Definition
The General Data Protection Regulation (GDPR) is a European Union regulation that came into effect on May 25, 2018. It governs how organisations handle the personal data of EU residents, including email addresses, names, and engagement data. GDPR applies to any organisation that processes the data of EU residents, regardless of where the organisation is based.
For email marketers, GDPR fundamentally changed how subscriber data is collected, stored, and used. It introduced strict consent requirements, expanded data subject rights, and imposed significant penalties for non-compliance. Fines can reach the higher of €20 million or 4% of annual global turnover.
Key GDPR Requirements for Email Marketing
| Requirement | Description |
|---|---|
| Lawful basis for processing | Must have consent, legitimate interest, or another lawful basis |
| Explicit consent | Consent must be freely given, specific, informed, and unambiguous |
| Right to erasure | Subscribers can request deletion of their data at any time |
| Data portability | Subscribers can request a copy of their data in a portable format |
| Record keeping | Document what data you collect, why, and how you process it |
| Privacy notice | Clear disclosure of data collection and processing at the point of collection |
How GDPR Affects Email Marketing Practices
- Consent must be explicit: Pre-checked boxes are not valid under GDPR. Consent must be given through a clear affirmative action, such as ticking an unchecked box or clicking a confirmation link. Passive consent (e.g. "by continuing you agree") is not sufficient.
- Double opt-in is strongly recommended: While not explicitly required, double opt-in provides clear evidence of consent. If questioned by a regulator, the confirmation email and timestamp prove the subscriber actively agreed.
- Unsubscribe must include data deletion: When a subscriber unsubscribes, they may also request deletion of all their personal data under the right to erasure. Simply suppressing them from future sends is not enough — you must delete their data unless you have a legal obligation to retain it.
- Legitimate interest is limited: You can rely on legitimate interest for direct marketing, but it must be balanced against the individual's rights. The ICO and other regulators take a narrow view of legitimate interest for email marketing. Consent is safer for most commercial email.
- Privacy notice at point of collection: The signup form must include a link to your privacy notice that explains what data you collect, how you use it, who you share it with, and how long you retain it. This notice must be in clear, plain language.
Penalties for Non-Compliance
GDPR violations are tiered. Lower-level violations (such as inadequate record-keeping) can result in fines up to €10 million or 2% of annual global turnover. More serious violations (such as processing data without a lawful basis) can result in fines up to €20 million or 4% of annual global turnover, whichever is higher. In addition to fines, regulators can issue bans on data processing, which would effectively end email marketing operations.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
AMP for Email
AMP for Email is a Google-developed framework that allows email messages to include interactive elements like forms, carousels, accordions, and live content. It turns static emails into dynamic, interactive experiences directly inside the inbox.
CAN-SPAM Act
The CAN-SPAM Act is a US law that sets rules for commercial email. It requires accurate subject lines, a physical address, a clear opt-out mechanism, and prompt processing of unsubscribes. Violations can result in penalties up to $51,744 per email.
Click-Through Rate
Click-through rate (CTR) is the percentage of email recipients who clicked one or more links in your email campaign. It measures how compelling your content and call-to-action are.
Click-to-Convert Rate
Click-to-convert rate measures the percentage of email clicks that result in a desired conversion action such as a purchase, signup, or download. It shows how effective your post-click experience is at turning interest into results.
Frequently Asked Questions
Yes. GDPR applies to any organisation that processes the personal data of EU residents, regardless of where the organisation is located. If you have EU subscribers on your email list, GDPR applies to how you handle their data. Many non-EU businesses have found it simpler to apply GDPR standards to all subscribers rather than maintaining separate compliance regimes.
Consent requires a clear affirmative action from the subscriber agreeing to receive marketing emails. Legitimate interest allows you to send marketing emails without explicit consent if you have an existing relationship and the recipient would reasonably expect to hear from you. However, the bar for legitimate interest is high, and the recipient can object at any time, after which you must stop processing their data.
GDPR does not specify a fixed retention period, but consent records should be kept as long as you are actively processing the data based on that consent. Once consent is withdrawn or the data is no longer needed, you should delete it. Many email marketers retain consent records for the duration of the subscriber's active engagement plus a reasonable period after unsubscribing (typically 6-12 months) to handle disputes.
Yes. Re-permission campaigns are common and generally accepted by regulators, provided the original consent was obtained under GDPR-compliant practices. Sending a single re-permission email to existing subscribers asking them to confirm their consent is considered a legitimate use of their data. If they do not reconfirm, you should delete their data.
A DPIA is a process required under GDPR for processing activities that are likely to result in high risk to individuals' rights and freedoms. For email marketing, a DPIA may be required if you process data at scale, use automated decision-making, or track behaviour across multiple services. Most standard email marketing operations do not require a full DPIA, but larger-scale operations should assess whether one is needed.