ACCEPTABLE RISK

You Bought the Data. You Still Own the Decision.

Paul Maxwell / Acceptable Risk

Precision-engineered decision mechanism showing third-party data moving through review, assessment and decision to proceed or hold.

Buying a marketing list can make the compliance question look deceptively simple. A supplier provides the data, a contract, perhaps a compliance statement, and the organisation receiving it moves on to campaign planning.

The harder question starts after the purchase: what exactly are we going to do with this information, and what evidence supports that use?

That distinction matters in UK B2B marketing because the rules are not the same for every recipient or every channel. The ICO’s current guidance distinguishes corporate subscribers from sole traders and some partnerships. The PECR rule on electronic-mail marketing does not apply to corporate subscribers in the same way it applies to individual subscribers. UK GDPR still applies where the organisation is processing personal data, such as a named business contact, and the organisation still needs a lawful basis, transparency and a way to respect objections.

So “B2B data” is not a legal answer. Neither is “the broker said it was compliant”.

The ICO’s guidance on buying or renting information for direct marketing is practical on this point. The organisation receiving the information remains responsible for its own compliance. The ICO says it must carry out proportionate checks and due diligence before obtaining the data, including understanding who compiled it, where it came from, what people were told, how old it is, how it was collected and what consent records exist where consent is relevant. The ICO also says the buyer must be able to demonstrate its own lawful basis and should not use information where the supplier cannot demonstrate that it is reliable.

Supplier assurance is useful, but it is an input to a decision about your intended use.

In May 2025, the CNIL fined SOLOCAL Marketing Services €900,000. SOLOCAL acquired prospect data from data brokers and used it for electronic marketing. The CNIL found that the consent obtained upstream was not valid for the activity it examined. It also found that SOLOCAL could not provide proof of consent for data supplied by one of its main providers. After discovering that the provider could not produce the evidence, SOLOCAL continued using the data for nearly 17 months before stopping.

The useful part of that case for a UK reader is not to import the French consent rule into every UK B2B campaign. It is the evidence problem. The CNIL found SOLOCAL’s upstream contractual requirements and the checks it said it carried out were insufficient. It also examined whether the organisation using the data could support the processing it was carrying out.

CALOGA, fined €80,000 by the CNIL in May 2025, provides corroboration from another part of the data-broker chain. The CNIL found problems with electronic-marketing consent and the legal basis for passing prospect data onwards, and found the contractual guarantees and checks insufficient in the circumstances. Its value here is narrow: supplier arrangements did not prevent the authority looking through to the underlying collection, evidence and use.

For a UK organisation, the practical job is to separate five questions that often get bundled together.


SOURCE: Where did the information actually come from?

“From our broker” may only describe the last transfer. The ICO suggests checking who compiled the information, the original source, the collection method and when it was gathered.


PURPOSE: What are we going to do with it?

Emailing a corporate subscriber, emailing a sole trader, making live calls, enriching an existing customer record and profiling people are different activities. The organisation needs enough specificity about its intended use to work out which rules apply.


AUTHORITY: What supports that use?

Recipient, channel and data type matter. PECR may require consent for one activity and not another. UK GDPR can still apply to a named business contact even where the PECR electronic-mail consent rule does not apply to a corporate subscriber. Where consent is not required under PECR, legitimate interests may be available as the UK GDPR lawful basis if the relevant test is satisfied.

The useful question is not “does the data have consent?” in isolation. It is “what legal and operational basis supports the use we actually intend?”


EVIDENCE: What have we actually seen?

The ICO’s current guidance goes beyond asking for a supplier statement. It points to the original source, privacy information, collection date and method, consent records where relevant, suppression checks and how rights and objections are handled. Due diligence should be proportionate, but the evidence should be good enough for the decision being made.


DECISION: Who accepted the evidence and authorised the use?

This is easiest to lose between marketing, procurement, privacy and legal teams. Procurement may establish what the supplier promised. Privacy may interpret the legal requirements. Marketing may define the campaign. Someone still needs to decide that the proposed use is supported by the evidence available, record any conditions and know what would cause the decision to be revisited.

In many cases a short decision note is more useful than another policy: intended use, relevant recipient/channel distinction, lawful basis, evidence reviewed, unresolved conditions and decision owner.

The ICO says a buyer should not use information if the third party cannot demonstrate that it is reliable or if the buyer is not satisfied with its explanations. SOLOCAL adds a useful consequence. Once a material evidence gap is known, continuing to use the data becomes a fresh organisational decision rather than a historical supplier problem.

I would therefore treat a broker’s compliance statement as supporting evidence. The operating control is the organisation’s ability to understand the source and intended use, identify what authority supports that use, examine proportionate evidence and make an accountable decision before the data is used.


References


About the author

Paul Maxwell writes about the gap between what organisations say is controlled and what the evidence shows is actually working.

Acceptable Risk is his practitioner-led library on governance in operational reality.

Discover more from Acceptable Risk (Documented)

Subscribe now to keep reading and get access to the full archive.

Continue reading