You buy a prospect list. Thirty thousand business addresses, presented as collected on an opt-in basis, delivered as a CSV, invoiced at a few thousand euros.
The GDPR then imposes an obligation the seller never mentions in the brochure: write to those thirty thousand people, within a month, to tell them you hold their data and who sold it to you.
That is not a harsh reading of the text. It is what the text says.
Article 14, and its one-month deadline
The GDPR distinguishes data collected from the individual, governed by Article 13, from data obtained elsewhere, governed by Article 14.
Article 14(3) sets the timetable for the notice: “within a reasonable period after obtaining the personal data, but at the latest within one month”, or, if the data is used to communicate with the person, “at the latest at the time of the first communication”.
The content of that notice is set by the same article, and it includes the controller’s identity, the purposes, the legal basis, the recipients, the retention period, the individual’s rights, and the source of the data.
The French authority applies that requirement without nuance to list resale: the buyer must inform individuals as soon as possible and at the latest within one month, and that notice must include the source of the data, meaning the name of the company that sold the customer file.
Naming your supplier. That is where most list purchase projects stop, when someone reads the text before signing.
The exemptions, and why they do not save you
Paragraph 5 provides exemptions: the person already has the information, providing it would involve disproportionate effort, obtaining the data is laid down by law, or the data is covered by professional secrecy.
The disproportionate effort exemption is the one always invoked, and it does not apply here. It covers situations where notice is materially impossible, such as archival processing of people with no known contact details.
You, on the other hand, hold precisely each person’s email address, and you are about to use it to write to them. The effort is in no way disproportionate: it is exactly the effort you intend to make in order to sell them something.
What purchased consent does not transfer
The authority is clear: if consent to electronic marketing was not collected by the seller on the buyer’s behalf, the buyer must ensure the compliance of its own electronic marketing operations by collecting consent itself, beforehand.
Consent is not movable property. It is given to someone, for something.
The technical bodies say the same thing, in blunter terms. Spamhaus: “Never buy or rent email addresses from anyone. Permission is not transferable!” and, without hedging, “All advertisements for lists of ‘opt-in email addresses’ are fraudulent.” M3AAWG, for its part, calls email appending a “direct violation of core M3AAWG values”, and restates that consent obtained on one channel is not transferable to another.
Two sanctions, two mechanics
On 5 December 2024, the CNIL issued a fine of 240,000 euros against KASPR, publisher of a sales intelligence extension collecting business contact details from a social network, with a database of around 160 million contacts.
Three breaches were found: no valid legal basis for collecting contact details whose visibility users had themselves restricted, disproportionate retention period, and failure to inform individuals for four years after the service launched. The decision was adopted in cooperation with counterpart European authorities.
On 15 May 2025, it issued a fine of 900,000 euros against SOLOCAL MARKETING SERVICES, a data broker, for failing to obtain consent before electronic marketing. The reasoning is instructive: the deceptive appearance of the forms used by the supplying brokers did not allow free and unambiguous consent to be collected. The fine came with an injunction under a penalty of 10,000 euros per day.
In other words, the broker was sanctioned for the quality of consent collected by its own suppliers, several links upstream. The whole chain is engaged, not just its last link.
In its review published on 9 February 2026, the CNIL states that marketing, commercial or political, was the subject of ten sanction decisions in 2025.
Buying a list, or querying a database
There is a difference in kind between buying a list and querying a database of business contacts, and it would be dishonest to pass over it as it would be to overstate it.
Buying a list means acquiring an undifferentiated stock, presented as consented, whose origin is lost upstream. That is the model authorities sanction and technical bodies condemn.
Querying a database to identify contacts whose role matches your offer is targeting work: you know why this particular person is concerned, and the approach is related to their profession, the condition the authority sets for the professional regime. That is what Sestaro’s contact search allows, where each record carries its role, its company and a reliability score.
But the nuance exempts you from nothing. In both cases the data was not collected from the individual, so Article 14 applies, so the notice obligation falls on you. The only thing targeting improves is your ability to justify the legitimate interest you are invoking.
What to do tomorrow morning
If you hold an acquired list, date its acquisition. Beyond one month without notice to the individuals, the breach is established and it cannot be repaired retroactively.
If you are considering a purchase, ask the seller for three things in writing: the exact form through which consent was collected, the date of that collection for each record, and the identity of the original collector. A serious supplier provides them. The others explain that it is confidential.
Finally, remember that this data has an expiry date, and that a list bought four years ago is already, for the most part, a list that should no longer exist.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 14(3) and 14(5)
- CNIL (5 December 2022). Vente de fichiers clients : la CNIL rappelle les règles
- CNIL (decision SAN-2024-020 of 5 December 2024). Aspiration de données : sanction de 240 000 euros à l’encontre de la société KASPR
- CNIL (decision SAN-2025-001 of 15 May 2025). Sanction de 900 000 euros à l’encontre de la société SOLOCAL MARKETING SERVICES
- CNIL (9 February 2026). Bilan des sanctions et mesures correctrices 2025
- Spamhaus. Marketing email FAQ
- M3AAWG (updated January 2019). M3AAWG Position on Email Appending
LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.
