the statute. Once someone opts out, you cannot sell or transfer their address. And Section 7704(b)(1) makes it an aggravated violation to have obtained addresses by automated harvesting from a website that carried a notice it would not give away addresses, or by dictionary attack; the FTC's guide describes harvesting as carrying criminal penalties. The nuance most guides miss: the aggravation applies only to a message already unlawful under the main rules. The civil penalty is up to $53,088 per email under 16 CFR 1.98, unchanged since January 2025. The FTC's largest CAN-SPAM penalty, $2.95 million against Verkada in August 2024 for more than 30 million B2B emails, turned on missing unsubscribe options and a missing postal address, not on where the list came from.

Regulation 22 of PECR bars unsolicited marketing email to individual subscribers without prior consent, with a soft opt-in for the sender's own similar products where details were collected during a sale or negotiations. The ICO's guidance on bought-in lists, updated April 2026, is direct: consent must have named your organisation, not "trusted partners" or similar; if it does not name you and the channel, it is not valid; the soft opt-in must not be used for bought-in lists; and publicly available details do not equal consent. B2B is different but not exempt: companies, LLPs and Scottish partnerships fall outside Regulation 22, but sole traders and ordinary partnerships are individuals, identity and an opt-out address are always required, and UK GDPR governs any named address. The ICO also says LinkedIn users are unlikely to be there exclusively in a business capacity. Since February 5, 2026 breaches attract the higher maximum of 17.5 million pounds or 4 percent of worldwide turnover, and directors can be fined personally for consent, connivance or neglect. The cases are about third-party data: ZMLUK was fined 105,000 pounds in December 2025 for 67,772,285 emails built on a sign-up that listed 361 partner companies; LADH paid 50,000 pounds in 2024 for texts sent on a supplier's verbal assurance; AFK Letters paid 90,000 pounds in 2025 because its supplier's consent statements did not name AFK.

European Union: the one-month letter

GDPR Article 6(1)(f) permits processing for legitimate interests subject to a balancing test, and Recital 47 says direct marketing may qualify. Article 14 is the rule a purchased list triggers: when data has not been obtained from the data subject, you must tell them who you are, why you hold the data, its source and their right to object, within one month or at the first communication, whichever is earlier when you use the data to contact them. The disproportionate-effort exception is narrow, and the CNIL rejected KASPR's reliance on it in December 2024 when it fined the B2B data vendor 240,000 euro for a 160-million-contact database with late, English-only notices. Email itself is governed by the ePrivacy Directive, which makes marketing email opt-in for natural persons and leaves companies to each member state, so a single EU-wide list has no single answer: Germany's Unfair Competition Act makes B2B email opt-in, while the CNIL's June 2026 guidance allows B2B prospecting on legitimate interest when the offer relates to the person's profession and they were informed and can object, including for data acquired from third parties.

Section 6 of Canada's anti-spam law prohibits sending a commercial electronic message without express or implied consent and requires identification and an unsubscribe honoured within 10 business days. The implied consent that list vendors rely on, conspicuous publication under Section 10(9)(b), requires that the recipient conspicuously published the address, that the publication carried no statement refusing unsolicited messages, and that the message is relevant to the person's business, role, functions or duties. Section 13 places the onus of proving consent on the sender, Section 9 reaches the vendor who procures a violation, and penalties run to 10 million dollars per violation for organisations. The leading case is still CompuFinder in 2017: a 1.1 million dollar notice reduced to 200,000 dollars over 317 B2B training emails, where every one of 132 conspicuous-publication claims failed. One address came from a third-party directory that had reproduced it, so the recipient had not published it; another directory's terms banned unsolicited messages; and relevance to the recipient's role was assumed rather than shown, including for info@ addresses.

Australia: acquiring the list is the offence

Section 16 of the Spam Act bars commercial electronic messages with an Australian link without the account holder's consent, and Section 16(5) places the evidential burden on the sender. Part 3 targets lists directly: Section 20 bans supplying address-harvesting software or a harvested-address list, Section 21 bans acquiring them, and Section 22 bans using them, each with an exception only where the use is unconnected with sending in breach of Section 16. Consent may not be inferred from the mere fact that an address was published; Schedule 2 infers it only from a conspicuously published work address, with no anti-spam statement, where publication reasonably appears to have been with the person's agreement, and only for messages relevant to their role. Penalties are in units worth 364 dollars from July 1, 2026: a company with no prior record faces up to 2,000 units, or 728,000 dollars, per day of multiple contraventions, and 10,000 units, 3.64 million dollars, per day with a prior record. The regulator collected more than 6.7 million dollars in spam penalties in 18 months, including 2,502,500 dollars from Pizza Hut Australia and 702,900 dollars from Lululemon.

What it means for operators

A purchased list is legal to hold in four of the five jurisdictions and legal to use in none of them without conditions the vendor cannot satisfy for you. In the UK the consent has to name your company; a list sold to 361 partners cannot. In Canada and Australia the burden of proof is yours by statute, and CompuFinder shows what "publicly available" is worth when the regulator asks for evidence. In the EU the list starts a one-month clock to notify every person on it. In the US the purchase is fine and the misuse is $53,088 an email.

This is why the question to ask a list vendor is not "is this compliant" but "show me, per contact, how the address was published, what consent statement it carried, and whether it named my company". Vendors that cannot answer are selling you the burden of proof. For most B2B teams the workable path is to build the list from sources the law treats as published for reuse, company registers, official APIs and genuinely public business listings, verify it, and send with the identification, opt-out and notification the strictest of your target countries requires. That is the shape of our lead generation work, and it is why the sends run through infrastructure that suppresses an opt-out across every domain, because the ignored unsubscribe is the fact pattern that turns a list question into a fine.

Checklist before you buy or use a list

  1. Per-contact provenance, in writing, from the vendor: source, date, consent text, whether it names you.
  2. Jurisdiction split. US rules on the message, UK and Canada on consent, EU on notification, Australia on acquisition.
  3. No harvested lists anywhere. Aggravated in the US, an offence in Australia, indefensible elsewhere.
  4. Article 14 notice within a month for every EU or UK individual, naming the source.
  5. Identification and a working opt-out in every message, the one rule all five share.
  6. Verify before you send. A bought list's bounce rate is a deliverability problem before it is a legal one; our verification guide covers the tooling.

The country-level rules are in our guides to the United States, the United Kingdom, Canada and Australia, and the scraping side of the same question in is web scraping legal. If you want a list built to those rules rather than bought against them, our cold email service starts there.

Want a list built to the strictest of your target markets instead of bought against them?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Yes. Neither CAN-SPAM nor the FTC's compliance guide prohibits buying a list, and the law makes no exception for B2B email. What is regulated is the message: accurate headers, a non-deceptive subject, identification as an ad, a physical address and a working opt-out honoured within 10 business days. Harvested addresses aggravate an already unlawful message, opted-out addresses cannot be sold or transferred, and the civil penalty is up to $53,088 per email.

Only if the consent named your organisation. The ICO's guidance on bought-in lists says consent that names trusted partners or a category rather than your company is not valid, that the soft opt-in must not be used for bought-in lists, and that publicly available details do not equal consent. Corporate subscribers fall outside the consent rule but you must still identify yourself and provide an opt-out. ZMLUK was fined 105,000 pounds for emails built on a 361-partner consent statement.

It can, on legitimate interest, but Article 14 requires you to tell each person who you are, why you hold their data, its source and their right to object within one month or at the first communication. The CNIL fined the B2B data vendor KASPR 240,000 euro in December 2024 partly for late, English-only Article 14 notices. Email itself is opt-in for natural persons under the ePrivacy Directive, with B2B rules varying by member state: opt-in in Germany, legitimate interest permitted in France.

For business addresses, conspicuous publication under Section 10(9)(b) of CASL: the recipient must have conspicuously published the address, the publication must not carry a statement refusing unsolicited messages, and the message must be relevant to the person's business role. Section 13 puts the burden of proving consent on the sender. In CompuFinder all 132 conspicuous-publication claims failed, including addresses reproduced by third-party directories.

Acquiring a harvested-address list or the right to use one is itself a civil penalty contravention under Section 21 of the Spam Act, supplying one breaches Section 20 and using one breaches Section 22. Consent may not be inferred from the mere fact that an address was published, and the sender bears the evidential burden under Section 16(5). Penalty units are worth 364 dollars from July 1, 2026, up to 2,000 units per day for a first offender and 10,000 units per day with a prior record.

The sender, in the jurisdictions that say so by statute: Section 13 of Canada's CASL places the onus of proving consent on the person alleging it, and Section 16(5) of Australia's Spam Act places the evidential burden on the sender. In the UK the ICO requires the consent record to name your organisation, and in the EU Article 14 requires you to disclose the source of the data to the person. A vendor's assurance does not discharge any of these.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us