Definition
The General Data Protection Regulation (GDPR) is a European Union regulation that came into effect on May 25, 2018. It governs how organisations handle the personal data of EU residents, including email addresses, names, and engagement data. GDPR applies to any organisation that processes the data of EU residents, regardless of where the organisation is based.
For email marketers, GDPR fundamentally changed how subscriber data is collected, stored, and used. It introduced strict consent requirements, expanded data subject rights, and imposed significant penalties for non-compliance. Fines can reach the higher of €20 million or 4% of annual global turnover.
Key GDPR Requirements for Email Marketing
| Requirement | Description |
|---|---|
| Lawful basis for processing | Must have consent, legitimate interest, or another lawful basis |
| Explicit consent | Consent must be freely given, specific, informed, and unambiguous |
| Right to erasure | Subscribers can request deletion of their data at any time |
| Data portability | Subscribers can request a copy of their data in a portable format |
| Record keeping | Document what data you collect, why, and how you process it |
| Privacy notice | Clear disclosure of data collection and processing at the point of collection |
How GDPR Affects Email Marketing Practices
- Consent must be explicit: Pre-checked boxes are not valid under GDPR. Consent must be given through a clear affirmative action, such as ticking an unchecked box or clicking a confirmation link. Passive consent (e.g. "by continuing you agree") is not sufficient.
- Double opt-in is strongly recommended: While not explicitly required, double opt-in provides clear evidence of consent. If questioned by a regulator, the confirmation email and timestamp prove the subscriber actively agreed.
- Unsubscribe must include data deletion: When a subscriber unsubscribes, they may also request deletion of all their personal data under the right to erasure. Simply suppressing them from future sends is not enough — you must delete their data unless you have a legal obligation to retain it.
- Legitimate interest is limited: You can rely on legitimate interest for direct marketing, but it must be balanced against the individual's rights. The ICO and other regulators take a narrow view of legitimate interest for email marketing. Consent is safer for most commercial email.
- Privacy notice at point of collection: The signup form must include a link to your privacy notice that explains what data you collect, how you use it, who you share it with, and how long you retain it. This notice must be in clear, plain language.
Penalties for Non-Compliance
GDPR violations are tiered. Lower-level violations (such as inadequate record-keeping) can result in fines up to €10 million or 2% of annual global turnover. More serious violations (such as processing data without a lawful basis) can result in fines up to €20 million or 4% of annual global turnover, whichever is higher. In addition to fines, regulators can issue bans on data processing, which would effectively end email marketing operations.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
Abuse Complaint
An abuse complaint is a report from a recipient who marks an email as spam, which negatively affects sender reputation and deliverability.
AI Email Summary
An AI email summary is a short, machine-generated overview of an email's key points, shown by Gmail, Outlook and Apple Mail before a recipient opens the message. It is reshaping how email marketers think about subject lines, preview text and open rates.
AI Inbox
An AI inbox is an email client that uses artificial intelligence to summarise, sort, prioritise and sometimes answer emails before the human recipient reads them. It is transforming email marketing metrics and copywriting.
AIDA Model for Email
The AIDA model (Attention, Interest, Desire, Action) is a classic copywriting framework used to structure email campaigns that guide subscribers from awareness to conversion.
Frequently Asked Questions
Yes. GDPR applies to any organisation that processes the personal data of EU residents, regardless of where the organisation is located. If you have EU subscribers on your email list, GDPR applies to how you handle their data. Many non-EU businesses have found it simpler to apply GDPR standards to all subscribers rather than maintaining separate compliance regimes.
Consent requires a clear affirmative action from the subscriber agreeing to receive marketing emails. Legitimate interest allows you to send marketing emails without explicit consent if you have an existing relationship and the recipient would reasonably expect to hear from you. However, the bar for legitimate interest is high, and the recipient can object at any time, after which you must stop processing their data.
GDPR does not specify a fixed retention period, but consent records should be kept as long as you are actively processing the data based on that consent. Once consent is withdrawn or the data is no longer needed, you should delete it. Many email marketers retain consent records for the duration of the subscriber's active engagement plus a reasonable period after unsubscribing (typically 6-12 months) to handle disputes.
Yes. Re-permission campaigns are common and generally accepted by regulators, provided the original consent was obtained under GDPR-compliant practices. Sending a single re-permission email to existing subscribers asking them to confirm their consent is considered a legitimate use of their data. If they do not reconfirm, you should delete their data.
A DPIA is a process required under GDPR for processing activities that are likely to result in high risk to individuals' rights and freedoms. For email marketing, a DPIA may be required if you process data at scale, use automated decision-making, or track behaviour across multiple services. Most standard email marketing operations do not require a full DPIA, but larger-scale operations should assess whether one is needed.