Scoring an Outbound Contact List for Lawful Send
You can score any prospecting list on six dimensions and land a documented send, fix, or hold verdict before the campaign launches.
Key takeaways
- A list can pass GDPR and still be unlawful to email: a GDPR-lawful email can breach PECR regulation 22 because the two consent regimes operate independently.
- Provenance carries documented enforcement weight - scraped personal data anchors to Clearview's roughly EUR 100 million in European fines, while enrichment from an unknown source anchors to Poland's EUR 220,000 Article 14 notice fine.
- A Legitimate Interest Assessment must be completed and documented in writing before processing starts; a retrospective LIA does not create a valid lawful basis.
- Retention has no safe number, only a defensible one: CNIL suggests up to 3 years for prospect data and the ICO benchmarks soft opt-in recency at roughly two years, both tied to purpose.
- Jurisdiction follows the data subject, not the server: Clearview, a US company with no EU offices, still accumulated roughly EUR 100 million in European fines.
- In Refolk's index, the UK returns 693 people with a current Data Protection Officer title against 78 in the US, an 8.9x ratio that tracks the density of the compliance function.
Before you launch an outbound campaign, someone has to decide whether this specific list is lawful to send to, and write down why. This guide is for the revenue-operations or data owner who is answerable for that call. It gives you a six-dimension scoring rubric so you grade every new list the same way twice, and land a documented send, fix, or hold verdict instead of re-reading the regulation each time.
The premise is simple: a list is not "compliant" or "non-compliant" as a whole. It is a mix of provenance, jurisdictions, subscriber types, and ages, and the lawful-send question resolves per record and then rolls up. The job is to make that roll-up repeatable.
Why one lawful-basis check is not enough
A list can pass GDPR and still be unlawful to email. That single fact is why this guide scores six dimensions instead of asking one question.
The trap is treating "do we have a lawful basis?" as the whole test. In the UK and EU it is not. A marketing email that is lawful under UK GDPR legitimate interest can still breach PECR regulation 22 if the recipient has not given separate PECR consent, because the two consent regimes operate independently. So you can build a spotless Legitimate Interest Assessment, satisfy GDPR, and still send an unlawful email to a sole trader who counts as an individual subscriber.
The same layering shows up across jurisdictions. California removed its shortcut in 2023: the CCPA employment and B2B exemptions sunset on January 1, 2023, so work emails, business phone numbers, and job titles are now covered personal information. And extraterritoriality removes "we are US-based" as a defence entirely. Clearview, a US company with no EU offices, accumulated roughly EUR 100 million in European fines. Jurisdiction follows the data subject, not the server.
The density of the compliance function tracks this complexity. In Refolk's index, the countries with the most layered regimes staff the accountable role most heavily.
| Country | DPO-titled people | Ratio vs US |
|---|---|---|
| United States | 78 | 1.0x |
| Germany | 201 | 2.6x |
| United Kingdom | 693 | 8.9x |
The mechanism behind the gap: PECR layered on UK GDPR, plus an ICO with a public enforcement register, makes a named accountable role near-mandatory. In the US the B2B exemption only lapsed in 2023. The takeaway for your scoring is that no single dimension is decisive, and the ones people skip - subscriber type, provenance, retention age - are exactly the ones enforcement turns on.
The six dimensions and what each one proves
Score every list on six dimensions. Each proves a different failure, and each has a tell when the score is lying to you.
- Provenance. Where the record came from. Proves whether you can even establish a lawful basis. It lies when a "compliant vendor" badge stands in for a signed contract.
- Lawful basis. For EU/UK, whether a completed Legitimate Interest Assessment exists. Proves the processing has a ground. It lies when the LIA was rubber-stamped after send.
- Role relevance. Whether the contact's job makes your message a genuine, expected interest. Proves the necessity and balancing halves of the LIA. It lies when the role is a loose keyword match, not a real buyer.
- Jurisdiction mix. Which regimes apply across the list. Proves which rules you must satisfy. It lies when "mostly US" hides a slice of EU residents.
- Opt-out readiness. Whether a working unsubscribe and a live suppression list exist. Proves you can honour PECR and CCPA opt-out obligations. It lies when the link is present but the suppression list is not actually wired in.
- Retention age. How long ago the data was collected, measured from original collection. Proves the storage-limitation principle is respected. It lies when a recent append date masks a years-old collection date.
The 2024 tightening matters here. The EDPB's October 2024 Guidelines 1/2024 replaced the previous Working Party opinions and set stricter criteria: the interest must be lawful, clearly articulated, and real. A vague "we want to grow" no longer clears the bar. When you score lawful basis, read the LIA for a specific, articulated interest, not a placeholder.
Grading provenance: the tier that anchors your risk
Provenance is the dimension with the clearest enforcement anchors, so grade it first and let it cap the others. Scraped personal data from an unknown source carries the highest documented risk; opt-in and a compliant vendor with a signed Data Processing Agreement carry the lowest.
| Provenance tier | Documented risk anchor | Relative risk |
|---|---|---|
| Opt-in / compliant vendor with DPA | none cited | Low |
| Enriched from unknown source | Article 14 notice failure (Poland EUR 220K) | High |
| Scraped personal data | Clearview roughly EUR 100M European fines | Highest |
Two cases do the work in this table. In the Clearview matter the ICO stated the onus is on the controller to demonstrate it can rely on one or more Article 6 lawful bases, and concluded Clearview had no processing ground it could rely upon. That is the scraped tier. The enriched tier is subtler and more common in outbound: Poland's DPA fined a data broker EUR 220,000 for scraping public business registries affecting 6.5 million people after it argued that notifying them was a "disproportionate effort." The fine turned on Article 14 notice failure, not the scraping itself.
That distinction is the whole reason enrichment is dangerous. Enrichment launders provenance without fixing it. When the original source is unknown, you cannot notify the data subject, so the defect travels with the record even after a clean-looking vendor appends it. A "compliant" marketing claim is not a contract. If a vendor cannot produce a signed DPA and name the original collection source, treat those rows as enriched-from-unknown and score them High.
Where a lawful-send verdict is built
- DocumentationLIA and decision filed in the Article 30 ROPA
- Opt-out and retentionworking unsubscribe, live suppression, collection date in range
- Subscriber and regimePECR subscriber type and applicable regime per row
- Lawful basiscompleted LIA with purpose, necessity, balancing
- Provenancedocumented origin you can actually notify from
Mapping jurisdiction to email rules
Jurisdiction sets which email default applies, and the defaults differ enough that a mixed list needs per-region scoring. Split every contact into UK/EU corporate, UK/EU individual, or California B2B, then read the rule off the matrix.
| Regime | Marketing email default | Retention benchmark cited |
|---|---|---|
| UK/EU corporate subscriber (PECR) | No prior consent; identity + opt-out required | ~2 yrs (ICO soft opt-in) |
| UK/EU individual subscriber (PECR) | Consent or soft opt-in required | CNIL 3 yrs prospect |
| California B2B (CCPA/CPRA post-2023) | Opt-out of sale/share; notice at collection | "reasonably necessary", no fixed period |
The corporate row is the one people over-read. You can send unsolicited electronic mail marketing to corporate subscribers without consent or a soft opt-in, but you must not disguise your identity and you must provide a valid opt-out address. The relief only applies to companies, LLPs, and Scottish partnerships. Sole traders and non-LLP partnerships count as individual subscribers, and so does a named personal address. Misclassify one and you have converted a lawful send into a regulation 22 breach.
For California, the operative change is that the old exemption is gone. By January 1, 2023, all California consumers, including B2B contacts, must have easy access to opt out of sharing of personal information that is sensitive, shared for behavioral marketing, or sold to third parties. This applies to for-profits meeting the thresholds: doing business in California with $25M or more in revenue, or holding data on 100,000 or more consumers. If you meet those thresholds, a California slice of your list needs a live opt-out and notice at collection, not a pre-2023 assumption.
A list is not compliant or non-compliant as a whole; the lawful-send question resolves per record and then rolls up.
When you need to find the accountable person to sign off the EU/UK slice - a DPO or privacy lead who can attach the LIA - the constraint is usually locating the right named role fast, not writing the assessment. Refolk turns that into a plain-English lookup instead of a manual hunt.
The scoring procedure
Run these steps in order for every new list. The output is a documented send, fix, or hold verdict filed in your records, not a gut feel.
Score a list from intake to filed verdict
- Intake and inventory the listLog source, field origins, record count, and jurisdiction split. Done when every row carries a documented provenance tag.
- Classify provenance per recordBucket each record into opt-in, compliant vendor with DPA, enriched-from-unknown, or scraped. Done when every record carries one of the four labels.
- Determine jurisdiction and regimeSplit EU/UK, California, and other, and map each contact to its regime. Done when every contact is tied to a named regime.
- Run and attach the LIAFor EU/UK legitimate-interest rows, record purpose, necessity, and balancing in writing before sending. Done when the LIA exists in writing and shows the three-part test was applied.
- Check PECR subscriber statusFlag sole traders, partnerships, and named personal addresses as individual subscribers. Done when each UK/EU email row is tagged with a subscriber type.
- Score opt-out readiness and retention ageConfirm a working unsubscribe, a live suppression list, and the original collection date. Done when every row has an age and a confirmed opt-out mechanism.
- Assign scores and land the verdictScore each dimension and decide send, fix, or hold with written reasoning. Done when a documented verdict names any failing dimensions.
- File the assessment into the ROPAStore the LIA and decision in the Article 30 record. Done when the assessment is retrievable for audit.
One order disagreement is worth flagging. Some practitioners run the LIA before mapping jurisdiction. ICO guidance implies jurisdiction and lawful basis are decided together, before processing begins, so I map regime first and attach the LIA to the EU/UK slice it actually covers. Doing it the other way risks writing an LIA for records that turn out to sit outside GDPR anyway.
The whole procedure is roughly a half-day of effort for a fresh list: intake and provenance classification take the most time, the LIA one to three hours depending on how novel the campaign is, and the scoring and filing under an hour combined.
The send, fix, hold decision
The verdict is a two-axis judgement: how strong is the provenance, and how ready is the compliance wrapper around it. That gives you four outcomes and a clear action for each.
The send / fix / hold decision
Read it plainly. Send rows have strong provenance and a complete wrapper: a compliant vendor with a DPA or opt-in, a written LIA, subscriber type tagged, working opt-out, and a collection date inside your retention window. Fix rows have good provenance but a missing piece you can add - most often an LIA that has not been written yet, an untagged subscriber type, or an unwired suppression list. Add it, re-score, and they become sends. Hold rows fail on provenance: enriched-from-unknown or scraped records where no wrapper can cure the underlying defect, because you cannot notify a data subject whose original source you do not know. Quarantine them and do not send.
How this goes wrong: the failure modes
Most bad sends come from a small set of repeatable errors, each with a false positive that makes a list look safer than it is. Score against this list explicitly, because these are the checks enforcement notices tend to expose.
- Treating legitimate interest as automatic for B2B. False positive: an LIA exists but was rubber-stamped after the send. Check: the LIA must record enough detail to demonstrate the three-part test was genuinely applied, with a specific articulated interest, not a template.
- Assuming a valid GDPR basis clears the email. False positive: the LIA passes but PECR consent for an individual subscriber is missing. Check: confirm subscriber type per row separately from the lawful-basis check.
- Misclassifying subscriber type. False positive: a sole trader or a named personal address treated as corporate. Check: if you are unsure whether details belong to an individual or a corporate subscriber, treat them as individual and comply with the electronic-mail rules.
- Assuming California B2B is still exempt. False positive: relying on a pre-2023 process. Check: confirm the opt-out and notice-at-collection are live for California rows.
- Stale lists dressed up as recent. False positive: a fresh enrichment date masks an original collection that is years old. Check: score against the original collection date, not the append date, and flag anything beyond two to three years.
- A vendor "compliant" claim with no DPA. False positive: a marketing badge treated as a contract. Check: the Polish broker's "disproportionate effort" defence for skipping Article 14 notice was rejected, so demand the signed DPA and the original source.
- Retention with no written schedule. False positive: data held indefinitely with no documented rule. Check: confirm a retention-principle statement citing Article 5(1)(e) exists, because the ICO looks for it specifically and its absence is a common enforcement finding.
The through-line is that each false positive replaces a check with an assumption. The rubric works because it forces the check back in: a subscriber type tagged per row, a collection date read from the right field, a DPA produced rather than claimed.
Before you call it done
Run this checklist before you release the list to the campaign owner. It is the minimum evidence a defensible verdict needs.
Lawful-send sign-off
- Every row carries one provenance label: opt-in, compliant vendor with DPA, enriched-from-unknown, or scraped
- Every contact is mapped to a regime: UK/EU, California, or other
- A written LIA with purpose, necessity, and balancing exists for the EU/UK legitimate-interest rows, dated before send
- Each UK/EU email row is tagged corporate or individual subscriber, with sole traders and personal addresses marked individual
- California rows have a live opt-out and notice at collection, not a pre-2023 assumption
- A working unsubscribe and an active suppression list are confirmed
- Each row has an original collection date, with anything past two to three years flagged
- A retention statement citing Article 5(1)(e) is on file
- The LIA and the send/fix/hold verdict are stored in the Article 30 ROPA
To document the reasoning consistently, use a fixed decision record. The point is that anyone auditing the list months later can reconstruct the call.
List name and campaign: Record count and jurisdiction split (UK/EU / California / other): Provenance breakdown (opt-in / vendor+DPA / enriched-unknown / scraped): Lawful basis for EU/UK rows (LIA reference and date completed): PECR subscriber types tagged (Y/N): California opt-out and notice-at-collection confirmed (Y/N/NA): Opt-out link and suppression list confirmed (Y/N): Oldest original collection date and count over 2-3 yrs: Retention statement (Article 5(1)(e)) on file (Y/N): Verdict: SEND / FIX / HOLD Failing dimensions and fix actions: Signed off by and date:
Fill one per list and store it in the ROPA next to the LIA. Keep the wording; change only the values.
Keeping the rubric current
The rubric is stable, but two inputs drift, so re-check them rather than trusting last quarter's answer. First, the retention benchmarks are guidance, not statute: CNIL suggests prospect data may be held up to three years and the ICO benchmarks soft opt-in recency at roughly two years, and both are ceilings tied to purpose. Re-read your regulator's current storage-limitation guidance when you set your list's cutoff, and keep the Article 5(1)(e) statement matched to it.
Second, the lawful-basis criteria tightened once already with the EDPB Guidelines 1/2024, which raised the bar on what a legitimate interest must show. Treat any new EDPB or ICO guidance on legitimate interest as a trigger to re-review your LIA template, because a template written to an older standard can quietly fall out of date while the list it covers keeps sending.
Score every new list the same way, file the decision every time, and the question "was this list lawful to send to?" stops being a re-reading of the regulation and becomes a lookup in your own ROPA.
Questions practitioners ask
Is cold email GDPR compliant for B2B?
It can be, but GDPR is only half the test in the UK and EU. A B2B cold email can rely on legitimate interest under Article 6(1)(f) if you complete a Legitimate Interest Assessment first, yet the same email can still breach PECR regulation 22 because the two consent regimes operate independently. Corporate subscribers need only your identity and a valid opt-out; individual subscribers such as sole traders need consent or soft opt-in. Score both dimensions, not one.
Do I still need a CCPA opt-out for California B2B prospects?
Yes. The CCPA employment and B2B exemptions sunset on January 1, 2023, so work emails, business phone numbers, and job titles of California residents are now covered personal information. California consumers, including B2B contacts, must have easy access to opt out of sale or sharing for behavioral marketing, and you owe notice at collection. Relying on a pre-2023 process is a live failure mode.
How do I document lawful basis for outreach?
Write a Legitimate Interest Assessment before processing starts, recording the interest, why the processing is necessary, and a balancing test showing your interest is not overridden by the person's rights. A retrospective LIA does not create a valid basis. Store the LIA inside your Article 30 Records of Processing Activities, and include a retention statement citing Article 5(1)(e), whose absence is a common enforcement finding.
How old is too old for a prospecting list?
There is no statutory number, only a defensible one tied to purpose. France's CNIL suggests prospect data may be held up to three years, and the ICO benchmarks soft opt-in recency at roughly two years for most consumer relationships. Score against the original collection date, not the enrichment or append date, since a recent append can mask data collected years earlier. Flag anything beyond two to three years for review.
What is the highest-risk provenance for a prospecting list?
Scraped personal data from an unknown source carries the highest documented enforcement risk. Clearview AI accumulated roughly EUR 100 million in European fines because it had no Article 6 basis it could rely upon. Enrichment from an unknown source is high risk too: Poland's DPA fined a broker EUR 220,000 for scraping business registries covering 6.5 million people, on Article 14 notice failure. Opt-in and compliant vendors with a signed DPA sit lowest.