GDPR for Emails: Rules for Marketing and Business Email
A practical guide to GDPR for emails: legal bases, consent rules, unsubscribe requirements, retention limits, and how to handle email data requests.
Email is where most small businesses first bump into the General Data Protection Regulation (GDPR), and GDPR for emails covers far more than the newsletter signup box. Every address in your CRM, every mailing list export, and every message sitting in a shared inbox is personal data subject to the same rules that govern the rest of your systems. This guide covers the legal bases, consent standards, retention limits, and practical controls you need, though you should consult a qualified attorney for advice specific to your situation.
Why GDPR for Emails Applies to Almost Every Business
The GDPR applies to any organization that processes personal data of people in the EU or the European Economic Area, regardless of where the organization is based (Article 3). If a US-based agency emails a prospect in Berlin, the regulation applies to that message and to the record behind it.
An email address is personal data whenever it can identify a natural person, directly or indirectly. Article 4(1) defines personal data as any information relating to an identified or identifiable natural person. That definition catches:
- Named addresses like
[email protected], including work addresses. - Personal addresses at consumer providers such as Gmail, Outlook, or Proton.
- Addresses combined with any other identifier, including an IP address or a customer number.
- Email metadata such as open times, click history, device, and approximate location.
Generic role addresses like info@, sales@, or support@ are generally not personal data on their own. They stop being anonymous the moment your records tie them to a specific person, which happens more often than teams expect.
The financial exposure is real. Article 83 sets maximum fines at 20 million EUR or 4% of global annual turnover, whichever is higher, for the most serious infringements, including breaches of the lawfulness and consent rules that govern email.
Choosing a Lawful Basis for Every Email You Send
You cannot process personal data without a lawful basis under Article 6(1). For email programs, three bases do almost all the work, and picking the wrong one is one of the most common compliance failures.
| Email type | Typical lawful basis | Key condition |
|---|---|---|
| Newsletter, promotions | Consent, Article 6(1)(a) | Freely given, specific, informed, unambiguous opt-in |
| Order confirmations, shipping, password resets | Contract, Article 6(1)(b) | Necessary to perform the contract with that person |
| Existing-customer upsell of similar products | Legitimate interests, Article 6(1)(f), plus ePrivacy soft opt-in | Balancing test documented, opt-out in every message |
| Security notices, breach notifications | Legal obligation, Article 6(1)(c) | Required by law, such as Article 34 breach notice |
Two rules keep teams out of trouble. First, you must decide the basis before you send, not after a complaint arrives. Second, you cannot switch bases when the first one fails: if consent is withdrawn, you cannot fall back on legitimate interests to keep mailing the same person.
Transactional vs Marketing Email
Transactional emails serve the contract. A receipt, a shipping update, a password reset, or a service outage notice runs on Article 6(1)(b) and does not need marketing consent. The moment you add a promotional block to that receipt, the message becomes marketing in the eyes of most regulators and needs a marketing basis.
Keep the two streams separate at the platform level. Mixing them means an unsubscribe from your newsletter can accidentally suppress an order confirmation, which creates its own contractual problems.
GDPR Email Consent: What a Valid Opt-In Looks Like
Article 4(11) defines consent as a freely given, specific, informed, and unambiguous indication of the person's wishes, given by a statement or clear affirmative action. Article 7 adds the operational requirements that trip up most signup forms.
A valid email opt-in must be:
- Unbundled. Consent to marketing cannot be a condition of buying a product or downloading a resource, unless the email is genuinely what you are delivering.
- Granular. If you send a weekly newsletter and partner offers, ask separately. One checkbox cannot cover unrelated purposes.
- Active. Pre-ticked boxes are invalid. The Court of Justice of the European Union confirmed this in the Planet49 ruling (C-673/17, October 2019).
- Named. Tell people who the controller is, and name any third parties who will also use the address.
- Withdrawable. Article 7(3) requires that withdrawing consent is as easy as giving it.
- Documented. Article 7(1) requires you to demonstrate that consent was given.
Your consent records should store the timestamp, the IP address or form source, the exact wording shown at signup, and the version of the privacy policy in force at that moment. Without those fields you have no defense when a regulator asks how a specific address entered your list.
Double Opt-In and the Soft Opt-In
Double opt-in, where the subscriber confirms via a verification email, is not mandated by the GDPR text. It is the cleanest way to satisfy Article 7(1) and to prevent someone from signing up an address they do not own. German and Austrian authorities treat it as the practical standard.
The soft opt-in comes from the ePrivacy Directive (Article 13(2)) rather than the GDPR itself. It allows you to email existing customers about your own similar products where you obtained the address in the context of a sale and gave a clear opt-out at that point and in every subsequent message. National implementations differ, so verify the rule in each country you mail into.
Unsubscribe Requirements Under GDPR and ePrivacy
Every marketing email must give the recipient a simple way to stop receiving them. The requirement comes from Article 7(3) of the GDPR combined with Article 13 of the ePrivacy Directive, and enforcement here is frequent because complaints are easy to file.
Practical requirements to meet:
- Include a working unsubscribe link in every marketing message.
- Process the opt-out promptly. Many regulators expect it within a few days, and 72 hours is a defensible internal target.
- Never require login, account creation, or a phone call to unsubscribe.
- Do not ask people to state a reason before you honor the request. You may ask after.
- Support one-click unsubscribe headers (RFC 8058), which Gmail and Yahoo now require for bulk senders.
Suppression is not the same as erasure. When someone unsubscribes, you keep a suppression record so they are not re-added. When someone requests erasure under Article 17, you delete their profile and retain only the minimum needed to honor the suppression, usually a hashed address.
Retention: How Long You Can Keep Email Data
Article 5(1)(e), the storage limitation principle, requires that personal data is kept in identifiable form no longer than necessary for the purposes it was collected for. The GDPR gives no numbers, so you must set and document your own schedule.
Common retention practices that hold up in practice:
- Marketing subscribers: delete or re-permission after 18 to 24 months of no opens or clicks.
- Unsuccessful leads: 12 months from last contact, unless the person re-engages.
- Transactional records: driven by tax and contract law, commonly six to 10 years depending on the member state.
- Suppression lists: indefinite, but hashed and used only to prevent re-contact.
- Email engagement analytics: aggregate or delete open and click data after 12 months.
The CNIL, France's data protection authority, has published guidance recommending a three-year limit from last contact for prospect data, which is a useful benchmark even outside France. Write your schedule into your privacy policy so subscribers can see it, and configure automatic deletion in your email platform rather than relying on someone remembering to run a cleanup.
Third-Party Tools, Processors, and International Transfers
Your email service provider, CRM, and analytics tools all process personal data on your behalf. Article 28 requires a written data processing agreement with each of them, covering the subject matter, duration, nature and purpose of processing, and the processor's security obligations.
Steps to get this right:
- Inventory every tool that touches email data. Include the newsletter platform, CRM, helpdesk, webinar tool, and any lead-capture form service.
- Sign a DPA with each one. Most major providers publish a standard DPA you can accept in your account settings.
- Check where data is stored. Transfers outside the EEA need a mechanism under Chapter V, most commonly Standard Contractual Clauses or, for US providers, certification under the EU-US Data Privacy Framework.
- List categories of recipients in your privacy policy. Article 13(1)(e) requires you to disclose who receives the data.
- Review sub-processors. Your provider's own vendors process your subscribers' data too.
If you scan your site regularly, form-capture scripts and tracking pixels from these tools show up alongside cookies, which makes it easier to keep your disclosures accurate. TermsBox runs that scan and updates the hosted privacy policy for subscribers when new third-party services appear.
Handling Data Subject Requests About Email
Subscribers have rights over the data you hold about them, and email is often the first place they exercise them. Chapter III of the GDPR gives you one month to respond under Article 12(3), extendable by two further months for complex requests if you tell the person within the first month.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowThe requests you will see most often for email data:
- Access (Article 15): provide a copy of the address, signup source and date, consent record, segment membership, and engagement history.
- Rectification (Article 16): correct a wrong address or profile field.
- Erasure (Article 17): delete the record, and instruct your processors to do the same.
- Restriction (Article 18): pause processing while a dispute over accuracy or lawful basis is resolved.
- Portability (Article 20): supply the data the person provided in a structured, commonly used, machine-readable format such as CSV or JSON.
- Objection (Article 21(2)): an absolute right to stop direct marketing, with no balancing test available to you.
Note that objection to direct marketing is unconditional. There is no scenario where you can keep marketing to someone who has objected, which is why suppression must survive list imports and platform migrations.
Security Obligations for Email Under Article 32
Article 32 requires appropriate technical and organizational measures for the data you hold. Email creates specific exposure because addresses move between systems and people constantly.
Controls worth implementing:
- Use BCC or a mailing platform for group sends. Exposing an entire list in the To field is one of the most fined mistakes in email compliance.
- Encrypt in transit. Enforce TLS on your mail servers and enable MTA-STS where your provider supports it.
- Restrict export rights. Limit who can download list CSVs, and log every export.
- Enable multi-factor authentication on the email platform, the CRM, and the shared inbox.
- Purge old exports. Subscriber CSVs sitting in a shared drive are a breach waiting to happen.
A misdirected email that reveals other recipients is a personal data breach. If it poses a risk to individuals, Article 33 requires notification to your supervisory authority within 72 hours of becoming aware, and Article 34 requires you to tell the affected people if the risk is high. The UK ICO has issued multiple fines for exactly this failure, including cases involving HIV clinics and support groups where the exposed list revealed sensitive information.
What to Disclose in Your Privacy Policy About Email
Articles 13 and 14 set out what you must tell people when you collect their data. For email programs, your privacy policy needs to cover:
- The identity and contact details of the controller, and of the data protection officer if you have one.
- The purposes of processing: newsletters, product updates, transactional messages, and behavioral segmentation if you do it.
- The lawful basis for each purpose, including the legitimate interests you rely on where relevant.
- Categories of recipients, meaning your email platform, CRM, and analytics vendors.
- Any transfer outside the EEA and the safeguard you rely on.
- The retention period or the criteria used to set it.
- The full list of data subject rights, including the right to withdraw consent and to complain to a supervisory authority.
Article 14 adds a duty when you did not collect the address from the person directly, such as through a partner list or a data provider. You must tell them within a reasonable period, at the latest one month, and disclose the source of the address. Meeting this requirement is what makes purchased lists so difficult to use lawfully.
Tracking pixels in emails need attention too. They read information from the recipient's device, which brings them under Article 5(3) of the ePrivacy Directive, and several regulators expect consent for open tracking. Disclose the practice in both your privacy policy and your cookie policy if you use it. If you need to build or refresh those documents, a privacy policy generator that covers GDPR disclosure requirements is faster than drafting from scratch, and the broader GDPR compliance rules apply to the rest of your stack as well.
A Practical GDPR Email Compliance Audit
Work through this list once, then repeat it quarterly or whenever you change email tools.
- Map your lists. Document every list, its source, and the lawful basis for each.
- Check your signup forms. No pre-ticked boxes, no bundled consent, clear purpose text, and a link to the privacy policy.
- Verify consent records exist. If you cannot produce a timestamp and source for an address, treat it as unverified.
- Re-permission or drop unverified addresses. A single re-permission campaign is safer than continuing to mail people you cannot account for.
- Test unsubscribe end to end. Click the link in a real send and confirm suppression propagates to every system.
- Confirm DPAs are in place with every processor, and check transfer mechanisms for non-EEA vendors.
- Set retention rules in the platform rather than in a document nobody enforces.
- Run a subject access request against yourself to see how long it actually takes to gather the data.
- Review who can export lists and remove access that is no longer needed.
- Update the privacy policy to match what you actually do, not what you intended to do.
The audit that finds the most problems is usually step four. Lists imported from an old platform, collected at a trade show, or inherited from an acquisition rarely carry usable consent records, and mailing them is where enforcement tends to start.
Frequently Asked Questions
Are email addresses considered personal data under GDPR?
Yes. An email address that identifies a person, including work addresses like [email protected], is personal data under Article 4(1) of the GDPR. Generic role addresses such as [email protected] are usually not personal data, though they can become so if they are linked to a named individual.
Do I always need consent to send marketing emails under GDPR?
No. Consent under Article 6(1)(a) is the most common basis, but the ePrivacy Directive also allows the soft opt-in: you may email existing customers about similar products if you collected the address during a sale and offered an opt-out at that point and in every message. B2B rules vary by country, so check the national implementation where your recipients are located.
How long can I keep email addresses under GDPR?
The GDPR sets no fixed period. Article 5(1)(e) requires you to keep personal data only as long as needed for the purpose you collected it for, so you must define and document your own retention period. Many organizations remove inactive marketing subscribers after 18 to 24 months and keep transactional email records only as long as tax or contract law requires.
Does GDPR require a double opt-in for newsletters?
No, double opt-in is not required by the text of the GDPR. It is a strong way to satisfy the Article 7(1) requirement that you can demonstrate consent, and regulators in Germany and Austria have effectively treated it as the expected standard. A single opt-in with reliable logging of time, source, and wording can also be defensible.
What happens to my email list if someone requests erasure?
Under Article 17 you must delete their data, usually within one month, and you should also tell any processors such as your email platform to delete it. You may keep a minimal suppression record, typically a hashed email address, to make sure you do not accidentally re-add them, which regulators accept as a legitimate interest under Article 6(1)(f).
Can I email people whose addresses I found on LinkedIn or a company website?
Scraping addresses and cold emailing them is high risk under the GDPR because you have no consent and must still satisfy the Article 14 duty to tell people where you got their data, normally within one month. Some countries allow B2B cold email under legitimate interests, but the CNIL and other regulators have fined companies for buying and using lists without a valid basis.