- Why this question confuses people
- What PECR requires
- The soft opt-in, and why it doesn't rescue bought lists
- What happened to a client of mine
- What the ICO fines people for
- The part people don't like admitting
- What about B2B, isn't that different?
- How to spot a list you should walk away from
- What to do instead
- The maths on building versus buying
- Frequently asked questions
- Where to check the details
Straight answer: In the UK, buying an email list is not itself illegal, there's no law against purchasing a spreadsheet of addresses. But sending marketing emails to those addresses almost always breaks the Privacy and Electronic Communications Regulations (PECR), because you need specific, informed consent from each person before you email them, and a purchased list virtually never has that. So the list itself isn't the crime. What you do with it is.
If you want to go deeper on this: email marketing platform for small businesses.
Why this question confuses people
I get asked this every few months, usually by someone who's just been pitched a list by a data broker promising "10,000 verified UK marketing directors, GDPR compliant, £450." The word "GDPR compliant" is doing a lot of lying in that sentence.
Here's the confusion in plain terms: buying and selling personal data is legal under UK GDPR, provided both parties have a lawful basis to process it. But sending unsolicited direct marketing by email is governed by a separate, older law called PECR, and PECR sets a much stricter bar than GDPR does. You can own the data legally and still be breaking the law the moment you press send.
What PECR requires
PECR (the Privacy and Electronic Communications Regulations 2003, updated since) says you need consent to send marketing emails to individuals, unless a narrow exception called the "soft opt-in" applies. Consent under PECR has to be:
- Freely given, specific, and informed, not buried in someone else's terms and conditions
- Given for your business specifically, not "we may share your data with third parties"
- Opt-in, never opt-out, a pre-ticked box does not count
- Recent, consent given three years ago to a company you've never heard of is worthless
When a data broker sells you a list, ask exactly who consented to what, and when. Nine times out of ten the answer is a vague reference to a "privacy policy" on a competition entry page from 2021. That is not consent for you to email them. It's consent, if anything, for the original company that collected it, and only if their privacy policy named third-party marketing as a use, which most don't.
The soft opt-in, and why it doesn't rescue bought lists
There's one legal shortcut people misuse constantly: the soft opt-in. It lets you email someone without fresh consent if you got their details in the course of a sale or negotiation, you're marketing similar products or services, and you gave them a clear chance to opt out at the time and in every message since.
Notice what that requires: you collected the details yourself, during a real transaction with that specific person. A list you bought from a broker fails on the first condition automatically. The soft opt-in exists to let a shop email a customer who bought trainers about new trainers, not to let you email 20,000 strangers because someone else sold you their addresses.
What happened to a client of mine
In 2022 I worked with a small events company that bought a B2B list, 40,000 contacts, £800, "verified corporate emails, no consumer addresses, fully compliant." They sent one campaign through their Mailchimp account promoting a conference.
Within 48 hours their account was suspended. Not fined, not warned, just switched off. Mailchimp's terms explicitly forbid sending to purchased or rented lists, and their spam complaint rate on that single send was high enough to trip automatic detection. The company lost access to their actual list too, the 3,000 genuine subscribers who'd opted in over four years, because everything sat in one account. It took nine days and two support tickets to get read-only access back so they could export their real contacts before rebuilding from scratch on a different platform.
Nobody reported them to the ICO. Nobody sued them. The damage came entirely from the email provider's own enforcement, and it was worse, in practical terms, than most PECR fines I've seen handed out. That's the bit people researching this question rarely get told: your biggest risk usually isn't the regulator, it's your own email service provider switching you off overnight and taking your legitimate list hostage with it.
What the ICO fines people for
The Information Commissioner's Office does enforce PECR, and the fines are public record. Honda Motor Europe was fined £13,000 in 2017 for emailing customers to ask them to confirm their marketing preferences, because that email was itself a form of marketing sent without consent. Flybe was fined £70,000 the same year for something similar. More recently the ICO has gone after companies sending unsolicited marketing texts and calls with fines running into six figures, Xheeda Ltd was fined £180,000 in 2023 for exactly that kind of bulk unsolicited messaging.
PECR fines are capped at £500,000. If the same conduct also breaches UK GDPR, which it usually does since you're processing personal data unlawfully, the ceiling rises to £17.5 million or 4% of global annual turnover, whichever is higher. Most small businesses never see fines that large because the ICO tends to start with warnings and enforcement notices for first offences. But "tends to" is not a guarantee, and the ICO has been clear that ignorance of where you got a list is not a defence.
The part people don't like admitting
Here's the uncomfortable bit. Most businesses that buy email lists never get caught. I've sat in enough marketing meetings to know this happens constantly, and the ICO simply doesn't have the resources to chase every small firm running one dodgy campaign a year. The realistic risk for most people isn't a knock from the regulator, it's slow, quiet damage: your domain reputation with Google and Microsoft degrades every time recipients mark you as spam, and that damage follows you even after you stop. If you want to understand exactly how that reputation gets built or wrecked, it's worth reading through the real reasons emails get marked as spam, because it's rarely the subject line, it's almost always sender behaviour like this.
So the honest picture is: you probably won't be fined, but you will almost certainly poison your sender reputation, and unlike a fine, that doesn't go away when you write a cheque. I've seen domains take eight to twelve months to recover deliverability after one bad bought-list blast, during which even emails to people who did opt in land in spam.
Want AI doing the heavy lifting in your marketing?
I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.
What about B2B, isn't that different?
Partially, but not in the way sellers claim. PECR does treat "corporate subscribers" a bit differently, a generic [email protected] or [email protected] address for a limited company can sometimes be emailed without individual consent, because the rules were written with named individuals in mind. But the moment a list gives you a named person, [email protected], that's personal data about an identifiable individual, and PECR's consent rules apply the same as they would to a private Gmail address. Almost every "B2B compliant" list I've seen sold in the UK is full of named individuals, which quietly kills the corporate-subscriber argument sellers use to justify the sale.
How to spot a list you should walk away from
If someone offers you a list, ask these questions before you pay anything:
- Exactly which company originally collected this data, and can you name the specific consent wording used at the time
- What date range was it collected in, anything older than 12 to 24 months is legally shaky even if consent existed
- Was the consent specific to third-party marketing by name, or a general privacy policy line
- Can they provide an audit trail or opt-in record for even a sample of contacts
- Will they put compliance warranties in writing, in the contract, with liability attached
If any answer is vague, "it's all compliant, trust us," that's your answer. A legitimate data provider selling consented data for a specific campaign, opted in for that exact purpose, does exist as a business model, but it's rare, expensive, and comes with paperwork. £450 for 10,000 verified emails is not that.
What to do instead
Building your own list is slower, but it's the only version of this that doesn't carry legal or deliverability risk, and it converts better because the people on it want to hear from you. If your website platform already has list-building tools built in, use them before paying for anything extra, and it's worth checking what you already have access to; I've written about how to check whether your website platform includes an email list feature because a surprising number of people pay for separate software they don't need.
A few things that build a list fast and cleanly:
- Gated content, a useful checklist or template behind an email form, not a thin five-point PDF
- A referral incentive on your existing list, ask current subscribers to forward to one colleague
- LinkedIn outreach that drives to a landing page opt-in, not a cold email in itself
- Webinars or short live trainings, people opt in willingly because the value is obvious and immediate
If you're distributing content to internal teams or partners rather than cold prospects, understand the difference between that and a marketing list, distribution lists and marketing lists get treated very differently under PECR, and I go through that distinction in this piece on email distribution lists and how to use them without getting your domain flagged.
And if you're building a career or a function around this rather than a one-off campaign, it helps to know what good practice looks like day to day, which is covered well in this look at what a career in email marketing involves.
The maths on building versus buying
A list of 10,000 opted-in subscribers, built through content and referrals over six to nine months, typically opens at 20 to 35%. A bought list, even a "clean" one, tends to open at 1 to 3%, generates spam complaints at a rate that damages your sending reputation for every future campaign, and carries legal exposure the whole time you hold it. £800 for a bought list that gets your account suspended and your domain blacklisted for a year is not cheaper than building slowly. It just feels cheaper in month one.
Related: legal: guidelines and how to pitch.
Before you send to a big list, clean it first, and my roundup of the best email verification tools shows how to cut bounces and protect your sender reputation.
Frequently asked questions
Is it illegal to buy an email list in the UK?
No, purchasing the list itself isn't illegal. What's illegal, under PECR, is sending marketing emails to the people on it without their specific, informed, opt-in consent, which purchased lists almost never have.
Can I email a bought list if I add an unsubscribe link?
No. An unsubscribe link doesn't create consent, it's required on every marketing email regardless, but it doesn't fix the underlying problem that you never had permission to email that person in the first place.
What's the fine for breaking PECR in the UK?
PECR fines are capped at £500,000. If the same activity also breaches UK GDPR, which it usually does, the maximum rises to £17.5 million or 4% of global turnover, though most small businesses receive warnings or enforcement notices before any fine.
Is buying a B2B email list any safer than a consumer one?
Slightly, but only for generic company addresses like info@ or sales@. The moment a list includes a named individual's work email, PECR's consent rules apply exactly as they would for a private address, and most "B2B" lists sold in the UK are full of named contacts.


