Don't risk getting blocked: identify your compliant and non-compliant lists
This reference page provides concrete examples of compliant, non-compliant, and borderline contact acquisition lists, alongside standard operating protocols to ensure your sending operations strictly respect digital consent laws and global deliverability standards.
Mastering these rules enables you to aggressively protect your sender reputation, maximize your inbox engagement rates, and completely neutralize the risk of domain blacklists or account suspensions.
I. Valid Examples of Fully Compliant Contact Lists
Compliant lists are built entirely on verified, direct user consent. They form the only secure foundation for long-term marketing operations.
1. Direct Opt-In Form Submissions
Contacts who voluntarily provided their email address through a clear form on your website represent your most reliable traffic base. These subscribers explicitly chose to receive your content, which drastically reduces spam complaint ratios.
- Voluntary Consent: The subscriber understands exactly what they requested (e.g., a newsletter, lead magnet, or promotional offers).
- Legal Security: This structure is fully compliant with European GDPR regulations and global anti-spam directives.
- Pro Tip: Always include an explicit checkbox stating "I want to receive promotional emails" linked directly to your active Privacy Policy page.
2. Explicit Checkout Checkbox Subscriptions
Adding a subscriber during a checkout flow is valid, but the consent must remain entirely voluntary. The simple act of completing a purchase does not automatically grant you permission to send marketing blasts.
- Active Opt-In: The newsletter subscription checkbox must remain unchecked by default. The customer must execute a deliberate click to opt-in.
- Clear Wording: Do not hide the consent parameters. Use exact phrasing like: "Yes, I want to receive news, tips, and exclusive offers by email."
- Proof Logs: The system logs the exact timestamp and opt-in action to guarantee GDPR compliance during potential audits.
3. Documented Offline Subscriptions
You can legitimately collect contacts offline (e.g., trade shows, physical storefronts, or scheduled sales calls), provided the consent remains completely voluntary and explicit.
- Clarity: Never use ambiguous phrasing. Explain precisely what the user will receive.
- Active Registration: The user must sign a physical intake sheet or actively check a digital tablet form acknowledging the marketing subscription.
- Pro Tip: Preserve physical copies, scanned images, or CRM logs demonstrating the explicit offline consent to protect yourself from future spam complaints.
4. Transactional Service Emails
You are permitted to send required operational messagesβsuch as purchase receipts, password reset links, or package tracking updatesβto existing customers even if they never checked a marketing opt-in box. These are classified strictly as transactional emails.
II. Examples of Non-Compliant (Forbidden) Lists
Broadcasting to any of the following list structures violates SystemeScale Terms of Service and will trigger permanent account suspension.
1. Purchased or Rented External Lists
Buying or renting external email lists from data brokers is the fastest way to destroy your business infrastructure. These contacts have never heard of your brand and never consented to your emails.
- Immediate Spam Reports: Unsolicited recipients will aggressively hit the "Report Spam" button, instantly tanking your domain metrics.
- Massive Bounces: Data broker lists are loaded with dead addresses, outdated domains, and active spam traps designed specifically to catch bad senders.
- Total Ban: The importation and use of purchased lists is strictly forbidden on SystemeScale.
2. "Partner" or Third-Party Shared Lists
Even if a partner business operates in the same niche and "shares" their list with you, broadcasting to them is illegal. Presumed interest never replaces explicit, direct consent to your specific business entity.
- Sending to shared lists constitutes a direct GDPR violation and violates global anti-spam regulations.
3. Social Media Data Scraping
Exporting or extracting email addresses from Facebook groups, LinkedIn connections, or webinar attendee rosters without providing an explicit secondary opt-in form is forbidden.
- A user logging into a social platform or joining a group does not grant you the right to harvest their data for marketing blasts. If you want to market to a social audience, you must direct them to a SystemeScale landing page to complete a verified opt-in flow.
4. Public Database Scraping
Extracting addresses listed publicly on corporate websites or directories is highly illegal. An address being visible on the internet does not constitute marketing consent.
5. Internal Employee Broadcasts
You must never route internal corporate memos or employee communications through an external marketing autoresponder.
- Marketing platforms mandate unsubscribe links. If an employee clicks unsubscribe, they will stop receiving vital internal updates. Internal messages should always route through dedicated operational tools (e.g., Google Workspace, Microsoft Teams, Slack).
III. Borderline Cases Requiring Manual Verification
1. Dormant or Cold Contacts
If you possess a list that hasn't received an email from you in over 6 months, their original consent has gone "cold." Suddenly blasting a massive promotional payload to them will likely trigger massive spam complaints as they won't remember your brand.
Action Required: Before resuming normal operations, deploy a strict re-engagement campaign. Send a polite, plain-text email asking: "Would you like to continue receiving our updates?" Only retain contacts who actively click to confirm.
For detailed instructions, refer to: Re-engagement campaign: practical guide to wake up your inactive subscribers.
2. Migration Verification
If you are moving a massive list from an external agency or previous platform, you must definitively verify that you hold opt-in proof for every row of data before initiating your warmup sequence. Do not import suspicious or undocumented segments.

