Your Email Was Shared Without Asking: Know Your Rights

If you ever signed up for the Channel 5 newsletter — the YouTube channel run by journalist Andrew Callaghan — your email address may have been handed to a third party without your knowledge. Channel 5 confirmed in a public statement that it transferred a CSV file containing its subscriber email list to Hunter Biden, who intended to use it to promote a new product. This is a straightforward case of subscriber email data shared without consent, and it raises questions that go well beyond one creator and one celebrity.

What happened

Channel 5 stated publicly that it gave a CSV file of its email subscriber list to Hunter Biden. The context was an ongoing relationship between Callaghan and Biden as interviewer and subject. At some point during that relationship, Biden asked whether he could use the mailing list when he launched something new. Channel 5 agreed.

The channel later clarified that emails from Biden’s team had not yet been sent to subscribers at the time the statement was posted. But that clarification does not undo the transfer itself. The CSV file had already changed hands before the channel said anything publicly.

Channel 5 did not respond to a press request for further comment. The total number of email addresses in the file, the date of the transfer, and exactly how the data was stored or handled by the receiving party have not been disclosed.

Who is affected

If you signed up for the Channel 5 newsletter through its members site or merchandise store, you are directly in scope. Those are the two sign-up points identified in the channel’s own statements.

Where you live matters too:

  • EU subscribers may have specific legal protections under GDPR. A data protection lawyer who reviewed the situation told 404 Media that the transfer appears inconsistent with that regulation.
  • California subscribers may have standing under the state’s Shine the Light law. Channel 5’s own privacy policy explicitly states it does not share user information with third parties for direct marketing — which is precisely what this transfer was set up to enable.

Beyond those groups, anyone who follows independent media creators on YouTube is affected indirectly. This incident surfaces a question most subscribers have never thought to ask: what does your favourite creator actually do with your email address?

What the real risk is

The most immediate problem is straightforward. Your email address ended up with a party you never agreed to share it with, for a marketing purpose you never consented to.

The data protection lawyer quoted by 404 Media said the transfer appears inconsistent with GDPR where that regulation applies. That means the act of handing over the CSV file may itself be the violation — not just what happens next with it.

Channel 5’s own privacy policy makes this harder to defend. The policy says user data is not disclosed to third parties for direct marketing. Sharing a subscriber list so someone can promote a product is, by definition, direct marketing.

There is also a practical problem that no statement can fix. Once a CSV file of email addresses leaves your hands, you cannot verify it has been deleted. You cannot confirm it will not be used later, by the original recipient or anyone they pass it to. The channel’s assurance that no emails have gone out yet does not address what happens to the file going forward.

What to do today

These are steps you can take this week, not vague advice to stay alert.

Unsubscribe if you want out

If you are on the Channel 5 newsletter, check your inbox for any past email from them. Every legitimate marketing email must contain an unsubscribe link. Use it if you no longer want to be on the list. This does not undo what already happened, but it limits future exposure.

If you are in the EU, submit a data request

Under GDPR, you have the right to ask any company what personal data it holds on you and to request its deletion. You can send this request directly to Channel 5 in writing. Keep a copy. If the company does not respond within 30 days, you can escalate to your national data protection authority.

If you are in California, invoke Shine the Light

California’s Shine the Light law lets you ask a business to disclose what personal information it has shared with third parties for direct marketing purposes in the past calendar year. Send a written request to Channel 5 asking specifically what data about you was disclosed, to whom, and for what purpose.

Check the privacy policy before your next sign-up

Before you join any newsletter or online community, spend two minutes finding the privacy policy and searching for the word “share.” If it says the platform will not share your data with third parties, screenshot it. That is a commitment you can point to later if something goes wrong.

Why this keeps happening

Independent creators often build audiences of tens of thousands of people without ever putting in place the legal or operational structure a traditional media company would have. Subscriber data gets treated as an informal asset — a spreadsheet in a folder — rather than as something with legal obligations attached.

Personal relationships make this worse. When a creator knows someone well, a request to use the mailing list can feel like a reasonable favour rather than a decision that affects every person on that list. The line between a professional obligation to subscribers and a personal gesture toward someone you know gets blurry fast.

Platform sign-up flows do not help. When you enter your email to get a newsletter, nothing in that flow signals that your address has any value or could ever be passed to someone else. Both the creator and the subscriber tend to underestimate what is actually at stake.

And there is rarely an immediate consequence. A public backlash may follow, as it did here, but regulatory investigations take time and are not guaranteed. Until the cost of mishandling subscriber data is reliably high, the incentive to build proper data governance stays low.

Frequently asked questions

Is it illegal to share a subscriber email list with a third party?

It depends on where the subscribers live and what the platform’s privacy policy says. Under GDPR, sharing personal data for a purpose the user did not consent to can be unlawful. Under California’s Shine the Light law, sharing data for direct marketing without disclosure creates specific obligations. A data protection lawyer told 404 Media that this transfer appears inconsistent with GDPR. Whether any law was broken is a legal determination — report what you experienced to your relevant data protection authority and let them assess it.

What should I do if I think my email was shared without my permission?

Start by documenting what you signed up for and what the privacy policy said at the time. Then send a written data request to the platform asking what information it holds on you and whether it has been shared. If you are in the EU, you can escalate to your national data protection authority. If you are in California, you can file a complaint with the California Attorney General’s office.

Does it matter that no marketing emails were actually sent to subscribers?

According to the data protection lawyer quoted in the 404 Media report, the transfer of the data itself may be the issue under GDPR — not just what happens after. The fact that no emails went out yet does not reverse the transfer or guarantee the file will be deleted.

Related reading

Originally reported by 404media.co. This article summarises that reporting and adds practical guidance.

Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to CDM Worlds to stay ahead of the decisions that shape your life in online spaces.

Grab Your Free Ebook

Subscribe to our mailing list and get your free copy of Escape the Plantation.

“No problem can withstand the assault of sustained thinking.”

                                                                                                                                                 — Voltaire

🔒 YOU own the information that identifies YOU.
The operation of this website is governed by the ordinances of the City of Osmio, including its Privacy Ordinance.
View Privacy Ordinance

No Tracking Pixels or Beacons

Today's internet has become infested with hidden trackers — tiny “pixel beacons,” scripts, and device tracking tools designed to follow you without your knowledge.

As a Member Enterprise of The Authenticity Alliance, the operator of this website uses no tracking pixels, no beacons, and no covert identity-reporting mechanisms of any kind.

If we want to know something about you, we’ll ask — we won’t spy.
Learn About Spyfree

What is Authenticity™?

The word “Authenticity™” identifies a digital or physical space of “accountable anonymity” in which people enjoy both privacy for themselves and accountability from others.

Authenticity™ is the condition that exists in a space where there are

  • Digital Signatures Everywhere backed by
  • Measurably Reliable Identity Certificates that are
  • Owned by their Users and which provide
  • Privacy via Accountable Anonymity.

 

Learn about digital signatures and identity certificates in this short video →

What is The Authenticity Alliance?

We are an Authenticity Growers Cooperative

Similar to familiar agricultural cooperatives in the physical world, The Authenticity Alliance is a network of enterprises and individuals whose purpose is to “grow” Authenticity and bring it to the digital world.

Each Authenticity Enterprise—that is, each Member Enterprise of the Alliance—solves a particular inauthenticity problem in its chosen target market or audience.

What Does The Authenticity Alliance Do?

The Alliance brings together independent enterprises that share a common mission: creating spaces of accountable anonymity where digital signatures, reliable identity certificates, and privacy protection work together to solve real-world inauthenticity problems.

Who is the Authenticity Alliance?

The Authenticity Alliance is comprised of two groups working together to promote trust and transparency across digital ecosystems.

  • Enterprises: Authenticity Enterprises that provide Authenticity solutions for the inauthenticity pains in a specific market or industry.
  • Individuals: People who understand the problems of inauthenticity that plague the world’s information systems and who want to help implement and promote Authenticity™ principles.

Authenticity Enterprises

Each is an Enterprise Member of The Authenticity Alliance

Individual Enterprise in The Authenticity Alliance

Customers and members of an Authenticity Enterprise are automatically eligible to become Individual Members of The Authenticity Alliance.You may also join directly as an individual Member here.

 

© 2026 The Authenticity Alliance. All rights reserved. REAL Security | REAL Privacy | REAL Accountability