gdpr / can-spam / ccpa

Three regimes, and a clear line about which side each duty sits on.

Buying data does not transfer legal responsibility for a campaign. The FTC has been explicit that hiring a vendor, agency or list broker does not move the obligation away from the business being promoted. So this page does two things: it sets out what each regime actually requires, and it states plainly which of those duties are ours and which are yours. It is not legal advice.
there is no official can-spam certification for list providers — treat any claim of one as a red flag
Regimes covered here
0
Compliance certifications that exist
0 M
Party responsible for the send
0
To ask a question
0 /7
what each regime requires

The obligations, in plain terms.

These are the requirements most directly relevant to sending a campaign to a purchased business list. They are summaries, not statute, and they do not replace advice from a lawyer in your jurisdiction.

01

CAN-SPAM (United States)

Accurate sender identity and header information. A subject line that does not mislead. A valid physical postal address in the message. A working opt-out mechanism, honoured promptly. Applies to commercial email regardless of whether the recipient opted in.

sender duty

02

GDPR (EU) and UK GDPR

A lawful basis is required before processing personal data — for B2B outreach this is usually legitimate interests, which requires a documented balancing assessment. Data subjects have rights of access, rectification and erasure. A Data Processing Agreement is expected where an EU or UK record is involved.

shared

03

PECR (United Kingdom)

Sits alongside UK GDPR and governs the electronic message itself. Corporate subscribers — limited companies and LLPs — may be emailed on a legitimate-interests basis; sole traders and unincorporated partnerships are treated closer to individuals.

sender duty

04

CCPA / CPRA (California)

California residents can request deletion of their personal information and opt out of its sale or sharing. A provider must be able to action those requests, and a buyer must be able to pass them on. Neither of us can ignore one and point at the other.

shared

05

CASL (Canada)

The strictest of the group: consent is generally required before sending, with limited implied-consent grounds such as an existing business relationship or a conspicuously published business address. Do not treat a Canadian segment as a US one.

ask first

what we can give you

Documentation you can actually ask for.

A provider that answers “we are fully compliant” and stops there has told you nothing. These are the four things worth having in writing before you send, and all four are available on request.

Data processing agreement

For any file containing EU or UK records. Sets out roles, purposes, retention and the handling of data subject requests between us.
Source statement for your file
Which of the three collection streams your specific records came from, and the contractual warranties behind any licensed portion of them.
Suppression before delivery
Send us your own do-not-contact list and it is screened out of the build before the file reaches you. No charge, and the single most effective way to avoid a complaint.
Verification date evidence
The date each record last passed the seven checks, so a due-diligence file has something in it other than a marketing claim.
the split

Who is responsible for what.

This is the part most providers leave vague. Being specific about it is cheaper for both of us than discovering the gap after a complaint.

Recording and retaining the source of every record

Contractual warranties from licensed data partners

Maintaining the permanent global suppression file

Actioning access and erasure requests sent to us

Providing a DPA where EU or UK records are involved

Establishing and documenting a lawful basis per market

Accurate sender identity, subject line and physical address

A working unsubscribe, honoured promptly on every send

Applying your own suppression list before each campaign

Passing on deletion and opt-out requests you receive

what nobody can sell you

There is no certification that makes a purchased list legally safe.

No government body certifies or approves list providers under CAN-SPAM. What protects you is knowing enough about how a list was built, maintained and suppressed to make an informed decision — and being able to show that due diligence if a complaint arrives. A provider claiming their data makes your campaign “100% compliant” is describing something that does not exist.

not legal advice · take advice for the jurisdictions your list touches

does not exist

A CAN-SPAM certification, seal or approved-provider register

does exist

A documented source, a verification date and a DPA

stays with you

Legal responsibility for the campaign you send

stays with us

The provenance and suppression of the data we sell

questions

Questions about the legal side

Is buying an email list legal?
In the United States, sending commercial email to a purchased business list is lawful provided the CAN-SPAM requirements are met. In the EU and UK, a lawful basis is required first, and legitimate interests must be documented rather than assumed. In Canada, consent rules are stricter and a purchased list is harder to justify. Take advice for the markets you are sending to.
If your file contains EU or UK records, yes — ask and we will provide one. For a US-only business file it is generally not required, though you should still confirm how CCPA requests are handled if California residents are included.
Honour it immediately in your own system, and send it to us as well. Addresses reported to us go into permanent global suppression and are screened out of every future build.
Practically, no. Contact data decays at roughly 20 to 30 percent a year, so a file that has sat unused for a year is a deliverability risk regardless of what the licence says. Re-verify before you send an old file.
[email protected]. Access, rectification and erasure requests are actioned and the address is added to permanent suppression.
the rest of the shelf

Fifteen resource pages, none of them gated.

Trust is what we can show you about the data. Proof is what happens when you test it. Guides are what to do with it once it is yours.
What we can show you about the data before you spend anything.

How we build & verify

3 sources

Coverage dashboard

live counts

Compliance center

policies

GDPR / CAN-SPAM / CCPA

3 regimes

Opt-out & removal

permanent

What happens when you test it, and what we owe you if it fails.

Free samples

100 rows

Customer reviews

4.7 / 5

Case studies

worked

Accuracy reporting

up to 85%

Refund policy

5% / 7 days

What to do with the file once it is yours.

Blog

58 posts

Email marketing guides

6 guides

Lead generation guides

7 steps

Data buying guide

10 questions

Deliverability guide

checklist

Ask for the DPA and the source statement before you order, not after your first send.

Sales and service are reachable 24/7 on WhatsApp at +1 (315) 215-1563, or at [email protected].

FREE 100-ROW SAMPLE

See 100 real rows before you spend anything.

Tell us who you’re trying to reach and we’ll pull a genuine slice of that list — with the date every address was last checked. Test it in your own tool, then decide.

EMAIL

COMPANY

TITLE

CHECKED

j.whitcombe@•••••.com

Northloop

Founder

Updated

priya.n@•••••••.io

Cadence AI

CEO

Updated

+ 98 More Rows in Your Sample

EmailProLeads

100 verified rows, free, before you pay a thing.

Tell us the audience you’re after and we’ll send a real slice of that file — with the date each address was last checked.

EMAIL

COMPANY

TITLE

CHECKED

j.whitcombe@•••••.com

Northloop

Founder

Updated

priya.n@•••••••.io

Cadence AI

CEO

Updated

+ 98 More Rows in Your Sample

WAIT!!!

Don’t Leave Empty Handed!

You've Qualified For An Additional Discount

Get FREE 100 Leads​

Seconds