Posted on

Purchased mailing lists and the trade in uncertain consent

An email address is easy to sell.

The history attached to that address is much harder to package.

A purchased mailing list may arrive as a tidy spreadsheet containing names, companies, job titles, locations, interests, or demographic labels. What it often does not make obvious is the exact chain of events that supposedly authorized the buyer to contact each person.

That distinction matters because possession of an address and permission to use it are different facts.

The Federal Trade Commission makes an important U.S. legal distinction here. Its CAN-SPAM guidance says the federal law generally does not require prior opt-in consent before sending commercial email, provided the sender follows the law’s requirements and honors opt-outs. But the FTC also warns that purchased lists can be risky because addresses may belong to people who already opted out or may have been collected through unlawful harvesting or dictionary attacks. See the FTC’s Candid answers to CAN-SPAM questions.

So legal ability to send one kind of commercial message is not the same thing as evidence that the recipient asked for it.

The list loses its story as it changes hands

Suppose a person enters an email address to download a report from Company A.

Did the form clearly say Company A would email them? Did it say their address would be sold? Did it identify the eventual buyer? Did it authorize unrelated marketing? Was the permission limited to one topic? Was the box pre-checked? When did this happen?

A CSV containing person@example.com answers none of those questions.

That is why large email platforms often impose standards stricter than the minimum federal rule. Mailchimp, for example, prohibits purchased, rented, and scraped third-party lists under its current audience requirements. See Mailchimp’s audience requirements.

The platform is protecting more than etiquette. Recipients who do not recognize a sender are more likely to ignore, unsubscribe from, or report the message, damaging delivery reputation for everybody sharing the infrastructure.

Consent needs provenance

A meaningful consent claim needs evidence.

Useful records might include the original collection page, the wording shown beside the form, the date and time of signup, what categories of communication were described, whether third-party sharing was disclosed, the identity of the entity collecting the address, and any later opt-out.

Without that provenance, “they were on a marketing list” is circular reasoning.

The Spam Empires problem is not merely that lists became large.

It is that addresses became tradable inventory while the expectations of the humans attached to them were often reduced to a column nobody bothered to include.