A list supplier's assurance that contacts are compliant is not enough to justify a campaign. Identify how the information was collected, what people were told and whether the proposed sender and channel are covered. The buyer remains responsible for assessing its own use.
Separate corporate subscribers from individuals and check the UK GDPR position for named people. Review the actual consent wording and evidence where consent is required. Do not assume a soft opt-in can be inherited simply because another organisation previously sold something to the contact.
Ask for evidence before accepting the commercial promise
A mailing list's description as compliant, verified or opted in should lead to questions, not immediate import. Identify the original collection method, date, wording and organisations named. Ask which channels and purposes the evidence covers. A vendor may have confirmed that an address exists without establishing any permission or other lawful route for your particular campaign to use it.
Request a representative evidence sample through a controlled process before buying the full dataset. Avoid taking unnecessary personal records merely to inspect the supplier's claims. Check whether the vendor can link each contact to the relevant collection version and status. A generic privacy policy from the supplier's current website may not establish what people were told several years earlier at an unrelated event.
Separate subscriber status and personal data use
Identify corporate and individual subscribers, including sole traders and relevant partnerships. A business list can contain both, so a single campaign rule may be unsuitable. The ICO's marketing list guidance addresses the buyer's responsibility to assess the proposed use and relevant permission evidence. [1] Do not assume a commercial soft opt-in transfers simply because the vendor once had a customer relationship with the recipient.
For named contacts, assess UK GDPR responsibilities as well as PECR. Consider source transparency, accuracy, reasonable expectations and objections. Keep the intended sender and purpose specific. A broad claim that the data can be used by selected partners does not eliminate the need to assess whether your organisation and message fit the evidence and applicable requirements.
Review the supply contract without confusing it with permission
Check the supplier's warranties about provenance, accuracy, permissions and suppression. Define what evidence must be delivered and how disputes about unusable entries are handled. An indemnity may allocate contractual risk between buyer and seller, but it does not create permission to contact people. Nor does it guarantee reimbursement if the supplier cannot pay or the claim falls outside the agreed wording.
Ask whether the supplier has checked objections and how updates will reach you. Identify duplicates, outdated roles and addresses that may now belong to another person. Plan a controlled import that preserves provenance and excludes unsupported entries. Do not merge the new list into the main CRM in a way that overwrites existing objections or makes it impossible to distinguish the purchased source later.
Set a campaign gate and monitor early signals
Use Marketing emails to business contacts to classify the proposed business outreach and Marketing consent and customer preferences to apply preferences across systems. Keep approval dependent on evidence for the actual audience and message. If significant records cannot be supported, consider rejecting that segment or the purchase. A large volume of cheap contacts is not useful if the business cannot establish an appropriate route to use them.
Review replies, complaints and source-related concerns promptly. Stop using a problematic segment while investigating rather than simply removing the people who complain. Retain enough source evidence to answer a question about where a named contact came from, with controlled access and a retention decision. Make sure agencies using the list follow the same restrictions and do not combine it with unrelated audiences without assessment.
For Business privacy notice review, provide the vendor proposal, collection evidence, contract and sample campaign. Ask for a clear decision on which categories can be used, under what conditions and what remains unsupported. Record that decision before payment or import where possible. The review should help choose a defensible acquisition route for contacts, not merely add reassuring language to a campaign whose underlying evidence is missing.
Sample provenance before committing to volume
Ask the supplier to demonstrate the evidence behind a small, representative selection of contacts, including older records and different business types. Examine whether the collection wording, source and subsequent changes can actually be traced. A polished sample containing only the newest entries may not represent the full dataset offered for sale.
Agree how unverifiable records will be excluded and how corrections or objections discovered later will be communicated. Keep these quality arrangements separate from your own assessment of whether a campaign is permitted. If the seller offers replacement contacts as the sole remedy, consider whether that addresses the practical problem: another unverified address does not resolve the original lack of evidence about lawful use.
Illustrative scenario
A supplier offers a list described as opted-in UK business leads. The buyer asks for the collection source, wording, dates, subscriber categories and suppression process. If the evidence does not support the planned campaign, the buyer does not treat the label as permission and considers another way to build its audience.
Preparation checklist
- Request provenance and the exact permission evidence.
- Check the sender, purpose and channels covered.
- Identify subscriber types and named personal data.
- Apply current objections and suppression records before any campaign.
Frequently asked questions
Does a vendor guarantee make the list lawful to use?
No. It may create contractual rights but does not replace assessment of your own campaign. Verify the source, subscriber categories, relevant permissions and personal data obligations.
Can we inherit another business's soft opt-in?
Do not assume so. That route has specific conditions and is not a general transferable permission attached to an address. Check the proposed sender and collection circumstances.
What if only some contacts have adequate evidence?
Separate supported and unsupported categories before import or sending. Do not let a few good sample records justify using the whole list without a reliable evidence process.
Should our agency perform the assessment alone?
Define responsibility and obtain the evidence and conclusion needed for your organisation's use. Outsourcing campaign operation does not make provenance and suppression questions disappear.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction