GDPR and Email Marketing: A Practical Compliance Guide
How GDPR and the ePrivacy Directive really govern email marketing: legal bases, consent, soft opt-in, proof, subscriber rights and practical implementation.
What GDPR Actually Requires of Email Marketers
Stated plainly: the General Data Protection Regulation (Regulation (EU) 2016/679) contains no rule saying “you need consent to send an email.” What it governs is the personal data behind your email programme. You need a lawful basis for processing it, transparency about it, accuracy, storage limitation, security, and proof of all of that. Article 5(2) puts it in one line: the controller “shall be responsible for, and be able to demonstrate compliance with” the processing principles.
The rule that decides whether you may press send sits in a different instrument, the ePrivacy Directive. Most articles on this topic collapse the two together and get the answer wrong. Keeping them apart is the point of this guide.
This article is practical guidance for marketers, not legal advice. It cites primary sources so you can check them, but data protection law is applied by national regulators and courts, national implementations differ, and your circumstances matter. Before you change a consent flow, a data retention rule or an international transfer, take advice from a qualified practitioner in your jurisdiction.
GDPR and ePrivacy: Two Instruments, One Send
What the ePrivacy Directive says
Directive 2002/58/EC, the ePrivacy Directive, as amended by Directive 2009/136/EC, sets the sending rule. Article 13(1) allows electronic mail for direct marketing only in respect of subscribers who have given their prior consent. “Electronic mail” is defined broadly and technology neutrally: the Article 29 Working Party’s Opinion 5/2004 confirmed it covers email newsletters as well as SMS and similar stored messages. Article 13(2) carves out the existing-customer exception, and Article 13(4) prohibits marketing email that disguises the sender’s identity or lacks “a valid address to which the recipient may send a request that such communications cease.”
Why this matters in practice
Consent is not defined in the ePrivacy Directive. It takes its meaning from general data protection law: Article 94(2) GDPR provides that references to the repealed Directive 95/46/EC are read as references to the GDPR. So ePrivacy decides when consent is needed for the act of sending, and the GDPR decides what counts as consent and how you prove it.
You can therefore have a valid GDPR basis for holding and analysing a contact record and still have no right to email that person. And because ePrivacy is a directive rather than a regulation, it is transposed into national law, so details differ between member states.
Choosing a Legal Basis for Email Marketing
Consent
Consent under Article 6(1)(a) is what most consumer email programmes rely on, for good reason: where ePrivacy requires prior consent for the send anyway, using consent as your GDPR basis keeps one story rather than two. The cost is that it can be withdrawn at any time under Article 7(3).
Legitimate interest
Article 6(1)(f) permits processing necessary for the controller’s legitimate interests, except where overridden by the interests or fundamental rights of the data subject. Recital 47 says explicitly that “the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.”
That sentence is quoted constantly to argue that consent is optional. Read it carefully. It concerns the GDPR basis for processing, it says “may be”, so you still have to run and document the balancing test, and it says nothing about the ePrivacy rule for the send. Legitimate interest is most defensible for the processing around your programme, such as segmentation, suppression and analytics, and for business-to-business contact where national rules treat corporate subscribers differently. It is a weak foundation for cold consumer email in the EU.
The soft opt-in for existing customers
Article 13(2) of the ePrivacy Directive is the real exception. Where a person obtains customers’ email contact details “in the context of the sale of a product or a service”, that same person may use them to market “its own similar products or services”, provided customers “clearly and distinctly are given the opportunity to object, free of charge and in an easy manner” both when the details are collected and in every subsequent message.
The Article 29 Working Party said this exception “is limited in several ways and must be interpreted restrictively.” Three limits are worth memorising:
- It applies only to actual customers. Someone who abandoned a checkout is not covered.
- Only the same legal person that collected the address may send. Subsidiaries and parent companies are not the same company.
- Only similar products or services qualify, judged from the recipient’s reasonable expectations rather than the sender’s ambitions.
How the soft opt-in varies between member states
Because the directive was transposed nationally, this is where the same advice genuinely diverges by market.
In Ireland, Regulation 13(11) of S.I. No. 336/2011 restates the exception and adds a hard time limit: the sale must have occurred “not more than 12 months prior to the sending of the direct marketing communication”, or the details must have been used for marketing email within that period.
In the United Kingdom, the equivalent rule is regulation 22 of PECR, and the ICO states no such time limit. It describes the soft opt-in as covering an existing customer “who bought (or negotiated to buy) a similar product or service from you in the past”, and notes it does not apply to prospective customers, bought-in lists, or non-commercial promotions such as charity fundraising and political campaigning.
Two neighbouring markets, two materially different rules. Never assume your home version travels.
What Valid Consent Actually Means
Article 4(11) defines consent as “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.” The EDPB expanded on each element in Guidelines 05/2020 on consent, adopted on 4 May 2020.
The four elements
- Freely given. Article 7(4) says “utmost account” is taken of whether a contract is made conditional on consent to processing not necessary for it. Do not make marketing consent a condition of checkout.
- Specific. Where processing has multiple purposes, consent should be given for all of them (Recital 32). Separate purposes need separate choices: a newsletter opt-in is not consent to SMS, nor to sharing data with partners.
- Informed. Article 7(2) requires a consent request bundled into a wider declaration to be “clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.”
- Unambiguous. There must be a statement or clear affirmative action.
What does not count
Recital 32 is blunt: “Silence, pre-ticked boxes or inactivity should not therefore constitute consent.” Nor does a checkbox buried in terms, or one tick covering email, SMS, profiling and partner sharing.
Withdrawal
Article 7(3) gives the right to withdraw consent at any time, requires the person to be told of that right beforehand, and states that “it shall be as easy to withdraw as to give consent.” If someone can subscribe in one click, a withdrawal flow requiring a login and a buried settings page does not meet the standard. Withdrawal is not retroactive: processing carried out before it stays lawful.
Proof: What You Must Be Able to Demonstrate
Article 7(1) is short and load-bearing: “Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented.” An “opted in: yes” column demonstrates nothing. A record that reconstructs the moment of consent does.
What to log at signup
Capture and store, per contact and per purpose:
- Timestamp of the consent action, in a stable timezone.
- Source and method: which form, page URL, channel or offline event.
- The exact consent wording and privacy notice version shown. A version identifier resolving to archived wording is more practical than storing full text on every row.
- The specific purposes agreed to, as separate flags rather than one boolean.
- Confirmation evidence and timestamp where you use double opt-in.
- IP address where proportionate to the risk. This is common practice and useful evidence, but not a statutory requirement, and is itself personal data.
Article 30 separately requires most organisations to keep records of processing activities: purposes, categories of data subjects and data, recipients, transfers, retention periods and security measures. The exemption for organisations employing fewer than 250 persons is narrow, falling away where processing is likely to risk rights and freedoms, is not occasional, or involves special category data. Regular marketing to a customer database is not occasional.
How long to keep consent evidence
The GDPR sets no fixed period. The workable principle is that consent evidence should outlive the marketing it justifies, plus the period in which a complaint could realistically be brought. Deleting a subscriber’s record while keeping a minimised log entry proving permission is normal.
Data Subject Rights That Hit Email Programmes
Five rights show up repeatedly in email operations.
- Access (Article 15). Confirmation of whether you process their data, a copy of it, and information including purposes, categories of data, recipients, retention periods, the source, and any automated decision-making or profiling. For email programmes that often means engagement history and segment membership, not just the address.
- Rectification (Article 16). Correction of inaccurate data without undue delay, and completion of incomplete data.
- Erasure (Article 17). Including at 17(1)(b), where consent is withdrawn and no other basis applies, and at 17(1)(c), where the person objects under Article 21(2).
- Objection to direct marketing (Article 21). The absolute one. Under 21(2) the data subject “shall have the right to object at any time” to processing for direct marketing, including related profiling. Under 21(3), “the personal data shall no longer be processed for such purposes.” There is no balancing test to apply.
- Portability (Article 20). Applies where processing rests on consent or contract and is automated, covering data the person provided. Derived scores and segments are generally outside it.
Response timelines
Article 12(3) requires you to act without undue delay and in any event within one month of receipt. That may be extended by two further months given complexity or the number of requests, and you must tell the person, with reasons, within the first month. An objection to marketing deserves better than the maximum: treat it as immediate suppression, then handle the paperwork within the statutory window.
Practical Implementation
Signup forms
One unticked, clearly labelled checkbox per purpose. Name the sender, say what you will send and roughly how often, and link the privacy notice rather than reproducing it. Do not bundle marketing consent with terms acceptance or gate the purchase on it. Store the form version so you can later prove what was on screen.
Double opt-in and its honest legal status
Double opt-in is not required by the GDPR or the ePrivacy Directive. No article mandates it. What it produces is evidence: a confirmation click, from the mailbox in question, at a recorded time, is close to the best available proof that a real person controlling that address agreed. The Article 29 Working Party noted that methods where a subscriber registers and is later asked to confirm this “seem to be compatible with the Directive.”
So it is recommended, sometimes strongly, and in some markets it is the norm. It is not the law. The mechanics are in our double opt-in guide.
Preference centres and unsubscribe handling
Every marketing message needs a valid address for opt-out requests, and under the existing-customer exception an easy free objection route in every message is a condition, not a courtesy. A preference centre offering frequency and topic choices is good practice, but a plain, one-step global unsubscribe must remain available. Process opt-outs automatically; manual queues are how organisations end up sending after an objection.
Suppression lists that must survive migrations
An unsubscribe is a permanent instruction, not a per-list setting. Suppression state has to be global across brands, across the channels the objection covers, and across platforms. The dangerous moment is a migration or re-import: subscribers move to the new system and the objection flags do not come along. This is the most common way a compliant programme quietly becomes a non-compliant one.
The same risk lives in every integration between a store, a CRM and an email platform, which is where consent and suppression state gets lost in transit. If you are moving Shopify data into Brevo, Tajo is the sync layer carrying those fields between systems. Whatever tooling you use, the test is the same: after any migration, confirm a known suppressed address is still suppressed.
Retention and re-permissioning stale lists
Storage limitation applies to marketing lists, so set a documented retention rule for inactive contacts and enforce it. If a list has gone unused for years, a re-permission campaign is often proposed. Be careful: a “confirm you still want to hear from us” email is itself a marketing communication in most readings, so it can only go to people you may lawfully email today. If you cannot demonstrate a basis now, the honest answer is deletion. Our email list cleaning guide covers the hygiene side.
Your ESP is a processor
Your email service provider processes personal data on your instructions, so Article 28 applies. There must be a contract or other binding legal act setting out subject matter, duration, nature and purpose of processing, types of data and categories of data subject. Article 28(3) then requires terms on documented instructions, confidentiality, Article 32 security, sub-processors, assistance with data subject requests and breach duties, deletion or return of data at the end of the service, and audit rights. Most providers publish a standard DPA. Read its sub-processor list.
International transfers
If personal data leaves the EEA, you need a transfer mechanism. Article 45 allows transfers to countries or frameworks the European Commission has found adequate. Otherwise Article 46 requires appropriate safeguards, most commonly the Commission’s standard contractual clauses, or binding corporate rules within a group. Adequacy decisions cover a number of jurisdictions, including the EU-US Data Privacy Framework adopted on 10 July 2023. Check where your ESP stores data, not just where it is headquartered.
What the Regulation Is Called in Your Market
The instrument is the same across the EU. The name is not.
| Market | Local name | Notes |
|---|---|---|
| Germany, Austria | DSGVO | Datenschutz-Grundverordnung, per the German federal authority |
| France | RGPD | Reglement general sur la protection des donnees, per the CNIL |
| Spain | RGPD | Reglamento General de Proteccion de Datos, per the AEPD |
| Netherlands | AVG | Algemene verordening gegevensbescherming, per the Autoriteit Persoonsgegevens |
| Poland | RODO | The abbreviation used by the Polish authority UODO |
| Italy | RGPD or GDPR | The Garante uses both, alongside Regolamento (UE) 2016/679 |
| Ireland, English usage | GDPR | Also common in Italian and Dutch business usage |
Outside the EU the vocabulary changes again. The United Kingdom has the UK GDPR alongside PECR. Turkey has the Kisisel Verilerin Korunmasi Kanunu, Law No. 6698, known as KVKK. Brazil has the Lei Geral de Protecao de Dados Pessoais, Law No. 13.709 of 14 August 2018, the LGPD. Indonesia has Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi. These are separate regimes with their own rules, not translations, and satisfying the GDPR does not automatically satisfy them.
Penalties, and What Regulators Actually Do
Article 83 sets two tiers: up to 10 million euro or 2 percent of total worldwide annual turnover under 83(4), and up to 20 million euro or 4 percent under 83(5), whichever is higher in each case. The higher tier covers the basic principles and conditions for consent in Articles 5, 6, 7 and 9, data subject rights in Articles 12 to 22, and transfer rules in Articles 44 to 49, so consent failures and ignored objections sit there. National ePrivacy rules add their own penalties: in Ireland, breaching Regulation 13 is a criminal offence and each message counts separately.
For a mid-sized sender, the everyday risk is not a headline fine. It is one complaint triggering a regulator’s question: show us the consent for this address.
Where Compliance and Performance Meet
Done properly, this also improves performance. Lists built on genuine, specific permission engage better and complain less, which is what deliverability systems reward. Our email deliverability guide explains that mechanism, and our email list building guide covers acquisition that holds up under scrutiny.