A B2C newsletter publisher buys a cold email list from a broker and begins promotional campaigns to EU recipients with whom it has no prior relationship and no recorded consent. What is the soundest compliance conclusion?
Select an answer to reveal the explanation.
Short Explanation
Buying a list is not the same as earning permission. Under the ePrivacy-plus-GDPR stack, cold B2C email usually needs consent—or a genuine prior customer soft-opt-in—not a broker handshake. If you never met these people, hitting send is the compliance problem.
Full Explanation
EU electronic direct marketing is shaped by the ePrivacy Directive (as implemented nationally) interacting with GDPR lawful-processing rules. For many B2C email campaigns, prior consent is required unless a narrow soft-opt-in for similar products from an existing customer relationship applies. Purchasing third-party cold lists without consent or qualifying prior relationship typically fails those rules; contractual indemnities from a broker do not substitute for a valid legal basis or data-subject rights.