Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

Email List Compliance Audit: How to Check Your List Meets Legal Requirements

On this page

Why Compliance Audits Matter

An email list compliance audit checks whether your email contact data meets legal requirements for the jurisdictions you operate in. Violations can result in significant fines, domain blacklisting and reputational damage:

Regulation Maximum penalty Jurisdiction
CAN-SPAM Act Up to $53,088 per violating email, checked 8 October 2026 United States
GDPR 20 million euros or 4% of global annual revenue European Union / EEA
CASL $10 million CAD per violation (business) Canada
CCPA / CPRA $7,500 per intentional violation California, USA
PECR Up to £17.5 million or 4% of global turnover, under powers commenced 5 February 2026 United Kingdom
Australian Spam Act Up to $2.22 million AUD per day Australia
PDPA (Singapore) Up to 10% of annual Singapore turnover for organisations above S$10 million local annual turnover; otherwise up to S$1 million Singapore
LGPD (Brazil) 2% of revenue, capped at R$50 million per infraction Brazil

Audit Checklist

1. Consent and permission audit

Check What to verify Pass criteria
Consent records exist Each contact has a documented source of consent or legitimate basis Every contact can be traced to how and when they were added
Consent type is recorded Opt-in type is documented (single opt-in, double opt-in, implied consent) Records show the consent mechanism used
Consent is specific Consent was given for the type of emails you are sending Marketing consent covers marketing emails; transactional consent covers transactional
Consent is informed The person knew what they were consenting to Privacy notice or consent language is documented
Consent is freely given No pre-checked boxes; no bundled consent Consent was not a condition of service (unless necessary)
Third-party data has consent Purchased or partner lists have verifiable consent for your emails Data provider can demonstrate consent records
Consent is current Consent has not expired or been withdrawn Re-consent campaigns run for stale contacts

2. Suppression and opt-out audit

Check What to verify Pass criteria
Unsubscribe mechanism works Every marketing email includes a working unsubscribe link Test unsubscribe from recent campaigns; confirm it works
One-click unsubscribe List-Unsubscribe header is implemented for bulk senders Email headers include List-Unsubscribe and List-Unsubscribe-Post
Unsubscribe is honoured within 10 days CAN-SPAM requires 10 business days; GDPR effectively requires faster Check processing time from unsubscribe to suppression
Global suppression list exists A master suppression list prevents re-adding unsubscribed contacts Suppression list is maintained and applied to all sends
Suppression list is applied before every send New imports and campaign sends check against suppression Test by adding a suppressed address to a new import; confirm it is blocked
Hard bounces are suppressed Invalid addresses are not re-mailed Hard bounces automatically added to suppression
Complaint addresses are suppressed Spam complaints trigger suppression Feedback loops (FBLs) are configured; complaints trigger suppression
Previous opt-outs are preserved during migrations CRM or platform migrations do not lose suppression data Migration plan includes suppression list transfer

3. Data source audit

Check What to verify Pass criteria
Source of every contact is recorded Each contact has a documented acquisition source Source field is populated for every record
Date of acquisition is recorded Each contact has a date stamp Date field is populated
No scraped data without legal basis Contacts obtained through scraping have appropriate legal basis Review scraping practices against applicable law
Purchased lists have documentation Data purchase agreements include consent warranties Contracts with data providers are on file
Co-registration sources are documented Contacts from co-registration have proper consent Co-registration consent language is on file
Event and conference lists have consent In-person collection included consent notice Registration forms or badge-scan agreements include consent
Website forms collect consent Online forms include consent checkbox or notice Review form designs and consent language

4. Data quality audit

Check What to verify Pass criteria
Email syntax is valid All addresses follow valid email format No malformed addresses in the list
Domains have valid MX records Email domains can receive email MX lookup confirms deliverability
Duplicate addresses are identified No address appears more than once Deduplication has been run
Role-based addresses are flagged info@, admin@, support@ addresses are identified Role-based addresses are segmented or removed from marketing
Disposable addresses are flagged Temporary email domains are identified Known disposable domains are filtered
Spam traps are absent No known spam trap addresses exist in the list Email verification service has checked for spam traps
Bounce rate is acceptable Historical bounce rate is within tolerance Under 2% hard bounce rate
Complaint rate is acceptable Spam complaint rate is within tolerance Under 0.1% complaint rate (Google postmaster threshold: 0.3%)

5. Data retention and minimisation audit

Check What to verify Pass criteria
Retention policy exists A documented policy defines how long contact data is kept Written retention policy is on file
Retention policy is enforced Contacts older than retention period are reviewed or removed Automated or manual cleanup runs on schedule
Inactive contacts are managed A sunset policy addresses contacts who have not engaged Contacts with no engagement in 6-12 months are reviewed
Unnecessary data is not collected Only data needed for the stated purpose is collected Forms do not collect fields that are never used
Data deletion requests are honoured GDPR and CCPA deletion requests are processed Deletion process is documented and tested

6. Security and access audit

Check What to verify Pass criteria
Access is restricted Only authorised personnel can access email lists Access controls and permissions are in place
Data is encrypted at rest Email databases are encrypted Encryption is enabled on storage systems
Data is encrypted in transit Email data transfers use encryption (TLS/SSL) API calls and file transfers use HTTPS/SFTP
Export controls exist List exports are logged and restricted Export activity is auditable
Third-party processors are vetted ESP and CRM providers meet compliance requirements Data processing agreements (DPAs) are signed
Breach notification plan exists Process for reporting data breaches is documented Breach response plan is on file and tested

Conducting the Audit

Step-by-step process

Step Action Tools needed
1 Export current email list from all sending platforms CRM, ESP, marketing automation platform
2 Consolidate and deduplicate across sources Email extraction and dedup tool
3 Map each contact to its source and consent record CRM data, source fields, consent logs
4 Run email verification to check validity Email verification service
5 Cross-reference against suppression lists Master suppression list
6 Identify contacts without documented consent Query contacts with empty source or consent fields
7 Flag contacts in regulated jurisdictions Map contacts by geography (GDPR, CASL, CCPA)
8 Review data retention compliance Check age of contacts against retention policy
9 Document findings and remediation steps Audit report
10 Implement fixes and re-audit Follow-up audit in 30-90 days

Regulation-Specific Requirements

CAN-SPAM (United States)

Requirement What it means for your list
No false or misleading headers Sender name and email must be accurate
Subject lines must not be deceptive Subject must relate to email content
Must identify message as advertisement Commercial email must be identifiable as such
Must include physical address Every email includes your valid postal address
Must include opt-out mechanism Working unsubscribe in every commercial email
Must honour opt-outs within 10 business days Suppression processing must complete within 10 days
Cannot require fee or personal info to opt out Unsubscribe must be simple and free
Note: CAN-SPAM does not require prior opt-in But ISPs and ESPs have stricter requirements

GDPR (European Union / EEA)

Requirement What it means for your list
Lawful basis required Consent, legitimate interest, or contractual necessity
Consent must be freely given, specific, informed, unambiguous No pre-checked boxes; clear consent language
Right to withdraw consent Easy unsubscribe; must be as easy as giving consent
Right to erasure Must delete data on request
Right to data portability Must provide data in machine-readable format on request
Records of processing Document what data you hold, why, and how it is processed
Data protection impact assessment Required for high-risk processing
Data breach notification Notify authority within 72 hours; notify individuals if high risk
Data processing agreements Required with all third-party processors (ESP, CRM, etc.)

CASL (Canada)

Requirement What it means for your list
Express consent required for commercial electronic messages Must have opt-in consent (not just opt-out)
Implied consent has time limits 2 years from purchase; 6 months from enquiry
Must identify sender and include contact information Sender name, address, phone or email in every message
Must include unsubscribe mechanism Working unsubscribe; must be processed within 10 business days
Consent records must be maintained Keep records of how and when consent was obtained
Installation of software requires consent Relevant if emails contain software downloads

Remediation Steps

For contacts without documented consent

Situation Remediation
Source is known but consent is not documented Send a re-consent email; suppress those who do not re-consent
Source is unknown Remove from active lists; do not email until consent is obtained
Purchased list with unclear consent Quarantine; contact data provider for consent documentation
Contacts from before compliance programme existed Run re-permission campaign; suppress non-responders
Contacts in GDPR jurisdictions without consent Remove immediately unless legitimate interest can be documented

For data quality issues

Issue Remediation
High bounce rate Run email verification; remove invalid addresses
Duplicate addresses Deduplicate; merge records where possible
Role-based addresses Segment out of marketing sends; use for transactional only
Spam trap addresses Remove immediately; investigate how they entered the list
Inactive contacts Run re-engagement campaign; sunset those who remain inactive

Preparing for the Audit

When consolidating email lists from multiple platforms (CRM exports, ESP exports, spreadsheets, legacy databases) for a compliance audit, upload the files to Email Extractor to extract and deduplicate email addresses across all sources. This creates a single unified list for the audit, making it easier to identify duplicates, check for suppressed addresses and verify that every contact has a documented source.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)