Skip to content
wiseguyxl

Quick answer

Buying an email list is not, by itself, a crime in the EU — but using a purchased list to send marketing to EU residents almost always breaks the law. The GDPR requires a lawful basis for processing personal data, and marketing consent must be freely given, specific, informed and unambiguous. Consent collected by a data broker for “partners” does not transfer to you, so a bought list gives you no valid basis to email anyone on it. On top of the GDPR sits a layer of national ePrivacy rules (Germany’s §7 UWG, France’s CNIL doctrine, Spain’s LSSI-CE, and so on) that separately require prior consent for electronic marketing. The short version: renting or buying lists is the fastest legal and deliverability mistake a European business can make, with fines reaching €20 million or 4% of global annual turnover, whichever is higher.

This guide explains what is and isn’t legal, where the narrow B2B exceptions exist, what it does to your sending reputation, and what to do instead.

Is it the purchase or the use that’s illegal?

It helps to separate two things. Acquiring a dataset is a commercial transaction; sending marketing to the people in it is data processing that needs its own lawful basis. Regulators care about the second part. Even if a broker swears every contact “opted in,” GDPR consent is purpose- and controller-specific: someone who agreed to hear from Company A (or from a vague list of “carefully selected third parties”) has not consented to hear from you. The European Data Protection Board and national authorities have been consistent on this — pre-ticked boxes and bundled consent are invalid (the CJEU confirmed this in Planet49), and “consent” that the recipient can’t trace back to a specific, named sender is no consent at all.

So in practice, a purchased B2C list is unusable for compliant marketing in every EU member state. The only real debates are around narrow B2B situations, and even those are tighter than most vendors admit.

The GDPR baseline (applies everywhere in the EU)

Four GDPR obligations make bought lists fail:

  1. Lawful basis (Art. 6). You need consent or a genuine, documented legitimate interest. Consent didn’t come with the list. Legitimate interest for cold email is possible in theory for B2B, but it requires a balancing test, transparency, and an easy opt-out — and it never overrides the separate ePrivacy consent rules below.
  2. Transparency (Arts. 13–14). When you obtain data indirectly, you must tell people within a month where you got it and why you’re processing it — before or at first contact. Brokers rarely give you the provenance you’d need to do this honestly.
  3. Data subject rights (Arts. 15–22). Recipients can demand access, erasure and objection. You can’t answer “where did you get my data?” for a laundered broker list.
  4. Accountability (Art. 5.2). You must be able to prove compliance. With a bought list you have no consent records, no source trail, nothing to show a regulator.

Fines sit in two tiers, the higher being up to €20 million or 4% of worldwide annual turnover. Since 2025–2026, authorities have widened enforcement well beyond big tech to small and mid-sized senders.

The ePrivacy layer changes country by country

The GDPR is the floor. Each country adds its own electronic-marketing rule, and this is where “localise, don’t translate” matters: the same bought list is illegal for different reasons in each market.

Market Core rule for email marketing B2B nuance
Germany 🇩🇪 DSGVO + §7 UWG; double-opt-in is the de-facto standard Among the strictest — cold B2B email also generally needs prior consent
France 🇫🇷 RGPD + CNIL doctrine; B2C strict opt-in B2B “soft”: professional address + message related to the person’s job, with clear identity + opt-out
Spain 🇪🇸 RGPD + LOPDGDD + art. 21–22 LSSI-CE; prior consent Existing-customer + similar-products exception only
Italy 🇮🇹 GDPR + Garante; art. 130 Codice Privacy — consent required Very limited; Garante fines unsolicited marketing
Netherlands 🇳🇱 AVG + Telecomwet art. 11.7; opt-in Soft opt-in for existing customers and B2B in some cases, always with opt-out
Poland 🇵🇱 RODO + PKE (Prawo komunikacji elektronicznej) Consent-based; a bought list has none
UK 🇬🇧 UK GDPR + PECR Corporate-subscriber B2B soft opt-in allowed, with identity + opt-out

Even in the “softer” B2B regimes (FR, NL, UK), the exception depends on relevance, transparency and an opt-out — none of which a broker list gives you, because the contacts don’t know you and never asked to. A purchased list fails the exception on day one.

It’s also a deliverability disaster

Legality aside, bought lists wreck the thing email marketing depends on: sender reputation. Contacts who never opted in mark you as spam, and native EU inbox providers — GMX and WEB.DE in Germany, Orange and Free in France, Libero and Virgilio in Italy, KPN and Ziggo in the Netherlands, WP, Onet and Interia in Poland — filter aggressively on complaint rate. Keep spam complaints under 0.1% and bounces under 2%, or your domain reputation drops for every campaign, not just the bought-list send. Marketing platforms know this: Mailchimp, Brevo and most ESPs ban purchased lists in their terms of use and freeze accounts that upload them, sometimes within 48 hours. High bounce rates from stale broker data also signal spam-trap hits, which can land your domain on a blocklist.

Permission is the whole point. As Seth Godin put it in Permission Marketing (1999):

“Permission marketing is the privilege — not the right — of delivering anticipated, personal, and relevant messages to people who actually want to get them.”

A bought list is the opposite of anticipated, personal and relevant.

What about “GDPR-compliant” list vendors?

Some brokers market “GDPR-compliant,” “opt-in verified,” or “consented” B2B data. Treat these claims sceptically. Consent is controller-specific and can’t be resold to you; brokers routinely recycle the same contacts across buyers, so provenance is unverifiable; and even a genuinely consented record doesn’t satisfy Germany’s §7 UWG or Italy’s Garante for your first cold email. At best you might build a research list of publicly available business contacts to inform manual, individually relevant outreach under a legitimate-interest analysis (with immediate opt-out and full transparency) — but that’s a world away from uploading 50,000 addresses to your ESP and pressing send.

What to do instead (and it works better)

Earned, first-party lists outperform bought ones on every metric that matters. Build with:

A list of 500 people who asked to hear from you will out-convert 50,000 who didn’t — with none of the legal exposure. For the full consent framework, see our guide to GDPR-compliant email marketing, and to protect the reputation those subscribers earn you, our email deliverability guide.

FAQ

Is it illegal to simply buy an email list in the EU?
Buying the data isn’t automatically illegal, but you’ll have no lawful basis to market to it, and sending to EU residents from a purchased B2C list breaks both the GDPR and national ePrivacy law.

Can I send cold B2B emails in the EU?
Sometimes, in “softer” regimes like France, the Netherlands and the UK, if the contact is a relevant professional, you identify yourself clearly and offer an easy opt-out. Germany and Italy are far stricter and generally require prior consent even for B2B.

What are the fines?
Up to €20 million or 4% of global annual turnover, plus national ePrivacy penalties. Enforcement now reaches small and mid-sized senders.

A vendor says their list is “GDPR-compliant.” Is that safe?
No. Consent can’t be transferred to you, provenance is usually unverifiable, and stricter national rules (e.g. §7 UWG) still apply to your first message.

Will my email platform allow a purchased list?
Almost never. Mailchimp, Brevo and most ESPs prohibit purchased lists and may suspend your account.

Sources

Want a list that’s legal and converts? WiseGuyXL builds permission-first email programmes across Europe — compliant capture, double opt-in, and flows that earn attention. 341% organic growth across 30+ projects in 9+ markets. See our insights or get in touch.