Compliance & lawful use
What buyers must do to use individual and business contact data lawfully, and what we do and do not claim.
Your responsibilities as a buyer
Buying a dataset does not give anyone's consent to be contacted. Before using the data you must make sure your use is lawful where you and the recipients are located. Depending on the country and channel, that may include:
- Telephone: screening against do-not-call registers such as the UK TPS/CTPS, the US National Do Not Call Registry, and equivalents elsewhere, and following telemarketing time and identification rules.
- Email: rules such as the UK PECR, EU ePrivacy rules and the US CAN-SPAM Act โ including identifying yourself, providing an opt-out and honouring it promptly.
- Data protection: individual contact records relate to identifiable people, and so can business records (for example a named contact or a sole trader). Laws such as the UK GDPR / EU GDPR apply to how you store, use and secure the data, and you need your own lawful basis for processing.
What we do
- Individual-contact datasets are published only with documented sourcing, permitted use, lawful basis and a compliance note, shown on each dataset page.
- We refuse sensitive personal categories.
- We act on removal requests and exclude removed records from future versions.
- We publish how our data is processed and measured.
What we do not claim
We do not claim any dataset is "GDPR compliant" or "pre-screened" for your purpose. Compliance depends on how you use the data, and only you can ensure that.
See also the acceptable use policy.
Last updated 2026-09-30
