port587/Docs

Is Buying B2B Email Lists Legal?

Short answer

Yes, buying B2B email lists is legal in most jurisdictions. The US (CAN-SPAM), EU (GDPR), and UK each have different rules, but none prohibit purchasing business contact data outright. What's regulated is how you use the data - not how you acquired it.

Last updated: March 2026


US: CAN-SPAM

CAN-SPAM does not prohibit buying email lists. It regulates how you send:

  • Include your physical mailing address.
  • Provide a working unsubscribe link.
  • Use accurate sender information (no misleading "From" names).
  • Honor opt-out requests within 10 business days.
  • Don't use deceptive subject lines.

As long as your emails comply with these requirements, sending to a purchased B2B list is legal in the US.


EU & UK: GDPR

GDPR is stricter but does allow B2B cold email under "legitimate interest" (Article 6(1)(f)):

  • You must have a legitimate business reason to contact someone (e.g., your product is relevant to their role).
  • You must be transparent - explain how you got their data if asked.
  • You must provide an easy way to opt out.
  • The person must have a reasonable expectation of being contacted in a business context.

GDPR applies to the individual, not the company. Business email addresses (name@company.com) are treated differently from personal emails in many EU member states.


Canada: CASL

Canada's Anti-Spam Legislation (CASL) is the strictest major framework:

  • Generally requires prior express or implied consent before sending.
  • Implied consent exists if you have a pre-existing business relationship (e.g., they bought from you in the last 2 years).
  • Cold emailing without consent is riskier under CASL than under CAN-SPAM or GDPR.

Best practices for purchased lists

  1. Use verified data - buy from sources that validate email addresses. Sending to invalid addresses damages your domain reputation regardless of legality.
  2. Include unsubscribe links - required by all major frameworks.
  3. Be transparent - if someone asks how you got their email, have a clear answer.
  4. Honour opt-outs immediately - this is both a legal requirement and a reputation issue.
  5. Focus on business relevance - your email should be relevant to the recipient's role. This is both a legal best practice and a conversion best practice.

The legality question is usually the wrong concern. The real question is data quality: are the emails valid, are the companies a fit, and will your outreach be relevant? Bad data creates legal risk (bounces, complaints) even when the purchase itself is legal.


How port587 handles compliance

  • Business-only data - only B2B company and professional contact information.
  • Email verification - all emails are validated before export.
  • Suppression support - contacts can request removal; processed within 72 hours.
  • Data minimisation - only data relevant to B2B outbound is collected.

Read more in our Data Specification.

Create a free account to explore the dataset.

Try the database yourself

Search, filter, and export verified B2B SaaS companies. Free account, no commitment required.

Create free account →