Is email verification GDPR compliant?

An email address identifies a person, which puts it inside the regulation's scope without argument. Sending a list to a verification service makes that service a processor acting on your instructions, and the agreement between you is a requirement rather than a formality.

Four things are worth confirming before a vendor receives a file. Whether they offer a data processing agreement, how long they retain uploaded lists, whether the data is used for anything besides your verification run, and where the processing physically happens.

Retention is the one that separates vendors. A service deleting lists after processing holds far less of your risk than one keeping them indefinitely to improve a shared database, and the second arrangement means your contacts are now in someone else's product.

Transfers outside the European Economic Area need a mechanism, usually standard contractual clauses. That is ordinary and manageable, and it belongs in the agreement rather than being discovered later.

Verification creates no new permission. Confirming that a mailbox exists tells you nothing about consent, and an address you had no lawful basis to mail is still one you cannot mail after it comes back valid.

A processing record for one cleanup, filled in

Say you're a twelve-person software firm in Dublin about to check 45,000 contacts. Before you upload, add an entry to your record of processing. It takes ten minutes, and it's the document a regulator or a large customer will ask to see.

Purpose: keeping contact data accurate. That's a duty the regulation places on you, since it asks that personal data be kept accurate and up to date. Lawful basis: the one you already hold the list under. Processor: the verification vendor, with the date the processing agreement was signed.

Then the practical lines. Data sent: email addresses only. Retention at the vendor: the number of days you've set, or the vendor's default. Transfer: where the processing happens and which safeguard covers it. Deletion: how you'll confirm the file is gone. If you can't fill in a line from the vendor's documents, that's your next question for them.

Send less: strip the file before you upload it

A verifier needs one column. Your export probably has twelve, including names, phone numbers, job titles and deal notes. Sending all of it is convenient, since the verdict comes back beside the full record. It also gives a third party data it has no use for, and the regulation asks you to avoid exactly that.

The fix is dull and quick. Add a row number to your export, copy the row number and the email column into a new file, and upload that. When results come back, join them to your full file on the row number. The vendor never sees a name.

Pick a vendor that lets you control the rest. With ZapBounce you set the retention window per API key, down to zero days, and you can delete a batch on demand. There's an erasure call for a single person too.

None of this is legal advice. A lawyer who knows your business should review anything you're unsure of.

Does verification need separate consent?

No. Processing data you already hold lawfully is covered by the basis that let you hold it.

What should I check in a vendor's terms?

A data processing agreement, the retention period, whether your data is reused, and where processing takes place.

Can I use legitimate interest for B2B email?

Often, with a documented balancing test and an easy opt-out. Consumer marketing is held to a stricter standard.

Does a valid result mean I can mail the address?

No. Validity is technical. Consent is about the person, and no check establishes it.

Check this against your own list

100 free credits a month, no card. Unknown results come back labeled and are never billed.