Table of Contents
Is It Legal to Buy a Trade Show Attendee List? 2027 Compliance Guide

Is it legal to buy a trade show attendee list? Yes, in the US under CAN-SPAM, and in the EU under GDPR’s legitimate interest basis.
Search results on this question mostly answer with a blanket warning: don’t buy lists, full stop. That warning skips the actual regulatory text, which puts the responsibility on two things: where the provider sourced the data and how you use it after the sale. Exhibitors Data is registered as a data broker and ISO 27001 certified, so here’s what the actual regulatory text says instead of the warning.
What does US law say about buying an attendee list?
Commercial emails in the United States are governed by the CAN-SPAM Act, which does not exempt B2B communications (as affirmed by the Federal Trade Commission). All commercial e-mail messages should contain:
- Valid mailing addresses for senders
- Truthful subject lines
- Physical mailing addresses for senders
- Working opt-out capabilities for recipients, with opt-outs to be recognized within ten business days.
The act does not require consumers to grant permission to receive an initial email; however, the act prohibits sending email using lists you have purchased (although this is not an “opt-in”).
FTC fines may exceed $50,000.00 for each individual commercial email message sent out of compliance with the act. Each message will be considered individually under the terms of the act.
Many complaints and violations occur based on misleading subject lines, failure to include a functioning unsubscribe link or ignoring consumer opt-out instructions. These issues arise from how the campaign is transmitted.
Does GDPR allow buying attendee data for EU contacts?
GDPR requires a lawful basis before processing anyone’s personal data. For B2B outreach, that basis is usually legitimate interest under Article 6(1)(f). Regulatory guidance treats a professional contacted at a work address, about something relevant to their role as lower-risk than cold contact with a private consumer.
The obligation GDPR does attach to a purchase is documentation. Whoever imports the list becomes the data controller and has to show the processing is necessary, proportionate, and open to objection at any time. Penalties for getting that wrong reach €20 million or 4% of global annual revenue, whichever is higher, so the paperwork matters as much as the outreach itself.
What about CCPA and other US state privacy laws?
The California Consumer Privacy Act (CCPA) and approximately twenty-five other state-based consumer privacy regulations (covering states as far west as Oregon and as far east as Virginia) allow for both the aggregation and purchase of business contact lists. The rights afforded by these state statutes include consumers’ right to access all data collected about them, their right to request deletion, and their right to opt out of certain processing activities, regardless of whether or not such records have been resold multiple times prior to being received by an entity.
Violations of the CCPA can result in penalties that reach up to $7,988 per violation, and entities that refuse to honor opt-out requests are now subject to multi-million-dollar fines, including one settlement paid after ignoring such requests.
Does the law work the same way in Canada and elsewhere?
Canada is the exception. Its Anti-Spam Legislation, CASL, requires consent before you send a single commercial message to a Canadian address, business, or person. CAN-SPAM and GDPR let you contact someone first and handle objections after. CASL flips that: the consent has to exist before you send anything.
Two paths establish that consent:
- Express consent: a clear action like checking an unchecked box or filling out a form. It stays valid until withdrawn.
- Implied consent: an active business relationship within the last two years, an inquiry within the last six months, or the recipient’s own conspicuous publication of their business contact information.
A purchased attendee list rarely satisfies either on its own, since it doesn’t come from a relationship, and a bulk-compiled record isn’t the same as someone publishing their own contact details. Verify the email is genuinely public and role-relevant before emailing a Canadian contact from a purchased list, or open the relationship through LinkedIn first. CASL penalties run up to $10 million CAD per violation for organizations.
Outside Canada, most other regulated markets follow the US and EU pattern. A Germany events database or UK trade show list falls under GDPR based on where the attendee is located.
What makes an attendee list provider trustworthy?
The purchase itself checks out across every major market covered here, so the real diligence happens at the provider level. Look for:
- Registration as a data broker in jurisdictions that require it
- A published compliance framework naming the specific regulations it aligns with
- Independent security certification, such as ISO 27001, covering how the data is stored and transferred
- A documented sourcing method you can point to if a regulator or a recipient asks where their information came from
- A working sample so you can verify field accuracy before the data enters your CRM
Exhibitors Data holds a Texas data broker registration and ISO 27001 certification. The data compliance page names the specific regulations it aligns with, including GDPR, CCPA, and CASL, among others. The client case studies show what that looks like in practice, and how the process works, walking through it step by step.
Also read- How to Get Verified Exhibitor Contacts in Minutes with Smart List Builder
Does the event organizer have to approve the sale?
A related but separate question: the show owner collected this list, so shouldn’t they control what happens to it?
Event organizers do control their own registration systems. A provider that pulls data directly off a ticketing platform without permission takes on exposure under that platform’s terms of service, a separate issue from privacy law. A provider working from public professional sources, industry directories, and organizer partnerships is compiling publicly available business information, a lower-risk sourcing method entirely.
Ask a provider directly which of the two describes their sourcing. A licensing agreement covers the first. Public sourcing covers the second. Confirm which one applies before signing a contract.
How do I use a purchased list without violating the law?
Buying the data lawfully is step one. How you use it after that decides the outcome. Segment by role and relevance before sending anything, since a generic blast to every title on a list fails the GDPR necessity test and reads as spam regardless of jurisdiction. Refresh the list on a schedule too: attendee rosters shift between registration and event dates, and outdated records drive bounce rates independent of any legal question.
Teams working on a specific show can filter by industry sector, pull data through the API integration directly into a CRM, or bring in the data consultancy team to build segmentation rules before the first send. The same rules apply to a companion exhibitor list pulled from the same event, which many teams use alongside attendee data to map competitors and partners.
Also read- What Can You Do With Exhibitor and Attendee Data Before a Trade Show?
What should you check before your next campaign?
- Ask the provider where the data came from, in writing.
- Confirm their registration and certification status directly.
- Pull a sample first and check the fields against what your outreach needs.
- Segment Canadian contacts separately and apply the stricter consent standard before sending.
- Build the unsubscribe and opt-out workflow before the first email goes out, and route objections straight to an immediate opt-out.
Review a sample dataset, check the compliance documentation, or run through the full FAQ to confirm each of these before a list is ready to send.
How to Build a Market Entry Strategy Without Wasting Resources
When a company is considering a new market, the starting point of any solid Market Entry Strategy is often the total size of that market. How much does the industry spend in that country? How fast is it growing? How...