If you ever signed up for the Channel 5 newsletter — the YouTube channel run by journalist Andrew Callaghan — your email address may have been handed to a third party without your knowledge. Channel 5 confirmed in a public statement that it transferred a CSV file containing its subscriber email list to Hunter Biden, who intended to use it to promote a new product. This is a straightforward case of subscriber email data shared without consent, and it raises questions that go well beyond one creator and one celebrity.
What happened
Channel 5 stated publicly that it gave a CSV file of its email subscriber list to Hunter Biden. The context was an ongoing relationship between Callaghan and Biden as interviewer and subject. At some point during that relationship, Biden asked whether he could use the mailing list when he launched something new. Channel 5 agreed.
The channel later clarified that emails from Biden’s team had not yet been sent to subscribers at the time the statement was posted. But that clarification does not undo the transfer itself. The CSV file had already changed hands before the channel said anything publicly.
Channel 5 did not respond to a press request for further comment. The total number of email addresses in the file, the date of the transfer, and exactly how the data was stored or handled by the receiving party have not been disclosed.
Who is affected
If you signed up for the Channel 5 newsletter through its members site or merchandise store, you are directly in scope. Those are the two sign-up points identified in the channel’s own statements.
Where you live matters too:
- EU subscribers may have specific legal protections under GDPR. A data protection lawyer who reviewed the situation told 404 Media that the transfer appears inconsistent with that regulation.
- California subscribers may have standing under the state’s Shine the Light law. Channel 5’s own privacy policy explicitly states it does not share user information with third parties for direct marketing — which is precisely what this transfer was set up to enable.
Beyond those groups, anyone who follows independent media creators on YouTube is affected indirectly. This incident surfaces a question most subscribers have never thought to ask: what does your favourite creator actually do with your email address?
What the real risk is
The most immediate problem is straightforward. Your email address ended up with a party you never agreed to share it with, for a marketing purpose you never consented to.
The data protection lawyer quoted by 404 Media said the transfer appears inconsistent with GDPR where that regulation applies. That means the act of handing over the CSV file may itself be the violation — not just what happens next with it.
Channel 5’s own privacy policy makes this harder to defend. The policy says user data is not disclosed to third parties for direct marketing. Sharing a subscriber list so someone can promote a product is, by definition, direct marketing.
There is also a practical problem that no statement can fix. Once a CSV file of email addresses leaves your hands, you cannot verify it has been deleted. You cannot confirm it will not be used later, by the original recipient or anyone they pass it to. The channel’s assurance that no emails have gone out yet does not address what happens to the file going forward.
What to do today
These are steps you can take this week, not vague advice to stay alert.
Unsubscribe if you want out
If you are on the Channel 5 newsletter, check your inbox for any past email from them. Every legitimate marketing email must contain an unsubscribe link. Use it if you no longer want to be on the list. This does not undo what already happened, but it limits future exposure.
If you are in the EU, submit a data request
Under GDPR, you have the right to ask any company what personal data it holds on you and to request its deletion. You can send this request directly to Channel 5 in writing. Keep a copy. If the company does not respond within 30 days, you can escalate to your national data protection authority.
If you are in California, invoke Shine the Light
California’s Shine the Light law lets you ask a business to disclose what personal information it has shared with third parties for direct marketing purposes in the past calendar year. Send a written request to Channel 5 asking specifically what data about you was disclosed, to whom, and for what purpose.
Check the privacy policy before your next sign-up
Before you join any newsletter or online community, spend two minutes finding the privacy policy and searching for the word “share.” If it says the platform will not share your data with third parties, screenshot it. That is a commitment you can point to later if something goes wrong.
Why this keeps happening
Independent creators often build audiences of tens of thousands of people without ever putting in place the legal or operational structure a traditional media company would have. Subscriber data gets treated as an informal asset — a spreadsheet in a folder — rather than as something with legal obligations attached.
Personal relationships make this worse. When a creator knows someone well, a request to use the mailing list can feel like a reasonable favour rather than a decision that affects every person on that list. The line between a professional obligation to subscribers and a personal gesture toward someone you know gets blurry fast.
Platform sign-up flows do not help. When you enter your email to get a newsletter, nothing in that flow signals that your address has any value or could ever be passed to someone else. Both the creator and the subscriber tend to underestimate what is actually at stake.
And there is rarely an immediate consequence. A public backlash may follow, as it did here, but regulatory investigations take time and are not guaranteed. Until the cost of mishandling subscriber data is reliably high, the incentive to build proper data governance stays low.
Frequently asked questions
Is it illegal to share a subscriber email list with a third party?
It depends on where the subscribers live and what the platform’s privacy policy says. Under GDPR, sharing personal data for a purpose the user did not consent to can be unlawful. Under California’s Shine the Light law, sharing data for direct marketing without disclosure creates specific obligations. A data protection lawyer told 404 Media that this transfer appears inconsistent with GDPR. Whether any law was broken is a legal determination — report what you experienced to your relevant data protection authority and let them assess it.
What should I do if I think my email was shared without my permission?
Start by documenting what you signed up for and what the privacy policy said at the time. Then send a written data request to the platform asking what information it holds on you and whether it has been shared. If you are in the EU, you can escalate to your national data protection authority. If you are in California, you can file a complaint with the California Attorney General’s office.
Does it matter that no marketing emails were actually sent to subscribers?
According to the data protection lawyer quoted in the 404 Media report, the transfer of the data itself may be the issue under GDPR — not just what happens after. The fact that no emails went out yet does not reverse the transfer or guarantee the file will be deleted.
Related reading
- AI Lawsuits and Local News: What Changes for Readers
- News Orgs Sue OpenAI: What It Means for Your Content
Originally reported by 404media.co. This article summarises that reporting and adds practical guidance.
Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to CDM Worlds to stay ahead of the decisions that shape your life in online spaces.
