# GDPR Consent Requirements for Purchased Email Lists

Source: https://joinbreaker.ai/blog-posts/gdpr-purchased-email-lists  
Published: 2026-09-28

> Purchased email lists rarely meet GDPR's consent bar. Learn the legal basis rules, PECR overlap, and safer alternatives before you hit send.

![GDPR & Purchased Email Lists: Consent Rules 2026 — gdpr purchased email list marketing consent requirements](https://media.joinbreaker.ai/01M3K1BNPECWZX0XT958HTQ7ND.png)

A list broker just sent over a spreadsheet with 40,000 "verified" B2B contacts, and the price is tempting. Before you upload a single row into your sending platform, here's what you need to know: **under GDPR, marketing to a purchased email list is almost never lawful, because the people on it never gave consent that specifically names your organization as the sender.** GDPR's consent standard requires an unambiguous, affirmative opt-in tied to the exact company doing the emailing. Generic "opted in to receive offers from our partners" consent collected by a third party fails that test in nearly every real-world case.

The short answer protects you from immediate legal exposure. The longer answer - the one that actually protects your business - requires untangling GDPR's legal basis rules from the UK's Privacy and Electronic Communications Regulations (PECR), understanding where B2B email gets slightly more breathing room, and knowing exactly what to do if a purchased list is already sitting in your CRM.

## The Core Rule: Why Purchased Lists Almost Always Fail

GDPR requires that consent for direct marketing be freely given, specific, informed, and unambiguous. That specificity must include knowing which organization will be emailing you. The UK's data regulator, the [Information Commissioner's Office (ICO)](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/electronic-and-telephone-marketing/using-marketing-lists/), puts it plainly: organizations "must be very careful before using bought-in lists" and can only use them "if all the people on the list specifically consented to receive that type of message" from that specific company.

That single sentence eliminates most purchased lists on the market.

A person who ticked a box in 2023 agreeing to hear from "select partners" of a sweepstakes site did not consent to your product demo email. A scraped list of names and job titles pulled from LinkedIn or a conference attendee sheet never involved consent at all. A "verified opt-in" list sold by a data broker almost never comes with proof that the specific recipient agreed to hear from your specific company, about your specific product.

There is a narrow exception. If a list vendor produces a timestamped, named-organization consent record - meaning the person agreed, in writing, to be contacted by your company by name, not a vague category of "trusted partners" - the list could theoretically satisfy the legal test. In practice, this is rare enough that most compliance teams treat purchased lists as a non-starter instead and build owned, permission-based lists. [Breaker's guide to building quality B2B email lists fast](https://joinbreaker.ai/blog-posts/how-to-build-quality-b2b-email-lists-fast) covers proven approaches to this.

## What GDPR Actually Requires for Marketing Consent

Understanding "consent" under GDPR requires separating two different legal questions that even some regulators blur together: the general legal basis for processing personal data, and the additional, stricter rule for unsolicited electronic marketing.

### The Four-Part Consent Test

GDPR Article 4(11) defines consent as "any freely given, specific, informed and unambiguous indication of the data subject's wishes" through "a statement or by a clear affirmative action." Here's what each element means in an email marketing context:

**Freely given** - The person had a genuine choice, with no penalty for declining and no bundling of consent into an unrelated transaction (like forcing marketing opt-in as a condition of downloading a whitepaper).

**Specific** - Consent covers a particular purpose and a particular sender. Blanket consent to "receive offers from our partners" does not name your company, so it fails this test for a purchased list.

**Informed** - The person knew, at the point of consent, who would process their data and roughly what kind of messages they'd receive.

**Unambiguous** - Consent requires a clear, affirmative action such as ticking an unchecked box. Pre-ticked boxes, inferred consent, or silence do not count.

You can read the operative text directly at [GDPR Article 4](https://gdpr-info.eu/art-4-gdpr/) and [Article 7](https://gdpr-info.eu/art-7-gdpr/), which sets out the conditions controllers must meet to demonstrate valid consent, including the ability to prove it and the requirement to make withdrawal as easy as giving it.

### GDPR Article 6 vs. Article 7: Legal Basis and Marketing Consent

Article 6 lists six legal bases that make any data processing lawful: consent, contract necessity, legal obligation, vital interests, public task, and legitimate interest. Consent is one option among six, and for most day-to-day data processing, legitimate interest is actually the more common basis.

Article 7 sets the conditions for when consent specifically is the chosen basis: it must be demonstrable, requested in clear and plain language, separable from other terms, and freely withdrawable at any time. Here's what trips people up: even though legitimate interest can serve as an Article 6 basis for holding someone's data, it does not automatically clear the separate bar for sending them unsolicited electronic marketing. That second bar comes not from GDPR alone but from the ePrivacy Directive and, in the UK, from PECR.

### How PECR and the ePrivacy Directive Layer Extra Rules for Email

The EU's [ePrivacy Directive (2002/58/EC)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02002L0058-20091219) and the UK's implementing regulation, PECR, add marketing-specific rules on top of GDPR. For unsolicited electronic mail to individual subscribers, PECR generally requires prior consent (opt-in) before you can send marketing messages at all, separate from whatever legal basis justifies holding the data. This is why a business can sometimes have a legitimate interest basis for processing a contact's data under GDPR Article 6, yet still be barred from emailing them under PECR because no marketing-specific consent exists.

**Key definitions:**

- **Consent:** a freely given, specific, informed, unambiguous yes, given through a clear affirmative action.
- **Legitimate interest:** an Article 6 legal basis that lets you process data without consent when your interest isn't overridden by the person's rights, but it does not authorize unsolicited email marketing under PECR/ePrivacy rules.
- **Soft opt-in:** a narrow PECR exception letting you email your own existing customers about similar products without fresh consent, covered in detail below.

For the fuller breakdown of how these consent mechanics apply across your whole email program, see [Breaker's guide to GDPR consent rules for email marketing](https://joinbreaker.ai/blog-posts/gdpr-consent-rules-email-marketing).

## Why Generic or Third-Party Consent Doesn't Transfer

List vendors often claim "100% opt-in" or "verified consent." Ask one follow-up question: opted in to hear from whom? If the answer is "our network of partners" rather than your company by name, that consent doesn't apply to you. The specificity requirement in Article 4(11) ties consent to a purpose and a controller, not a category. A person agreeing to receive marketing from Company A doesn't extend that permission to Company B just because Company A sold the data.

### Data Provenance: The Harder Question

Even when a vendor claims consent exists, the critical question is provenance: where did this record originate, when was it collected, and can the vendor produce the original opt-in language and timestamp? Most purchased lists change hands multiple times, get merged with scraped or co-registration data, and lose any audit trail along the way. If a list was compiled by scraping public directories, LinkedIn profiles, or conference badges, no consent exists at all. Under the GDPR accountability principle, the burden of proof sits with you, the sender, not the vendor who sold you the list.

## Real Enforcement Examples

Regulators across Europe have already penalized companies for exactly this pattern: buying or renting lists and emailing people without valid, specific consent.

<div class="table-wrap" style="overflow-x:auto"><table><thead><tr><th>Regulator</th><th>Approximate Fine</th><th>What Happened</th></tr></thead><tbody><tr><td>Spanish DPA (AEPD)</td><td>€70,000</td><td>Penalized a company for sending marketing communications using contact data obtained from third parties without valid consent, tracked in <a href="https://www.enforcementtracker.com/">GDPR enforcement records compiled by CMS Law</a></td></tr><tr><td>French DPA (CNIL)</td><td>€250,000</td><td>Fined a company over unsolicited commercial prospecting emails sent without proper consent verification</td></tr><tr><td>ICO (UK)</td><td>Multiple fines up to £130,000 under PECR</td><td>Issued against organizations for sending unsolicited direct marketing emails and texts without consent, per <a href="https://ico.org.uk/action-weve-taken/enforcement/">ICO enforcement action reports</a></td></tr></tbody></table></div>

These numbers sit well below the headline GDPR maximum, which reaches [up to €20 million or 4% of a company's total worldwide annual turnover, whichever is higher](https://gdpr-info.eu/art-83-gdpr/). That ceiling is reserved for the most serious violations. Purchased-list marketing cases have historically drawn smaller, more targeted fines, but the reputational damage and the cost of a full compliance investigation often outweigh the fine itself.

## B2B Email: Does It Get Special Treatment?

### Named Individual Work Emails vs. Generic Role Addresses

This distinction matters more than most guidance admits, and it's the exact question practitioners argue about in forums: does emailing [sarah.jones@company.com](mailto:sarah.jones@company.com) carry the same restrictions as emailing [info@company.com](mailto:info@company.com)?

Under GDPR, a named individual's work email address is personal data because it identifies a specific natural person, even in a B2B context. A generic role-based address like info@ or sales@ that isn't tied to a named individual generally isn't personal data at all, since it doesn't identify a specific person. That distinction changes GDPR's data protection scope, but it does not fully exempt you from PECR-style marketing consent rules, which in several EU member states still restrict unsolicited commercial email to corporate subscribers.

### Legitimate Interest in B2B Contexts

GDPR itself doesn't carve out a blanket B2B exception, but two things soften the practical risk:

Legitimate interest is easier to justify for relevant B2B outreach. Contacting a marketing director about a marketing tool, where the relationship is professional and the person would reasonably expect this kind of contact, is more defensible under a legitimate interest assessment than cold-emailing a consumer about an unrelated product.

National implementations of the ePrivacy Directive vary for corporate subscribers. Some EU countries apply lighter marketing-consent rules to corporate email addresses than to individual consumers, though the UK's PECR still generally expects either consent or the soft opt-in exception for company recipients.

None of this legitimizes a purchased list outright. Legitimate interest still requires you to run and document a genuine balancing test, and it still doesn't override PECR's separate opt-in expectation for unsolicited marketing in most cases.

<div class="table-wrap" style="overflow-x:auto"><table><thead><tr><th>Factor</th><th>B2C Consent Expectation</th><th>B2B Consent Expectation</th></tr></thead><tbody><tr><td>Legal basis commonly used</td><td>Explicit consent</td><td>Consent or documented legitimate interest</td></tr><tr><td>Purchased list viability</td><td>Essentially never compliant</td><td>Rarely compliant, slightly more defensible with strong relevance and opt-out</td></tr><tr><td>Named individual required?</td><td>Yes</td><td>Yes, if targeting a person rather than a generic inbox</td></tr><tr><td>Opt-out requirement</td><td>Mandatory, immediate</td><td>Mandatory, immediate</td></tr><tr><td>Risk level for purchased lists</td><td>Very high</td><td>High</td></tr></tbody></table></div>

For deeper walkthrough of legitimate list-growth tactics, [Breaker's B2B email list building strategies guide](https://joinbreaker.ai/blog-posts/email-list-building-strategies) covers permission-based growth channels built for exactly this audience.

## The Soft Opt-In Exception: A Loophole for Purchased Lists?

### What Soft Opt-In Actually Covers

PECR includes a narrow exception, often called the "soft opt-in," that lets a business email its own existing customers without fresh explicit consent, provided three conditions all hold: the business collected the contact's details in the course of a sale or negotiation for a sale, the marketing is for the business's own similar products or services, and the person was given a clear, free chance to opt out both at collection and in every subsequent message. [Breaker's explainer on implied consent](https://joinbreaker.ai/blog-posts/what-is-implied-consent) walks through how this exception functions alongside explicit opt-in mechanics.

### Why It Doesn't Apply to Bought-In Lists

Soft opt-in exists specifically for a business's own customer relationship, built on a real transaction or negotiation between that business and that person. A purchased list, by definition, involves no prior relationship between your company and the contact. There was no sale, no negotiation, and no direct interaction. The exception doesn't reach that far, and no reputable compliance source treats it as a workaround for bought-in data. Anyone offering a purchased list as "soft opt-in compliant" is misusing the term.

## How GDPR, PECR, and CAN-SPAM Actually Compare

Marketers running campaigns across the US, UK, and EU often get tripped up assuming one region's rules apply everywhere.

<div class="table-wrap" style="overflow-x:auto"><table><thead><tr><th>Feature</th><th>GDPR (EU-wide)</th><th>PECR (UK)</th><th>CAN-SPAM (US)</th></tr></thead><tbody><tr><td>Default model</td><td>Opt-in required for marketing consent</td><td>Opt-in required, with soft opt-in exception</td><td>Opt-out model; consent not required before first email</td></tr><tr><td>Consent standard</td><td>Freely given, specific, informed, unambiguous</td><td>Aligns with GDPR consent plus marketing-specific rules</td><td>No prior consent needed; must honor opt-out requests</td></tr><tr><td>Purchased lists</td><td>Generally unlawful without specific, named-org consent</td><td>Generally unlawful; ICO explicitly warns against bought-in lists</td><td>Legal to email purchased lists if honesty and opt-out rules are followed</td></tr><tr><td>Unsubscribe requirement</td><td>Must be as easy as giving consent</td><td>Must be included in every message</td><td>Must be honored within 10 business days</td></tr><tr><td>Maximum penalty</td><td>Up to €20 million or 4% of global annual turnover</td><td>Fines issued by ICO, historically up to hundreds of thousands of pounds</td><td>Over $53,000 per violation (email), per the <a href="https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business">FTC's CAN-SPAM guidance</a></td></tr><tr><td>Geographic scope</td><td>Any company processing EU residents' data</td><td>UK-specific implementation of ePrivacy rules</td><td>US-based sends or sends to US recipients</td></tr></tbody></table></div>

This gap trips up global teams consistently: a purchased list might be technically permissible for a US-only campaign under CAN-SPAM's opt-out model, yet be flatly non-compliant the moment a single EU or UK contact is on that same list. For a full side-by-side breakdown of obligations, see [Breaker's GDPR vs. CAN-SPAM compliance rules guide](https://joinbreaker.ai/blog-posts/gdpr-vs-can-spam-email-compliance-rules) and [Breaker's CAN-SPAM requirements primer for B2B marketers](https://joinbreaker.ai/blog-posts/can-spam-act-requirements-b2b-marketers-know).

## Vendor Due Diligence Checklist

If a purchased list still seems worth considering, run the vendor through every item on this checklist before you sign anything:

- Ask for the exact opt-in language shown to the person at the point of collection, word for word.
- Confirm your company is named in that opt-in language, not described as a generic "partner" or "advertiser."
- Request a timestamp for each record showing when consent was captured.
- Ask where the data was originally collected (which website, form, or event) and get it in writing.
- Confirm whether consent was double opt-in or single opt-in, and ask for evidence either way.
- Get a written right-to-audit clause letting you verify consent records on request.
- Ask how many other companies have purchased or licensed the same list.
- Confirm the vendor's own privacy policy actually disclosed third-party resale to the original data subject.
- Check whether any contacts have since withdrawn consent and how that's tracked.
- Get indemnification language in the contract in case the list turns out to be non-compliant.

If a vendor can't produce clear answers to more than one or two of these, walk away. Breaker's own [email list compliance checklist](https://joinbreaker.ai/blog-posts/gdpr-email-list-compliance-checklist) offers a broader audit framework you can apply to any list, purchased or organically grown.

## Compliant vs. Non-Compliant Consent Language: Real Examples

Here's what the difference actually looks like, since vague legal standards get much clearer with real examples.

**Non-compliant (fails the specificity and unambiguous tests):** "By submitting this form, you agree to receive communications from us and our trusted partners." (pre-checked box)

**Compliant:** "[ ] Yes, I'd like to receive product updates and marketing emails from Breaker. You can unsubscribe at any time." (unchecked box, requires active click, names the specific sender)

The compliant version names the exact organization, requires an affirmative action, and makes withdrawal easy to find. If a purchased list's origin story doesn't resemble the compliant example, treat every record on it as unconsented.

## If You Already Purchased a List: Remediation Steps

Mistakes happen, and plenty of well-meaning teams bought a list before understanding the risk. Here's the sequence to run immediately.

**Stop sending immediately.** Pause any active campaign using the list the moment you suspect a consent gap. Continued sending compounds the violation and your exposure.

**Audit the list's consent trail.** Go back to the vendor and request the documentation from the checklist above. If they can't produce it within a reasonable window, assume no valid consent exists.

**Run a re-permission campaign.** For contacts where you have a plausible legitimate interest (for example, an existing lead who engaged with your brand elsewhere), send one clear, honest message asking them to opt in, with no pressure tactics and a clear no-obligation framing. Anyone who doesn't respond affirmatively gets removed.

**Delete non-consenting records.** Anyone who doesn't produce documented, specific consent should be deleted from your database entirely, not just suppressed from sends. GDPR's data minimization principle means you shouldn't retain data you have no lawful basis to hold.

[Breaker's ultimate guide to email list compliance audits](https://joinbreaker.ai/blog-posts/ultimate-guide-to-email-list-compliance-audits) walks through this process in more depth. A professional [email list cleaning service](https://joinbreaker.ai/blog-posts/email-list-cleaning-service) can help you separate genuinely engaged, consenting contacts from records that need to go.

Watching how a practitioner talks through GDPR consent mechanics for email campaigns can clarify these steps faster than reading legal text alone.

<div class="video-embed" style="position:relative;padding-bottom:56.25%;height:0;overflow:hidden"><iframe src="https://www.youtube-nocookie.com/embed/QNFyHstjpSE" title="Embedded video" loading="lazy" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen style="position:absolute;top:0;left:0;width:100%;height:100%;border:0"></iframe></div>

## Maximum Fines and Real-World Enforcement Trends

GDPR Article 83 sets two tiers of maximum fines. Lower-tier violations, which cover many record-keeping and procedural failures, can reach €10 million or 2% of global annual turnover. Higher-tier violations, which include failures of the core principles like lawful basis and consent, can reach [€20 million or 4% of global annual turnover, whichever is higher](https://gdpr-info.eu/art-83-gdpr/). In practice, purchased-list marketing violations have drawn fines in the tens to low hundreds of thousands of euros or pounds rather than headline sums. Regulators have shown a clear willingness to act on this specific violation pattern, and the [European Data Protection Board](https://edpb.europa.eu/) continues to publish guidance reinforcing that consent obtained by one controller cannot simply be inherited by another.

Beyond the fine itself, a formal investigation typically forces a company to produce its entire consent trail for every contact in the disputed list, a process often more expensive in staff time and legal fees than the penalty.

## GDPR-Compliant Alternatives to Buying Email Lists

### Building an Owned, Opt-In List

The durable fix is building a list people actually chose to join. That means gated content with clear opt-in language, event and webinar sign-ups with explicit marketing checkboxes, and referral programs where existing subscribers invite people who already expect to hear from you. [Breaker's B2B growth playbook for building quality email lists fast](https://joinbreaker.ai/blog-posts/how-to-build-quality-b2b-email-lists-fast) and [growing your email list with proven B2B tactics](https://joinbreaker.ai/blog-posts/grow-your-email-list-fast) lay out channel-by-channel approaches that produce consented, engaged contacts instead of legal exposure.

A video walkthrough on pairing GDPR-safe practices with active list-building can help translate this into a weekly routine your marketing team can actually run.

<div class="video-embed" style="position:relative;padding-bottom:56.25%;height:0;overflow:hidden"><iframe src="https://www.youtube-nocookie.com/embed/0s9BqZ40e1k" title="Embedded video" loading="lazy" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen style="position:absolute;top:0;left:0;width:100%;height:100%;border:0"></iframe></div>

### Using Intent-Based and Enrichment Tools Instead of Cold Lists

Instead of buying static lists, many B2B teams now combine intent data, firmographic enrichment, and outbound sequencing tools to identify relevant prospects. You then reach them through channels like LinkedIn outreach or a genuine sales conversation, which don't require blanket email consent up front. Engaged replies later convert into a properly opted-in email relationship. This approach costs more time than a spreadsheet purchase, but it produces a list that survives a compliance audit instead of triggering one.

## Frequently Asked Questions

**Is buying an email list legal under GDPR?** Buying a list isn't illegal by itself, but emailing the people on it almost always is unless you can prove each contact gave specific, informed consent naming your organization as a sender. In practice, that proof rarely exists for purchased data.

**What are the GDPR rules for email marketing?** GDPR requires a valid legal basis for processing contact data (commonly consent or legitimate interest) plus, for unsolicited electronic marketing, a marketing-specific opt-in under PECR or the equivalent national ePrivacy law, unless the narrow soft opt-in exception applies.

**Do you need consent for every marketing email under GDPR?** Not always through the GDPR consent mechanism specifically, since legitimate interest can sometimes serve as the legal basis. But PECR and equivalent ePrivacy rules generally still require either prior opt-in consent or the soft opt-in exception before sending unsolicited marketing email.

**What counts as "specific" consent for a purchased list?** Specific consent must name the exact organization that will send the marketing, not a category like "partners" or "advertisers." Consent given to one company cannot be resold or transferred to authorize marketing from a different company.

**Does legitimate interest ever apply instead of consent for email marketing?** Legitimate interest can serve as the GDPR Article 6 basis for processing certain B2B contact data, particularly when the relationship and content are clearly relevant. But it does not override the separate PECR/ePrivacy requirement for marketing-specific consent in most electronic mail scenarios.

**What is the soft opt-in exception, and does it cover purchased lists?** Soft opt-in lets a business email its own existing customers about similar products without fresh consent, if the data was collected during a sale and an opt-out was offered. It requires a prior direct relationship, so it never covers purchased or third-party lists.

**Can I use a purchased list of B2B work email addresses?** Only if you can verify specific, named-organization consent exists for each contact, which is rare for purchased data. Named individual work emails are still personal data, and generic role addresses carry lower data protection risk but don't resolve the marketing-consent requirement.

**Is a generic email address like** [**info@company.com**](mailto:info@company.com) **treated differently under GDPR?** Yes. A role-based address not tied to an identifiable person generally isn't personal data under GDPR, though marketing-specific consent rules under PECR-style regulations can still apply depending on jurisdiction.

**Is an email address considered personal data under GDPR?** Yes, when it identifies or can identify a specific natural person, which includes most named individual work and personal email addresses.

**How can I verify a purchased list actually has valid consent?** Request the original opt-in wording, the collection timestamp, the collection source, and proof your organization was specifically named at the point of consent. If the vendor can't produce all four, treat the list as non-compliant.

**What questions should I ask a list vendor before buying?** Ask for exact opt-in language, timestamps, original collection source, whether consent was single or double opt-in, how many other buyers received the same data, and whether they'll provide audit rights and contractual indemnification.

**What happens if I email a purchased list without proper consent?** You risk regulatory investigation, fines under GDPR or PECR, spam complaints that damage your sender reputation and deliverability, and reputational harm with recipients who never asked to hear from you.

**How much can a company be fined for GDPR email violations?** Fines can reach up to €20 million or 4% of global annual turnover for the most serious violations, though real-world purchased-list enforcement actions have typically landed in the tens to low hundreds of thousands of euros or pounds.

**Are there real examples of companies fined for using purchased lists?** Yes. European data protection authorities including Spain's AEPD and France's CNIL have issued fines against companies for marketing to contacts obtained from third parties without valid consent. The UK's ICO has issued PECR enforcement notices for unsolicited marketing sent without consent.

**What should I do if I've already sent to a purchased list?** Stop sending immediately, audit the list for any documented consent, run a re-permission campaign for plausible legitimate-interest contacts, and delete every record that lacks specific, verifiable consent.

**How do I run a re-permission campaign?** Send a single, clear message asking recipients to actively opt in to future communications. Explain why they're hearing from you, avoid pressure tactics, and automatically remove anyone who doesn't respond affirmatively within a defined window.

**Do GDPR and PECR have different rules for purchased lists?** GDPR sets the general consent standard and legal bases for processing. PECR adds the UK-specific requirement that unsolicited electronic marketing needs prior consent or a qualifying soft opt-in. Both effectively block most purchased-list marketing, just through slightly different legal mechanisms.

**How does GDPR differ from CAN-SPAM regarding purchased lists?** CAN-SPAM in the US permits marketing to purchased lists as long as messages are honest and include a working opt-out, since it's an opt-out model. GDPR and PECR require opt-in consent before sending, making purchased lists far riskier for any campaign touching EU or UK residents.

**Can I share or sell my own email list to another company?** Only if your original opt-in language specifically told subscribers their data might be shared with or sold to third parties. Even then the receiving company still needs its own valid basis to market to those contacts.

**How long does consent remain valid before it goes stale?** GDPR doesn't set a fixed expiration date, but the [ICO recommends reviewing consent periodically](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/electronic-and-telephone-marketing/using-marketing-lists/). Most compliance teams treat consent older than 24 months as needing refresh, especially if engagement has dropped.

**What records must I keep to prove valid consent?** Keep the exact wording shown at collection, the date and time consent was given, the method of collection (web form, event, etc.), and any subsequent withdrawal requests, all retrievable on demand.

**Does double opt-in fully satisfy GDPR consent requirements?** Double opt-in, which requires a confirmation click after the initial signup, provides strong evidence of consent and is widely recommended. But it satisfies GDPR only if the original signup language was itself specific, informed, and unambiguous. Confirming a vague or misleading original request doesn't fix the underlying problem.

## The Bottom Line

Purchased lists almost never meet GDPR's specific-consent standard, because consent tied to one organization can't transfer to another. Consent must be freely given, specific, informed, and unambiguous, backed by a genuine affirmative action. PECR and the ePrivacy Directive add marketing-specific opt-in rules on top of GDPR's general legal basis framework.

Named individual work emails count as personal data; generic role addresses carry lower risk but don't solve the marketing-consent problem. Soft opt-in only covers your own existing customers, never third-party or bought-in contacts. Fines for purchased-list violations have reached into the hundreds of thousands of euros or pounds, with GDPR's theoretical ceiling at 4% of global turnover.

If you've already bought a list, stop sending, audit the consent trail, run a re-permission campaign, and delete anyone without documented consent. The lasting fix is owned, opt-in list growth paired with strong [list hygiene practices](https://joinbreaker.ai/blog-posts/email-list-hygiene-best-practices) rather than repeated list purchases.

Building a list the right way takes longer than a data broker invoice, but it's the only version that survives an audit, a regulator inquiry, or a simple spam complaint. Every subscriber who opted in because they wanted to hear from you specifically is worth more, in deliverability and in trust, than ten thousand names bought at a discount.

## Sources

- [ICO: Using Marketing Lists (Guide to PECR)](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/electronic-and-telephone-marketing/using-marketing-lists/)
- [ICO: Enforcement Action Reports](https://ico.org.uk/action-weve-taken/enforcement/)
- [GDPR Article 4: Definitions (gdpr-info.eu)](https://gdpr-info.eu/art-4-gdpr/)
- [GDPR Article 7: Conditions for Consent (gdpr-info.eu)](https://gdpr-info.eu/art-7-gdpr/)
- [GDPR Article 83: General Conditions for Imposing Administrative Fines (gdpr-info.eu)](https://gdpr-info.eu/art-83-gdpr/)
- [ePrivacy Directive 2002/58/EC (EUR-Lex)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02002L0058-20091219)
- [European Data Protection Board](https://edpb.europa.eu/)
- [FTC: CAN-SPAM Act Compliance Guide for Business](https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business)
- [GDPR Enforcement Tracker (CMS Law)](https://www.enforcementtracker.com/)
