# Are bought leads GDPR compliant?

Bought leads can be fully compliant with UK GDPR and PECR if the person gave clear, specific consent to be contacted by a business like yours, and that consent is passed to you with the lead. They are not compliant if they were scraped, sold as a cold list, or only ever consented to the original website. Always check the consent trail before you buy.

Category: Compliance  
Reading time: about 6 minutes

## The rules in plain English

Two things govern this in the UK: UK GDPR, which covers how personal data is handled, and PECR, which covers electronic marketing like calls, texts and emails. Together they mean you generally need the person’s consent, or another lawful basis, to contact them.

This is general guidance, not legal advice. If you work in a regulated area, take your own advice.

## What real consent looks like

Consent has to be a positive, informed choice. In practice that means:

## First-party versus list-broker leads

First-party leads come from a form the person filled in themselves, with consent captured at that moment. These are the ones worth buying. Cold lists bought from a broker, where nobody asked to hear from you, are the ones that land businesses in trouble.

## Questions to ask any provider

Before you buy, ask:

## Frequently asked questions

### Can I legally cold-call a bought list?

Usually not for consumers, and you must screen against the TPS and CTPS for phone marketing. This is exactly why first-party, consented leads are safer than cold lists.

### How does AceLeads handle consent?

Every lead is first-party and captured with consent under UK GDPR and PECR. Regulated leads, such as claims, are supplied only to appropriately authorised firms.

---

Source: https://aceleads.co.uk/guides/are-bought-leads-gdpr-compliant
Last reviewed: 2026-08-13
Contact: info@aceleads.co.uk
AceLeads is a UK-registered business.
