Scraped email lists break GDPR Articles 6 & 7, risk €20M fines, and get your ESP account suspended. Learn the legal reality and the compliant path forward.

Scraped email lists violate GDPR. Under GDPR Articles 6 and 7, marketing emails require both a valid lawful basis and explicit consent from each recipient. Scraped contacts never consented to hear from you, which means no lawful basis exists - making their use illegal for email marketing regardless of your email service provider (ESP).
The consequences are severe. Fines reach €20 million. Domain blacklisting destroys sender reputation that took years to build. And in 2026, every major ESP enforces upload restrictions on top of the law itself. If you have been offered a scraped list or already hold one, this guide explains the legal reality, practical risks, and the compliant path forward.
Email scraping is the automated collection of email addresses from websites, directories, LinkedIn, or any publicly accessible source using bots or harvesting tools - without the knowledge or agreement of the people whose addresses are collected. This is different from buying a list (where a vendor claims to have collected addresses) and entirely different from an opt-in list (where each subscriber actively chose to hear from you).
Scraping tools crawl public websites, LinkedIn profiles, online directories, and event pages to extract any string that looks like an email address. Tools like Hunter.io can harvest thousands of addresses per hour and save them to a spreadsheet or database for bulk email import.
The defining problem: the person whose address was collected had no interaction with you whatsoever. They did not fill out a form. They did not click anything. They did not even know their address was being harvested.
| Dimension | Scraped List | Purchased List | Opt-In List |
|---|---|---|---|
| Consent obtained | Never | Rarely (vendor claims vary) | Yes - by the subscriber |
| Lawful basis available | None | None without audit trail | Consent or contract |
| GDPR-compliant | No | Almost never | Yes, when documented |
| ESP acceptance | Rejected or account suspended | Rejected or account suspended | Accepted |
| Expected hard bounce rate | 15-40% | 10-25% | Under 2% |
| Legal exposure | High - fines up to €20M | High - fines up to €20M | Low, when managed correctly |
| Average open rate | Under 5% | Under 8% | 20-35% (industry average) |
Purchased lists deserve a clarification. Vendors who sell email data sometimes claim their lists are "GDPR-compliant." This is almost never verifiable. GDPR Article 7 requires your organisation to produce proof that the specific individual consented to receive communications specifically from you. A vendor's consent record for a third-party newsletter doesn't transfer to your campaigns.
GDPR Article 6 lists exactly six lawful bases for processing personal data. You need one. With scraped lists, you have none.
| Lawful Basis | What It Requires | Why It Fails for Scraped Lists |
|---|---|---|
| Consent | Freely given, specific, informed, unambiguous agreement | The data subject never interacted with you - no consent exists |
| Contract | Processing necessary to fulfil a contract with the data subject | No contract exists with strangers whose addresses were harvested |
| Legal obligation | Processing required by law | Marketing emails are never legally mandated |
| Vital interests | Processing necessary to protect life | Clearly inapplicable to commercial email |
| Public task | Processing for an official government function | Inapplicable to private commercial email marketing |
| Legitimate interests | Legitimate purpose, necessary processing, rights of data subject don't override | Almost always fails the balancing test for unsolicited marketing |
The ICO's guidance on lawful basis confirms that you must identify a lawful basis before you begin processing - not after. Scraping and then looking for a justification puts you in violation from the moment data collection starts.
GDPR Article 7 sets strict conditions for valid consent. It must be:
Scraping satisfies none of these requirements. The data subject was never presented with a choice. They never saw your brand name. The burden of proof rests entirely with you, and with scraped data, that proof is impossible. The European Data Protection Board guidelines on consent are explicit: silence, pre-ticked boxes, and inactivity do not constitute consent.
A widespread belief holds that work email addresses are "less personal" than personal inboxes and therefore less protected under GDPR. This is wrong. GDPR applies to any information relating to an identified or identifiable natural person, and a named work email address (john.smith@company.com) qualifies as personal data.
Legitimate interest under Article 6(1)(f) requires three things: a legitimate purpose, a necessity test (is processing actually necessary?), and a balancing test (do your interests override the individual's rights?). GDPR Recital 47 mentions direct marketing as a potentially legitimate interest but notes that the rights of data subjects must be carefully weighed.
For unsolicited cold email to scraped addresses, the balancing test nearly always fails. The recipient had no reasonable expectation of being contacted. There is no prior relationship. There is no genuine relevance guarantee. A legitimate interest assessment (LIA) - the documented analysis every organisation must complete before relying on this basis - will expose this weakness immediately.
The ePrivacy Directive (2002/58/EC) adds another layer. It governs electronic communications and applies alongside GDPR. For unsolicited commercial email, the ePrivacy Directive requires prior consent - full stop. Even if you somehow constructed a legitimate interest argument under GDPR, the ePrivacy Directive overrides it for email marketing. There is no B2B exception.
GDPR Articles 13 and 14 require that data subjects be informed - at the point of collection or as soon as practicable - of who is processing their data, the lawful basis, the purposes, and their rights. With a scraped list, you cannot notify thousands of people at the point of collection because you were never in contact with them. Sending a "privacy notice" email to a scraped list is itself a GDPR violation: you are processing personal data without a lawful basis.
Every reputable ESP - including Acumbamail, Mailchimp, Brevo, ActiveCampaign, and HubSpot - prohibits scraped or purchased list uploads in their Terms of Service. This is not just gesture toward GDPR. ESPs share sending infrastructure, IP pools, domains, and relationships with mailbox providers like Gmail and Outlook. When one customer sends to a scraped list and triggers spam complaints, the damage spreads to other senders on the same infrastructure.
ESPs catch violations through list quality checks on import (suspiciously uniform domains, high-risk address patterns, known spam trap addresses), real-time bounce threshold monitoring (accounts that spike bounce rates after import get flagged), engagement analysis (sends to contacts with zero prior engagement trigger automated review), and account suspension (repeated violations result in termination).
The consequences of sending to a scraped list follow a cascade that is difficult and expensive to reverse:
No monitoring tool repairs reputation damage caused by a scraped list send. Prevention is the only strategy.
GDPR operates a two-tier fine structure:
Scraped list usage typically triggers Tier 2 violations (Articles 5, 6, and 7). Enforcement authorities across Europe include:
| Authority | Jurisdiction | Notable Focus |
|---|---|---|
| ICO | United Kingdom | Direct marketing, email lists, subject access |
| CNIL | France | Consent standards, cookie enforcement, B2B email |
| AEPD | Spain | Spam enforcement, consent documentation |
| DPC | Ireland | Major tech platforms, cross-border cases |
Enforcement cases confirm this is not theoretical. The French CNIL has fined companies for sending unsolicited marketing emails without valid consent. The AEPD regularly issues fines for B2B spam campaigns relying on purchased or harvested data. The ICO published detailed direct marketing guidance explicitly identifying scraped list usage as a serious violation. Enforcement of email data violations is active and growing in 2026.
GDPR is not the only law that scraped email lists violate. If your list includes US recipients, the CAN-SPAM Act applies. CAN-SPAM requires:
CAN-SPAM does not require prior consent for commercial email, but it does require honoured opt-outs, and sending to scraped lists makes consistent opt-out management practically impossible. Penalties reach $53,088 per email in violation under FTC enforcement.
The California Consumer Privacy Act (CCPA) adds another layer: any Californian whose data was scraped without disclosure has rights to know, delete, and opt out of the sale of their personal information. At scale, your scraped list almost certainly includes Californian residents, exposing you to CCPA liability alongside GDPR.
Canada's CASL (Canada's Anti-Spam Legislation) goes further than GDPR. It requires express consent before sending commercial electronic messages to Canadian recipients, with fines up to CAD $10 million per violation.
Is email harvesting illegal?
Email harvesting for marketing purposes is illegal throughout the European Union and United Kingdom under GDPR and the ePrivacy Directive. In the US, it does not require prior consent under CAN-SPAM, but using harvested addresses violates CAN-SPAM if unsubscribe requests are not honoured. In Canada, it is prohibited under CASL without express consent.
Can I use a mailing list with GDPR?
Yes - but only under specific conditions. The list must have been built with documented, freely given, specific, informed, and unambiguous consent from each subscriber, or another valid lawful basis under Article 6 must exist. Every subscriber must have been informed of who is collecting their data and why. You must produce consent records on request and process unsubscribe requests promptly.
Is sharing email addresses a breach of GDPR?
Sharing email addresses with a third party breaches GDPR when the data subjects did not consent to that transfer, or when no other lawful basis exists. Selling or transferring an email list to another organisation without the subscribers' knowledge violates the purpose limitation principle in Article 5(1)(b) and exposes both parties to regulatory action.
What if I have already sent campaigns to a scraped list?
Stop sending immediately. Document what data you held and what was sent. Delete the list. Consult your Data Protection Officer or legal counsel about whether a breach notification to your supervisory authority is required. Then build a fresh, compliant list from scratch using opt-in methods.
Can I use legitimate interest as a basis for emailing a scraped list?
Almost certainly not. Legitimate interest under Article 6(1)(f) requires a documented balancing test showing your interests outweigh the data subject's rights. For cold, unsolicited email to people with no prior contact with your brand, this test fails. The ePrivacy Directive also requires prior consent for marketing emails in the EU, overriding any GDPR legitimate interest argument.
What is the penalty for sending emails to a scraped list under GDPR?
Violations of Articles 5, 6, and 7 - which scraped list usage breaches - fall under Tier 2 fines: up to €20 million or 4% of global annual turnover, whichever is higher. Supervisory authorities can also order you to stop processing and delete the data.
Does GDPR apply to B2B email marketing?
Yes. Work email addresses are personal data under GDPR when they identify a natural person. There is no B2B exemption. The ePrivacy Directive requires prior consent for unsolicited commercial email to business addresses in most EU member states.
Will Acumbamail allow me to upload a scraped email list?
No. Acumbamail's Terms of Service prohibit the import of scraped or purchased lists lacking proper consent documentation. Attempting to upload such a list may result in account suspension.
What is the difference between a scraped list and a purchased list?
A scraped list is assembled by automated tools harvesting addresses from public sources without the owners' knowledge. A purchased list is bought from a vendor who may claim to have collected consent - but that consent is almost never transferable to your organisation under Article 7. Both are non-compliant for the same core reason: no valid lawful basis exists for your use of the data.
Can I use a LinkedIn-scraped contact list for email marketing?
No. Scraping LinkedIn violates LinkedIn's Terms of Service and produces data with no GDPR lawful basis for marketing email. Even LinkedIn's own data export feature requires a valid lawful basis and transparency obligations for outbound marketing.
This is the question most guides avoid. Here is the remediation path.
Step 1 - Stop sending immediately. Halt all campaigns to the list. Every additional email increases your legal exposure and deepens deliverability damage.
Step 2 - Audit and document. Record exactly what data you hold, where it came from, how it was collected, and whether any lawful basis was ever established. This documentation is relevant if a supervisory authority investigates.
Step 3 - Delete the list. GDPR Article 17 (right to erasure) requires deletion when there is no lawful basis for retention. Without a valid basis, you must delete the list - not archive it. Use a list cleaning service for verified opt-in data, not to rehabilitate a scraped list.
Step 4 - Notify your DPO or legal counsel. If you sent campaigns to the scraped list, this likely constitutes unlawful processing. Your Data Protection Officer must be informed. In some circumstances, breach notification to your supervisory authority may be required within 72 hours.
Step 5 - Build a clean list. Deleting the scraped list is the beginning of a compliant growth strategy, not the end.
Double opt-in works in two stages: a user submits their email address, then receives an automated confirmation email they must click to verify their intent. Only after that confirmation are they added to your active list.
This approach produces the clearest consent record available. You have a timestamp, an IP address, and a verified action - all of which constitute documented proof Article 7 requires. Here is how to set it up:
Offering genuine value in exchange for an email address - a PDF guide, a template, a data report - is one of the most reliable organic list-building methods. The subscriber self-selects because they want the content. Be explicit that subscribing to a mailing list is part of the exchange. Do not bury consent language in small print. Deliver the promised content immediately to reinforce the subscriber relationship. Segment subscribers by the lead magnet they downloaded to send relevant follow-up.
Organic social content drives traffic to a landing page with a clear opt-in form. This is a compliant conversion path when the landing page presents a specific, honest consent statement, the form uses a positive opt-in action (not a pre-ticked box), the confirmation email is sent immediately, and the subscriber can unsubscribe from the first email onward.
B2B marketers often have the most legitimate-sounding excuses for scraping - and the most to lose if caught. Compliant B2B list building includes:
A well-planned B2B strategy built on inbound acquisition consistently outperforms any scraped list on open rates, click-through rates, and long-term subscriber value.
Acumbamail includes tools that support GDPR-compliant list management:
What Acumbamail's GDPR features do not protect you from is importing a scraped or purchased list. The platform's compliance tools help you manage consented subscribers correctly. Uploading scraped data bypasses the entire consent architecture and places you in immediate violation.
Use this before every campaign send. All boxes must be checked:
Last reviewed: September 2026. This article reflects GDPR enforcement guidance current as of that date and will be updated annually.
Build a B2B newsletter that drives real pipeline. Covers audience definition, content structure, frequency, deliverability, and ROI measurement.
Every B2B newsletter eventually runs into the same wall: content is going out reliably, the format works, and the list still isn't growing fast enough.
Learn what email open rate really measures, how to calculate it, what a good benchmark looks like, and the tactics that actually lift opens in 2026.