Refolk
FrameworkProcess, data, and compliance

Scoring an Outbound Contact List for Lawful Send

You can score any prospecting list on six dimensions and land a documented send, fix, or hold verdict before the campaign launches.

16 min readLast reviewed August 1, 2026Read as Markdown

Key takeaways

  • A list can pass GDPR and still be unlawful to email: a GDPR-lawful email can breach PECR regulation 22 because the two consent regimes operate independently.
  • Provenance carries documented enforcement weight - scraped personal data anchors to Clearview's roughly EUR 100 million in European fines, while enrichment from an unknown source anchors to Poland's EUR 220,000 Article 14 notice fine.
  • A Legitimate Interest Assessment must be completed and documented in writing before processing starts; a retrospective LIA does not create a valid lawful basis.
  • Retention has no safe number, only a defensible one: CNIL suggests up to 3 years for prospect data and the ICO benchmarks soft opt-in recency at roughly two years, both tied to purpose.
  • Jurisdiction follows the data subject, not the server: Clearview, a US company with no EU offices, still accumulated roughly EUR 100 million in European fines.
  • In Refolk's index, the UK returns 693 people with a current Data Protection Officer title against 78 in the US, an 8.9x ratio that tracks the density of the compliance function.

Before you launch an outbound campaign, someone has to decide whether this specific list is lawful to send to, and write down why. This guide is for the revenue-operations or data owner who is answerable for that call. It gives you a six-dimension scoring rubric so you grade every new list the same way twice, and land a documented send, fix, or hold verdict instead of re-reading the regulation each time.

The premise is simple: a list is not "compliant" or "non-compliant" as a whole. It is a mix of provenance, jurisdictions, subscriber types, and ages, and the lawful-send question resolves per record and then rolls up. The job is to make that roll-up repeatable.

Why one lawful-basis check is not enough

A list can pass GDPR and still be unlawful to email. That single fact is why this guide scores six dimensions instead of asking one question.

The trap is treating "do we have a lawful basis?" as the whole test. In the UK and EU it is not. A marketing email that is lawful under UK GDPR legitimate interest can still breach PECR regulation 22 if the recipient has not given separate PECR consent, because the two consent regimes operate independently. So you can build a spotless Legitimate Interest Assessment, satisfy GDPR, and still send an unlawful email to a sole trader who counts as an individual subscriber.

The same layering shows up across jurisdictions. California removed its shortcut in 2023: the CCPA employment and B2B exemptions sunset on January 1, 2023, so work emails, business phone numbers, and job titles are now covered personal information. And extraterritoriality removes "we are US-based" as a defence entirely. Clearview, a US company with no EU offices, accumulated roughly EUR 100 million in European fines. Jurisdiction follows the data subject, not the server.

The density of the compliance function tracks this complexity. In Refolk's index, the countries with the most layered regimes staff the accountable role most heavily.

CountryDPO-titled peopleRatio vs US
United States781.0x
Germany2012.6x
United Kingdom6938.9x
8.9x
UK Data Protection Officer supply vs the US, in Refolk's index
The UK returns 693 people with a current DPO title against 78 in the US, tracking the density of a compliance function where PECR sits on top of UK GDPR.

The mechanism behind the gap: PECR layered on UK GDPR, plus an ICO with a public enforcement register, makes a named accountable role near-mandatory. In the US the B2B exemption only lapsed in 2023. The takeaway for your scoring is that no single dimension is decisive, and the ones people skip - subscriber type, provenance, retention age - are exactly the ones enforcement turns on.

The six dimensions and what each one proves

Score every list on six dimensions. Each proves a different failure, and each has a tell when the score is lying to you.

  • Provenance. Where the record came from. Proves whether you can even establish a lawful basis. It lies when a "compliant vendor" badge stands in for a signed contract.
  • Lawful basis. For EU/UK, whether a completed Legitimate Interest Assessment exists. Proves the processing has a ground. It lies when the LIA was rubber-stamped after send.
  • Role relevance. Whether the contact's job makes your message a genuine, expected interest. Proves the necessity and balancing halves of the LIA. It lies when the role is a loose keyword match, not a real buyer.
  • Jurisdiction mix. Which regimes apply across the list. Proves which rules you must satisfy. It lies when "mostly US" hides a slice of EU residents.
  • Opt-out readiness. Whether a working unsubscribe and a live suppression list exist. Proves you can honour PECR and CCPA opt-out obligations. It lies when the link is present but the suppression list is not actually wired in.
  • Retention age. How long ago the data was collected, measured from original collection. Proves the storage-limitation principle is respected. It lies when a recent append date masks a years-old collection date.

The 2024 tightening matters here. The EDPB's October 2024 Guidelines 1/2024 replaced the previous Working Party opinions and set stricter criteria: the interest must be lawful, clearly articulated, and real. A vague "we want to grow" no longer clears the bar. When you score lawful basis, read the LIA for a specific, articulated interest, not a placeholder.

Grading provenance: the tier that anchors your risk

Provenance is the dimension with the clearest enforcement anchors, so grade it first and let it cap the others. Scraped personal data from an unknown source carries the highest documented risk; opt-in and a compliant vendor with a signed Data Processing Agreement carry the lowest.

Provenance tierDocumented risk anchorRelative risk
Opt-in / compliant vendor with DPAnone citedLow
Enriched from unknown sourceArticle 14 notice failure (Poland EUR 220K)High
Scraped personal dataClearview roughly EUR 100M European finesHighest

Two cases do the work in this table. In the Clearview matter the ICO stated the onus is on the controller to demonstrate it can rely on one or more Article 6 lawful bases, and concluded Clearview had no processing ground it could rely upon. That is the scraped tier. The enriched tier is subtler and more common in outbound: Poland's DPA fined a data broker EUR 220,000 for scraping public business registries affecting 6.5 million people after it argued that notifying them was a "disproportionate effort." The fine turned on Article 14 notice failure, not the scraping itself.

That distinction is the whole reason enrichment is dangerous. Enrichment launders provenance without fixing it. When the original source is unknown, you cannot notify the data subject, so the defect travels with the record even after a clean-looking vendor appends it. A "compliant" marketing claim is not a contract. If a vendor cannot produce a signed DPA and name the original collection source, treat those rows as enriched-from-unknown and score them High.

Where a lawful-send verdict is built

  1. Documentation
    LIA and decision filed in the Article 30 ROPA
  2. Opt-out and retention
    working unsubscribe, live suppression, collection date in range
  3. Subscriber and regime
    PECR subscriber type and applicable regime per row
  4. Lawful basis
    completed LIA with purpose, necessity, balancing
  5. Provenance
    documented origin you can actually notify from
Each layer must hold before the one above it counts, so a defect at the base cannot be patched at the top.

Mapping jurisdiction to email rules

Jurisdiction sets which email default applies, and the defaults differ enough that a mixed list needs per-region scoring. Split every contact into UK/EU corporate, UK/EU individual, or California B2B, then read the rule off the matrix.

RegimeMarketing email defaultRetention benchmark cited
UK/EU corporate subscriber (PECR)No prior consent; identity + opt-out required~2 yrs (ICO soft opt-in)
UK/EU individual subscriber (PECR)Consent or soft opt-in requiredCNIL 3 yrs prospect
California B2B (CCPA/CPRA post-2023)Opt-out of sale/share; notice at collection"reasonably necessary", no fixed period

The corporate row is the one people over-read. You can send unsolicited electronic mail marketing to corporate subscribers without consent or a soft opt-in, but you must not disguise your identity and you must provide a valid opt-out address. The relief only applies to companies, LLPs, and Scottish partnerships. Sole traders and non-LLP partnerships count as individual subscribers, and so does a named personal address. Misclassify one and you have converted a lawful send into a regulation 22 breach.

For California, the operative change is that the old exemption is gone. By January 1, 2023, all California consumers, including B2B contacts, must have easy access to opt out of sharing of personal information that is sensitive, shared for behavioral marketing, or sold to third parties. This applies to for-profits meeting the thresholds: doing business in California with $25M or more in revenue, or holding data on 100,000 or more consumers. If you meet those thresholds, a California slice of your list needs a live opt-out and notice at collection, not a pre-2023 assumption.

A list is not compliant or non-compliant as a whole; the lawful-send question resolves per record and then rolls up.

When you need to find the accountable person to sign off the EU/UK slice - a DPO or privacy lead who can attach the LIA - the constraint is usually locating the right named role fast, not writing the assessment. Refolk turns that into a plain-English lookup instead of a manual hunt.

The scoring procedure

Run these steps in order for every new list. The output is a documented send, fix, or hold verdict filed in your records, not a gut feel.

Score a list from intake to filed verdict

  1. Intake and inventory the list
    Log source, field origins, record count, and jurisdiction split. Done when every row carries a documented provenance tag.
  2. Classify provenance per record
    Bucket each record into opt-in, compliant vendor with DPA, enriched-from-unknown, or scraped. Done when every record carries one of the four labels.
  3. Determine jurisdiction and regime
    Split EU/UK, California, and other, and map each contact to its regime. Done when every contact is tied to a named regime.
  4. Run and attach the LIA
    For EU/UK legitimate-interest rows, record purpose, necessity, and balancing in writing before sending. Done when the LIA exists in writing and shows the three-part test was applied.
  5. Check PECR subscriber status
    Flag sole traders, partnerships, and named personal addresses as individual subscribers. Done when each UK/EU email row is tagged with a subscriber type.
  6. Score opt-out readiness and retention age
    Confirm a working unsubscribe, a live suppression list, and the original collection date. Done when every row has an age and a confirmed opt-out mechanism.
  7. Assign scores and land the verdict
    Score each dimension and decide send, fix, or hold with written reasoning. Done when a documented verdict names any failing dimensions.
  8. File the assessment into the ROPA
    Store the LIA and decision in the Article 30 record. Done when the assessment is retrievable for audit.

One order disagreement is worth flagging. Some practitioners run the LIA before mapping jurisdiction. ICO guidance implies jurisdiction and lawful basis are decided together, before processing begins, so I map regime first and attach the LIA to the EU/UK slice it actually covers. Doing it the other way risks writing an LIA for records that turn out to sit outside GDPR anyway.

The whole procedure is roughly a half-day of effort for a fresh list: intake and provenance classification take the most time, the LIA one to three hours depending on how novel the campaign is, and the scoring and filing under an hour combined.

The send, fix, hold decision

The verdict is a two-axis judgement: how strong is the provenance, and how ready is the compliance wrapper around it. That gives you four outcomes and a clear action for each.

The send / fix / hold decision

Strong provenanceWeak provenance
Documented but unsourceable
Hold: an LIA cannot cure records you cannot notify or trace
Send-ready
Send: opt-in or DPA-backed rows with LIA, subscriber type, opt-out, and age all in range
Hold
Hold: neither provenance nor wrapper holds, so quarantine the whole slice
Fixable
Fix: good origin, missing LIA or subscriber tag or opt-out; close the gap then re-score
Weak compliance wrapperStrong compliance wrapper
Provenance sets the floor; compliance readiness sets whether you can act on it now.

Read it plainly. Send rows have strong provenance and a complete wrapper: a compliant vendor with a DPA or opt-in, a written LIA, subscriber type tagged, working opt-out, and a collection date inside your retention window. Fix rows have good provenance but a missing piece you can add - most often an LIA that has not been written yet, an untagged subscriber type, or an unwired suppression list. Add it, re-score, and they become sends. Hold rows fail on provenance: enriched-from-unknown or scraped records where no wrapper can cure the underlying defect, because you cannot notify a data subject whose original source you do not know. Quarantine them and do not send.

How this goes wrong: the failure modes

Most bad sends come from a small set of repeatable errors, each with a false positive that makes a list look safer than it is. Score against this list explicitly, because these are the checks enforcement notices tend to expose.

  • Treating legitimate interest as automatic for B2B. False positive: an LIA exists but was rubber-stamped after the send. Check: the LIA must record enough detail to demonstrate the three-part test was genuinely applied, with a specific articulated interest, not a template.
  • Assuming a valid GDPR basis clears the email. False positive: the LIA passes but PECR consent for an individual subscriber is missing. Check: confirm subscriber type per row separately from the lawful-basis check.
  • Misclassifying subscriber type. False positive: a sole trader or a named personal address treated as corporate. Check: if you are unsure whether details belong to an individual or a corporate subscriber, treat them as individual and comply with the electronic-mail rules.
  • Assuming California B2B is still exempt. False positive: relying on a pre-2023 process. Check: confirm the opt-out and notice-at-collection are live for California rows.
  • Stale lists dressed up as recent. False positive: a fresh enrichment date masks an original collection that is years old. Check: score against the original collection date, not the append date, and flag anything beyond two to three years.
  • A vendor "compliant" claim with no DPA. False positive: a marketing badge treated as a contract. Check: the Polish broker's "disproportionate effort" defence for skipping Article 14 notice was rejected, so demand the signed DPA and the original source.
  • Retention with no written schedule. False positive: data held indefinitely with no documented rule. Check: confirm a retention-principle statement citing Article 5(1)(e) exists, because the ICO looks for it specifically and its absence is a common enforcement finding.

The through-line is that each false positive replaces a check with an assumption. The rubric works because it forces the check back in: a subscriber type tagged per row, a collection date read from the right field, a DPA produced rather than claimed.

Before you call it done

Run this checklist before you release the list to the campaign owner. It is the minimum evidence a defensible verdict needs.

Lawful-send sign-off

  • Every row carries one provenance label: opt-in, compliant vendor with DPA, enriched-from-unknown, or scraped
  • Every contact is mapped to a regime: UK/EU, California, or other
  • A written LIA with purpose, necessity, and balancing exists for the EU/UK legitimate-interest rows, dated before send
  • Each UK/EU email row is tagged corporate or individual subscriber, with sole traders and personal addresses marked individual
  • California rows have a live opt-out and notice at collection, not a pre-2023 assumption
  • A working unsubscribe and an active suppression list are confirmed
  • Each row has an original collection date, with anything past two to three years flagged
  • A retention statement citing Article 5(1)(e) is on file
  • The LIA and the send/fix/hold verdict are stored in the Article 30 ROPA

To document the reasoning consistently, use a fixed decision record. The point is that anyone auditing the list months later can reconstruct the call.

Per-list lawful-send decision record
List name and campaign:
Record count and jurisdiction split (UK/EU / California / other):
Provenance breakdown (opt-in / vendor+DPA / enriched-unknown / scraped):
Lawful basis for EU/UK rows (LIA reference and date completed):
PECR subscriber types tagged (Y/N):
California opt-out and notice-at-collection confirmed (Y/N/NA):
Opt-out link and suppression list confirmed (Y/N):
Oldest original collection date and count over 2-3 yrs:
Retention statement (Article 5(1)(e)) on file (Y/N):
Verdict: SEND / FIX / HOLD
Failing dimensions and fix actions:
Signed off by and date:

Fill one per list and store it in the ROPA next to the LIA. Keep the wording; change only the values.

Keeping the rubric current

The rubric is stable, but two inputs drift, so re-check them rather than trusting last quarter's answer. First, the retention benchmarks are guidance, not statute: CNIL suggests prospect data may be held up to three years and the ICO benchmarks soft opt-in recency at roughly two years, and both are ceilings tied to purpose. Re-read your regulator's current storage-limitation guidance when you set your list's cutoff, and keep the Article 5(1)(e) statement matched to it.

Second, the lawful-basis criteria tightened once already with the EDPB Guidelines 1/2024, which raised the bar on what a legitimate interest must show. Treat any new EDPB or ICO guidance on legitimate interest as a trigger to re-review your LIA template, because a template written to an older standard can quietly fall out of date while the list it covers keeps sending.

Score every new list the same way, file the decision every time, and the question "was this list lawful to send to?" stops being a re-reading of the regulation and becomes a lookup in your own ROPA.

Questions practitioners ask

Is cold email GDPR compliant for B2B?

It can be, but GDPR is only half the test in the UK and EU. A B2B cold email can rely on legitimate interest under Article 6(1)(f) if you complete a Legitimate Interest Assessment first, yet the same email can still breach PECR regulation 22 because the two consent regimes operate independently. Corporate subscribers need only your identity and a valid opt-out; individual subscribers such as sole traders need consent or soft opt-in. Score both dimensions, not one.

Do I still need a CCPA opt-out for California B2B prospects?

Yes. The CCPA employment and B2B exemptions sunset on January 1, 2023, so work emails, business phone numbers, and job titles of California residents are now covered personal information. California consumers, including B2B contacts, must have easy access to opt out of sale or sharing for behavioral marketing, and you owe notice at collection. Relying on a pre-2023 process is a live failure mode.

How do I document lawful basis for outreach?

Write a Legitimate Interest Assessment before processing starts, recording the interest, why the processing is necessary, and a balancing test showing your interest is not overridden by the person's rights. A retrospective LIA does not create a valid basis. Store the LIA inside your Article 30 Records of Processing Activities, and include a retention statement citing Article 5(1)(e), whose absence is a common enforcement finding.

How old is too old for a prospecting list?

There is no statutory number, only a defensible one tied to purpose. France's CNIL suggests prospect data may be held up to three years, and the ICO benchmarks soft opt-in recency at roughly two years for most consumer relationships. Score against the original collection date, not the enrichment or append date, since a recent append can mask data collected years earlier. Flag anything beyond two to three years for review.

What is the highest-risk provenance for a prospecting list?

Scraped personal data from an unknown source carries the highest documented enforcement risk. Clearview AI accumulated roughly EUR 100 million in European fines because it had no Article 6 basis it could rely upon. Enrichment from an unknown source is high risk too: Poland's DPA fined a broker EUR 220,000 for scraping business registries covering 6.5 million people, on Article 14 notice failure. Opt-in and compliant vendors with a signed DPA sit lowest.

Read next