Definition
An email marketing database is the structured store of the people you are allowed to email: each person's address, the fields you segment on, the consent you hold and where it came from, and the record of what you have already sent them.
The word database is doing real work in that sentence. A file of email addresses tells you who to email. An email marketing database tells you who to email, why you are permitted to, what they care about, how they reacted last time, and who must never be emailed again.
It is also the marketing audience you control most directly. Search rankings, ad accounts and social reach depend on rules someone else sets. The database stays useful until you let it decay, or until the people in it ask to leave, and both of those are under your control.
In B2B the records describe people at companies, which is why this page sits next to B2B data and customer data. Those pages cover the data itself. This one covers the structure that makes it safe and useful to email.
An email database and an email list are not the same thing
Many teams use the two words interchangeably and then find their email campaigns cannot be targeted. An email list is one output of a database. The email marketing database is the layer underneath that makes many different lists possible from the same records.
| Compared | An email list | An email marketing database |
|---|---|---|
| What it holds | Email addresses, sometimes a first name | A record per person, with many fields |
| Structure | Flat, usually a spreadsheet or an export | Relational: person, company, consent, events |
| Consent | Assumed, rarely recorded | Recorded with date, method and wording |
| Segmentation | Whatever columns happen to be filled | Planned fields, filled on purpose |
| History | None, or a separate report | Sends, clicks, replies, bounces, complaints |
| What leaves it | Nothing, until somebody deletes a row | Suppressed addresses, permanently |
The practical test is simple. Ask for every contact in manufacturing, at companies in your mid-size band, who clicked something this quarter and has never been sent the pricing email. A database answers in seconds. A list cannot answer at all.
What an email marketing database should include
Many email marketing databases disappoint not because they are small but because they are empty in the columns that matter. You cannot segment by industry if the industry field is blank on most records, however many contacts the database holds.
Identity fields
| Field | Why it earns its place | Where it usually comes from |
|---|---|---|
| Email address | The key for the whole record, stored once and normalized | Form, import, enrichment |
| First and last name | Greeting and any human personalization | Form, enrichment |
| Job title | A core B2B filter alongside company | Form, enrichment |
| Role or function | A normalized version of title you can actually query | Derived from title |
| Company and domain | Links the person to an account record | Email domain, enrichment |
| Country or region | Decides which consent rules apply to this person | Form, IP, enrichment |
Note the fourth row. Job titles are free text, so a database that segments on raw titles is segmenting on noise. Normalize the title into a role field once, and every segment built afterwards stays stable.
Company fields
Company attributes belong on an account record that many contacts point to, not copied onto every person. When a customer grows from a small team to a large one, you want to change that in one place, not on every contact who works there.
- Industry: normalized to your own short list, not the long list of options a form offers.
- Employee count and revenue band: stored as bands, because exact numbers change and a band survives small changes.
- Technologies in use: the stack that tells you whether your product fits.
- Account status: prospect, open opportunity, customer, churned, partner, competitor.
- Owner: the rep who owns the account, so marketing and sales do not arrive on the same day.
Engagement history at the contact level
An email address plus attributes is a snapshot. The history is what turns the snapshot into something you can act on, and it is the input that both segmentation and hygiene depend on.
- Sends: which email campaign, which date, from which sending domain.
- Opens: stored, but weak as a per-person signal, for the reason given below the list.
- Clicks: a routine engagement signal the recipient has to act on.
- Replies: rare and valuable, and a strong sign that a human read the message.
- Bounces: hard and soft, with the provider response stored, not just a flag.
- Complaints and unsubscribes: the two events that must trigger suppression immediately.
Apple says its Mail Privacy Protection prevents senders from seeing whether a message was opened. Any subscriber using it leaves open data you cannot read as attention, so this page builds inactivity rules on clicks and replies instead of opens.
How the pieces fit together
The shape below is the minimum that supports real segmentation. Each layer feeds the next, and a break anywhere upstream shows up as an email campaign that cannot be targeted.
Suppression sits last on purpose. It is the final filter applied to any audience, after segmentation, so that no clever new segment can accidentally reach a person who already left.
Segmentation fields, and the segments they make possible
Segmentation fields are the ones you decide to keep because an email marketing campaign will filter on them. Everything else is storage. The useful exercise is to write the segments first and then list the fields each one needs.
| Segment you want to send | Fields it needs filled | How the field gets filled |
|---|---|---|
| Heads of sales at mid-market software firms | Role, industry, employee band | Title normalization plus enrichment |
| People who downloaded the buyer's guide but never replied | Source, asset name, reply flag | Form capture and send history |
| Customers on the old plan before a price change | Account status, plan, renewal date | Sync from the billing or CRM system |
| Everyone in the EU, the UK and California | Country or state, consent basis | Form capture, IP fallback, enrichment |
| Contacts with no click or reply in your inactivity window | Last engagement date | Calculated from event history |
| Accounts showing research activity this week | Account id, intent signal, date | Intent data feed |
Two rules keep this honest. Never create a field you have no plan to fill, and never create a segment that depends on a field filled on a minority of records. Both produce email campaigns that look targeted and are not.
Behavioral fields are written by systems rather than typed by people, which makes them more consistent than profile fields. Industry and title are information someone typed into a form, or a vendor inferred, and both can be wrong in ways nobody notices until a segment misfires.
From the database to email marketing campaigns
A database is only worth maintaining if it changes what you send. The link between the two is a campaign map: a short document saying which segment receives which email marketing campaign, and what each one is for.
| Email campaign | Segment it draws | Data the database must hold |
|---|---|---|
| Welcome series | New subscribers, first two weeks | Signup date, source, preferences |
| Lead nurture | Contacts with an open lead and no meeting yet | Lead stage, asset history, owner |
| Product or feature news | Customers using the affected feature | Account status, product usage data |
| Renewal and expansion | Customers inside the renewal window | Renewal date, plan, account owner |
| Re-engagement | No click or reply in the inactivity window | Last engagement date |
| Win-back | Churned accounts, past the cooling period | Churn date and reason |
Every row is a test of the data. If the renewal campaign cannot be built, the renewal date is missing or stale, and that is information the database was supposed to carry. Broken campaigns are a fast audit of data quality.
Build the campaign map before the campaigns. It tells you which fields to fill first, and it stops email marketing from defaulting to one message for the whole database, which is how a program slides back into the email blast.
Consent and source tracking fields
These fields are the difference between an email marketing database you can defend and one you hope nobody asks about. They are boring to build and close to impossible to reconstruct later, which is why they have to exist from the first import.
| Field | What it records | What it protects you from |
|---|---|---|
| Consent basis | Consent, soft opt-in, corporate subscriber, legitimate interests | Sending to a person the rules treat as an individual |
| Consent date | When permission was given | Relying on permission that is too old to cover this send |
| Consent wording | The exact text shown next to the checkbox | Sending a message type that was never described |
| Source | The form, event, import or vendor the record came from | Not knowing which batch caused a complaint spike |
| Source detail | The page URL, event name or file name | Guessing when you have to remove one bad intake |
| Preferences | Which message types this person accepted | Treating one opt-in as permission for everything |
The ICO tells organizations to keep clear records of consent, and to keep a do not contact list of anyone who objects or opts out. Both are database structures, and a team that has them can answer a complaint in a minute instead of a week.
A compliance review is far simpler when this information sits in fields rather than in somebody's memory. On a fixed schedule, sample records from each source and check that the consent basis, date and wording still match what the form actually showed the subscriber.
Source detail pays for itself the first time one channel goes wrong. If complaints spike, you want to filter by source and find that a single imported file is responsible, rather than suspecting the entire email marketing database.
How email platforms store it: properties, segments, tags and subscription types
You rarely build the tables yourself. A CRM or email marketing platform holds the database, and its documentation describes the building blocks. The names differ by tool, but the same four ideas appear in the HubSpot and Mailchimp help pages.
| Building block | What the vendor's documentation says | Where it maps on this page |
|---|---|---|
| Properties | HubSpot describes properties as fields that store information on records, with defaults plus custom ones | Identity and company fields |
| Active and static segments | HubSpot's active segments update as records meet or stop meeting criteria; static ones do not update automatically | Segmentation fields |
| Tags | Mailchimp calls tags labels you create to organize contacts based on data you know about them | Source detail, campaign history |
| Subscription types | HubSpot says they represent categories of marketing email, and contacts can opt in only to the ones they want | Preferences and consent wording |
Mailchimp recommends one primary audience, organized with tags, groups or segments, rather than many separate audiences. It sorts contacts into subscribed, unsubscribed and non-subscribed, and says it will not let you send to purchased, rented or third-party lists.
HubSpot also separates marketing contacts from non-marketing contacts, so you can store existing customers you do not plan to market to without setting them as marketing contacts. That split is a database decision, not a campaign setting.
Treat these as illustrations, not a recommendation of either tool. The point is that a well-run platform already expects the structure this page describes. If yours does not, the structure has to live somewhere else and sync in.
Where the records come from
Every intake route has a different consent quality, and an email marketing database should never blend them into one undifferentiated pile. The source field exists so that these stay distinguishable forever.
The strongest records. The subscriber typed the email address on your website, saw what they were agreeing to, and the wording is on file.
Accurate because the business depends on it. Consent is narrower than marketers assume: an account contact did not necessarily agree to promotional email.
Usable when the sign-up said clearly that you would be in touch. Record the event name, because the context behind these records fades quickly.
Not opt-in, and it should never be merged into the marketing audience. It belongs to cold email, on a separate sending domain with its own rules.
Enrichment is a fifth route, and a different kind. It does not add contacts, it fills fields on the contacts you already hold. Lead enrichment can populate role, industry and employee band, but it adds no consent to the record.
Keep the prospecting records physically separate, or at minimum flagged so no email marketing campaign can select them. A prospecting import quietly joining a newsletter audience mixes people who never signed up into mail sent to people who did.
Hygiene, bounces and a sunset policy
Email marketing databases decay by themselves. People change jobs, domains are retired, mailboxes are closed, and an address that worked last year can belong to nobody. Data decay covers why that happens and how to measure it on your own records.
Hygiene is the standing process that keeps decay from reaching your send. The full routine is on the email hygiene page. The parts that shape the database itself are below.
- Hard bounce: a permanent failure, such as an address that does not exist. Suppress it on the first occurrence, with the provider response stored.
- Soft bounce: a temporary failure such as a full mailbox or a throttled server. Retry, then suppress after repeated failures.
- Block: the receiving system refused you rather than the address. That is a reputation problem, not a data problem, and it needs fixing before the next send.
- Role addresses: info, sales, support and similar shared mailboxes. Keep them out of email marketing audiences even when they accept email.
- Spam traps: addresses kept to catch senders who mail without permission or never clean. Removing dead and long-inactive records is the practical defense.
Google tells senders to automatically unsubscribe recipients who have multiple bounced messages, and to consider unsubscribing recipients who do not open or read their messages. Yahoo asks senders to monitor hard and soft bounces as well as inactive recipients, and to remove invalid recipients from the list promptly.
Validation at the point of capture is cheaper than cleanup. Checking syntax and whether the domain can receive mail when a form is submitted keeps many typos out. Yahoo also suggests double or confirmed opt-in to reduce the number of invalid recipients.
Vendors publish list decay percentages and average bounce or open rates measured on their own customers. They vary by industry and intake route, so they are not targets for your database. Measure your own bounce rate per source and per email campaign, and compare it to your own last quarter.
Sunset policy and re-engagement
A sunset policy is a written rule for when a non-engaging contact stops receiving regular marketing email. Without one, the inactive share grows quietly until it is large enough to drag every send down.
A common sequence: define inactive for your sending frequency, reduce the email to that group, send one short re-engagement message that asks directly, and suppress the people who do not respond. Google tells senders to periodically confirm that recipients want to stay subscribed, and Yahoo suggests periodic reconfirmation email to inactive subscribers.
Keep the threshold tied to your frequency. A weekly newsletter and a quarterly product update produce very different definitions of inactive, and using one number for both retires people who were never given a chance to engage.
Suppression lists: the part that says no
A suppression list is the set of email addresses that must not receive marketing email, checked against every audience before every send. It is not a segment you can edit for convenience. It is the record of decisions other people made about you.
| What goes on it | Why | How long |
|---|---|---|
| Unsubscribes | The person asked to stop | Permanent |
| Spam complaints | The person pressed the spam button | Permanent |
| Hard bounces | The address does not exist | Permanent |
| Objections under GDPR | Article 21(3): data shall no longer be processed for direct marketing | Permanent |
| Businesses that objected | The ICO calls a do not email list of businesses that object good practice | Permanent |
| Do-not-contact from sales | An account asked the rep to stop all contact | Until the account says otherwise |
Suppression must live above the tools, not inside one of them. If unsubscribes are stored only in the email marketing platform, the first campaign sent from a different platform emails every one of those contacts again.
CAN-SPAM adds a rule people forget. Once someone opts out, you may not sell or transfer their email address, even in the form of a mailing list. The only exception the FTC names is a company you hired to help you comply with the law.
Deliverability: what mailbox providers publish
An email marketing database is only as good as its ability to reach an inbox, and mailbox providers such as Gmail and Yahoo decide that. Both publish sender requirements, which makes this a less speculative part of email marketing than most. The full treatment is on the email deliverability page.
| Requirement | Google, for personal Gmail accounts | Yahoo |
|---|---|---|
| Bulk sender threshold | More than 5,000 messages a day to Gmail accounts | Separate bulk sender requirements; the page gives no number |
| Spam rate | Below 0.3% required; aim below 0.10% and never reach 0.30% | Below 0.3% |
| Authentication, all senders | SPF or DKIM, plus valid forward and reverse DNS | SPF or DKIM, plus valid forward and reverse DNS |
| Authentication, bulk senders | SPF, DKIM and DMARC, with From alignment; policy can be none | DMARC policy of at least p=none that passes, with From alignment |
| One-click unsubscribe | Required on marketing and subscribed messages above the bulk threshold | Required for bulk senders, honored within 2 days |
| Purchased addresses | Do not purchase email addresses from other companies | Do not purchase mailing lists |
Google's guidelines cover mail sent to personal Gmail accounts, the ones ending in gmail.com or googlemail.com. The page defines its scope that way, so read the thresholds as rules for those mailboxes in your database.
Read the spam rate thresholds as a database instruction rather than a sending instruction. Google says recipients who did not sign up might mark your messages as spam. The surest way to keep the rate low is to hold records that wanted the email.
DMARC under RFC 9989
RFC 9989, the DMARC specification published in May 2026, obsoletes RFC 7489. It removes the old pct tag and introduces a t tag for testing. It also states that a DMARC pass by itself does not guarantee that delivery to the inbox would be safe or desirable.
That last point belongs in a database discussion. Authentication proves the mail is yours. It does not make the recipients want it, which is a property of the records you hold. Email warm up follows the same logic, starting with the most engaged slice of the database.
Why buying an email database is not a strategy
Buying an email database is a shortcut many teams consider under a deadline. Regulators and mailbox providers describe the conditions in their own words, and this section sticks to those words.
What the ICO says about bought-in lists
The ICO says you must be very careful before using bought-in lists for emails. You can only use them if all the people on the list specifically consented to receive that type of message from you, and generic consent covering any third party will not be enough.
The checking falls on the buyer. You must satisfy yourself that the list is accurate, that the details were collected fairly, and that the consent is specific and recent enough to cover your marketing. The ICO also says the soft opt-in does not apply to new contacts from bought-in lists.
What the European Commission says
Before acquiring a contact list, the Commission says the seller must be able to show the data was obtained in compliance with the GDPR and may be used for advertising. If the seller relied on consent, that consent should have covered passing the data to others for their own direct marketing.
The buyer must keep the list up to date, must not send advertising to people who objected, and must follow the ePrivacy Directive for email. It must also tell people, at the latest at the first communication, that it collected their data and will use it for advertising.
What the FTC says
The FTC guide says CAN-SPAM makes no exception for business-to-business email, and that opted-out addresses cannot be sold or transferred, even as a mailing list. It also lists harvesting email addresses, or generating them through a dictionary attack, among the conduct that can bring criminal penalties.
The purchase looks cheap next to the cost of building an audience. The cost arrives later, on the sending domain that also carries your customer email, and in the time spent proving where each record came from. Rules differ by market: check with counsel for the countries you sell into.
Buying company and contact research to decide who to approach individually is a different activity from loading a file into an email marketing audience, though the same laws still apply to both. Keep the two apart in the database and in the sending setup.
What CAN-SPAM requires of the database
CAN-SPAM is about the email messages themselves, but several of its requirements are really database requirements, because you cannot satisfy them at send time if the data is not there.
- Accurate header information: the From, To, Reply-To and routing details must be accurate, which means the sending identity is a stored property, not a per-campaign guess.
- A valid physical postal address: stored once and injected into every message.
- A working opt-out: the mechanism must be able to process opt-out requests for at least 30 days after you send.
- Opt-outs honored within 10 business days: which only happens if unsubscribes write to a suppression list all your tools read.
- No sale or transfer after opt-out: a suppression flag that also blocks exports.
The FTC is clear that CAN-SPAM covers all commercial messages, not just bulk email, and makes no exception for business-to-business email. Hiring another company to send does not move the responsibility: both the promoted company and the sender may be held legally responsible.
Penalties are per message. The FTC compliance guide puts each separate email in violation at up to $53,088, which is the arithmetic that makes a careless bulk send an unusually expensive mistake.
The ICO position on consent and corporate contacts
If you email anyone in the UK, the ICO's rules on electronic mail marketing apply, and they start from consent for individuals. The ICO notes that this guidance is under review because of the Data (Use and Access) Act, so check the current page before relying on it.
You can email any corporate body. Sole traders and some partnerships are treated as individuals, so they need consent or the soft opt-in. The ICO calls it good practice to keep a do not email list of businesses that object, and to screen new lists against it.
The soft opt-in covers your own previous customers for similar products, provided you gave them a clear chance to opt out when you collected the details and in every message since. Store that opt-out offer as a fact on the record, because it is what makes the route available.
Two more obligations are structural. You must not disguise or conceal your identity, and you must provide a valid contact address so people can opt out. Store the sending identity and the address with the database, so no campaign can ship without them.
A B2B email database is still personal data: GDPR and California
A common assumption is that a B2B email database holds company data, not personal data. The GDPR defines personal data in Article 4(1) as any information relating to an identified or identifiable natural person, and a named contact at a company is one.
- Lawful basis: Article 6(1)(f) allows processing for legitimate interests unless the person's interests or rights override them, and Recital 47 says direct marketing may be regarded as a legitimate interest.
- Right to object: Article 21(2) gives people the right to object at any time to direct marketing, and under Article 21(3) their data shall no longer be processed for it.
- Telling them: Article 21(4) requires that right to be brought to their attention at the latest at the first communication.
- Email itself: the Commission adds that marketing by email must also follow the ePrivacy Directive.
California closed the same gap. The California Privacy Protection Agency says CCPA rights extend to residents who are contacts for business customers, vendors or contractors, and that the business-to-business exemption expired on December 31, 2022.
For the database, this means a country or state field, a lawful basis field, and an objection flag that suppression reads. Who must comply, and which rights apply, depends on your business. The B2B data page linked at the top covers the wider legal picture.
How to build an email marketing database that holds up
Write the segments before the schema
List the email campaigns you want to be able to send this year. The fields those sends need are your schema. Everything else can wait.
Pick one system of record
Decide which tool owns the person record, and make the rest sync to it. Two systems both believing they are authoritative is how contradictory segments appear.
Capture consent properly at every entry point
Store the basis, date, wording and source on the record as it is created. Wording a person saw years ago cannot be reliably reconstructed after the fact.
Normalize on the way in
Lowercase addresses, trim whitespace, map job titles to roles and industries to your own short list. Cleaning at intake beats cleaning in bulk later.
Enrich the fields you will filter on
Fill role, industry and employee band first, starting with the accounts that matter. Enrichment fills fields; it never adds consent.
Put suppression above the tools
One suppression list, read by every email platform that can send. Unsubscribes, complaints and objections write to it automatically and are never removed.
Run hygiene on a schedule
Suppress hard bounces, handle repeated soft bounces, and review the long-inactive on a fixed cadence, so it happens without anybody deciding to do it.
The order matters. Teams that start at step five, buying enrichment for a database with no consent fields and no suppression discipline, end up with better data they still cannot safely send to.
Growing the database without damaging it
Growth and quality pull against each other only when the intake is careless. Each route below adds subscribers who arrived knowing who you are, which is the property that keeps complaint rates down. The list building guide goes deeper on forms and opt-in.
- Useful gated content: a resource worth an address, with the follow-up described next to the field.
- A newsletter subscribers choose: stated frequency, stated subject, easy to leave.
- Sign-up forms and landing pages on your website: placed where readers already are, with the consent wording visible.
- Webinars and events: strong intent, short shelf life, so mail them while the topic is current.
- Product and account sign-ups: accurate data, narrow consent, kept in their own segment.
- Preference choices at sign-up: let contacts pick message types, and send fewer people more relevant email.
- Confirmed opt-in: Google tells senders to confirm each recipient's address before subscribing them, which keeps typos out.
Google also tells senders to avoid opt-in forms that are checked by default, and Yahoo says not to subscribe users through a box checked automatically. A pre-ticked box creates records with no real consent behind them.
Judge new intake by what it does to your email campaigns, not by how many rows it added. A source that grows the database while lifting complaints is a source to switch off, however good the headline number looked.
Email marketing database tools, by category
No single product is the email marketing database. It is usually spread across a few tool categories, and the question is which one holds the master record. This page names categories, not vendors.
| Category | What it does for the database | Where it falls short |
|---|---|---|
| CRM | Holds person and account records, owners and deal stages | Often weak on send history and unsubscribe handling |
| Email marketing platforms | Store subscribers, consent status, segments and send events | Usually thin on company and account structure |
| Marketing automation tools | Combine records, forms, scoring and triggered email | Add complexity a small database does not need |
| Verification services | Check addresses at intake or before a send | Check deliverability, not consent |
| Enrichment and B2B data vendors | Fill company and role fields | Add no consent and need their own source tag |
Many free tools and free tiers are enough to start: a CRM with custom fields, an email platform with tags and segments, and a shared suppression list. Paying for more makes sense when a planned campaign needs a field or an automation the free version cannot hold.
Measuring database health
Email campaign metrics tell you about a single message. These tell you about the asset underneath it, and they are the numbers to review on a fixed schedule rather than after a bad send.
Field completeness is the one many teams never look at. Run it quarterly per field, and the reason an email campaign underperformed is often visible before the campaign is written.
Common mistakes with an email marketing database
- Merging prospecting research into the email marketing audience, so cold records inherit the newsletter's sending domain.
- Keeping unsubscribes inside one platform, so the next email platform mails them again.
- Treating business contacts as company data, when the GDPR and the CCPA treat named people as personal data.
- Creating twenty fields at setup and filling four of them, then wondering why segments are thin.
- Segmenting on raw job title text instead of a normalized role field.
- Copying company attributes onto every contact, so updating one customer means updating many rows.
- Treating open rate as readership, when Apple Mail Privacy Protection hides opens from senders.
- Buying an email database to hit a growth target without the checks the ICO and the Commission describe.
- Running hygiene only when a send goes badly, instead of on a schedule.
In a sequence
The re-engagement email is where an email marketing database decides its own size. It should be short, honest about why it arrived, and give the reader a real choice, including the choice to leave. The example below was written for this page.
Subject: Still useful, or should I stop? Hi {{firstName}}, You signed up for {{listName}} on {{signupDate}}, and you have not clicked or replied to anything from us since {{lastEngagementDate}}. Rather than keep sending, I would rather ask: is {{topic}} still relevant to your work at {{companyName}}? Stay on the list: {{stayLink}} Change what you get: {{preferencesLink}} Leave: {{unsubscribeLink}} If I do not hear back, I will stop sending and you will not need to do anything. {{senderName}} {{companyName}}, {{postalAddress}}
You send it to people who are engaged, or to a segment defined by opens rather than clicks.
Apple says Mail Privacy Protection stops senders from seeing whether a message was opened, so an open-based rule can ask active readers whether they want to leave, and some take the invitation.
Define inactivity on clicks and replies, and exclude anyone who bought or replied recently.
Frequently asked questions
What is an email marketing database?
An email marketing database is the structured store of the people you are allowed to email. It holds each address, the fields you segment on, the consent you hold and where it came from, and the history of everything you have sent that person.
What is the difference between an email database and an email list?
A list is flat: addresses, maybe a first name, no consent record and no history. An email database stores a record per person, linked to a company record, with consent, source and events. A list is one output you pull from the database.
What should an email marketing database include?
Identity fields such as address, name, normalized role and country. Company fields such as industry, employee band and account status. Consent fields covering basis, date, wording and source. Plus preferences, and the event history of sends, clicks, replies, bounces and complaints.
What fields do I need for email segmentation?
Only the ones a planned send will filter on. For many B2B teams that means role, industry, employee band, country, source, account status and last engagement date. Write the campaigns you want to send this year, then keep the fields those sends require.
Can I buy an email marketing database?
The ICO says bought-in lists can be used for email only if everyone on them specifically consented to that type of message from you, and generic third-party consent is not enough. The European Commission says the seller must show the data was collected lawfully and may be used for advertising.
Is a B2B email database covered by GDPR?
Yes, for the people in it. GDPR Article 4(1) defines personal data as information about an identified or identifiable person, which includes named business contacts. Article 6(1)(f) allows legitimate interests as a basis, and Article 21 gives people the right to object to direct marketing at any time.
Does the CCPA apply to business email contacts?
The California Privacy Protection Agency says CCPA rights cover California residents who are contacts for business customers, vendors or contractors, and that the business-to-business exemption expired on December 31, 2022. Whether your company must comply depends on whether it meets the law's coverage tests.
Does CAN-SPAM apply to B2B email?
Yes. The FTC says CAN-SPAM covers all commercial messages and makes no exception for business-to-business email. Each message needs accurate headers, a valid postal address and a working opt-out, and opt-outs must be honored within 10 business days.
How often should I clean an email marketing database?
On a fixed schedule rather than after a bad send. Suppress hard bounces immediately, handle repeated soft bounces, and review inactive contacts at a cadence tied to how often you send. Validating addresses at the form is cheaper than cleaning in bulk later.
What is a suppression list in email marketing?
The set of addresses that must never receive marketing mail, checked against every audience before every send. It holds unsubscribes, spam complaints, hard bounces, objections and sales do-not-contact requests. It has to sit above your tools, not inside one of them.
Does a bad email database hurt deliverability?
It can. Google requires spam rates below 0.3% for mail to personal Gmail accounts and advises staying below 0.10%, and Yahoo requires below 0.3%. Google also warns that people who did not sign up might mark your messages as spam.
How do I record consent in an email marketing database?
Store four things on the record as it is created: the basis, the date, the exact wording shown next to the checkbox, and the source. The ICO tells organizations to keep clear records of consent and a do not contact list of anyone who objects or opts out.
What tools do I need for an email marketing database?
Usually a CRM for person and account records, an email marketing platform or marketing automation tool for consent status, segments and sends, and one suppression list every sending tool reads. Verification and enrichment services fill gaps, but neither adds consent.
What is an email sunset policy?
A written rule for when a non-engaging contact stops receiving regular mail. Define inactive for your sending frequency, reduce the mail to that group, send one direct re-engagement message, then suppress the people who do not respond. Yahoo suggests periodic reconfirmation email to inactive subscribers.
- Federal Trade Commission, CAN-SPAM Act: A Compliance Guide for Business, for coverage of all commercial email with no business-to-business exception, header and postal address rules, the 30 day opt-out mechanism, the 10 business day deadline, the ban on selling or transferring opted-out addresses, shared liability, the penalty amount and the criminal penalties for address harvesting, checked Oct 1, 2026.
- Google Workspace Admin Help, Email sender guidelines, for the personal Gmail scope, the more than 5,000 a day bulk threshold, spam rate limits, authentication and alignment, one-click unsubscribe, bounce and inactive recipient handling, confirmed and pre-checked opt-in, and the rule against purchased addresses, checked Oct 1, 2026.
- Yahoo, Sender Best Practices, for the spam rate, authentication and the DMARC policy, unsubscribe within 2 days, bounce and inactive recipient handling, double opt-in, reconfirmation email and the rule against purchased lists, checked Oct 1, 2026.
- Information Commissioner's Office, Electronic mail marketing, for consent for individuals, the soft opt-in, corporate bodies, sole traders, the do not email list for businesses that object, identity and contact address rules, and the review notice under the Data (Use and Access) Act, checked Oct 1, 2026.
- Information Commissioner's Office, Using marketing lists, for the UK guidance on bought-in lists, the checks a buyer must make, clear consent records and the do not contact list, checked Oct 1, 2026.
- EUR-Lex, Regulation (EU) 2016/679 (GDPR), Articles 4(1), 6(1)(f) and 21 and Recital 47, for the definition of personal data, legitimate interests, direct marketing as a legitimate interest, and the right to object with its first communication notice, checked Oct 1, 2026.
- European Commission, Can data received from a third party be used for marketing?, for the conditions on acquired contact lists, keeping lists up to date, excluding objectors, the ePrivacy Directive and the notice at first communication, checked Oct 1, 2026.
- California Privacy Protection Agency, Frequently Asked Questions, for business contacts as California residents and the business-to-business exemption that expired on December 31, 2022, checked Oct 1, 2026.
- RFC 9989, Domain-Based Message Authentication, Reporting, and Conformance (DMARC), for its May 2026 replacement of RFC 7489, the removal of the pct tag, the t tag and the note that a DMARC pass does not guarantee inbox delivery, checked Oct 1, 2026.
- HubSpot Knowledge Base, Create and edit properties, for properties as fields that store information on records, checked Oct 1, 2026.
- HubSpot Knowledge Base, Create segments, for active and static segments and how each updates, checked Oct 1, 2026.
- HubSpot Knowledge Base, Set up email subscription types, for subscription types as categories of marketing email that contacts opt in to, checked Oct 1, 2026.
- HubSpot Knowledge Base, Set contacts as marketing, for marketing and non-marketing contacts, checked Oct 1, 2026.
- Mailchimp, Getting Started with Your Audience, for one primary audience organized with tags, groups or segments, the three contact types and the rule against purchased, rented or third-party lists, checked Oct 1, 2026.
- Mailchimp, Getting Started with Tags, for tags as labels that organize contacts, checked Oct 1, 2026.
- Apple, Use Mail Privacy Protection on iPhone, for the statement that it prevents senders from seeing whether a message was opened, checked Oct 1, 2026.
- Jeluvi entries this term builds on: B2B data, customer data, data decay, email hygiene, email list building, email deliverability.
- The re-engagement template on this page was written for this page. It is not copied from any company's mail.