Home › Blog › Buying Email Lists in 2026: Is It Legal, What It Costs & How to Buy Safely
|
Getting your Trinity Audio player ready...
|
Ask a room of marketers whether buying an email list is legal, and you will hear two confident answers: “Of course it is” and “Absolutely not.” Both are wrong, and the space between them is where domains get blocklisted, sending accounts get suspended, and regulators start writing letters.
The honest answer in 2026 is that buying an email list is not one decision. It is five. Acquiring the data, holding it, emailing the people in it, sending through your platform, and landing in the inbox are each judged by a different rulebook. A list can clear the first and fail the other four.
The short answerBuying email lists is not automatically legal or illegal. In the US, federal law allows commercial email without opt-in if every message follows CAN-SPAM. The UK, EU, Canada and Australia generally require consent that a purchase cannot create. Deliverability and platform rules add risk even where the law allows outreach.
This guide walks through all five decisions: what the law says in the US, UK, EU, Canada and Australia, what lists really cost once you count everything, and the questions that separate usable prospect data from a liability with a .csv extension.
Buying an email list is neither universally legal nor universally illegal. It is a chain of five separate permissions, and your campaign is only as safe as the weakest one.
Most articles on this topic answer one question, usually “Is it legal under CAN-SPAM?”, and stop there. That is how teams end up with a list their lawyer approved, their email platform bans, and Gmail quietly routes to spam. Before you evaluate a vendor or a price, map the purchase against all five clearances.
The Five Clearances: every gate must pass before a purchased list is safe to use
What decides the outcome at each gate is rarely the list itself. It is where each recipient is located; whether they are a consumer, a sole trader or an employee of an incorporated company; how the seller collected the data; and whether any consent the seller claims actually extends to you.
That last point catches more buyers than any other. Consent is not a transferable asset. In stricter regimes, an “opt-in” that a seller collected for its own purposes, or for unnamed “trusted partners”, usually does nothing for the buyer.
Keep the five clearances in mind as we go region by region, because the law only covers the first three.
The US is the only major market where federal law does not require opt-in before commercial email. Almost everywhere else, a purchase does not create the consent you need to send.
How strict is each market about consent before commercial email?
| Region | Opt-in generally required before commercial email? | What it means for a bought list | Main rules |
|---|---|---|---|
| United States | No federal opt-in requirement | Usable only if every send complies with CAN-SPAM; suppression and state privacy duties still apply | CAN-SPAM, state privacy and data-broker laws |
| United Kingdom | Yes for individual subscribers, unless an exception applies | Bought-in consent must name you and the channel; the soft opt-in is not available | PECR, UK GDPR |
| European Union | Varies by country under ePrivacy; GDPR always applies | Needs a lawful basis to process and compliance with national e-marketing rules | GDPR, ePrivacy Directive, national laws |
| Canada | Yes, consent-based | Buying a list does not create consent | CASL |
| Australia | Yes, consent-based | A third-party source does not remove your obligation | Spam Act 2003 |
A simplification, of course. Recipient type and the facts of your campaign can change the answer in every row.
What getting it wrong can cost: penalties and enforcement cited in this guide
The FTC’s CAN-SPAM compliance guide is clear on two points marketers often get backwards. The law covers all commercial messages, not only bulk email, and it makes no exception for B2B. It also does not generally require recipients to opt in first.
A US campaign to purchased contacts can therefore be lawful, provided every message uses accurate header and routing information, avoids deceptive subject lines, identifies itself as an ad where required, includes a valid postal address and a clear opt-out, and honors opt-outs promptly. You are also responsible for any agency or partner sending on your behalf.
The FTC flags a risk specific to bought lists: they can contain people who have already unsubscribed from you. Scrub every purchased file against your own suppression list before the first send. Each violating email can carry a penalty of up to $53,088.
California raises the stakes for 2026. Under the Delete Act, registered data brokers had to begin accessing the state’s Delete Request and Opt-out Platform (DROP) from August 1, 2026, at least once every 45 days, and process the deletion requests it returns (California Privacy Protection Agency). If your vendor sells California consumer data, ask whether it is registered and how deletions flow down to your copy of the file.
The ICO’s electronic mail marketing guidance, updated on April 28, 2026 to reflect the Data (Use and Access) Act 2025, sets a high bar for bought-in lists. Valid consent has to name your organization, not just “selected partners”, cover email specifically, and be recorded so you can show who agreed, when and how.
The soft opt-in will not rescue you either. It depends on collecting details directly from the person, which a purchased list never does.
The nuance B2B teams need: PECR treats corporate subscribers differently from individuals, sole traders and some partnerships, so emailing a limited company is not judged like emailing a consumer (ICO B2B marketing guidance). UK GDPR still applies to a named employee’s work address, though. Enforcement is active, too: in May 2026, the ICO fined KRA Consultancy Ltd £300,000 for sending more than 5.5 million unsolicited marketing texts (ICO enforcement notice).
GDPR governs whether you can process the personal data. The ePrivacy Directive, implemented differently in each member state, governs whether you can send electronic marketing. You have to pass both.
On third-party data, the European Commission says the original collection and your intended reuse must both be compatible with GDPR. Where the seller relied on consent, that consent should have contemplated passing the data to other organizations for their own marketing. Legitimate interests can sometimes support processing, but they do not override a national rule that requires consent to send.
That is why “GDPR allows cold email under legitimate interest” is a dangerous shortcut. It answers the processing question and skips the sending one.
Canada’s Anti-Spam Legislation requires consent, sender identification and a working unsubscribe for commercial electronic messages (CRTC FAQ). Buying a contact file does not establish express or implied consent for you. Penalties reach CAD $1 million per violation for individuals and CAD $10 million for organizations, and the CRTC’s March 2026 enforcement update signals that it now expects mature compliance.
The ACMA requires consent before commercial email, plus accurate sender details and a functional unsubscribe. A vendor’s assurance that contacts are “business leads” or “publicly available” does not shift responsibility away from you. In March 2026, Lululemon Athletica Australia paid a AUD $702,900 penalty after more than 370,000 commercial emails went out without a way to unsubscribe (ACMA). That case did not involve a bought list, but it shows how strictly the basics are enforced.
There is no single market rate for an email list, because “email list” now describes at least five different products with five different pricing models.
When someone quotes you a price per thousand, the first question is: a thousand what? A one-off CSV, a year of platform access, and a custom-built enterprise file are not comparable purchases, even if each ends in a spreadsheet of names and addresses.
| What you are buying | How it is usually priced | What to watch |
|---|---|---|
| One-off bulk CSV list | Flat fee or per thousand records | Often cheapest up front, and often weakest on source, age and verification |
| List rental | Per send or per thousand impressions | You never own or see the addresses; the list owner sends for you |
| Pay-per-contact credits | Per credit, often bundled into monthly or annual plans | Credits may expire, so check exactly what one credit unlocks |
| Seat-based sales intelligence | Per user per month, with credit allowances | Credits often cover other actions, so cost per email is not the real price |
| Custom B2B data build | Quoted per project or annual license | Highest ceiling, but it should include sourcing documentation and replacement terms |
Published 2026 pricing from two widely used prospecting platforms illustrates the spread.
One credit-based platform charges $99 a month for 170 contacts or $199 a month for 400 on monthly plans, falling to about $74 and $149 a month when billed annually, with larger yearly allowances. Worked through, that lands between roughly $0.37 and $0.58 per contact, or about $373 to $582 per 1,000 records, with extra credits at around $0.50 to $0.60 each.
A seat-based platform comes in far lower on paper, at roughly $20 per 1,000 credits across its paid tiers. But those credits also pay for other features, so the figure reflects subscription economics, not the price of a standalone list.
Effective cost per 1,000 records on published 2026 plans (USD)
These figures come from vendors’ public pricing pages as observed in October 2026 and change often. Treat them as a range, not a quote.
Expect the quote to rise or fall with:
A list that costs half as much but bounces three times as often is not cheaper. Count verification tools, enrichment, suppression management, email infrastructure, legal review, and the hardest line item to price: damage to a sending domain you spent years warming.
The sticker price is the smallest cost you will pay for a bad list.
Want to see what cost per usable contact looks like for your own segment? Ask LakeB2B for a sample file built to your exact targeting criteria, then test match rates and bounces before you commit to any volume. If your needs are narrower than a standard file, our industry-specific data lists are a useful starting point.
Your sender reputation is an economic asset, and a poor list can spend it faster than any regulator could fine you.
Clearances four and five have nothing to do with statute law. They are run by the companies that carry and accept your email, and in 2026 their thresholds are tight.
Google’s email sender guidelines ask all senders to keep user-reported spam rates below 0.10% and never to reach 0.30%. Anyone sending 5,000 or more messages a day to Gmail accounts must also have SPF, DKIM and DMARC in place, valid forward and reverse DNS, TLS, properly formatted messages, and one-click unsubscribe on marketing mail.
Yahoo’s sender best practices require the same authentication trio, a visible and easy unsubscribe, prompt handling of opt-outs, and complaint rates below 0.3%.
Put those numbers next to a list nobody asked to receive. At 0.3%, just three complaints in every thousand delivered emails puts you in the danger zone, and a cold, unfamiliar audience can reach that on a single send.
User-reported spam rate: where Gmail and Yahoo draw the lines
Spamhaus strongly discourages purchased and rented lists on the grounds that permission does not transfer. The damage it describes compounds:
A list can be lawful to email in one country and still break your email service provider’s rules. Mailchimp, for example, prohibits third-party lists outright, including purchased, rented and scraped addresses. Many sales engagement tools have similar clauses, and breaking them can mean a suspended account in the middle of a campaign.
A verified email is a deliverable address, not a permission to send. Verification partly answers clearance five. It says nothing about clearances one to four.
Buying safely does not mean finding a list you can blast. It means reducing legal, data-quality and deliverability risk before a single record lands in your CRM.
A reputable vendor will answer every question below in writing, and quickly. Hesitation on any of them tells you more than a glossy sales deck.
Walk away, or at least slow right down, if you hear any of these:
These are the same questions we expect buyers to put to LakeB2B. Bring this checklist to your next vendor call, ask for the answers in writing, and see who responds without flinching. If you want a benchmark to compare against, put the ten questions to our data team. For a wider view of the market, see our ranking of US email list providers by accuracy, coverage and compliance.
Even a well-sourced list can hurt you if it goes out all at once to every address. Treat launch as a controlled test, not a broadcast.
Once the data has passed vendor due diligence, work through these steps in order:
A static purchased list is only one route to new contacts, and often not the strongest. Compare it with:
A high-quality list is not merely verified. It is relevant, current, legally usable, suppressible, documented at the source, and compatible with the platform you send from.
B2B teams will keep using third-party data in 2026. The ones that win treat it as intelligence to be governed, not a list to be blasted.
Read the Five Clearances again and a pattern appears. Almost every risk in this guide traces back to something a buyer could not see: where the data came from, how old it was, whether opt-outs had been applied, and what it was licensed for. Cheap lists stay cheap by hiding those answers. Good data makes them easy to find.
That is the gap LakeB2B was built to close. Rather than selling static files, LakeB2B works as a B2B data intelligence partner, supplying verified B2B contact and company data with accuracy often around 95 to 98%, segmented by geography, industry, job function and company size. That covers everything from healthcare email lists to technology buyers, delivered with the sourcing and verification detail you need to make your own compliance decisions. It also plugs into the safer routes above, from enriching the CRM you already own to building account-based contact maps around your target companies.
Compliance still sits with the sender, and no vendor can make a campaign lawful on your behalf. What the right partner can do is give you the visibility to make that call with confidence.
Ready to pressure-test your next list? Request a free sample from LakeB2B built to your targeting criteria, run it through the ten vendor questions, and check the results before you spend a dollar on volume.
Generally, yes. Federal CAN-SPAM law does not ban buying contact data or require opt-in before commercial email. Every message must still use accurate headers, honest subject lines, a postal address and a working opt-out, and you must honor unsubscribes. State privacy and data-broker laws, such as California’s Delete Act, can add further obligations.
Sometimes. It depends on where recipients are located, whether they are corporate or individual subscribers, how the data was sourced, and whether you hold a valid consent or legal basis. US corporate outreach is often possible under CAN-SPAM, while the UK, EU, Canada and Australia set much stricter conditions. Your email platform’s rules also apply.
Not automatically. GDPR regulates how personal data is processed, so you need a lawful basis, transparency and a way to honor rights such as objection and deletion. Sending marketing email is governed separately by the ePrivacy Directive and national laws, which often require consent. A purchased list has to satisfy both sets of rules.
No. Verification confirms that an address exists and is likely to accept mail, which helps deliverability. It does not prove consent, establish a lawful basis or give you permission to market. Treat verification as a data-quality check, and handle legal and platform requirements as separate steps in your buying process.
Prices vary by product. Public 2026 pricing from one credit-based prospecting platform works out to roughly $0.37 to $0.58 per contact, while one-off bulk lists can be cheaper and custom builds are usually quoted per project. Compare cost per usable contact, including verification, suppression and deliverability risk, rather than headline price.
No. Mailchimp’s published audience requirements prohibit third-party lists, including purchased, rented and scraped addresses, even where local law might allow the outreach. Uploading one risks account suspension. Many other email and sales engagement platforms have similar clauses, so read your provider’s acceptable use terms before buying any third-party contact data.
For most B2B teams, it is damage to sender reputation rather than the purchase price. Bounces, spam complaints and spam-trap hits can push you past Gmail’s 0.3% complaint threshold, trigger blocklisting and reduce inbox placement for every email you send, including messages to existing customers. The effects can outlast the campaign that caused them.
A note on legal advice. This article is educational information, not legal advice. Anti-spam and privacy rules apply differently depending on the recipient, the data source, the message content, your company’s location and how you target. For high-volume or international campaigns using third-party personal data, get a qualified privacy or legal review before launch.
About LakeB2B. LakeB2B is a B2B data intelligence company that helps sales and marketing teams reach the right buyers with verified contact and company data, data appending and account-based marketing support.
LakeB2B helps you find, enrich, and connect with verified B2B contacts using accurate data, intent signals, and audience intelligence so your sales and marketing teams can reach the right decision-makers with confidence.
Achieve Greater Transparency and Enhanced Visibility in Reaching and Engaging with Ideal Customers
Submit the form below and our team will contact you.
September 02, 2026 / 16 min read
By: Martin Mosses
August 17, 2026 / 22 min read
By: Bryan Scott
July 15, 2026 / 13 min read
By: William Shepherd