Generating Email Addresses from Public Data: The Privacy Rules

In Brief
Guessing an email address from public information does not make it free to use for marketing. UK GDPR applies when the address identifies a person, and the sender needs a lawful basis, fair and transparent handling, and accurate data. PECR adds a separate test: consent is normally needed for unsolicited email marketing to individual subscribers, unless a valid soft opt‑in applies; corporate subscribers are treated differently. A name in an address does not, by itself, decide which PECR rule applies.
This is something that I've been meaning to write about for a while. A recent update from the ICO about a complaint I have submitted about this very subject, combined with a little downtime around the holidays, means that I've finally found time to write it all down.
In the second half of last year, I very suddenly started receiving a growing number of spam emails targeting a personal email address that I have hosted under one of my business domain names and had never used or shared. This sudden influx of uninvited spam was coming from reputable brands that you would recognise, such as Vitality and Expedia (amongst others).
These are brands that should know better than to send out unsolicited spam emails to non‑subscribers. I had no relationship with these companies and had never agreed to receive emails from them, and yet, here these emails were arriving ‑ uninvited ‑ in my inbox in their tens each day, taking time out of my day and interrupting my workflow.
How Was It Happening?
As you may know, I'm the director of two companies: PixelCounter Ltd. (which I began the process of striking off at the end of last year) and Kavanagh Digital. Both of these companies have websites, and both have a readily available business email address posted on them:
A business wanting to contact either company could find a published address on its website. I would expect a genuine business enquiry there, rather than in a private inbox I had never shared. Publishing an address does not itself amount to consent to marketing.
What I was receiving, though, was spam targeted much closer to me personally: sent to addresses formatted with my name in them (john@domain.com and john.kavanagh@domain.com, for example). These were private addresses that I had never shared, published or used for public or business purposes. I wanted to know how the senders had obtained them and what justified using them for marketing.
The Role of B2B Data
Many lead generation companies create and sell what they label as "valid" and "compliant" business data, including email addresses. They generate this data by scraping publicly available information ‑ reportedly from Companies House, amongst others ‑ to obtain company officer names and then attempt to combine those with guessed email address patterns (e.g., john.smith@company.com, or johnsmith@company.com, or jsmith@company.com, or john@company.com). They will call this process things like 'proprietary lead generation', because it sounds better than 'made it up by matching patterns and hoping for the best'.
This is pattern matching rather than finding an address someone has chosen to publish. Even a successful guess tells the sender very little about the person's expectations or whether the address can lawfully be used for marketing.
Generating, checking, sharing and using an address can all involve processing personal data. Each needs a lawful basis and must meet the UK GDPR's other requirements. An address that works is not proof of compliance, but neither is guessing an address automatically unlawful in every case.
The public origin of a name or company record does not settle those questions. Combining it with a domain to identify a contact is a further use of the information, and the organisation must be able to justify what it does with that personal data.
The ICO's B2B guidance makes this distinction clear: public availability does not remove UK GDPR protection. The source, the intended use and the person's reasonable expectations all matter.
The businesses I associated with this unwanted mail included Growthonics, Seed Data Solutions, InFynd, Acquirz, Red Flag Alert and Go Data. At its worst, I was receiving more than forty spam emails a day. My concern was that my private address had been generated and passed on without my agreement. This is my account of the unwanted mail and my attempts to trace it; it is not a published regulatory finding against each of those businesses.
The lack of a clear explanation about the source and use of my address was part of the problem. Whether a particular organisation has broken the law depends on its actual processing and the evidence, rather than on my lack of consent alone.
Businesses buying these lists have their own responsibilities, too. A vendor's promise that data is "compliant" does not establish a lawful basis for the buyer's use or show that its planned messages meet PECR. I would want an explanation of the source, the intended recipients and the checks behind that promise.
When an Email Address is Personal Data
Under UK GDPR, personal data is defined as:
“Any information relating to an identified or identifiable natural person.
An email address such as john.kavanagh@businessname.com will be personal data when it identifies or relates to a particular person. A first name alone may be less conclusive, but the address and its surrounding information can still identify someone. Article 4(1), UK GDPR is the definition that matters, rather than a rule that any name‑like string must identify a real person.
Even in a business context, this is still personal data and needs to be handled as such:
- It relates directly to a natural person, not the business entity.
- It can be used to contact or infer information about that person.
Guessing an address does not take it outside those rules. An inaccurate record about an identifiable person can still be their personal data; accuracy is one of the obligations the organisation must address.
The ICO Guidance on Personal Data covers this in great detail, including a specific section dedicated to the classification of email addresses that include personal names ‑ even in a business setting.
Why "Legitimate Interests" Needs a Proper Assessment
Whilst attempting to track down the sources of this spam, I was repeatedly told that legitimate interests justified using my address. It can be a valid basis for some direct marketing, but saying the words is not enough. The organisation must work through three questions:
- Purpose: What legitimate interest is the organisation pursuing?
- Necessity: Is this use of personal data needed, or could it reasonably achieve the same result in a less intrusive way?
- Balance: Do the person's interests, rights and freedoms outweigh that interest?
Why I Challenged That Explanation
- Accuracy: A guessed address may be wrong or may reach someone other than the intended business contact.
- Expectations: I had not published this private address or invited marketing to it. That matters when assessing fairness and the effect on my privacy.
- Necessity: My businesses already provided public contact addresses. I wanted to know why reaching a private address was considered necessary.
Those are reasons to challenge the assessment, rather than proof that legitimate interests can never apply. Where PECR requires consent and no exception applies, legitimate interests cannot be used to get around that requirement.
Why Generic Email Addresses are Different
A general company inbox such as info@businessname.com may not identify a person, so the address alone may fall outside UK GDPR. Context can change that: the sender may hold other information that links the inbox to someone. There are two separate checks:
- Does the address, alone or with the information held about it, identify a person? That determines whether personal data rules apply.
- Who is the subscriber? PECR's email rules distinguish corporate subscribers from individual subscribers; they do not simply distinguish named inboxes from generic ones.
However, even when targeting generic addresses, companies must:
- Avoid misleading practices (e.g., pretending to have an existing relationship).
- Provide clear opt‑out mechanisms in all communications.
When a Generic Email Address is Still Personal Data
The whole address and the information held about it matter. Looking only at the part before the @ will miss that context.
For example, mail@johnkavanagh.co.uk contains my name in the domain. Starting with mail does not stop the address identifying me.
Using that personal data requires a valid lawful basis and compliance with the other UK GDPR duties. Whether PECR also requires consent depends on the subscriber and the circumstances, not the presence of my name.
Before sending a campaign, the business needs reliable checks for the address, the subscriber type and its legal basis for using the data. Guessing those answers is a poor starting point. There is no universal rule that each address must be checked manually, but automating a list does not remove responsibility for its accuracy or use.
I spent months challenging the explanation from one data company that had used my address. That correspondence is part of my experience; it should not be confused with a court or regulator deciding that every generated address is unlawful.
The Role of Companies House Data in This Practice
The Companies House register publishes information about companies and their officers. Since March 2024, companies have also been required to supply a registered email address, with existing companies doing so through their next eligible confirmation statement. That email address is held by Companies House but is not published on the public register. A guessed address is therefore not the same thing as retrieving that registered email address.
Public access to a company record does not answer whether a later use of personal data is lawful. For marketing, the organisation still needs to consider:
- Its lawful basis, including any valid consent required by PECR.
- Fairness, transparency, accuracy and the person's reasonable expectations.
The Companies House data products explain ways to access company information. Access to a data product is not permission to ignore privacy law when using information about an individual.
Public Access and Permission to Reuse Data
The relevant data product's terms and the privacy rules need to be considered separately. Permission to access public records does not settle whether a later use of personal data is lawful. The Open Government Licence, for example, excludes personal data from the rights it grants; it does not supply a UK GDPR lawful basis.
LinkedIn is a separate example of contractual restrictions. Its December 2022 account of the hiQ dispute describes enforcement against scraping and fake accounts. A platform's access rules and UK data protection law raise different questions, even when the same activity engages both.
In December 2022, LinkedIn reported that hiQ had agreed to a permanent injunction prohibiting scraping and fake accounts. That account describes the outcome of a particular US dispute; it does not establish a general UK prohibition on generating email addresses.
Public visibility, contractual permission and lawful processing are separate things to check. A company should be able to explain each one that applies to its proposed use of the data.
When This Practice Can Break the Law
The legal problem is not the spelling pattern used to guess an address. It is processing personal data without meeting UK GDPR requirements, or sending messages that breach PECR. Keeping those questions separate makes it easier to challenge the actual conduct.
UK GDPR Requirements
Where an address identifies a person, generating or using it must comply with the UK GDPR. These are the questions I would ask:
What is the Lawful Basis?
If the organisation relies on legitimate interests, ask what purpose it identified, why using this address was necessary, and how it balanced that use against the person's rights. A successful address check is not a substitute for that assessment.
If PECR requires consent for the planned email and no valid exception applies, an alternative UK GDPR basis cannot make that email permissible.
Has the Use Been Fair and Transparent?
When information comes from elsewhere, the right to be informed normally requires privacy information within a reasonable period and at most one month, or earlier at the first communication or disclosure. Exceptions exist, but simply putting a policy on a website does not necessarily tell the person how their address was obtained and will be used. Fairness and accuracy need separate attention, too.
PECR Requirements
For unsolicited email marketing, the subscriber distinction is central. It is possible for a named work address to be personal data under UK GDPR whilst the subscriber is a company for PECR purposes.
Individual and Corporate Subscribers
PECR's email marketing rules generally require consent for individual subscribers unless the soft opt‑in applies. Corporate subscribers, such as limited companies and limited liability partnerships, do not need to consent under that particular rule. Senders must still identify themselves and provide a valid opt‑out address.
The presence of a name in an inbox does not change a company subscriber into an individual subscriber. UK GDPR can still apply to the named contact's personal data.
Sole Traders and Some Partnerships
Sole traders and certain partnerships count as individual subscribers. The commercial soft opt‑in is limited: the sender must have obtained the details during a sale or negotiations for a sale to that recipient, market its own similar products or services, and offer an opt‑out both when collecting the details and in every message. A bought or guessed address does not, by itself, meet those conditions.
A business‑like address can therefore belong to an individual subscriber. Equally, some partnerships, including Scottish partnerships and limited liability partnerships, are corporate subscribers. Check the actual subscriber rather than inferring it from the inbox name.
What the Enforcement Cases Actually Show
Leave.EU and Eldon Insurance (2019)
The Upper Tribunal's February 2021 decision records penalties of £45,000 for Leave.EU and £60,000 for Eldon over insurance marketing in Leave.EU newsletters, plus a separate £15,000 Leave.EU penalty for a newsletter sent to Eldon customers. Those cases concerned particular unsolicited messages and consent; they did not decide that guessing email addresses is always unlawful.
Protecting Yourself from This Misuse
Unless you want to spend your days sifting through reams of emails containing irrelevant offers for services you just don't need, then it is important to take action if you suspect that your data has been misused.
Where the sender appears to be a real business rather than a scammer, the first step is to ask where they got your email address from. In my experience, there are only a handful of 'data' companies providing these email addresses to hundreds or thousands of clients.
Then, you can:
- Keep the messages and any explanation of their source, then complain to the ICO if you believe your information has been misused.
- Use the spam and blocking controls in your email service where appropriate.
- Object to the use of your personal data for direct marketing. The organisation must stop that use; it may retain a minimal suppression record to avoid contacting you again. Ask about erasure as a separate right, which has its own conditions.
Wrapping Up
A company cannot justify using my private address simply by saying that my name was public or that its software guessed correctly. I am entitled to ask where the data came from, why it was used and how to stop the marketing.
The precise legal answer depends on the processing and the subscriber. Some B2B marketing can rely on legitimate interests; other messages require consent under PECR. Neither route removes the duty to handle personal data fairly and transparently or to respect an objection to direct marketing.
As recipients, we have the right to push back, report violations, and demand better adherence to privacy laws.
Key Takeaways
- An address is personal data when it identifies or relates to a person, including through the information held alongside it.
- Legitimate interests can support some marketing, but it needs a proper assessment and cannot replace consent where PECR requires it.
- PECR distinguishes corporate and individual subscribers; the inbox name alone does not decide which one it is.
- Public company data does not supply a lawful basis for every later use. Check the applicable privacy duties and any separate access or reuse terms.
If you are in any doubt about the source of the email addresses you are using in your marketing campaign, please just don't send the email at all.