Definition
An email privacy policy is the specific section of an organisation's overall privacy policy that addresses how personal data is collected, used, stored, and shared for email marketing purposes. It must be provided to subscribers at the time of data collection (typically via a link on the sign-up form) and must be easily accessible at all times. Under the GDPR's transparency principle, privacy policies must be written in clear, plain language that the average subscriber can understand, not in complex legal jargon.
The email-specific disclosures that a privacy policy must cover include: what personal data is collected through email sign-up forms and engagement tracking (name, email address, IP address, browser type, open and click behaviour, purchase history), the lawful basis for processing (typically consent or legitimate interest depending on jurisdiction), how data is shared with third parties (ESP platforms, analytics providers, data enrichment services), how long data is retained (referencing the data retention policy), and what rights subscribers have (access, rectification, erasure, portability, restriction, objection). Many privacy policies fail to engage-specific these details with sufficient precision, using vague language that does not meet regulatory standards.
Privacy policies must also address data transfers across borders. If your email programme uses an ESP based in the US, Canada, or other non-UK/EEA country, you must disclose this transfer and the safeguard mechanism used (International Data Transfer Agreement, UK BCRs, or EU SCCs). The privacy policy should name the specific ESP or data processors used for email marketing. Following the Schrems II decision and subsequent UK adequacy developments, the legal basis for data transfers has become more complex, and privacy policies should be reviewed by legal counsel to ensure transfer mechanisms are accurately described.
Best Practices
Create a dedicated email marketing section within your privacy policy. Rather than scattering email disclosures throughout the document, group them in a clearly labelled section. This makes it easier for subscribers to find the information relevant to their email relationship with you and demonstrates a structured approach to transparency that regulators recognise.
Link directly to the privacy policy from every sign-up form and email footer. The privacy policy link should be clearly labelled and placed where subscribers can easily find it. Burying the link in small text at the bottom of the page or within general terms and conditions does not satisfy the transparency requirement. The link should be present before consent is obtained.
Review and update the privacy policy annually and after any material change in email operations. Changes in ESP provider, addition of new tracking technologies, changes in data retention periods, or changes in legal basis all require privacy policy updates. Notify existing subscribers of material changes, particularly changes in lawful basis or new data uses. An out-of-date privacy policy is a compliance risk.
Use layered privacy notices for email data collection. Present the key information (what data is collected, why, and the lawful basis) in a concise notice at the point of sign-up, with a link to the full privacy policy for details. This layered approach satisfies the GDPR's requirement that information be provided "at the time" of collection while keeping the sign-up experience uncluttered.
Maintain version control of your privacy policy with dated changelogs. Document when each version was published and what changed. This helps demonstrate transparency if a regulator asks about disclosures at a specific point in time. Version control also helps manage consent: if consent references the privacy policy, you need to know which version was in effect when each subscriber consented.
Related Glossary Terms
Australia Spam Act
Australia's Spam Act 2003 regulates commercial electronic messages including email. It requires consent, functional unsubscribe mechanisms within 5 working days, and sender identification. Penalties reach AUD $2.22 million per day.
Email CASL
Canada's Anti-Spam Legislation requirements for commercial electronic messages, including consent types, record-keeping, and penalties up to $10 million per violation.
Email CCPA
California Consumer Privacy Act requirements for email marketing, including consumer rights to access, delete, and opt out of data collection and sale.
Email Consent Record
Email consent record-keeping captures proof of opt-in including timestamp, IP address, method, and exact wording shown. GDPR requires controllers to demonstrate consent upon request.
Email Data Portability
Data portability under GDPR Article 20 gives subscribers the right to receive their email marketing data in a machine-readable format and transfer it to another provider. Common export formats are CSV and JSON.
Email Data Retention
Email data retention policies govern how long subscriber data, activity logs, consent records, and campaign data are kept. GDPR requires data not be kept longer than necessary for the processing purpose.
Frequently Asked Questions
At minimum: what personal data is collected through email sign-up and tracking, the lawful basis for email processing, which third-party processors (ESPs) are used, data retention periods for email data, cross-border transfer mechanisms, and a complete description of subscriber rights (access, erasure, portability, rectification, restriction, objection). Each disclosure must be specific to your email operations.
The privacy policy does not need to be explicitly accepted (ticked), but it must be clearly presented and easily accessible at the point of data collection. Most organisations include a link to the privacy policy next to the consent checkbox or submit button. The key requirement is that the subscriber can readily access the policy before providing their data.
This is a breach of the transparency principle under GDPR Article 5(1)(a) and can result in regulatory enforcement action. Inaccurate privacy policies may also invalidate consent if the subscriber was not properly informed about how their data would be used. Regular audits to ensure the privacy policy matches actual practices are essential for compliance.
Name the specific ESP providers used (e.g., "We use Klaviyo, Inc. as our email service provider") and describe the data shared with them. Explain the contractual safeguards in place, the data processing agreement, and any cross-border transfer mechanism. Generic language like "we may share data with third-party service providers" is insufficient.
Post-Brexit, UK GDPR and EU GDPR have diverged slightly. A single privacy policy can cover both UK and EU subscribers if it addresses both regulatory frameworks. Alternatively, separate privacy policies can be maintained for UK and EU audiences. The safest approach is a single policy that includes specific disclosures for each jurisdiction where you operate.