Privacy & Data · US & EU/UK Can a company sell my email address to another company?

Can a company sell my email address to another company?

Only with a valid legal basis — and increasingly, only if you haven't opted out first.

Kibbo Consumer Desk · Updated September 2026 · 6 min read

Not freely — both major privacy frameworks put real limits on this, though they work differently. In the EU/UK, GDPR requires a valid legal basis (most commonly your consent) for sharing your data with a third party for a new purpose. In California, the CCPA takes a different approach: rather than requiring opt-in consent for every sale, it requires businesses to let you opt out via a clearly available "Do Not Sell or Share My Personal Information" mechanism — the default is closer to "yes, unless you say no."

Two different models, worth understanding separately

EU/UK (GDPR) California (CCPA)
Default position A lawful basis is required before sharing — most commonly consent, for a purpose beyond what you originally agreed to Sale/sharing is allowed by default, but you have a right to opt out
What you have to do Nothing extra — the company needs your consent before sharing in the first place Actively opt out, via the required link or a Global Privacy Control browser signal
Special protection for minors Generally requires parental consent for processing children's data Businesses cannot sell the data of a known minor under 16 without opt-in consent (parental consent required under 13)

What "consent" for sharing actually has to look like under GDPR

If your email was collected on the basis of consent for one specific purpose (say, order confirmations from a retailer), using that same email for an unrelated purpose — including sharing it with a separate company for marketing — generally requires new, specific consent. A pre-checked box, or consent buried in a long terms-of-service document you scrolled past, generally doesn't meet GDPR's standard for valid consent, which has to be freely given, specific, informed, and unambiguous.

The practical opt-out tool most people don't know about

In California, you don't have to hunt down and click "Do Not Sell" on every individual website. Global Privacy Control (GPC) is a browser-level signal — supported by several major browsers and privacy extensions — that automatically communicates your opt-out preference to every site you visit. California law requires businesses covered by the CCPA to honor a GPC signal as a valid opt-out request, without you having to take any further action per-site.

What to do if your data was shared without proper consent

  1. In the EU/UK: request confirmation of the legal basis relied on for the sharing (see our related question on this) — if it wasn't valid consent for that specific purpose, this is a real GDPR violation to raise with the company or your national data protection authority.
  2. In California: use the required "Do Not Sell or Share" link, or enable Global Privacy Control in your browser going forward.
  3. If a company continues sharing data after you've opted out or withdrawn consent, this is a specific, escalatable violation — document the date of your opt-out request and any continued unwanted contact from third parties.
  4. Complaints can go to the ICO (UK), your national DPA (EU), or the California Privacy Protection Agency, depending on jurisdiction.

Related questions

Official sources

Take action with Kibbo

Think your data was shared without proper consent?

Use Kibbo's Privacy & Data tools to draft a formal request or opt-out notice.

Explore Privacy & Data tools →