Definition
Email list rental and email list purchase are two methods of acquiring access to third-party subscriber lists, both of which carry significant legal and deliverability risks. Rented lists provide temporary access to send to another company's subscribers, typically on a per-send basis. Purchased lists involve buying a database of email addresses outright. Neither method is compliant with GDPR, CASL or most modern privacy regulations because the subscribers on these lists have not consented to receive emails from your organisation.
Why They Are Problematic
- Consent does not transfer — consent given to one company does not extend to another under GDPR or CASL
- Deliverability damage — sending to unengaged recipients triggers spam complaints and damages sender reputation
- Spam traps — purchased lists often contain spam trap addresses that can permanently blacklist your sending domain
- Low engagement — recipients who never opted in rarely open, click or convert
Best Practices
- Build your list organically through permission-based acquisition methods
- If acquiring another business, migrate subscriber data with proper consent notifications and opt-in confirmation
- Use list rental only in strictly regulated contexts (B2B, CAN-SPAM only) with clear disclosure
- Never purchase email lists from brokers or data vendors under any circumstances
- Audit any third-party list against consent requirements before sending a single message
Related Glossary Terms
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Right to Data Portability (GDPR)
The right to data portability allows individuals to obtain and reuse their personal data across different services, including exporting subscriber data from email marketing platforms.
Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that defines how personal data will be handled, required under GDPR for email service providers.
Data Retention Schedule (Email Marketing)
A data retention schedule defines how long subscriber personal data is stored after unsubscribing or becoming inactive, ensuring compliance with GDPR, CCPA, and similar privacy laws.
Data Subject Access Request (DSAR)
A Data Subject Access Request (DSAR) is a GDPR right allowing individuals to request access to their personal data held by an organisation, including email marketing data.