Email list monetisation

Is it legal to monetise an email list?

Yes, monetising an email list is legal in the UK, EU and US, provided you have a lawful basis to contact each recipient, you can prove it, and every send meets the disclosure and unsubscribe requirements of the relevant law. In the UK and EU that mostly means UK GDPR plus PECR; in the US it means CAN-SPAM. This is general information, not legal advice; check with a qualified adviser for your situation.

UK and EU: UK GDPR and PECR

Marketing emails to individuals in the UK and EU generally require prior, freely given, specific and informed consent. The narrow exception is the soft opt-in: a business may email its own existing customers about similar products and services, provided each message offers an easy unsubscribe and the original collection point made the marketing use clear.

Business-to-business sending to corporate addresses has more flexibility under PECR, but UK GDPR still applies to any personal data and a clear unsubscribe is required every time.

United States: CAN-SPAM

CAN-SPAM does not require prior consent for commercial email, but it does require accurate headers, a non-deceptive subject line, a clear identification that the message is an advertisement where applicable, a valid physical postal address, and a working unsubscribe processed within ten business days. State laws (notably in California) add further requirements.

Practical checks before you send

  • Document the lawful basis for every contact: consent source, timestamp and the exact wording shown.
  • Make the unsubscribe one click from the inbox; honour it immediately, across every list.
  • Identify the sender clearly in the From name and address.
  • Include a valid postal address in every message.
  • Suppress any address that has unsubscribed, complained or hard bounced.
  • If you use processors or sub-processors, list them in your privacy notice.

Buying, renting or sharing lists

Buying or renting a consumer email list and emailing it from your own domain almost never produces lawful consent under UK GDPR and PECR. The standard practical alternatives are: licensing access to a list via the original collector who has the consent, running a co-registration flow with clear, layered consent at the point of capture, or working with a managed sender that holds and honours the consent on behalf of advertisers.

Why compliance is also good deliverability

Almost every regulatory requirement also reduces spam complaints and bounces. Clear sender identification, easy unsubscribe and honest content keep mailbox providers happy at the same time as the regulator. Cutting corners on consent tends to show up first as a deliverability problem, not a legal one.

This guide is general information, not legal advice. For specific situations, especially cross-border or high-volume programmes, take qualified legal advice.

Frequently asked questions

Do I need consent to send marketing emails in the UK?

Usually yes. Consent is the safest lawful basis under UK GDPR and PECR. The soft opt-in covers existing customers receiving information about similar products, with a clear unsubscribe in every message.

Can I email purchased B2B lists?

PECR is more permissive for corporate addresses, but UK GDPR still applies to personal data. Senders relying on legitimate interest must complete a balancing test and offer a clear opt-out. Quality and source of the list matter; many purchased B2B lists fail this test in practice.

What happens if I get it wrong?

Regulators in the UK (ICO) and EU member states can fine senders and order the practice to stop. The faster commercial penalty is usually that mailbox providers throttle or block the sender, taking the revenue with them.

Keep reading

Stop thinking about the inbox.

We run the sending, protect the reputation and create the campaigns. You approve.