Definition
Privacy regulations require that marketing emails contain a clear link to your privacy policy. The policy must explain: what personal data you collect, how you use it, who you share it with, how long you keep it, and the subscriber's rights over their data. The link is typically placed in the email footer alongside the unsubscribe link. It must be clearly visible and accessible — not hidden in tiny, low-contrast text. The privacy policy itself must be reviewed and updated when your data processing practices change.
Related Glossary Terms
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Consent Expiry (Email Marketing)
Consent expiry is the time period after which a subscriber's permission to send marketing emails legally expires and must be re-obtained, varying by jurisdiction and consent type.
Right to Data Portability (GDPR)
The right to data portability allows individuals to obtain and reuse their personal data across different services, including exporting subscriber data from email marketing platforms.
Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that defines how personal data will be handled, required under GDPR for email service providers.
Data Retention Schedule (Email Marketing)
A data retention schedule defines how long subscriber personal data is stored after unsubscribing or becoming inactive, ensuring compliance with GDPR, CCPA, and similar privacy laws.
Data Subject Access Request (DSAR)
A Data Subject Access Request (DSAR) is a GDPR right allowing individuals to request access to their personal data held by an organisation, including email marketing data.