Blog

Useful tips when using third party mailing lists

Having had an interesting chat with a client recently about using bought-in or rented mailing lists from third parties to undertake direct marketing activities I thought it would be useful to share some useful tips and reminders when it comes to using such lists for your own direct marketing activities.

Remember, when it comes to direct marketing you must comply with:

  • General Data Protection Regulation (GDPR)
  • Data Protection Act 2018
  • Privacy & Electronic Communications Regulations 2003

I must stress these useful tips relate to consented mailing lists, i.e. the individual has consented for their personal data to be used for direct marketing activities.  These tips are also in line with the ICO’s guidance (as at May 2020).

1. It is a requirement when buying or renting a consented marketing list, that the consent request has identified you specifically as a business who will use the contact details of the individual to send them marketing.  This means that the third-party business who compiled the marketing list specifically identified you on the opt-in/consent form used by individuals to sign up to receive direct marketing.  You should ensure you have a copy of the consent form to make sure your business is named on the list and that it allows the individual to opt-in to different ways to receive your marketing.

2. It is your responsibility to check that the third party who compiled the list has obtained the personal data fairly and lawfully and that the individuals who signed up knew that their details would be passed on to you for marketing purposes.

3. It is your responsibility to check how and when the consents from the individuals were obtained, along with what they were told at the time of signing the consent.  You need to ask for evidence from the third party that you are buying or renting the list from for these details.

4. It is your responsibility to undertake all necessary due diligence checks with the third party to ensure the marketing list you are buying or renting does have the valid consent of individuals and complies with other areas of data protection and e-privacy laws. These are just some of the types of questions you should be asking:

  • When was the list compiled?
  • Has the list been amended or updated since it was originally compiled?
  • When were the consents of the individuals obtained?
  • Did the consents list your organisation by name, by general description or was the consent for disclosure to any third party?
  • Has the list been screened against the TPS?
  • What was the individual told at the time of consent and how did they provide consent?

5. You must ensure your own privacy notices include information on how you obtained an individual’s personal data – this includes when you buy or rent marketing lists from third parties.

6. Your marketing messages should include the name and contact details of the third party who you bought or rented the marketing list from.

These are just some of the things you need to do when it comes to using consented bought or rented marketing lists within your business. 

If this now raises questions with you on your data protection compliance relating to your marketing activities, or any other aspect of data protection for that matter, do get in touch for a chat.