SPAM AND INBOX OVERLOAD
How Marketers Buy and Sell Email Lists — and How to Keep Yours Off Them
By AUTHOR NAME · September 14, 2026 · 12 min read
THE SHORT VERSION
|
The mail you didn’t sign up for mostly doesn’t come from criminals. It comes from an ordinary commercial supply chain, staffed by people with job titles and quarterly targets, operating largely in the open. It has its own terminology, and learning four of those terms tells you more about your inbox than any amount of filtering.
The simplest arrangement is the one people picture when they say “they sold my email.” A file of addresses changes hands, the buyer now holds it, and can mail it as often as they like.
It is also, in a lot of the market, the least common of the arrangements — because a list owner who hands over the file has sold the asset once and lost control of it forever. The industry mostly prefers models that keep the asset.
This is the mechanism most worth understanding, because it explains a sentence that appears in thousands of privacy policies.
In a rental, an advertiser pays a list owner to send its message to the owner’s subscribers. The list owner does the sending. The advertiser never receives the addresses — often not even a count of who opened. The file never moves.
So a company can say, accurately, that it has never sold or shared your email address, while third-party offers arrive in your inbox with its blessing and its sending infrastructure. Both halves are true at once. The distinction is real in data protection terms and invisible from where you’re sitting.
HOW TO SPOT IT Rented mail usually arrives from a brand you recognise, promoting one you don’t — “our friends at…”, “a message from our sponsor”, “we thought you’d like…”. If an unfamiliar offer reaches an address only one company ever had, and the sender’s domain is that company’s, you’re looking at rental rather than a leak. |
Co-registration is how a single sign-up becomes a dozen senders.
You enter a competition, download a guide, or claim an offer. Somewhere on the form is a line about hearing from “our partners,” “carefully selected third parties,” or “sponsors of this promotion” — sometimes with a checkbox, sometimes pre-ticked, sometimes phrased so that unticking it is what signs you up. Agreeing once enrols you with every participating company.
This is the route that most often produces genuine bafflement: mail from companies you have never heard of, arriving at an address you barely use, with no breach involved anywhere. You agreed, technically, in a sentence you didn’t read on a form you filled in for something else.
Two more arrangements complete the picture.
Lead generation inverts the usual relationship. On a lead-gen site, the quiz, the insurance comparison, the “check your eligibility” form is not the product — you are. Details are collected specifically to be sold on to whoever buys leads in that category, and the site’s entire business model is the onward sale.
Data append is quieter still. Here a company already holds a partial record — a name, a postal address, a purchase history — and pays a broker to fill in the missing fields, including your email address. Nobody sold your address to a stranger; a stranger who already knew something about you bought the rest.
This is where the picture splits sharply, and it’s worth knowing which regime applies to you before deciding what to do.
Federal law governs how commercial email is sent, not how the address was obtained. CAN-SPAM requires accurate headers, honest subject lines, identification of advertising, a valid postal address and a working opt-out honoured within ten business days. It does not require that you asked to hear from the sender. Buying a list is therefore not, in itself, a federal violation.
Data protection law takes the opposite approach by starting from consent. Under Article 4(11), consent means
“any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement” GDPR, Article 4(11) — as quoted in ICO guidance |
Every one of those words does work, but specific and informed are the ones that dismantle the bought-list model. The ICO’s guidance is unusually direct about it: if you buy in “consented” data, that consent is only valid for your processing if you were specifically identified when it was collected. A generic agreement to hear from unnamed “partners” doesn’t transfer.
The same guidance is blunt about the mechanics that make co-registration work: silence, pre-ticked boxes and inactivity do not constitute consent.
THE PRACTICAL UPSHOT If you’re in the UK or EU, an unfamiliar company emailing you off a bought list is very likely processing your data without a valid lawful basis — not a grey area, and worth saying so when you complain. If you’re in the US, the same message may be entirely lawful, and your lever is the opt-out rather than the legality. |
Californian law has moved furthest on the specific problem of brokers who hold data on people they’ve never dealt with.
Under the state’s Delete Act, a data broker is a business that knowingly collects and sells the personal information of a consumer with whom it has no direct relationship — a definition broad enough to catch lead generators, enrichment services and retailers selling audience segments, whether or not they think of themselves as brokers.
The enforcement mechanism is DROP, the Delete Request and Opt-out Platform, which went live on 1 January 2026. It is a single deletion request that reaches every registered broker at once. From 1 August 2026, registered brokers must check DROP at least every 45 days, match requests using standardised identifiers, delete matching records unless a statutory exception applies, and complete their determinations within 90 days — with penalties accruing per request per day for non-compliance.
One request, every registered broker, legally mandated. Nothing comparable exists elsewhere yet.
| MECHANISM | WHAT IT MEANS FOR YOU | WHAT ACTUALLY STOPS IT |
|---|---|---|
List purchase | A stranger holds your address permanently | Nothing retroactively; unsubscribe from each sender |
List rental | Third-party offers via a brand you trusted | Unsubscribe from the brand, or withdraw marketing consent |
Co-registration | One sign-up, many senders | Reading the partners line at the form — prevention only |
Lead generation | Your details were the product | Don’t complete the form; the sale is the business model |
Data append | Someone filled in your address from a broker | Broker deletion requests — DROP in California |
Notice that four of the five are addressed at the point of collection, not afterwards.
In rough order of how much good each does.
Use a different address for every company. This is the only measure that works against all five mechanisms at once, and it converts an unanswerable question into a certainty: mail arriving at an address only one company held identifies the source exactly.
If you’re in California, file a DROP request. One request reaching every registered broker is a far better use of ten minutes than opting out of brokers individually.
If you’re in the UK or EU, object to direct marketing. The right to object to processing for direct marketing is absolute — there’s no balancing test for the controller to apply and no legitimate interest that outweighs it. Say plainly that you object under Article 21 and that you want to know the source of your data.
Read the partners line before submitting. Tedious, and the single highest-leverage second in the whole process. Co-registration only works if you don’t look.
Unsubscribe from senders you recognise. Legitimate businesses are bound by working opt-out requirements and honour them. Unknown senders get marked as spam instead, without interaction.
ONE CAUTION Paid “remove me from all data brokers” services exist and vary enormously in what they actually deliver. Before paying for one, check whether the free statutory route covers you — a Californian has DROP; a UK or EU resident has an absolute right to object that costs nothing to exercise. |
Is it legal to buy and sell email lists?
It depends where the recipient is. In the US, CAN-SPAM regulates how commercial mail is sent rather than how the address was obtained, so buying a list isn’t itself prohibited. Under UK and EU law it’s far harder: the ICO states that if you buy in “consented” data, that consent is only valid for your processing if you were specifically identified when it was collected. Most purchased lists can’t meet that test.
How can a company say it never sells my data and still send me other companies’ offers?
List rental. The list owner never hands over the file — the advertiser pays for a message to be sent to the list by its owner, so no addresses change hands. The statement is literally true and the effect is identical from where you sit.
What is co-registration?
Signing you up to several mailing lists from one interaction — typically a single checkbox agreeing to hear from a company’s partners, sponsors or selected third parties. It’s how one sign-up becomes a dozen senders, with your technical agreement.
How do I get my details deleted from data brokers?
Californians have the strongest mechanism: DROP, the Delete Request and Opt-out Platform, live since 1 January 2026. From 1 August 2026 registered brokers must check it at least every 45 days and delete matching records unless an exception applies. Elsewhere, UK and EU residents can object to direct-marketing processing, which controllers must honour without any balancing test.
How can I tell which company sold my address?
Give every company a different address. Unexpected mail arriving at one of them identifies the source exactly — and it works whether the address was sold, rented, leaked or scraped.
The trade in email addresses is not a conspiracy. It’s an industry with contracts, compliance teams and a vocabulary designed to be accurate rather than clear — which is why “we never sell your data” can appear beside a stream of third-party offers without anybody lying.
Two things follow. Where you have a statutory lever, use it: DROP in California and the right to object in the UK and EU are both stronger than most people realise. And everywhere else, the only durable defence is structural. A company that receives an address used nowhere else can sell it, rent it or append to it as much as it likes — and all it can ever tell a buyer is that one person, once, wanted one thing.