Brazil LGPD Email Marketing Consent Requirements for Purchased and Third-Party Lists

Brazil LGPD Email Marketing Consent Requirements for Purchased and Third-Party Lists

By:

Date:

Do not send marketing emails to a purchased Brazilian list unless you can prove each person agreed to that exact use. Under Brazil’s LGPD, “we bought the list” is not a magic shield. You still need a valid legal basis, clear records, and an easy way to unsubscribe.

TLDR: Purchased and third-party email lists are risky under the LGPD because you must prove valid consent or another legal basis for each contact. If a vendor gives you 20,000 emails but only 35% have clear opt-in records, the other 13,000 contacts are trouble waiting to happen. Example: if Ana signed up for “shoe discounts from Store A,” that does not mean you can email her about “crypto webinars from Company B.” Keep proof, honor opt-outs fast, and do not trust vague vendor promises.

The simple rule

The LGPD is Brazil’s main data protection law. It applies when you process personal data in Brazil. An email address can be personal data. A name plus email is even more obvious.

If you use that data for email marketing, you are processing personal data. That means you need a legal basis. For purchased and third-party lists, the safest legal basis is usually consent. But not just any consent.

LGPD consent must be:

  • Free: no pressure tricks.
  • Informed: the person knew what they agreed to.
  • Unequivocal: the action was clear.
  • Specific: tied to a clear purpose.

That last word matters a lot. Specific means the person understood who would contact them and why. “Receive partner offers” is often too fuzzy. “Receive weekly email offers from XYZ Travel and selected hotel partners” is better.

Why purchased lists are a headache

The catch is that purchased lists often come with weak paperwork. The seller may say, “All contacts opted in.” Great. Where is the proof? What did the form say? When did the user click it? Was the buyer named? Was the purpose marketing? Was third-party sharing explained?

If the answer is “not sure,” you have a problem.

Under the LGPD, the company using the list must show that processing is lawful. Blaming the broker will not save you from every mess. You may still face complaints, lawsuits, bad sender reputation, and attention from Brazil’s data protection authority, the ANPD.

It drives me crazy that some list vendors send a spreadsheet in 8 seconds but need 8 days to send opt-in proof. That tells you a lot.

Can you use legitimate interest instead?

Sometimes, yes. LGPD allows processing based on legitimate interest. Some businesses use it for limited marketing to existing customers or people with a real prior relationship.

But bought lists are different. The people often have no relationship with you. They may not expect your email. That makes legitimate interest harder to defend.

If you try to use legitimate interest, you should have:

  • A real and lawful business purpose.
  • A link between the person and your offer.
  • A low privacy impact.
  • A clear opt-out in every message.
  • A documented balancing test.

For random cold email blasts, that will feel thin. Very thin. Like carnival confetti in a rainstorm.

What valid third-party consent should show

If a list seller or partner claims the contacts consented, ask for proof before sending anything.

You want records showing:

  • Date and time of consent.
  • Source of the signup.
  • Exact wording shown to the user.
  • Purpose of the email marketing.
  • Identity of the controller or clear partner category.
  • Proof of action, such as a checked box or signup confirmation.
  • Withdrawal method offered to the user.

A pre-checked box is a bad idea. Silence is not a friendly yes. Hiding permission inside long terms is also risky. People should understand what they are agreeing to without needing coffee, a lawyer, and a magnifying glass.

Third-party lists need extra care

A third-party list can mean many things. A co-marketing list. A sponsor list from an event. A data broker file. A partner newsletter audience. Each one has a different risk level.

Ask one blunt question:

Would the person be surprised to get our email?

If yes, pause.

If Maria signs up for a fitness expo and agrees to receive offers from “event sponsors,” she may expect emails from gyms, sportswear brands, and nutrition companies. She may not expect emails from a car loan company. Context matters.

What your first email should include

If you decide the list is usable, your email still needs to be clean and honest.

Include:

  • Your company name.
  • Why the person is receiving the email.
  • A clear unsubscribe link.
  • A link to your privacy notice.
  • Contact details for privacy requests.

Do not make unsubscribe painful. Do not force a login. Do not ask for a password. Do not make people click through five screens. One or two clicks should do it.

Also, process opt-outs quickly. If João unsubscribes on Monday and gets another promo on Friday, he will not think, “Ah, batch sync issue.” He will think, “Spam.” Fair enough.

What about consent withdrawal?

Under the LGPD, people can withdraw consent. The process should be easy and free. If consent is your legal basis, you must stop using the email for that purpose after withdrawal.

You can keep a suppression record. That means you keep just enough data to avoid emailing the person again. This is usually practical and wise. Otherwise, you may delete them today and re-import them next month from another messy spreadsheet. Nobody wants that clown show.

Watch out for sensitive data and children

Some email lists are much riskier than others. Health, religion, politics, union membership, biometrics, and similar data can be sensitive personal data. Marketing based on these traits needs extra caution.

Children’s data is also special. The LGPD requires processing to be in the child’s best interest. Parental consent may be needed. Do not buy kids’ email lists. Just do not.

Vendor contracts matter

If you buy or receive a list, your contract should not be fluffy. It should require the vendor to prove lawful collection and sharing.

Add terms covering:

  • LGPD compliance.
  • Consent proof on request.
  • Data source details.
  • Limits on use.
  • Security duties.
  • Help with privacy requests.
  • Indemnity for bad data claims.

Contracts help. They do not fix bad consent. A beautiful contract attached to an illegal list is still a shiny problem.

A quick yes or no test

Before using a purchased or third-party list in Brazil, ask these questions:

  • Do we know where the emails came from?
  • Can we prove consent or another legal basis?
  • Was our company named, or was our category clear?
  • Was marketing clearly described?
  • Can users unsubscribe easily?
  • Did we check for sensitive data?
  • Do we have a privacy notice in Portuguese?
  • Can we answer a user complaint fast?

If you answer “no” to several items, do not send. Clean the list first. Or skip it.

Better options than buying lists

Build your own list. Yes, it takes longer. It also performs better.

Try:

  • Newsletter signups with clear checkboxes.
  • Lead magnets with honest consent language.
  • Webinar registration forms.
  • Customer loyalty emails.
  • Referral campaigns with careful rules.
  • Co-marketing where each brand is named.

A smaller list with real permission can beat a giant cold list. A 5,000-person opt-in list with a 28% open rate gives you 1,400 opens. A 50,000-person purchased list with a 2% open rate gives you 1,000 opens, plus complaints. That math is not cute.

The practical bottom line

For Brazil LGPD email marketing, purchased lists are not banned by name. But they are often hard to use lawfully. You need proof. You need clear purpose. You need easy opt-out. You need respect for user rights.

Best move: treat every purchased or third-party list as guilty until the records prove it clean. If the consent trail is vague, stale, or missing, do not hit send. Your sender score, legal team, and future customers will thank you.

Categories:

Tags:

Leave a Reply

Your email address will not be published. Required fields are marked *