Definition
An email privacy policy is the specific section of an organisation's overall privacy policy that addresses how personal data is collected, used, stored, and shared for email marketing purposes. It must be provided to subscribers at the time of data collection (typically via a link on the sign-up form) and must be easily accessible at all times. Under the GDPR's transparency principle, privacy policies must be written in clear, plain language that the average subscriber can understand, not in complex legal jargon.
The email-specific disclosures that a privacy policy must cover include: what personal data is collected through email sign-up forms and engagement tracking (name, email address, IP address, browser type, open and click behaviour, purchase history), the lawful basis for processing (typically consent or legitimate interest depending on jurisdiction), how data is shared with third parties (ESP platforms, analytics providers, data enrichment services), how long data is retained (referencing the data retention policy), and what rights subscribers have (access, rectification, erasure, portability, restriction, objection). Many privacy policies fail to engage-specific these details with sufficient precision, using vague language that does not meet regulatory standards.
Privacy policies must also address data transfers across borders. If your email programme uses an ESP based in the US, Canada, or other non-UK/EEA country, you must disclose this transfer and the safeguard mechanism used (International Data Transfer Agreement, UK BCRs, or EU SCCs). The privacy policy should name the specific ESP or data processors used for email marketing. Following the Schrems II decision and subsequent UK adequacy developments, the legal basis for data transfers has become more complex, and privacy policies should be reviewed by legal counsel to ensure transfer mechanisms are accurately described.
Best Practices
Create a dedicated email marketing section within your privacy policy. Rather than scattering email disclosures throughout the document, group them in a clearly labelled section. This makes it easier for subscribers to find the information relevant to their email relationship with you and demonstrates a structured approach to transparency that regulators recognise.
Link directly to the privacy policy from every sign-up form and email footer. The privacy policy link should be clearly labelled and placed where subscribers can easily find it. Burying the link in small text at the bottom of the page or within general terms and conditions does not satisfy the transparency requirement. The link should be present before consent is obtained.
Review and update the privacy policy annually and after any material change in email operations. Changes in ESP provider, addition of new tracking technologies, changes in data retention periods, or changes in legal basis all require privacy policy updates. Notify existing subscribers of material changes, particularly changes in lawful basis or new data uses. An out-of-date privacy policy is a compliance risk.
Use layered privacy notices for email data collection. Present the key information (what data is collected, why, and the lawful basis) in a concise notice at the point of sign-up, with a link to the full privacy policy for details. This layered approach satisfies the GDPR's requirement that information be provided "at the time" of collection while keeping the sign-up experience uncluttered.
Maintain version control of your privacy policy with dated changelogs. Document when each version was published and what changed. This helps demonstrate transparency if a regulator asks about disclosures at a specific point in time. Version control also helps manage consent: if consent references the privacy policy, you need to know which version was in effect when each subscriber consented.
Related Glossary Terms
Anonymized Data
Anonymized data is email subscriber or interaction data that has been stripped of personally identifiable information so individuals cannot be re-identified.
Email Account Health Score
A composite metric that evaluates the overall health of an email sending programme based on deliverability, engagement, list quality, and compliance factors.
Email Anti-Spam Laws
Overview of global anti-spam regulations including CAN-SPAM, CASL, GDPR, the Australian Spam Act, and POPIA with compliance requirements for each jurisdiction.
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email B2B Consent
The legal requirements for B2B email marketing consent, covering GDPR legitimate interest, CASL implied consent, CAN-SPAM exemptions, and jurisdiction-specific best practices.
Email CASL
Canada's Anti-Spam Legislation requirements for commercial electronic messages, including consent types, record-keeping, and penalties up to $10 million per violation.
Frequently Asked Questions
At minimum: what personal data is collected through email sign-up and tracking, the lawful basis for email processing, which third-party processors (ESPs) are used, data retention periods for email data, cross-border transfer mechanisms, and a complete description of subscriber rights (access, erasure, portability, rectification, restriction, objection). Each disclosure must be specific to your email operations.
The privacy policy does not need to be explicitly accepted (ticked), but it must be clearly presented and easily accessible at the point of data collection. Most organisations include a link to the privacy policy next to the consent checkbox or submit button. The key requirement is that the subscriber can readily access the policy before providing their data.
This is a breach of the transparency principle under GDPR Article 5(1)(a) and can result in regulatory enforcement action. Inaccurate privacy policies may also invalidate consent if the subscriber was not properly informed about how their data would be used. Regular audits to ensure the privacy policy matches actual practices are essential for compliance.
Name the specific ESP providers used (e.g., "We use Klaviyo, Inc. as our email service provider") and describe the data shared with them. Explain the contractual safeguards in place, the data processing agreement, and any cross-border transfer mechanism. Generic language like "we may share data with third-party service providers" is insufficient.
Post-Brexit, UK GDPR and EU GDPR have diverged slightly. A single privacy policy can cover both UK and EU subscribers if it addresses both regulatory frameworks. Alternatively, separate privacy policies can be maintained for UK and EU audiences. The safest approach is a single policy that includes specific disclosures for each jurisdiction where you operate.