US: CAN-SPAM
CAN-SPAM does not prohibit buying email lists. It regulates how you send:
- Include your physical mailing address.
- Provide a working unsubscribe link.
- Use accurate sender information (no misleading "From" names).
- Honor opt-out requests within 10 business days.
- Don't use deceptive subject lines.
As long as your emails comply with these requirements, sending to a purchased B2B list is legal in the US.
EU & UK: GDPR
GDPR is stricter but does allow B2B cold email under "legitimate interest" (Article 6(1)(f)):
- You must have a legitimate business reason to contact someone (e.g., your product is relevant to their role).
- You must be transparent - explain how you got their data if asked.
- You must provide an easy way to opt out.
- The person must have a reasonable expectation of being contacted in a business context.
GDPR applies to the individual, not the company. Business email addresses (name@company.com) are treated differently from personal emails in many EU member states.
Canada: CASL
Canada's Anti-Spam Legislation (CASL) is the strictest major framework:
- Generally requires prior express or implied consent before sending.
- Implied consent exists if you have a pre-existing business relationship (e.g., they bought from you in the last 2 years).
- Cold emailing without consent is riskier under CASL than under CAN-SPAM or GDPR.
Best practices for purchased lists
- Use verified data - buy from sources that validate email addresses. Sending to invalid addresses damages your domain reputation regardless of legality.
- Include unsubscribe links - required by all major frameworks.
- Be transparent - if someone asks how you got their email, have a clear answer.
- Honour opt-outs immediately - this is both a legal requirement and a reputation issue.
- Focus on business relevance - your email should be relevant to the recipient's role. This is both a legal best practice and a conversion best practice.
The legality question is usually the wrong concern. The real question is data quality: are the emails valid, are the companies a fit, and will your outreach be relevant? Bad data creates legal risk (bounces, complaints) even when the purchase itself is legal.
How port587 handles compliance
- Business-only data - only B2B company and professional contact information.
- Email verification - all emails are validated before export.
- Suppression support - contacts can request removal; processed within 72 hours.
- Data minimisation - only data relevant to B2B outbound is collected.
Read more in our Data Specification.
Create a free account to explore the dataset.