Is It Legal to Buy an Email List?

Yes, buying an email list is legal in the United States. No federal statute bans the purchase itself, including a list of lawyers at US law firms; the law regulates how the list was built and how you use it. The CAN-SPAM Act governs every commercial email sent to the list, the TCPA governs autodialed calls and texts to its mobile numbers, and California law reaches the people and sellers behind the records. Estimate those duties before the first send. This guide is general information, not legal advice.

Key facts

Buying the list
No federal ban on the purchase
Emails sent to the list
CAN-SPAM Act, 15 U.S.C. § 7704
Opted-out addresses
Sale or transfer prohibited
Autodialed texts to cell numbers
Prior express consent required
California business contacts
Covered by the CCPA since January 1, 2023
California data brokers
Register with the CPPA by January 31 each year

Short answer

Yes. Buying an email list is legal in the US, and federal law regulates what you send to it. CAN-SPAM requires no opt-in before commercial email, so messages to a purchased list are lawful under the Act when each one carries accurate headers, an advertisement notice, a postal address and a working opt-out.

The legality of buying an email list turns on 2 questions: how the seller built the list, and how the buyer contacts the people on it. Neither the CAN-SPAM Act nor the FTC's CAN-SPAM Rule at 16 CFR Part 316 prohibits the purchase itself, and the same answer holds for whether buying an attorney email list is legal, because the Act treats email to law firms like email to any other business.

List construction matters on the seller's side. The FTC's compliance guide lists harvesting email addresses and generating them through a dictionary attack among the practices that carry criminal penalties, including imprisonment. Under 15 U.S.C. § 7704(b)(1), a message that already breaks subsection (a) becomes an aggravated violation where the sender knew, or knowledge is fairly implied from the objective circumstances, that the address came from either practice.

The buyer's duties start with the first message. The opt-out rules for emailing purchased contacts apply in full: a clear opt-out notice, a mechanism that keeps working for at least 30 days, and removal within 10 business days of each request.

Rules by law

Which laws apply after you buy an email list?

The CAN-SPAM Act, the TCPA, the CCPA and state data broker statutes apply after you buy an email list. Email rules bind the buyer from the first send, telephone rules attach to every call or text, and California's privacy law and the data broker registries bind the businesses that hold and sell the records.

The table answers the legal questions before buying an email list in the order they arise: sending email, calling or texting, holding California residents' data, and selling data about people the seller has no direct relationship with.

Email and telephone duties fall on the buyer from the first contact, while registration duties fall on the seller, so a lawful purchase still leaves 2 separate compliance checks: the campaign and the source.

Laws that apply to a purchased business contact list
LawWho it bindsWhat it requiresCitation
CAN-SPAM ActEvery business that initiates commercial emailAccurate headers and subject lines, an advertisement notice, a postal address and opt-outs honored within 10 business days15 U.S.C. § 7704
CAN-SPAM opt-out transfer banSenders and anyone who knows of an opt-out requestNo sale, lease, exchange or transfer of the opted-out address, including through mailing list transactions15 U.S.C. § 7704(a)(4)(A)(iv)
Telephone Consumer Protection ActBusinesses that call or textPrior express consent for autodialed or prerecorded calls and texts to wireless numbers47 U.S.C. § 227(b)(1)(A)(iii)
Telemarketing Sales RuleTelemarketers calling businessesBusiness-to-business calls are exempt from the Rule, except the bans on misrepresentations and false or misleading statements and calls selling nondurable office or cleaning supplies16 CFR 310.6(b)(7)
California Consumer Privacy ActCovered businesses holding California residents' personal informationRespond to requests to know, delete, correct and opt out of sale or sharingCal. Civ. Code § 1798.140
California Delete ActData brokers selling California residents' personal informationAnnual registration; DROP deletion requests processed at least every 45 days from August 1, 2026Cal. Civ. Code § 1798.99.82; § 1798.99.86
Vermont, Texas and Oregon data broker lawsData brokers within each state's definitionAnnual registration: Vermont Secretary of State, Texas Secretary of State ($300), Oregon Division of Financial Regulation ($600)9 V.S.A. § 2446; Tex. Bus. & Com. Code ch. 510; ORS 646A.593

Consent

No. Buying an email list transfers data, not consent. CAN-SPAM counts consent only when a recipient expressly agreed and, for a different sender, received clear notice that the address was transferable. The Act needs no consent to send, while email platforms such as Mailchimp demand proof of opt-in.

Under 15 U.S.C. § 7702(1), affirmative consent means the recipient expressly consented to receive the message, either in response to a clear and conspicuous request or at the recipient's own initiative. A message from a party other than the one that collected that consent qualifies only when the recipient received clear and conspicuous notice that the address was transferable for that purpose, so ask the seller for that record before treating any purchased address as opted in.

Platform contracts add a separate layer. Mailchimp's Acceptable Use Policy, effective September 26, 2025, forbids uploading or sending campaigns to purchased, rented, third-party, co-registration, publicly available data or partner lists, and requires evidence of consent for any commercial or marketing email. Breaching a platform policy is a contract matter between the sender and the platform, not a violation of federal law.

Calls and texts

Can you call or text phone numbers from a purchased list?

Yes, with consent rules for automated calls and texts to mobile numbers. The TCPA requires prior express consent before an autodialed or prerecorded call or text reaches a wireless number, and FCC rules require prior express written consent when that call or text advertises or telemarkets.

The statute defines an automatic telephone dialing system as equipment with the capacity to store or produce numbers using a random or sequential number generator and to dial them (47 U.S.C. § 227(a)(1)). FCC rule 47 CFR 64.1200(a)(2) sets the written-consent standard for advertising and telemarketing calls to wireless numbers, and paragraph (a)(10) lets a called party revoke consent to calls or text messages by any reasonable method.

Violations carry a private right of action. Under 47 U.S.C. § 227(b)(3), a person can recover actual monetary loss or $500 for each violation, whichever is greater, and a court can raise the award to as much as 3 times that amount for willful or knowing violations.

The national Do-Not-Call registry protects residential telephone subscribers under 47 CFR 64.1200(c)(2), and paragraph (e) applies those rules to telephone solicitations and text messages sent to wireless numbers. The FTC's Telemarketing Sales Rule exempts calls between a telemarketer and a business, with 2 carve-outs in 16 CFR 310.6(b)(7): the bans on material misrepresentations and on false or misleading statements to induce payment (16 CFR 310.3(a)(2) and (a)(4)) keep applying, and calls to induce the retail sale of nondurable office or cleaning supplies stay inside the Rule.

State laws

Do state privacy and data broker laws affect email list buyers?

Yes. California's CCPA binds buyers that meet its thresholds, and data broker laws in California, Vermont, Texas and Oregon bind sellers. A covered buyer answers privacy requests from California contacts, while a seller that sells data about people it has no direct relationship with registers as a data broker.

The CCPA reaches a for-profit business doing business in California that meets 1 of 3 tests: annual gross revenue above the statutory threshold, buying, selling or sharing personal information of 100,000 or more California consumers or households, or earning 50% or more of annual revenue from selling or sharing personal information. The California Privacy Protection Agency puts the revenue threshold at $26,625,000 effective January 1, 2025, and adjusts it in every odd-numbered year. According to the California Attorney General, the exemption for personal information reflecting business-to-business transactions expired on December 31, 2022.

California Civil Code § 1798.99.80(c) defines a data broker as a business that knowingly collects and sells to third parties the personal information of a consumer with whom it has no direct relationship, and carves out entities to the extent they are covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the Insurance Information and Privacy Protection Act or the CCPA's health information exemption. Each data broker registers with the California Privacy Protection Agency on or before January 31 for the prior year, owes a $200 administrative fine for each day it fails to register, and appears in the registry the Agency publishes for download after the registration period ends.

Vermont's definition in 9 V.S.A. § 2430(4)(C) states that providing publicly available information related to a consumer's business or profession, and collecting and selling data incidental to that activity, does not by itself make a business a data broker. The Texas Secretary of State registers data brokers under Business and Commerce Code chapter 510 for a $300 fee, and Oregon's Division of Financial Regulation registers them under ORS 646A.593 for $600.

Related lists and guides

Review the attorney data before you decide

Legal review starts with knowing what a file contains. Request a free sample before buying an attorney email list for business outreach: each record carries the firm name, mailing address, direct phone and practice area, and orders start at 1,000 records under a 12-month license with no resale.

Questions

Frequently asked questions

Is it legal to buy email lists under the GDPR?

Yes, with conditions. A buyer needs a lawful basis under GDPR Article 6, must give people the Article 14 information for data obtained from another source, and must honor objections under Article 21; EU ePrivacy rules set a separate consent rule for emailing individuals.

Can you buy mailing lists for direct mail?

Yes. The CAN-SPAM Act does not reach printed mail, and federal postal statutes in Title 39 regulate the mailings themselves, such as solicitations formatted like invoices and sweepstakes offers, rather than the purchase of the address list.

Can you resell an email list you bought?

No for opted-out addresses, and no for this attorney data. 15 U.S.C. § 7704(a)(4)(A)(iv) bars transferring an address after its owner opts out, and the license sold with this database runs 12 months and permits no resale.

Do CAN-SPAM duties change when the list is purchased?

No. The header, advertisement notice, postal address and opt-out duties are identical for a bought list and a list built in-house. The source matters in 1 situation: harvested or dictionary-generated addresses aggravate violations under 15 U.S.C. § 7704(b).

Sources

  1. CAN-SPAM Act: A Compliance Guide for Business, Federal Trade Commission, 2023-08. Accessed 2026-09-16.
  2. 15 U.S.C. § 7702 – Definitions, Legal Information Institute, Cornell Law School (US Code text). Accessed 2026-09-16.
  3. 15 U.S.C. § 7704 – Other protection for users of commercial electronic mail, Legal Information Institute, Cornell Law School (US Code text). Accessed 2026-09-16.
  4. 16 CFR Part 316 – CAN-SPAM Rule, Legal Information Institute, Cornell Law School (CFR text), 2008-05-21. Accessed 2026-09-16.
  5. 47 U.S.C. § 227 – Restrictions on use of telephone equipment, Legal Information Institute, Cornell Law School (US Code text). Accessed 2026-09-16.
  6. 47 CFR § 64.1200 – Delivery restrictions, Legal Information Institute, Cornell Law School (CFR text). Accessed 2026-09-16.
  7. 16 CFR § 310.6 – Exemptions, Legal Information Institute, Cornell Law School (CFR text). Accessed 2026-09-16.
  8. 16 CFR § 310.3 – Deceptive telemarketing acts or practices, Legal Information Institute, Cornell Law School (CFR text). Accessed 2026-09-16.
  9. California Consumer Privacy Act (CCPA), State of California Department of Justice, Office of the Attorney General, 2026-08-28. Accessed 2026-09-16.
  10. California Civil Code § 1798.140, California Legislative Information, 2026-01-01. Accessed 2026-09-16.
  11. Updated Monetary Thresholds in CCPA, California Privacy Protection Agency, 2024-12-17. Accessed 2026-09-16.
  12. California Civil Code § 1798.99.80, California Legislative Information, 2024-01-01. Accessed 2026-09-16.
  13. California Civil Code § 1798.99.82, California Legislative Information, 2026-01-01. Accessed 2026-09-16.
  14. California Civil Code § 1798.99.86, California Legislative Information. Accessed 2026-09-16.
  15. Data Broker Registry, California Privacy Protection Agency, 2026-07-29. Accessed 2026-09-16.
  16. 9 V.S.A. § 2430 – Definitions, Vermont General Assembly. Accessed 2026-09-16.
  17. Data Broker, Vermont Secretary of State. Accessed 2026-09-16.
  18. Data Brokers, Texas Secretary of State. Accessed 2026-09-16.
  19. Data Broker Registry, Oregon Division of Financial Regulation. Accessed 2026-09-16.
  20. Mailchimp Acceptable Use Policy, Mailchimp (Intuit), 2025-09-26. Accessed 2026-09-16.
  21. Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex, Publications Office of the European Union, 2016-04-27. Accessed 2026-09-16.
  22. Directive 2002/58/EC (ePrivacy Directive), EUR-Lex, Publications Office of the European Union, 2002-07-12. Accessed 2026-09-16.