Definition
GDPR data processing covers any operation on personal data, including collecting, storing, using, and deleting subscriber information.
Each activity needs a lawful basis and appropriate safeguards.
Every email operation processes personal data, so understanding processing obligations is foundational. Mapping what you process, why, and on what basis keeps you compliant. Processor agreements and data minimisation complete the picture.
Mapping Your Processing
Document what data you process, why, and on what basis.
Ensure processors like ESPs have GDPR-compliant agreements.
Why It Matters
Every email operation processes personal data, so understanding processing obligations is foundational.
Best Practices
- Map what data you process and why.
- Use processors with GDPR-compliant agreements.
- Document bases and minimise data.
- Support data subject rights.
- Review processing regularly.
Was this useful?
Related Glossary Terms
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
Consent Banner
A consent banner is an on-site notice that informs visitors about data collection and allows them to agree to or manage email marketing preferences.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Cookieless Tracking in Email
Cookieless tracking in email is the measurement of email-driven behavior using methods that do not rely on third-party browser cookies.
Data Retention Schedule (Email Marketing)
A data retention schedule defines how long subscriber personal data is stored after unsubscribing or becoming inactive, ensuring compliance with GDPR, CCPA, and similar privacy laws.
Email Account Health Score
A composite metric that evaluates the overall health of an email sending programme based on deliverability, engagement, list quality, and compliance factors.
Frequently Asked Questions
Any operation on personal data, including storage and use. Every email operation processes personal data, so understanding processing obligations is foundational.
Consent, contract, legitimate interest, or another lawful basis. Mapping what you process, why, and on what basis keeps you compliant.
Yes, when third parties process data for you. Processor agreements and data minimisation complete the picture.
Collect only what you need and delete what you do not. Every email operation processes personal data, so understanding processing obligations is foundational.
It is a breach with potential fines. Mapping what you process, why, and on what basis keeps you compliant.