Definition
Email retargeting, also known as email-to-ad retargeting or customer match advertising, is the practice of uploading hashed email subscriber lists to advertising platforms — including Google Ads, Facebook Ads, LinkedIn, Pinterest, and TikTok — to create custom audience segments for paid media targeting. When a subscriber's hashed email address matches a user account on the advertising platform, the platform can serve advertisements to that user across its properties. This technique bridges email marketing and paid advertising, allowing brands to reach known contacts with display, social, and search ads. According to a 2024 eMarketer study, 62 per cent of US retail brands use email retargeting as part of their digital marketing mix, and those using it report an average 32 per cent uplift in overall campaign ROI.
The technical process involves generating a cryptographic hash (typically SHA-256) of each subscriber's email address and uploading the hashed list to the ad platform's audience management interface. The platform matches the hashed values against its own hashed user database and builds a targetable audience segment from the matched profiles. Google Customer Match, Facebook Custom Audiences, and LinkedIn Matched Audiences all operate on the same hashing principle, though each platform has specific implementation requirements for data formatting, hashing algorithm, and minimum audience size thresholds. Facebook, for example, requires a minimum of 200 matched users before a Custom Audience can be used for ad targeting, while Google Customer Match requires a minimum of 1,000 matched users for search ad campaigns.
Privacy and consent implications of email retargeting have become a central regulatory concern. Under GDPR, using email addresses for ad retargeting constitutes processing for a purpose beyond the original collection purpose, requiring separate consent unless the retargeting falls within the subscriber's reasonable expectations at the time of data collection. The ePrivacy Directive (EU Cookie Law) further requires that subscribers be informed about and consent to the use of their data for cross-platform advertising. California's CPRA includes email retargeting within its definition of "sharing" personal information for cross-context behavioural advertising, triggering opt-out rights and disclosure obligations. According to a 2025 IAB Europe survey, 38 per cent of advertisers restricted email retargeting activities in response to GDPR enforcement actions.
Best Practices
Obtain explicit consent from subscribers before using their email addresses for ad retargeting purposes, separate from the consent collected for email marketing. Include a specific checkbox or toggle in your subscription preference centre labelled something like "Use my email to show relevant ads on social media and search engines." Do not rely on a general marketing consent to cover retargeting uses.
Hash email addresses client-side before uploading to ad platforms to minimise the risk of exposing raw subscriber data to third-party advertising systems. Use SHA-256 hashing with consistent lowercasing and whitespace removal as specified by each platform's requirements. Verify your hashing implementation produces correct outputs using the platform's test tools before uploading production audiences.
Segment your retargeting audiences by recency, purchase behaviour, and engagement level to avoid wasting ad spend on subscribers who are unlikely to convert. Build separate audiences for recent purchasers (retarget with complementary products), cart abandoners (retarget with incentive offers), engaged non-purchasers (retarget with social proof and testimonials), and disengaged subscribers (retarget with re-engagement messaging rather than acquisition-focused ads).
Respect subscriber consent revocation comprehensively — when a subscriber withdraws consent for retargeting, remove them from all ad platform custom audiences within 24 hours. Implement automated synchronisation between your consent management platform and ad platform audience lists to ensure that opt-outs propagate across all channels. Retaining a revoked subscriber in a retargeting audience constitutes a data protection violation in most jurisdictions.
Monitor the overlap between your email retargeting audiences and your organic social media following to avoid serving redundant advertising to users who already follow your brand. Exclude current followers from retargeting campaigns to reduce frequency and improve return on ad spend. Track frequency caps across both email and paid channels to prevent over-exposure to the same subscriber across touchpoints.
Related Glossary Terms
Email CASL
Canada's Anti-Spam Legislation requirements for commercial electronic messages, including consent types, record-keeping, and penalties up to $10 million per violation.
Email CCPA
California Consumer Privacy Act requirements for email marketing, including consumer rights to access, delete, and opt out of data collection and sale.
Email Consent Record
Email consent record-keeping captures proof of opt-in including timestamp, IP address, method, and exact wording shown. GDPR requires controllers to demonstrate consent upon request.
Email Data Portability
Data portability under GDPR Article 20 gives subscribers the right to receive their email marketing data in a machine-readable format and transfer it to another provider. Common export formats are CSV and JSON.
Email Data Retention
Email data retention policies govern how long subscriber data, activity logs, consent records, and campaign data are kept. GDPR requires data not be kept longer than necessary for the processing purpose.
Email Right to Erasure
Right to erasure under GDPR Article 17 allows subscribers to request deletion of their personal data. Email marketers must process requests within 30 days and manage suppression list interactions carefully.
Frequently Asked Questions
Email retargeting is lawful under GDPR only if you have a valid legal basis — typically consent — for processing subscriber data specifically for advertising purposes. Consent must be specific, informed, and withdrawable. Relying on legitimate interest for email retargeting is high-risk and has been rejected by several European data protection authorities.
Facebook Custom Audiences require a minimum of 200 matched users before the audience can be used for ad targeting. Google Customer Match requires 1,000 matched users. LinkedIn Matched Audiences require 300 matched users. Audiences below these thresholds cannot be activated for advertising.
Hashing converts the email address into an irreversible fixed-length string using algorithms such as SHA-256. Ad platforms match the hashed values without ever seeing the original email address. However, hashing is not anonymisation because email addresses can be re-identified through dictionary attacks if the hash is reversed against known email lists.
Email retargeting uses email subscriber lists specifically, while CRM retargeting uses the full customer database which may include postal addresses, phone numbers, and offline identifiers. Both operate on the same principle of matching first-party data to ad platform user accounts through hashed identifiers.
Unsubscribing from email marketing does not necessarily revoke consent for ad retargeting, but best practice is to treat an unsubscribe as a signal to remove the subscriber from retargeting audiences. Continuing to serve ads to unsubscribed contacts undermines trust and may violate the spirit of the subscriber's opt-out request.